Privacy Policy

Last updated: September 16, 2026

SnapMuse ("SnapMuse", "we", "us", or "our"), accessible via https://snapmuse.app and operated by SnapMuse Team, is a bookmark and note assistant that helps video creators organize public inspiration and generate AI-assisted scripts. This Privacy Policy explains what data we collect, how we use it, where it is processed, and your rights. We designed SnapMuse to be privacy-first: we collect the minimum data required to provide the service, strictly avoid downloading or storing any audio or video bytes, and never sell your personal data.

1. Information We Collect

We only collect information that is strictly necessary to provide the service. Specifically:

  • Account information: when you sign in with Google, we receive your email address, display name, profile picture URL, and Google account identifier (the "sub" claim). We do not receive or store your Google password.
  • Public video metadata you choose to save: objective, factual metadata of publicly accessible videos, such as video title, text tags/hashtags, view/like/comment/favorite/share counts, background music (BGM) title, publish date, platform name, and public video URL.
  • User-created notes and context: boards, custom tags, and creative notes you create or input to organize your inspiration cards.
  • Usage and billing data: subscription plan tier, quota usage counters (AI script generation credits), and transaction records processed by our payment provider (we do not store full payment card numbers).
  • Technical data: coarse country/region derived from your IP address (used solely for AI regional compliance routing), language preference, and secure session tokens.

2. Information We Do NOT Collect

To respect third-party privacy and strictly comply with platform terms, SnapMuse limits collection to objective, public metadata. We explicitly do NOT collect:

  • Any audio or video file bytes — neither our browser extension nor our servers download, capture, stream, record, cache, or store audio or video media files.
  • Private or personal data of third parties appearing in videos, including private messages, private accounts, or comment content.
  • Media thumbnails and portrait images are not stored in our database. Cover images are loaded on demand directly by your browser from the respective platform CDN.
  • We never sell, rent, or trade your personal information to advertisers, data brokers, or any third parties.

3. How We Use Your Information

  • To authenticate your identity and maintain your account and inspiration boards.
  • To provide core features: saving inspiration cards, organizing boards, and generating AI-assisted analysis and remix scripts based on public metadata.
  • To enforce usage quotas and process subscriptions and billing.
  • To send essential service, security, and account-related communications.
  • To maintain security, prevent unauthorized abuse, and comply with applicable legal obligations.

4. AI Processing and Cross-Border Data Transfers

In line with GDPR Article 44, we disclose our AI data-processing chain transparently. When you request an AI script generation, only the relevant textual data (video public metadata and your optional creative notes) is transmitted to AI models through the OpenRouter gateway to return structured text.

We route data based on regional compliance standards: requests from users in the US, EU, and Western jurisdictions are processed by models hosted on US/EU infrastructure (e.g., GPT-4o-mini); requests from Asia-Pacific users may be processed by DeepSeek V3. EU/EEA user data is never transferred directly to servers in mainland China. For EU/EEA users, we prioritize processing options with EU data residency where available.

Administrative access to systems handling EU/EEA data is restricted, encrypted, and limited to technical maintenance and customer support.

5. Third-Party Services

We rely on trusted third-party service providers to deliver the service, each governed by its respective privacy policy:

  • Google (Sign-In / OAuth) — user authentication and account login.
  • OpenRouter and underlying model providers (e.g., OpenAI, DeepSeek) — AI text analysis and script generation.
  • Creem — subscription billing and payment processing (acting as Merchant of Record).
  • Cloudflare — application hosting, CDN distribution, security protection, and privacy-friendly, cookieless aggregate web analytics.

6. Cookies and Local Storage

We use strictly necessary cookies and browser local storage to maintain your logged-in session, remember your language preference, and persist interface settings. These are essential for the service to function and do not require cookie consent banners under ePrivacy rules.

We use Cloudflare Web Analytics to understand aggregate website usage. It does not use cookies, does not collect personal data, and does not track users across sites. We do not use third-party advertising or cross-site tracking cookies.

7. Data Retention and Deletion

We retain your account data and saved content for as long as your account remains active. When you delete a card, a board, or your entire account, the associated data is deleted from our active databases within thirty (30) days.

Payment transaction records are retained only as required to comply with statutory legal, taxation, and accounting obligations in a pseudonymized format.

8. Data Security

We implement industry-standard technical and organizational security measures to protect your information, including HTTPS/TLS encryption in transit and access-controlled production environments. Social login eliminates the need to store passwords. While no transmission or storage system is 100% secure, we continuously maintain safeguards to protect against unauthorized access.

9. Your Rights

Depending on your jurisdiction (including the EU/EEA under the GDPR and California under the CCPA), you have the right to:

  • Access, inspect, or request a copy of your personal data.
  • Request correction of inaccurate or incomplete personal data.
  • Request deletion of your personal data ("Right to be Forgotten").
  • Export your saved boards and notes in a portable format.
  • Object to or restrict certain processing activities, and withdraw consent at any time.
  • Lodge a complaint with your local data protection supervisory authority.

10. Children's Privacy

SnapMuse is intended for creators and is not directed to individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal information, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Any updates will be published on this page with an updated "Last updated" date. Continued use of SnapMuse after changes take effect constitutes your acknowledgment of the updated policy.

12. Data Controller and Contact

SnapMuse is operated by SnapMuse Team, acting as the Data Controller under applicable data protection laws. For any questions regarding this Privacy Policy or to exercise your privacy rights, please contact us at support@snapmuse.app.

EU/EEA users: under GDPR Article 27(2), given our limited scale and low-risk processing of non-sensitive data, we communicate directly through our contact email. You may direct all data protection inquiries to support@snapmuse.app.