Privacy Policy
What MuseLovin stores, why, and what we promise never to do with it. Effective date: to be set on legal sign-off.
1. What we collect and why
MuseLovin is an identity service, so it necessarily handles identifiers. Here is everything we store, and why:
- Developer email — to identify your developer account and contact you about the service.
- Signup and request IP addresses — stored with app registrations and pairing sessions, used only for rate limiting and abuse prevention (for example, 3 signups per hour per address).
- App metadata — your app’s name, requested scopes, verification status, and timestamps. Displayed back to humans on pairing consent screens.
- Agent identifiers — each paired agent gets an opaque, random UUID. We also store the display name and platform the agent reports about itself when it redeems a pairing code (for example, a name like “Proto” and a platform like “muse”). We do not collect anything about the human behind the agent.
- Pairing codes and secrets — short-lived pairing codes (10-minute expiry, single use) and hashes of poll secrets. Raw secrets are never stored — hashes only.
- Token metadata — hashes of API keys and agent bearer tokens, plus creation, last-used, and revocation timestamps and the scopes each token carries. Used to verify requests and detect abuse.
- Message bodies — the content your app sends through the message pipe, kept only as long as the retention schedule requires (see “Data retention” below).
2. How the message pipe handles your data
The message pipe is a pull system with at-least-once delivery: your app queues a message, the agent fetches pending messages at the start of its turn, then explicitly acknowledges them. A message stays queued until it is fetched and acknowledged, so a lost network response never loses a message.
We don’t keep messages forever. An acknowledged message is deleted 30 days after the agent acknowledges it; a message that is never acknowledged expires 30 days after your app sent it — undelivered means undeliverable, so there’s nothing to wait for. A daily automatic cleanup job deletes both. We do not use message content for anything other than delivering it to the paired agent that it was addressed to. See “Data retention” below for the full schedule.
Messages are strictly scoped to the (agent, app) pair: a token minted for one app can never see another app’s messages. The pipe requires the human-approved message scope — identity-only pairings cannot send or receive messages.
3. What we explicitly do not do
- No advertising use. We never use agent data, message content, or developer data for advertising, ad targeting, or ad measurement.
- No sale of personal data. We do not sell, rent, or trade your email, your app’s data, or any agent data to third parties.
- No tracking. The MuseLovin website sets no tracking cookies and runs no analytics or ad pixels.
- No human profiling. Agent IDs are opaque and not linked to any human identity on our side.
4. Cookies and hosting
We set no cookies of our own. The service is hosted on Vercel with a Postgres database on Neon; their infrastructure necessarily processes standard server logs (such as request timestamps and IP addresses) to operate the service. We do not add any tracking on top of that.
5. Data retention
- Pairing codes expire after 10 minutes and are single use. Pairing records — pending, expired, redeemed, or revoked — are deleted 90 days after creation.
- Acknowledged messages are deleted 30 days after the agent acknowledges them.
- Unacknowledged messages expire 30 days after the app sent them.
- Agent tokens live until revoked — re-pairing revokes the previous token automatically.
- Revoked API keys and tokens are retained as hashes so we can recognize and reject them; the raw secrets were never stored.
A daily automatic cleanup job enforces this schedule — nothing above relies on anyone remembering to delete anything.
If you close your developer account, contact us and we will delete your apps, keys, and associated data.
6. Your choices
- Revoke an API key or agent token at any time — it stops working immediately.
- Ask us to correct or delete your developer data: james@adsnventures.com.
- Humans can end a pairing by re-pairing or asking the developer to revoke the app’s access.
7. Changes to this policy
We will post updates here with a new effective date. If a change materially expands what we collect or how we use it, we will note it plainly at the top of this page.
8. Contact
Privacy questions or deletion requests: james@adsnventures.com.