Legal
Privacy policy
What Muzeum actually collects during the founding beta, in plain language.
Version 1.1 · Effective August 5, 2026
What this policy covers
Muzeum (the "Service") is a cinematic portfolio and client-presentation builder in founding beta. A deployment may offer only the public demo or may enable creator accounts, private uploads, publishing, inquiries, and review links behind rollout controls. There are no payments. This policy covers those implemented founding-beta workflows and identifies where provider configuration changes availability.
What we collect today
Contact and interest forms. When you use the contact form or the beta application form, we receive what you type in — typically your name, email address, and your message or answers. We use those details to reply and to send founding-beta updates you asked for.
Creator accounts and work. If creator access is enabled, we store your authenticated account identifier, verified email, profile, handle, workspace and membership records, onboarding answers, project and room drafts, revisions, artwork metadata, private inventory fields, upload status, and published manifests. Uploaded originals and derivatives remain private unless an authorized publishing or review route serves a specific derivative.
Creator inquiries and private reviews. If you submit an inquiry or review response, we store the name and email you provide, your message or decision, the relevant world/version/artwork and optional timestamp, consent/reference data, and delivery status. That record is visible only to the intended creator and authorized workspace editors. The creator's delivery email is not placed in the public page or manifest.
Abuse prevention. Public inquiry and review forms use human verification and rate limits. We process request information such as IP address and user agent for those checks. Inquiry abuse identifiers stored in the database are secret-keyed hashes rather than raw IP addresses.
Error reports. If something breaks, our error-reporting tool captures technical details such as the error message, the page it happened on, and browser and device information, so we can fix the problem.
Product analytics, optional and off by default. The Service can run product analytics (page views and interaction events), but it is disabled unless explicitly turned on for a given environment. When it is off, no analytics events are sent.
What stays in your browser
The guest Studio sandbox and recovery layer save scene choices and recovery drafts in browser storage on your device. Clearing site data removes those local copies. If you explicitly claim a guest draft into an authenticated account, or use cloud save while signed in, the selected draft is also sent to the private creator database.
Services that process data for us
Vercel hosts and serves the Service, which involves standard server request logs. Supabase provides authentication and private database storage. Cloudflare R2 stores creator media, Turnstile performs human verification, and Upstash Redis enforces short-lived rate limits when those workflows are enabled. Inngest coordinates retryable background work. Resend delivers form, inquiry, and review emails when configured. Sentry receives error reports. PostHog receives privacy-limited analytics events only when analytics is enabled. Amazon S3 serves public sample media collections shown in the demo.
We share data with these providers only so they can run the Service on our behalf, and only the data each one needs for its job.
What we do not do
We do not sell personal information. We do not run advertising trackers. We do not share your details with data brokers. The Service holds very little data today, and we intend to keep it that way.
How long we keep things
General contact and interest submissions are kept as long as needed to reply and run the founding beta, then deleted. Creator inquiry settings include a 30-day to seven-year retention choice, but automated retention enforcement remains a deployment gate; ask us or the receiving creator to delete an inquiry sooner. Review records remain with the creator's private project until the link or project data is deleted. Error reports and analytics expire under the configured provider retention windows.
Your choices
You can ask what we hold about you, ask us to correct it, export creator inbox records where that control is available, or ask us to delete data—the fastest route is the contact form. You can remove guest Studio data by clearing browser site data. Account-wide export and deletion are closed-beta security gates and must not be represented as self-service until those controls ship.
Changes to this policy
This is a founding-beta policy, written to match what the product actually does today. Before we launch paid plans it will be expanded and reviewed by counsel, and the version number and effective date at the top of this page will change. Material changes will be flagged here.
Questions? Reach us through the contact form. See also our terms of service, acceptable use policy, and copyright policy.
