Last updated August 2026
This policy explains what MyTinySecret collects and why. MyTinySecret is an early-access product and collects the minimum needed to run it.
A username and password, and a display name. Your date of birth, to confirm you are 18 or over and as a research variable, and optionally your sex/gender. Sex/gender is used for research only and is never shown on your profile. An email address is optional, for account recovery and notifications.
We record product analytics events (e.g. screens opened, shades collected) linked to your account, to improve the product and study engagement. They are keyed to your account id, not to any external identity.
No banking details, card numbers, or payments — MyTinySecret has no money in it at all. We deliberately do not collect your legal full name: it is identifiable information with no purpose here. We never sell records that identify you, and we never sell or share anything at all about you unless you have given the research consent in section 2a.
Taking part in the research is optional and always has been optional in principle — but until August 2026 the sign-up form required it, which means consent given before then was a condition of getting an account rather than a free choice. We are asking everyone affected again, and until they answer their existing consent stands. Nothing about an account depends on the answer: Founding Member status is granted to everyone who joins during the beta, and every feature works identically either way.
If you consent, your in-app activity also contributes to aggregated, anonymised taste and trend insight, which may be shared or sold commercially. Those outputs describe groups, never individuals, and are only produced from people who have consented. If you decline, your activity is excluded from them.
We record the time and the version of the consent you gave, so it is always clear exactly what was agreed to. You can turn the consent on or off at any time in Settings — the same single control, either direction. Withdrawing takes effect on the next rebuild of our models, which happens daily; because those models are rebuilt from scratch each time rather than accumulated, withdrawing removes you from them entirely rather than flagging you inside them.
Your collection, your profile, your prices and everything else you can see are unaffected by this choice. It governs research and commercial insight only, not the running of the game itself.
We store the messages you send to Muse and Muse's replies, so your conversations are still there when you come back. They are kept until you delete the conversation or your account — there is no automatic expiry.
When Muse needs a model-backed reply, a bounded window of your most recent messages in that conversation is sent to our AI provider along with your message.
Deleting a conversation permanently removes its messages. Notes you saved separately are not deleted. Records of how Muse was used — timing, token counts, cost, and technical details such as the kind of request and whether it succeeded — which contain none of your message content, are kept for billing and reliability.
This feature is not available yet. The setting exists so you can decide before it arrives; nothing about images applies to your account until both the feature ships and you have turned the permission on.
When it does, you will be able to send Muse images you choose: a selfie or a face or lip close-up, makeup and beauty products, fashion or product inspiration you are entitled to use, a full outfit, or garments and accessories from your wardrobe. You must not send an image of another person's face without their permission.
Images, and the observations Muse derives from them, are personal data. Muse reads what is directly visible for the beauty or fashion task you asked about — colour, finish, texture, how garments relate, proportion, and the geometry of a lip or face where that is what the question is about. Visible skin tone and undertone may be used to answer a matching question; they are never turned into a claim about ethnicity or identity.
Muse will not identify or authenticate a person, perform face recognition or matching, build a facial identity template, infer ethnicity or race, health or diagnosis, emotion, sexuality, religion or any other sensitive trait, present cosmetic analysis as a medical diagnosis, or be used for surveillance or access control.
Processing an image you deliberately send is for providing the service you asked for. Reusing images or context across your other conversations is a separate, optional choice with its own switch in Settings, off unless you turn it on. It can only be on while image processing is on, and turning image processing off turns it off too — turning image processing back on later does not bring it back.
An image belongs to the conversation you sent it to, together with everything Muse derived from it. Both are kept until you delete that conversation. There is no automatic expiry. Deleting the conversation removes the image and its derived observations from everywhere Muse could later retrieve them, including across conversations.
Answering a question about an image requires sending it to an AI provider. We require of any provider we use: no training on what we send, short or zero retention where the provider offers it, appropriate data-processing terms, encryption in transit, and that an image is sent only when the question actually needs it.
Your images and conversations are not used to train or improve models — ours or a provider's. Any future research or training use would require a separate, specific opt-in that does not exist today.
Operational analytics about image requests record only timing, size and success — never image content, filenames or what Muse observed.
Image features are intended for the United Kingdom, the European Union, the United States and Brazil. That is where we intend to offer them; it is a statement of intent and not a claim that jurisdiction-specific legal certification has been completed.
To run the product: to personalise your daily shade, your Beauty Profile and your recommendations, to operate the collection and the market, and to keep the service working.
Data is stored in managed Postgres (Supabase) and served through Vercel. Passwords are hashed and never stored in readable form.
As a beta, data may be reset between phases.
Account deletion is handled by our team, not by a button in the app. Write to us and we will delete your account and its data, including any images and derived observations. We are being plain about this rather than implying an automatic mechanism that does not exist yet.
You can delete any individual Muse conversation yourself, at any time, from the conversation list.
Questions about any of this, or a deletion request: