SelfMuse: AI Photoshoot

PRIVACY POLICY

Effective Date: July 8, 2026
Last Updated: September 3, 2026

Welcome to SelfMuse: AI Photoshoot.

SelfMuse: AI Photoshoot (“SelfMuse,” the “App,” the “Service,” “we,” “us,” or “our”) is an AI-powered portrait and image-generation application. SelfMuse allows users to select and upload photos to generate realistic AI portraits, professional headshots, lifestyle portraits, fashion portraits, social profile images, and other AI-generated visual content.

This Privacy Policy explains how we collect, use, store, disclose, share, transfer, protect, and delete your personal information when you access or use SelfMuse.

By using SelfMuse, you acknowledge that you have read and understood this Privacy Policy. Where applicable law requires consent, including for photo library access, camera access, microphone access, voice input or speech-to-text processing, processing user-uploaded photos, third-party AI processing, third-party login, analytics technologies, attribution and advertising tracking technologies, push notifications, text or voice input content safety checks, sensitive content detection, credit and generation consumption records, or international data transfers, we will obtain your consent before the relevant processing begins.

1. Scope of This Privacy Policy

This Privacy Policy applies to personal information processed through:

This Privacy Policy does not apply to third-party websites, applications, platforms, or services that operate independently under their own privacy policies.

2. Our Core Privacy Principles

SelfMuse processes user-selected photos and related information only to provide the AI photoshoot features requested by the user.

Unless we clearly tell you otherwise and obtain any consent required by law:

We may use aggregated, anonymized, or de-identified technical information to improve service performance, reliability, security, attribution accuracy, and user experience, provided that such information cannot reasonably identify a specific individual.

We may use limited device information, technical information, attribution information, and advertising measurement information as described in this Privacy Policy, subject to App Tracking Transparency permission, consent, opt-out rights, and applicable law.

3. Face Detection, Photo Upload, and Third-Party AI Processing Disclosure

This section specifically explains how SelfMuse processes face-related information, user photos, and third-party AI processing when users select photos, upload photos, and use AI photoshoot features.

3.1 Does SelfMuse Collect Face Data?

When you choose to use SelfMuse’s AI photoshoot features, you may select photos that contain a human face.

Before upload or generation, SelfMuse may perform a temporary face check on the photos you select to determine whether the photos meet the basic requirements for the Service.

This check may include:

SelfMuse does not use this check to create an identity profile about you or to identify your real identity.

SelfMuse does not create, store, or use facial templates, facial recognition profiles, facial databases, or biometric identity profiles for identity recognition.

3.2 Where Does Face Detection Take Place?

SelfMuse performs face detection only to determine whether selected photos meet upload and usage requirements.

The face detection process does not upload face detection data to our servers, does not send face detection data to third parties, and does not use face detection data for any other purpose.

Unless you continue to use the AI photoshoot feature and actively submit the selected photos for image generation, SelfMuse will not send your selected photos for AI processing.

3.3 Is Face Detection Data Stored?

No.

SelfMuse does not store face data generated during the face detection process, including but not limited to:

Face detection data exists only temporarily during the detection process and is deleted or released immediately after the check is completed.

SelfMuse does not save such face detection data to servers, user accounts, databases, logs, backups, or third-party systems.

3.4 Is Face Detection Data Uploaded or Shared?

No.

SelfMuse does not upload face detection data to SelfMuse servers, and does not share face detection data with third-party AI service providers, cloud service providers, advertising service providers, analytics providers, or any other third party.

SelfMuse does not sell, rent, trade, or otherwise commercialize face detection data.

SelfMuse does not use face detection data for:

3.5 Are User Photos Uploaded for AI Photoshoot Generation?

If you choose to continue using the AI photoshoot feature and confirm generation, the photos you actively select may be uploaded and sent to SelfMuse and our contracted AI service providers to generate the AI photoshoot results you requested.

Data sent for AI photoshoot generation may include:

For clarity, face detection data generated before upload is not uploaded, stored, or shared.

SelfMuse’s current contracted AI processing providers may include, depending on feature availability, region, service availability, and technical configuration:

We require our contracted AI service providers to process relevant data only according to our instructions and only for the purpose of providing AI image-generation services to SelfMuse.

We require these providers not to:

3.6 How Long Is Face-Related Information Retained?

SelfMuse does not retain face detection data.

Face detection data is processed only temporarily to determine whether a photo meets upload and usage requirements, and is deleted or released immediately after the check is completed.

For photos that you actively confirm and upload for AI photoshoot generation, our standard retention periods are:

3.7 In-App Consent Before Third-Party AI Processing

Before SelfMuse sends the photos you actively confirm for upload, templates, prompts, or generation parameters to contracted AI service providers, the App will display an AI data processing notice.

The notice explains:

Users must tap “Agree and Continue” before the relevant processing begins. If the user chooses “Cancel,” the selected photos will not be sent for that AI photoshoot request.

3.8 Specific Face Data Processing Disclosure Text

SelfMuse’s face data practices are summarized as follows:

“SelfMuse may perform a temporary face check on photos selected by the user before upload or generation to determine whether the photos contain a usable face, are too blurry, obstructed, too dark, or otherwise unsuitable for AI photoshoot generation.”

“SelfMuse does not store, upload, share, or retain face detection data. Face detection data exists only temporarily during the detection process and is deleted or released immediately after the check is completed.”

“SelfMuse does not create facial recognition templates, facial feature databases, biometric identity profiles, or face data used to identify users.”

“If the user chooses to continue using the AI photoshoot feature and confirms generation, the photos actively selected by the user may be sent to SelfMuse and its contracted AI service providers solely to generate the AI photoshoot results requested by the user.”

“SelfMuse does not sell user photos or face detection data, and does not use them for targeted advertising, identity verification, surveillance, tracking, or general-purpose AI model training.”

4. Other Personal Information We Collect

In addition to photos and the temporary face detection information described above, SelfMuse may collect the following categories of personal information.

4.1 Account and Authentication Information

When you create, access, or manage an account, we may collect:

SelfMuse may support account creation and login through Sign in with Apple, Google Sign-In, Firebase Authentication, or other authentication services made available in the App.

If you use Sign in with Apple, Google Sign-In, Firebase Authentication, or another third-party authentication service, we may receive information made available by that provider, such as:

We do not receive your Apple ID password, Google account password, Firebase password, or full login credentials used by any third-party authentication provider.

4.2 Subscription and Transaction Information

Purchases and subscriptions completed through the Apple App Store are processed by Apple.

We may receive:

We generally do not receive or store your complete payment-card number, card security code, Apple ID payment password, or full payment-account credentials.

4.3 Refund Review and Related Usage Data

If you submit a refund request, we may review information reasonably necessary to evaluate and process the request, including:

We use this information to ensure fair use of the Service, prevent fraud or abuse, process refunds, respond to app store or payment service provider requirements, resolve disputes, and comply with applicable legal and recordkeeping obligations.

Where necessary, we may disclose limited information related to the refund request to the applicable app store, payment service provider, customer support provider, fraud-prevention provider, legal adviser, or other necessary third party solely for refund review, refund processing, risk control, dispute resolution, or legal compliance purposes.

Refund review information is retained only for as long as reasonably necessary to process the refund request, prevent fraud or abuse, resolve disputes, comply with legal obligations, and maintain compliance records.

4.4 Device, Technical, and Usage Information

When you use SelfMuse, we may automatically collect:

We do not collect precise GPS location unless a feature clearly requires it, we explain the purpose, and you grant permission.

4.5 Prompts, Preferences, and Generation Settings

When you configure an AI photoshoot request, we may collect:

Please do not include unnecessary sensitive information in free-text prompts or voice input. Inputs that violate content policies or applicable laws may be blocked, and you may be asked to enter a new request.

4.6 Customer Support Information

When you contact us, we may collect:

Support personnel access relevant information only to the extent necessary to address user requests, technical failures, security incidents, refund issues, or violations of our terms.

4.7 Notifications and Marketing Information

Where permitted by law, we may collect:

You may disable push notifications through your device settings and unsubscribe from marketing communications using the method provided in the relevant communication.

4.8 Attribution, Advertising Measurement, and Tracking Data

Where permitted by law and platform rules, SelfMuse may collect or receive limited attribution, advertising measurement, and campaign performance information from attribution and advertising partners such as AppsFlyer, Meta, Apple AdServices, SKAdNetwork, or similar services.

This information may include:

SelfMuse does not send uploaded photos, face detection data, prompts, or generated images to advertising or attribution service providers.

Where Apple App Tracking Transparency or other applicable law requires consent, we will request permission before tracking or sharing data for advertising attribution or cross-app advertising purposes. If you deny permission, SelfMuse’s core AI photoshoot features will remain available.

4.9 Analytics, Crash Reporting, and Consent Preferences

SelfMuse may use analytics and crash-reporting tools such as Firebase Analytics, Firebase Crashlytics, or similar services to understand App performance, diagnose crashes, improve stability, measure feature usage, and maintain security.

Analytics and crash-reporting information may include device information, App version, session events, screen views, button interactions, performance metrics, crash logs, and error logs.

SelfMuse does not send uploaded photos, face detection data, prompts, or generated images to analytics or crash-reporting providers.

Where consent is legally required for non-essential analytics, tracking, marketing, or similar technologies, we may collect and retain consent status, consent version, consent timestamp, and withdrawal or opt-out records to demonstrate compliance and enforce your choices.

4.10 Voice Input and Speech-to-Text Information

When you choose to use the voice input feature, SelfMuse may process audio input actively provided by you or text converted from audio in order to convert your natural-language request into image-generation prompts or editing instructions.

Information we may process includes:

The voice input feature is used only when you actively tap or enable the microphone entry point. You may also choose not to use voice input and instead enter prompts or generation requirements by text.

Unless necessary to complete a speech-to-text request actively initiated by you, SelfMuse does not retain original audio. Speech-to-text results may be processed as prompts, generation settings, or service records in accordance with the terms in this Privacy Policy regarding prompts, generation settings, and related service records.

SelfMuse does not use voice input data to create voiceprint templates, voiceprint databases, or voice identity profiles, and does not use voice input data for advertising, identity verification, surveillance, tracking, or general-purpose AI model training.

4.11 Content Safety, Sensitive Input, and Prohibited Input Blocking Information

When you enter generation requirements, editing instructions, or prompts through text or voice, SelfMuse may automatically perform content safety checks on the input content and its speech-to-text results to determine whether the request complies with our content policies, platform rules, and applicable laws.

This check may involve:

If the detection result indicates that the relevant input does not meet requirements, SelfMuse may block the generation, ask you to enter a new request, restrict relevant features, or take measures necessary to prevent abuse and protect service safety.

To enforce content policies, maintain safety, prevent fraud or abuse, process appeals, troubleshoot technical issues, or comply with legal obligations, we may process necessary detection results, risk categories, blocking reasons, timestamps, account status, and limited technical information.

SelfMuse does not sell content safety check results, sensitive keyword match records, or prohibited input blocking records, and does not use them for advertising profiling, targeted advertising, identity recognition, or general-purpose AI model training.

5. How We Use Personal Information

We may use personal information to:

We do not use uploaded photos, face detection data, prompts, or generated images for targeted advertising or general-purpose AI model training.

6. Legal Bases for Processing

Where applicable law requires a legal basis, we may rely on one or more of the following.

6.1 Performance of a Contract

We process information where necessary to provide the services you request, including AI photo generation, account management, third-party login, subscriptions, purchases, refund processing, and customer support.

6.2 Consent

We rely on consent where required by law, including for:

You may withdraw consent at any time. Withdrawal does not affect processing completed before withdrawal.

If processing is necessary to provide an AI photoshoot feature, withdrawing consent may prevent you from using that feature.

6.3 Legitimate Interests

Where permitted by law, we may process information based on legitimate interests, such as:

We do not rely on legitimate interests to avoid obtaining consent where explicit consent is legally required for sensitive data or tracking activities.

6.4 Legal Obligations

We may process information where necessary to comply with tax, accounting, consumer-protection, data-protection, judicial, law-enforcement, payment-service, app-store, platform, advertising, or other legal obligations.

6.5 Legal Claims and Safety

We may process information where necessary to establish, exercise, or defend legal claims, protect user safety, protect third-party safety, prevent serious harm, resolve disputes, or respond to refund-related claims.

7. Artificial Intelligence Processing

SelfMuse uses artificial intelligence and machine-learning technologies to generate and modify images.

AI systems may analyze the photos you actively confirm for upload and generate new images based on your selected templates, prompts, and preferences.

When you use text or voice input features, AI systems may also help understand natural-language requests, convert or optimize generation prompts, and perform safety checks or blocking for inputs that clearly do not comply with content policies.

Depending on feature availability and technical configuration, SelfMuse may use OpenAI / Microsoft Azure OpenAI, Google Gemini / Google AI services, BytePlus AI, or similar contracted AI infrastructure providers.

Generated images are synthetic content and may contain inaccuracies, unexpected details, clothing changes, hairstyle changes, background changes, or other differences from the original photo.

SelfMuse’s AI image-generation features are not used to make decisions that produce legal or similarly significant effects concerning employment, credit, insurance, housing, education, healthcare, criminal justice, or access to essential services.

SelfMuse does not use AI processing to evaluate your personality, creditworthiness, health status, criminal risk, social status, or eligibility for important opportunities.

8. How We Share or Disclose Personal Information

We may disclose personal information to the following categories of recipients.

8.1 Contracted AI Processing Providers

These providers process photos actively confirmed for upload by the user, prompts, templates, and generation parameters only to generate the AI photos requested by users.

SelfMuse does not upload or share face detection data with contracted AI processing providers.

8.2 Cloud Hosting and Storage Providers

These providers help us host the App, store user content, maintain databases, provide content delivery, and maintain system reliability.

SelfMuse does not store temporary face detection data generated before upload in cloud hosting or cloud storage services.

8.3 Analytics and Crash-Reporting Providers

These providers help us analyze App performance, detect crashes, identify software errors, and improve the product experience.

Analytics and crash-reporting providers may include Firebase Analytics, Firebase Crashlytics, or similar services.

Where required by law, we obtain consent before enabling non-essential analytics technologies.

SelfMuse does not send uploaded photos, face detection data, prompts, or generated images to analytics or crash-reporting providers.

8.4 Payment and Subscription Providers

Apple and related platforms process purchases, subscriptions, renewals, refunds, transaction verification, and purchase restoration.

8.5 Authentication Providers

Apple, Google, Firebase Authentication, or other authentication providers may help users create accounts, access accounts, verify sessions, verify account status, and protect account security.

We may disclose or receive account identifiers, email addresses, authentication tokens, credential status information, and limited profile information necessary for account authentication.

We do not receive your Apple ID password, Google account password, Firebase password, or full authentication credentials used by these providers.

8.6 Customer Support Providers

Customer support platforms may process contact information, support messages, ticket records, screenshots voluntarily provided by users, photos or generated images voluntarily provided by users, and refund-related support information.

8.7 Communications Providers

Email and push-notification providers may process email addresses, notification tokens, communication preferences, delivery information, and interaction information.

8.8 Security and Fraud-Prevention Providers

These providers may help detect malicious activity, account attacks, payment abuse, refund abuse, attribution fraud, automated attacks, unauthorized access, and other security threats.

8.9 Professional Advisers

Where reasonably necessary, we may disclose information to lawyers, accountants, auditors, insurers, security consultants, and other professional advisers.

8.10 Legal and Safety Disclosures

We may disclose personal information to comply with applicable law, respond to binding legal process, protect users or third parties, investigate fraud or abuse, enforce our terms, process refund-related disputes, or establish, exercise, or defend legal claims.

8.11 Business Transfers

If the business associated with SelfMuse is involved in a merger, acquisition, financing, restructuring, insolvency, asset sale, or business transfer, personal information may be transferred as part of that transaction.

We require recipients to protect personal information in accordance with applicable law.

8.12 Attribution and Advertising Measurement Providers

Where permitted by law, your settings, and Apple App Tracking Transparency requirements, SelfMuse may disclose limited device information, technical information, event information, and attribution information to attribution and advertising measurement providers, including AppsFlyer, Meta, Apple AdServices, SKAdNetwork, or similar providers.

Such disclosures may be used to:

SelfMuse does not disclose uploaded photos, face detection data, prompts, or generated images to attribution or advertising measurement providers.

8.13 Speech Recognition and Speech-to-Text Providers

If you actively use the voice input feature, SelfMuse may use system-level speech recognition capabilities or contracted speech-to-text providers to convert your voice input into text prompts or generation instructions.

These providers may process relevant data only to complete the voice input request you actively initiate, and may not use voice input data for advertising, identity recognition, voiceprint recognition, surveillance, tracking, or training their own general-purpose AI models.

SelfMuse does not disclose uploaded photos, face detection data, or generated images to speech recognition or speech-to-text providers unless such disclosure is necessary to complete a function actively requested by you and has been disclosed in the App.

8.14 Content Safety and Compliance Check Providers

To enforce content policies, identify prohibited inputs, prevent abuse, or maintain service safety, SelfMuse may use internal rules, system-level capabilities, or contracted content safety, text moderation, AI safety, or risk-control providers to perform necessary checks on text prompts, speech-to-text content, generation instructions, or related technical information.

These providers may process relevant information only to the extent necessary for content safety checks, prohibited input blocking, risk control, appeal handling, compliance recordkeeping, or security protection.

SelfMuse does not disclose face detection data to content safety or compliance check providers. Unless necessary to complete a user-requested function or enforce safety policies and disclosed in the App, SelfMuse does not disclose uploaded photos or generated images to these providers.

9. Sale, Sharing, and Targeted Advertising

We do not sell personal information for monetary consideration.

We do not sell the following information:

We do not share uploaded photos, face detection data, prompts, or generated images for cross-context behavioral advertising, targeted advertising, or advertising profiling purposes.

Where permitted by law and platform rules, and only after obtaining any required consent or App Tracking Transparency permission, SelfMuse may share limited device identifiers, advertising identifiers, App events, subscription or purchase events, and attribution information with advertising and attribution partners for advertising measurement, campaign attribution, performance analysis, fraud prevention, or advertising optimization.

Depending on your jurisdiction, such limited disclosure may be considered “sharing,” “targeted advertising,” or “cross-context behavioral advertising.” Where applicable, you may opt out through in-App privacy controls, device settings, App Tracking Transparency settings, or by contacting us.

We do not use sensitive personal information to infer user characteristics for advertising, profiling, or eligibility decisions.

If our practices materially change, we will update this Privacy Policy and provide any legally required notice, opt-out mechanism, or consent request before the new practice begins.

10. App Permissions

10.1 Photo Library

Photo library permission is used to let you select photos for upload and save generated images to your device.

Where supported by iOS, you may grant SelfMuse access only to selected photos.

10.2 Camera

Camera permission allows you to take photos directly within SelfMuse.

10.3 Notifications

Notification permission may be used to notify you when image generation is complete, send account notices, subscription notices, refund-related notices, or other communications you have agreed to receive.

10.4 Tracking

Before engaging in activity that Apple defines as “tracking,” including certain IDFA use, advertising attribution, advertising measurement, or sharing data with advertising partners for cross-app or cross-website purposes, we will request authorization in accordance with Apple’s App Tracking Transparency requirements.

If you grant tracking permission, SelfMuse and its attribution or advertising partners may process limited device identifiers, App events, attribution information, and campaign performance information as described in this Privacy Policy.

If you deny tracking permission, SelfMuse will not access IDFA for tracking purposes and will not use data requiring ATT permission for tracking. Declining tracking permission will not prevent you from using SelfMuse’s core AI photoshoot features.

You may change permissions at any time through iOS settings.

10.5 Third-Party Sign-In

If you choose to sign in using Apple, Google, Firebase Authentication, or another authentication provider, that provider may process your information according to its own privacy policy and account settings.

You may manage authentication permissions through your Apple account, Google account, device settings, or other relevant provider controls.

10.6 Microphone and Voice Input

Microphone permission is used to record voice when you actively use the voice input feature and to convert voice into text prompts or generation instructions.

If you deny microphone permission, you may still use text input to create prompts or use SelfMuse’s core AI photoshoot features.

You may disable or change microphone permission at any time through iOS settings.

10.7 Text and Voice Input Safety Checks

When you enter generation requirements through text or voice, SelfMuse may perform safety checks on the input content or speech-to-text results. If the input contains sexual, violent, hateful, self-harm, illegal, or other restricted content, the App may ask you to enter a new request or may prevent generation from continuing.

11. Data Retention

We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy.

11.1 Face Detection Data

SelfMuse does not retain face detection data.

Face detection data is processed only temporarily to determine whether a photo meets upload and usage requirements, and is deleted or released immediately after the check is completed.

Face detection data is not saved to servers, user accounts, databases, logs, backups, or third-party systems.

11.2 Account Information

Account information is generally retained while the account remains active.

After account deletion, account information is deleted or de-identified within 30 days, unless continued retention is required by law.

11.3 Uploaded Photos

Uploaded source photos are retained no longer than 30 days after completion of the relevant generation request.

If you delete the related project or submit a valid deletion request earlier, the photos may be deleted sooner.

11.4 Generated Images

For registered users, generated images are generally retained until:

For guest or temporary-session users, generated images are generally deleted within 30 days after generation, unless they are saved to a registered account.

11.5 Failed Uploads

Failed or incomplete uploads are generally deleted within 7 days.

11.6 Deleted Data

After a valid deletion request is received, relevant information is generally removed from active systems within 30 days.

Where applicable law requires a shorter period, we comply with that shorter period.

11.7 Backup Data

After deletion from active systems, backup copies are deleted or overwritten within the normal backup cycle, generally within 90 days.

11.8 Technical and Security Logs

Technical and security logs are generally retained for no longer than 12 months, unless longer retention is necessary for security, fraud prevention, legal, or dispute-resolution purposes.

11.9 Analytics Data

Analytics, attribution, advertising measurement, and campaign performance data are generally retained for no longer than 24 months, after which they are deleted, aggregated, or de-identified, unless a shorter or longer period is required by law, platform rules, fraud-prevention needs, or dispute-resolution obligations.

11.10 Customer Support Records

Customer support records are generally retained for no longer than 24 months after a ticket is closed, unless longer retention is required for disputes, refunds, fraud prevention, security, or legal compliance.

11.11 Subscription, Transaction, and Refund Records

Subscription, transaction, refund, accounting, and tax records are retained for the period required by applicable law, app store requirements, payment-service requirements, dispute-resolution needs, and compliance obligations.

This period may be up to 7 years or another legally required period.

11.12 Consent and Privacy Request Records

We may retain consent records, consent-withdrawal records, tracking permission records, analytics consent records, marketing consent records, privacy-request records, and request-resolution records for as long as necessary to demonstrate compliance, enforce your choices, address complaints, or establish or defend legal claims.

11.13 Authentication Records

Authentication records, including third-party login identifiers, session tokens, credential status information, and related security records, are generally retained while the account remains active and are deleted or de-identified after account deletion, unless longer retention is necessary for security, fraud prevention, legal, dispute-resolution, or compliance purposes.

Third-party authentication providers may retain related information according to their own privacy policies and account settings.

11.14 Voice Input and Speech-to-Text Records

Unless necessary to complete a speech-to-text request actively initiated by you, SelfMuse does not retain original audio.

Speech-to-text results may be retained as part of prompts, generation settings, generation history, or customer support records, and are handled according to the retention periods for the relevant data categories in this Privacy Policy.

If relevant speech-to-text content is linked to an account, project, or generation history, such content is generally deleted when the account, project, or generation history is deleted, unless limited records must be retained for legal, security, refund, dispute-resolution, or compliance purposes.

11.15 Content Safety and Prohibited Input Blocking Records

Content safety check results, risk categories, blocking reasons, related timestamps, and limited technical information are generally retained only for as long as reasonably necessary to enforce content policies, prevent abuse, handle appeals, troubleshoot issues, comply with legal obligations, or maintain compliance records.

If specific input content is no longer needed for the above purposes, we may delete, aggregate, or de-identify related records. Records linked to accounts, projects, generation history, customer support, refunds, disputes, or security incidents are handled according to the retention periods for the corresponding data categories.

12. Account and Content Deletion

You may use available in-App features to delete:

You may initiate account deletion through:

Settings > Account > Delete Account

You may also submit a deletion request using the contact methods provided in this Privacy Policy.

Account deletion generally removes:

Because SelfMuse does not retain face detection data, there is no face detection data to delete from your account during account deletion.

Account deletion does not automatically delete information retained by Apple, Google, Firebase Authentication, or other third-party authentication providers under their own policies. You may need to manage or delete such information separately through the relevant third-party account or provider settings.

We may retain limited information where necessary to comply with legal obligations, preserve transaction records, process refunds, prevent fraud or refund abuse, respond to legal proceedings, establish or defend legal claims, or demonstrate that a privacy request was completed.

Deleted information may temporarily remain in encrypted backups until the applicable backup cycle expires.

Deleting your SelfMuse account does not automatically cancel an App Store subscription. You must separately cancel your subscription through your Apple account or App Store subscription-management settings.

13. Data Security

We use reasonable technical, organizational, administrative, and contractual measures designed to protect personal information.

Such measures may include:

No internet transmission or electronic storage method is completely secure. We cannot guarantee that personal information will never be subject to a security risk.

You are responsible for protecting your device, account login credentials, email account, Apple account, Google account, authentication-provider account, and other access methods associated with your SelfMuse account.

If a personal-data security incident occurs, we will investigate and notify affected users and relevant regulators where required by applicable law.

14. International Data Transfers

To provide services globally, we and our service providers may process personal information in different countries and regions.

Processing locations may include:

The data-protection laws in those jurisdictions may differ from the laws in your country or region.

Where required by law, we may use safeguards such as data-processing agreements, standard contractual clauses, transfer-risk assessments, supplementary technical and organizational measures, explicit user consent, or other legally recognized transfer mechanisms.

You may contact us to request more information about safeguards applicable to international transfers of your personal information.

15. Your Privacy Rights

Depending on your country or region, you may have some or all of the following rights:

You may submit a request through available in-App privacy controls or through the contact methods provided in this Privacy Policy.

Before processing a request, we may need to verify your identity.

Verification information is used only to confirm the requester’s identity, prevent unauthorized access, and complete the privacy request.

If a request is submitted by an authorized agent, we may require proof of authorization and may contact you directly to confirm the request.

We respond within the period required by applicable law.

Certain rights may be subject to legal exceptions.

16. Users in the European Economic Area, United Kingdom, and Switzerland

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may have the following rights:

Where we process personal data based on legitimate interests, you may object based on your particular circumstances.

Where we process personal data based on consent, you may withdraw consent at any time.

Where we process personal data for direct marketing, tracking, or targeted advertising purposes, you may object or withdraw consent where required by applicable law.

SelfMuse’s AI image-generation services do not make automated decisions that produce legal or similarly significant effects concerning you.

Where applicable law requires a local representative, relevant contact details will be provided through an appropriate channel.

17. United States Privacy Disclosures

During the preceding 12 months, we may have collected the following categories of personal information:

SelfMuse may temporarily process face detection data before photo upload or generation to determine whether a photo meets upload and usage requirements, but such face detection data is not stored, uploaded, shared, or retained.

We may disclose relevant information to service providers and contractors for business purposes, including AI processing providers, cloud providers, authentication providers, analytics providers, attribution providers, advertising measurement providers, speech recognition or speech-to-text providers, customer support providers, security providers, payment platforms, and professional advisers.

We do not sell personal information for monetary consideration.

Where permitted by law and subject to any required consent or opt-out rights, we may share limited identifiers, device information, App events, purchase or subscription events, and attribution information with advertising and attribution partners for advertising measurement, campaign attribution, performance analysis, fraud prevention, or advertising optimization. Under some U.S. state privacy laws, this may be considered “sharing,” “targeted advertising,” or “cross-context behavioral advertising.”

We do not sell or share uploaded photos, face detection data, prompts, or generated images for advertising purposes.

We also do not sell or share voice input content, speech-to-text content, content safety check results, or prohibited input blocking records for advertising purposes.

We do not knowingly sell or share personal information of users under 16.

Sensitive personal information is used only as reasonably necessary to provide requested services, maintain account security, prevent fraud, address security incidents, comply with law, process refunds, resolve disputes, or perform other legally permitted service purposes.

18. United States Facial and Biometric Data Notice

SelfMuse does not store, upload, share, or retain face detection data, and does not create facial templates, facial databases, or biometric identity profiles used to identify users.

If applicable state law treats temporary pre-upload face detection as biometric information processing:

Photos actively confirmed by the user for AI photoshoot generation are processed according to the relevant uploaded-photo and AI-processing terms in this Privacy Policy.

19. Users in Brazil

Where Brazilian data-protection law applies, you may have the right to:

You may submit a request using the contact methods provided in this Privacy Policy.

20. Users in Canada

Where Canadian privacy law applies, we process personal information according to principles including accountability, identified purposes, meaningful consent, limited collection, limited use, limited retention, safeguards, openness, access and correction, and complaint-handling procedures.

You may request access to or correction of personal information and may withdraw consent, subject to applicable legal or contractual restrictions.

Personal information may be processed by providers outside your country or region and may be subject to the laws of the jurisdiction in which it is processed.

21. Users in Hong Kong

Where Hong Kong personal-data protection law applies, we comply with principles relating to lawful and fair collection, notice of processing purposes, information accuracy, limited retention, restrictions on unauthorized use, reasonable security measures, transparency, access, and correction.

You may request access to or correction of your personal data as permitted by applicable law.

22. Children’s Privacy

SelfMuse is intended for users who are 18 years of age or older.

We do not knowingly allow children under 18 to independently create accounts or submit photos.

Users must not upload photos of a minor unless:

SelfMuse may block text, voice, or image generation requests involving inappropriate use of minors, sexualization, exploitation, impersonation, or other high-risk purposes.

SelfMuse is not directed to children under 13.

We do not knowingly collect personal information online from children under 13.

If we learn that we collected a child’s information in violation of applicable law, we will take reasonable steps to delete it.

Parents or guardians who believe that a child’s information has been submitted may contact us using the methods provided in this Privacy Policy.

23. Third-Party Services and Links

The Service may include links to third-party websites, social platforms, applications, or services, including third-party authentication, AI, analytics, attribution, advertising measurement, payment, and customer support services.

Those third parties may independently process personal information under their own privacy policies.

We are not responsible for data-processing activities independently determined by third parties.

When you export or share generated images to another platform, that platform may collect and process generated images, sharing records, account information, device information, or other related information.

Please review the third party’s privacy policy before logging in through a third-party service, sharing content to a third-party service, or using a third-party service.

When you use third-party login, advertising attribution, analytics, push notification, voice input, or AI processing features, relevant third-party service providers may process necessary information under their own privacy policies. We recommend that you review the relevant provider’s privacy policy to understand its independent processing activities.

24. Changes to This Privacy Policy

We may update this Privacy Policy due to:

When this Privacy Policy is updated, we will revise the “Last Updated” date at the top of the page.

Where a change materially affects your rights or the processing of sensitive information, we may provide additional notice through an in-App notice, pop-up message, email, official website, or another appropriate method.

Where required by law, we will obtain renewed consent before implementing the new processing activity.

25. How to Contact Us

If you have questions about this Privacy Policy, wish to submit a complaint, withdraw consent, or exercise a privacy right, please contact us through:

Please provide sufficient information for us to understand and verify your request.

Do not send account passwords, payment passwords, complete payment-card information, unnecessary identity documents, or sensitive information unrelated to the request through ordinary email.

26. Language

This Privacy Policy may be made available in multiple languages.

Translations are provided for user convenience.

To the extent permitted by applicable law, the English version will prevail in the event of a conflict between language versions.

Where local law requires a local-language version to prevail, the requirements of local law will apply.

27. Severability

If any provision of this Privacy Policy is determined by a competent authority to be invalid, unlawful, or unenforceable, the remaining provisions will continue in effect to the fullest extent permitted by applicable law.

28. Third-Party Service Provider List

This list summarizes the major categories of third-party service providers that SelfMuse may use. Actual providers may vary depending on feature availability, region, device settings, user consent, and technical configuration.

28.1 Authentication Providers

These providers may process account identifiers, email addresses, authentication tokens, credential status information, and limited profile information necessary for account creation, login, session management, and account security.

28.2 AI Processing Providers

These providers process photos actively confirmed for upload by the user, prompts, templates, and generation parameters only to generate the AI photos requested by users. SelfMuse does not upload or share face detection data with AI processing providers.

28.3 Analytics, Crash Reporting, and Performance Providers

These providers may process device information, App version, session events, screen views, performance metrics, crash logs, and error logs. SelfMuse does not send uploaded photos, face detection data, prompts, or generated images to analytics or crash-reporting providers.

28.4 Attribution and Advertising Measurement Providers

Where permitted by law, platform rules, device settings, and user consent, these providers may process limited device identifiers, App events, conversion events, campaign information, attribution information, and anti-fraud signals.

SelfMuse does not send uploaded photos, face detection data, prompts, or generated images to attribution or advertising measurement providers.

28.5 Payment, Subscription, and Platform Providers

These providers may process purchase, subscription, transaction, refund, storefront, and entitlement information according to their own policies and platform rules.

28.6 Communications and Support Providers

These providers may process contact information, notification tokens, support messages, ticket records, and related operational information only to the extent necessary to provide communications, support, and service notices.

28.7 Speech Recognition and Speech-to-Text Providers

If SelfMuse provides voice input features, it may use the following services or capabilities depending on device system, region, and technical configuration:

These services are used only to convert voice input actively provided by you into text prompts or generation instructions, and not for advertising, identity recognition, voiceprint recognition, surveillance, tracking, or general-purpose AI model training.

28.8 Content Safety, Sensitive Input, and Compliance Check Providers

These providers may process necessary information only for content safety checks, prohibited input blocking, risk control, appeal handling, security protection, or compliance recordkeeping. SelfMuse does not sell content safety check results or prohibited input blocking records, and does not use them for advertising profiling, targeted advertising, identity recognition, or general-purpose AI model training.

End of Privacy Policy