Introduction
Welcome to Muzza (muzza.ai), operated by Crebox Labs LLC, a Wyoming Limited Liability Company (Entity ID: 2G8GD7C4). We are committed to protecting your privacy and ensuring the security of your personal data. This privacy policy explains how we collect, use, and protect your data when you use our platform.
Data We Collect
We strive to collect only the minimum data necessary to provide our services:
- Account data: Email address — used to create your account and log in. When signing in via an external account, we only receive the identifier and username.
- Chat data: Your conversation content is stored to provide the chat experience and protected by strict access controls. We do not sell your conversation content or use it for advertising.
- Generated images: Metadata about images you create (such as date and associated character) and the generated media needed to provide your collection and image features.
- Payment data: Transaction history, prepaid-access status, Token balance, provider invoice references, and payment status. Cryptocurrency payment details are also processed by the payment provider.
- Usage and analytics data: Page views, product and funnel events, referral source, approximate region, and device/browser information. These signals may be associated with pseudonymous analytics or visitor identifiers.
- Visitor, security, and operational data: A pseudonymous visitor ID is sent to our server with a hash derived from the trusted request IP for journey continuity, earned-Token attribution, fraud prevention, rate limiting, and aggregate measurement. We may also process IP addresses, request/error identifiers, timestamps, and reliability signals for security and operations.
AI Memory
The platform uses an AI memory system to improve conversation quality. This system stores summaries derived from your interactions to provide a more personalized experience. These summaries are account-, conversation-, and persona-linked data; they are not anonymous. This memory:
- Is linked to your account only and isolated from other users.
- May contain details summarized from your conversations with a character.
- Is scheduled for deletion with your account, subject to the retention limits below.
Chat Storage
Conversation content is protected by strict access controls and stored only as needed to provide the chat experience, safety checks, and account features. We do not sell conversation content or use it for advertising.
Analytics and Tracking
Google Analytics, Umami, PostHog, Vercel Analytics, Vercel Speed Insights, and optional session replay run only after you explicitly accept them in the privacy prompt. Confirming age is not analytics consent. Essential server-side payment, entitlement, security, abuse-prevention, and reliability records still operate so we can provide and protect the service.
- No optional browser analytics provider is mounted before explicit acceptance.
- PostHog automatic interaction recording remains disabled.
- You can withdraw that consent from the persistent Privacy settings control; trackers then unmount and remain off on later visits.
Push Notifications
You can optionally enable push notifications. When you do, we store an account-linked push endpoint, the cryptographic keys used to secure the notification channel, and related browser/device and operational identifiers needed to deliver and manage notifications. You can turn notifications off from your account settings or browser controls. Notification delivery also sends the notification title and body to the push service for your device.
Third-Party Service Providers
We work with trusted third-party service providers to operate the platform. Each provider only accesses the data necessary to perform its function:
- Database hosting and authentication — Servers in the European Union
- Website hosting — Content delivery and global distribution
- AI model processing — To power character conversations
- AI memory system — Processing account-, conversation-, and persona-linked summaries to improve conversations
- Image generation — AI-powered image creation service; this path is temporarily paused in the controlled pilot until private media delivery is complete
- Payment processing — NOWPayments for one-time cryptocurrency invoices. The provider handles blockchain and billing data under its own policy.
- Optional advertising provider — Disabled during the controlled pilot. If advertising is considered later, this policy and the required consent controls will be updated before activation.
- Pseudonymous visitor and device signals — To preserve journey continuity and earned-Token attribution, prevent abuse, and produce aggregate measurements
- Optional browser analytics providers — Google Analytics, Umami, PostHog, Vercel Analytics, and Vercel Speed Insights are available only after you explicitly accept them and remain off after refusal or withdrawal.
- Email service — For verification emails and password resets
Account Deletion
Account settings opens a support-assisted request addressed to privacy@muzza.ai. Send it from the account email. Support verifies identity and scope, then confirms receipt and the next steps; opening the draft alone does not disable access or start deletion. Once an accepted request is processed, encrypted backups expire on their rotation schedule, and limited records may be retained where needed for payment reconciliation, fraud prevention, safety reporting, dispute handling, or applicable law. The request may cover these account-linked categories:
- Your email address and account data
- Conversation records associated with the account
- Generated images and your collection
- Payment history and token balance
- Prepaid-access data
- AI memory linked to your account
- Push notification subscriptions
Your Rights
Under the General Data Protection Regulation (GDPR) and applicable laws, you have the following rights:
- Right of access: You can request a copy of your personal data stored with us.
- Right to rectification: You can request correction of any inaccurate data.
- Right to erasure: You can request account deletion or erasure, subject to applicable legal and retention limits.
- Right to data portability: You can request an export of your data in a machine-readable format.
- Right to object: You can object to the processing of your data for specific purposes.
- Right to withdraw consent: You can withdraw your consent to data processing at any time.
Account Settings also provides a limited self-service core JSON export containing your profile, readable conversation text, payment-intent history, and privacy-request history. It does not currently include binary images, AI memory, or every other account-linked category. For a complete access request, contact privacy@muzza.ai.
To exercise any of these rights, contact us at privacy@muzza.ai. We will acknowledge and handle your request within the time required by applicable law. If you need confirmation or believe account-linked data remains after deletion, email us from the account address so support can follow up.
Child Protection
Muzza is intended for adults only (18 years or older). We do not knowingly collect data from minors. If we become aware that a user under 18 has created an account, we will disable the account immediately and handle associated data under applicable safety, reporting, and retention duties. If you believe a minor is using the platform, report it to privacy@muzza.ai.
Data Breach Notification
If a security breach affects your personal data, we will:
- Notify affected users without undue delay when applicable law requires it.
- Report to relevant authorities within the deadlines required by applicable law.
- Explain the nature of the breach, the data affected, and the measures taken to address it.
- Provide recommendations to protect your account.
Security
We implement strict security measures to protect your data:
- TLS encryption for all data in transit.
- Strict access controls for conversation content.
- Encrypted storage of data on servers in the European Union.
- Logging minimization and restricted access to operational logs, which may contain IP, request, error, or pseudonymous identifiers needed for security and reliability.
- Strict row-level security (RLS) policies at the database level.
Policy Updates
We may update this privacy policy from time to time. We will notify you of any material changes via email or a notification on the platform. We recommend reviewing this page periodically.
Contact
If you have any questions or inquiries about this privacy policy or how we handle your data, you can contact us via email at: privacy@muzza.ai
Postal address: Crebox Labs LLC, 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, USA.