Skip to content
AlgoMuse

Privacy Policy

Last updated: September 29, 2026

How AlgoMuse handles personal data on algomuse.io and in the app at app.algomuse.io.

1. Introduction

This policy explains what personal data we collect when you use AlgoMuse, an AI-powered social media management platform, what we use it for, who we share it with and the choices you have.

AlgoMuse LLC ("AlgoMuse", "we", "us" or "our") is the data controller for the personal data described here. For the content your workspace stores about other people, such as messages from your audience, you are the controller and we process it on your behalf; our Data Processing Addendum covers that.

2. Information we collect

2.1 Information you give us

  • Account information: your name, email address, password (stored only as a hash) and, if you add them, a profile picture and company name.
  • Billing information: for paid plans, card details are entered into and held by our payment provider, Stripe. We never receive full card numbers.
  • Connected accounts: the access tokens and profile information of the social, ad and commerce accounts you connect.
  • Content: posts, images, videos and other material you create, upload or generate, and the messages and comments your connected accounts receive.
  • Communications: messages you send us by email or through our forms.

2.2 Information collected automatically

  • Usage data: the pages and features you use in the app.
  • Device and log data: IP address, browser and operating system, and error logs.

2.3 Information from others

  • Platforms you connect: profile data, posts, analytics and messages from the accounts you connect, as allowed by the permissions you grant.
  • Sign-in providers: if you sign in with Google or GitHub where offered, your name, email address and profile picture from that provider.
  • Your team: a workspace owner or admin who invites you gives us your email address.

3. How we use your information

  • To provide the service: running your account and workspaces, publishing and scheduling your content, and showing your analytics.
  • For AI features: generating and analyzing content when you ask us to.
  • To communicate with you: account, security and billing emails, and replies to your messages.
  • Marketing: our newsletter, only if you subscribe.
  • To improve the product: understanding how the site and app are used.
  • Security and legal compliance: preventing abuse and fraud, and meeting legal obligations.

Legal bases (GDPR)

  • Contract: to provide the service you signed up for.
  • Consent: for the newsletter and for website analytics cookies, which you can withdraw at any time.
  • Legitimate interests: securing and improving the service, balanced against your rights.
  • Legal obligation: where the law requires us to process data, such as keeping billing records.

4. Sharing and subprocessors

We do not sell your personal data. We share it only as described below.

4.1 Where the service runs

The AlgoMuse application, its PostgreSQL database, Redis cache and S3-compatible file storage run on infrastructure we operate ourselves, not on a public cloud provider. The hosting location is available on request from [email protected].

4.2 Service providers (subprocessors)

These providers process personal data on our behalf, only for the purpose given. Those marked “where enabled” are used only when configured.

  • Network: Cloudflare
  • AI model providers: Ollama (Ollama Cloud), Anthropic (where enabled), OpenAI (where enabled), Google (Gemini API) (where enabled), Together AI (where enabled), Replicate (where enabled), Cohere (where enabled)
  • Email: Fastmail, Resend (where enabled)
  • Billing: Stripe (where enabled)
  • Error monitoring: Sentry (where enabled)
  • Website analytics (algomuse.io, only with your consent): Google Analytics, Microsoft Clarity

When you use an AI feature, the content you submit for that request is sent to the AI provider handling it. Our Subprocessors page lists what each provider does and the data it may process.

4.3 Platforms you connect

When you connect an account, we exchange data with that platform on your instructions: to publish, read engagement and messages, or sync products and ad data. Supported platforms include Facebook, Instagram, Threads, X (Twitter), LinkedIn, TikTok, YouTube, Pinterest, Reddit, Bluesky and Discord; Meta Ads, Google Ads and TikTok Ads; and Shopify, WooCommerce, Magento, PrestaShop, eBay and Etsy. Each platform handles the data it receives under its own privacy policy.

4.4 Your workspace

People you invite to a workspace can see its content according to their role.

4.5 Legal and safety

We may disclose information when the law, a court order or a government request requires it, or when necessary to protect the rights, safety or property of our users, the public or AlgoMuse.

4.6 Business transfers

If AlgoMuse is involved in a merger, acquisition or sale of assets, your information may be transferred as part of it, and we will tell you if that happens.

5. Cookies and analytics

The app uses essential cookies to keep you signed in and to protect forms. On algomuse.io, Google Analytics and Microsoft Clarity load only if you accept them in the cookie banner. Our own analytics (Umami) runs on our infrastructure. The Cookie Policy lists each of them. You can change your choice at any time: .

6. How long we keep it

  • Your account: until you delete it. Deleting your account deletes your user record and signs you out everywhere straight away.
  • Workspace content: belongs to the workspace and is kept until the workspace is deleted. The workspace owner can delete it in its settings, which deletes its content straight away. Deleting your own account does not delete workspaces you own, so delete those first if you want their content gone, or ask us.
  • Ended trials and subscriptions: when a free trial ends unpaid or a subscription ends, the workspace is suspended and nothing is deleted straight away. A workspace still suspended after 6 months is deleted with its content; we email the owner before that happens.
  • Backups: deleted data can remain in our database backups for up to 14 days, after which the backups are deleted.
  • Audit logs: 365 days.
  • Sign-in sessions: expire after 7 days without use, and at most 30 days after sign-in.
  • Billing records: as long as tax and accounting law requires.
  • Emails to us: as long as needed to deal with them.

7. Your rights

Depending on where you live, including under the GDPR and UK GDPR, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data deleted;
  • restrict or object to how we use it, including for marketing;
  • receive your data in a portable, machine-readable format;
  • withdraw consent where we rely on it;
  • complain to your data protection authority.

To exercise any of these rights, email [email protected]. We may need to confirm your identity first, and we will reply within one month. In the EU, you can find your data protection authority on the EDPB website.

California residents

You have the right to know what personal information we collect, to have it deleted and corrected, and not to be treated differently for exercising these rights. We do not sell personal information.

8. Security

Measures in place today include:

  • TLS for every connection to the service, and AES-256-GCM encryption of stored credentials such as connected-account tokens and two-factor secrets; passwords are hashed.
  • Role-based permissions in each workspace and optional two-factor sign-in.
  • A tamper-evident log of changes made in workspaces and by our administrators.
  • Nightly database backups, each kept for 14 days.

Our Security page describes these in more detail.

9. International transfers

Several of our subprocessors are based outside the European Economic Area (EEA) and the UK, most of them in the United States (see the Subprocessors page). Where personal data from the EEA or UK reaches them, the transfer relies on an adequacy decision where one applies, or otherwise on the Standard Contractual Clauses in that provider's data processing terms. The location of our own hosting is available on request from [email protected].

10. Children

AlgoMuse is not intended for anyone under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, email [email protected] and we will delete it.

11. Changes to this policy

We will post any change on this page and update the date at the top. If a change is significant, we will also tell you by email or in the app.

12. Contact

Questions or requests about this policy or your data go to our privacy address.

Privacy contact