Last updated: 2026-07-20
This Privacy Policy explains what information Muze collects when you use Muze CMO, why we collect it, who we share it with, and the choices you have. It covers both the Muze CMO dashboard and the hosted Muze MCP server (backend.muzecmo.com/mcp) that lets your own AI assistant read your marketing data and take confirm-gated actions on your connected ad accounts.
Who We Are
Muze CMO is a product of Muze AI ("Muze," "we," "us," "our"). We provide marketing intelligence and campaign-management tooling for advertisers running on Meta Ads, Google Ads, Amazon Ads, and Shopify. Our website is muzecmo.com. For any privacy question, or to exercise the rights described below, contact us at hello@muzecmo.com.
Meta, Google, Amazon, Shopify, Anthropic (Claude), OpenAI (ChatGPT), and Cursor are trademarks of their respective owners. Muze is an independent product and is not endorsed by, sponsored by, or affiliated with any of them.
Muze is the data controller for the account information you give us directly. For the advertising and store data we fetch on your behalf, we act as your service provider / data processor — we access it only to operate the features you turn on.
Data controller of record:
- Entity and address: AgentProd Inc., San Francisco, California, United States
- Privacy contact: hello@muzecmo.com
Information We Collect
Account information. When you sign up, we collect your email address, authentication credentials, and profile details managed through our authentication provider. If you subscribe to a paid plan, our payment processor collects and holds your billing details — we do not store full card numbers on our own systems. We also keep customer-support communications you send us, and any notification destinations you configure (such as a Slack workspace connection for digests and alerts).
Ad-platform data you authorize. When you connect Meta Ads, Google Ads, or Amazon Ads, you grant Muze scoped access through each platform's OAuth flow. We then fetch the data needed to power analysis and actions: ad accounts, campaigns, ad sets, ads, creatives, budgets, targeting, and performance insights (spend, impressions, clicks, conversions, ROAS, and similar metrics). We only request the scopes each feature needs. We never collect or store your Meta, Google, Amazon, or Shopify passwords — authorization happens entirely through each platform's own OAuth flow, and you can revoke it from either side at any time. For Meta lead-generation campaigns, we fetch lead-form metadata (form names, IDs, and questions) to set up campaigns; we do not retrieve your leads' submissions or their personal information.
Shopify store data. When you connect a Shopify store, we sync product catalog and order-level data at the shop level to inform creative generation and performance analysis. This data can qualify as Protected Customer Data under Shopify's requirements. We handle it accordingly: we sync shop-level product and order data and do not persist individual end-customer identities — no buyer email, name, phone, or address is stored in our systems.
MCP usage logs. When your AI assistant calls a tool on the Muze MCP server, we record a metering and audit entry for that call: the tool name, the number of billing units it consumed, a timestamp, the API key used, and your user ID. We do not receive the content of your conversation with your AI assistant. Your chat messages, prompts, and the assistant's replies never reach Muze. What does reach Muze is each tool call itself — the tool name and the parameters needed to execute it, which can include content you asked your assistant to use (for example, ad copy for a campaign you are creating). Parameters are used to execute the request; only the tool name and unit cost are kept in the metering log above.
Generated creatives. Ad images and videos produced by our creative features are stored as media assets so they remain available to you inside the product.
Technical data. We collect standard operational data such as request logs, IP address, and error diagnostics to keep the service secure and reliable.
How We Use Your Information
We use the information above to:
- Authenticate you and operate the dashboard and MCP server.
- Fetch, analyze, and display your advertising and store performance.
- Generate campaign analysis, benchmarks, and creative recommendations.
- Execute the confirm-gated actions you (through your AI assistant or the dashboard) explicitly approve.
- Meter usage against your plan's quotas and bill you correctly.
- Detect abuse, debug problems, and improve reliability and security.
- Communicate with you about your account, billing, and material changes to the service.
Legal Bases for Processing (GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal data only when we have a lawful basis to do so. The bases we rely on are:
- Performance of a contract. We process your account information and connected-platform data to deliver the service you signed up for — authenticating you, fetching and displaying your marketing data, executing the actions you confirm, and metering usage against your plan. Without this processing we cannot provide Muze CMO.
- Legitimate interests. We process technical and usage data to secure the service, prevent abuse, debug problems, meter and bill correctly, and understand how the product is used so we can improve it. We weigh these interests against your rights and process only what is proportionate.
- Legal obligation. We process certain data to comply with legal and regulatory requirements, including tax and accounting rules and mandatory platform-compliance webhooks (such as Shopify's GDPR deletion webhooks).
- Consent. Where we rely on consent — for example, non-essential analytics or marketing cookies on our website, or optional communications — you may withdraw it at any time without affecting processing that already took place. See our Cookie Policy for cookie-specific choices.
What We Do Not Do
- We do not sell your data. We do not sell, rent, or trade your personal information or your advertising data to anyone.
- We do not train AI models on your data. We do not use your campaign data, store data, or creatives to train our own or any third party's foundation models.
- We do not mix customer data. Each customer's data is isolated to their account. We do not blend one customer's data into another customer's analysis, benchmarks, or outputs.
Platform Data-Use Commitments
The advertising and store data we access on your behalf is governed not only by this policy but by each platform's developer terms, and we commit to their restrictions:
- We use data obtained from Meta, Google, Amazon, and Shopify solely to provide and improve the Muze features you use — never for our own advertising, never for other customers, and never for building audience profiles outside your account.
- Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We handle Meta data under the Meta Platform Terms and Developer Policies, Amazon data under the Amazon Ads API terms, and Shopify data under Shopify's API Terms and Protected Customer Data requirements.
AI and Agent-Specific Disclosures
Muze CMO is designed to work with your own AI assistant (such as Claude, ChatGPT, or Cursor) through the Model Context Protocol.
Your AI assistant provider is not us. When you connect an AI assistant to the Muze MCP server, the conversation between you and that assistant is processed by the assistant's provider (for example, Anthropic or OpenAI) under that provider's own privacy policy and terms — not this one. Muze has no visibility into and no control over how your chosen assistant provider handles your conversation. The Muze MCP server is a passthrough to the underlying advertising platform APIs; it does not run Muze's own AI analysis on the tool calls it serves. Note that tool results flow back the other way: when a tool returns your campaign data or metrics, that result is delivered into your conversation and is from that point handled by your assistant's provider under its own policy.
Muze's own AI features. Separately, the Muze dashboard offers AI analysis and creative-generation features. When you use those features, we send the relevant campaign performance data and creative inputs to the LLM and media subprocessors listed below so they can generate the analysis or asset you requested. These subprocessors act on our instructions and do not receive your AI-assistant conversations.
Analytics and Conversion Tracking
Product analytics. We use PostHog and Amplitude to understand how people use Muze CMO — which features are used, where users get stuck, and whether the product is working — so we can improve it. These tools receive product-usage events tied to your user ID. They do not receive your AI-assistant conversations or your customers' personal data.
Server-side conversion measurement. To measure how well our own marketing of Muze CMO performs, our backend sends server-side conversion events (such as sign-up and purchase) to Meta through its Conversions API. Identifiers such as your email address are hashed (SHA-256) before transmission, so Meta receives a pseudonymized signal rather than your raw details. This measures our advertising of Muze CMO — it does not involve any data from your connected advertising accounts. Website-side analytics and marketing pixels are described separately in our Cookie Policy.
Subprocessors
We rely on the following subprocessors to operate Muze CMO. This list is current as of the "last updated" date and may change as the service evolves.
| Subprocessor | Purpose |
|---|---|
| Supabase | Application database (PostgreSQL) and user authentication |
| Amazon Web Services (S3) | Storage of generated ad creatives and media assets |
| Redis | Caching, rate limiting, and usage metering |
| Stripe | Payment processing and subscription billing |
| OpenRouter | LLM routing for campaign-analysis and creative features |
| Google (Gemini API) | LLM analysis of campaign performance data |
| OpenAI | LLM analysis and generation features |
| FAL (fal.ai) | AI image and video creative generation |
| PostHog | Product usage analytics |
| Amplitude | Product usage analytics |
Business customers who require a Data Processing Agreement (DPA) covering this processing can request one at hello@muzecmo.com.
Legal disclosures and business transfers. We may disclose information where we believe it is necessary to comply with law or valid legal process, to enforce our terms, to protect the rights, safety, or security of Muze, our users, or the public, or to detect and prevent fraud or abuse. If Muze is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to protections consistent with this policy.
The AI assistant provider you connect over MCP (Anthropic, OpenAI, or another MCP client's provider) is your processor, not a Muze subprocessor, because it processes your conversation under your own agreement with that provider.
International Data Transfers
Muze operates in the United States, and the subprocessors listed above process data in the United States and, in some cases, other countries. If you access Muze from outside the United States — including from the European Economic Area or the United Kingdom — your information will be transferred to and processed in the United States, which may have data-protection laws different from those in your own country.
Where such transfers require additional safeguards, we rely on appropriate mechanisms — such as the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) or a valid adequacy decision — together with the contractual commitments in our agreements with each subprocessor.
[COUNSEL TO CONFIRM: verify the transfer mechanism(s) actually in place with each subprocessor (SCCs, UK IDTA/Addendum, EU-US Data Privacy Framework participation, or adequacy) and align this section with the executed data processing agreements.]
Data Retention
We retain your account information and connected-platform data for as long as your account is active, so the product keeps working for you. Platform OAuth tokens are kept only until you disconnect that platform, revoke access on the platform's side, delete your account, or the token expires — whichever comes first; disconnecting a platform removes our stored authorization for it. MCP usage logs are retained to support billing, quota enforcement, and abuse detection. When you delete your account, we delete your data as described below. Backups may retain deleted data for a limited period before automatic purge.
Specifically, MCP usage logs and technical/operational logs are retained for up to 90 days after account closure for billing reconciliation, quota enforcement, abuse detection, and security, after which they are deleted or reduced to non-identifying aggregate statistics. Encrypted backups that may still contain deleted data are automatically purged within 35 days.
Deletion and Your Rights
Deleting your account. When you request account deletion, we run a cascading deletion across our database that removes your records — including ad accounts, connected-platform authorizations, campaigns, analyses, creatives, and usage records — associated with your user ID and your connected ad accounts.
Shopify data deletion. We honor Shopify's mandatory GDPR webhooks. When a store owner uninstalls or requests deletion, our shop/redact handler verifies the request and synchronously deletes all shop-scoped data we hold for that store. Because we do not store individual end-customer identities, the customers/redact and customers/data_request webhooks are acknowledged and logged for audit, and return an empty export — there is no end-customer personal data for us to erase or disclose.
Your rights. Depending on where you live, you may have rights under the GDPR, the CCPA/CPRA, or similar laws — including the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. We do not sell personal information, so there is nothing to opt out of on that front. To exercise any right, email hello@muzecmo.com and we will respond within the timeframe the applicable law requires. You may also disconnect any platform at any time, which revokes Muze's access to that platform going forward.
Security Practices
We take practical, honest measures to protect your data:
- Encryption in transit. Traffic to and from Muze, including all MCP calls, is served over HTTPS/TLS.
- Hashed API keys. Muze MCP API keys (
mz_live_...) are stored only as SHA-256 hashes. We keep a short non-secret prefix to help you identify a key, but the full key is never stored in recoverable form — if you lose it, you rotate it rather than recover it. - Scoped OAuth. Platform connections use each provider's OAuth flow with the minimum scopes each feature needs, and stored access credentials are held securely. Shopify access tokens are additionally encrypted at rest.
- Access controls. Data is isolated per account, and internal access to production data is limited to what is needed to operate and support the service.
No system is perfectly secure, and we do not claim otherwise. If we ever become aware of a breach affecting your data, we will notify you as required by law.
Children
Muze CMO is a business tool and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a minor has provided us information, contact hello@muzecmo.com and we will delete it.
Changes to This Policy
We may update this Privacy Policy as the product or the law changes. When we make a material change, we will update the "last updated" date above and, where appropriate, notify you by email or in the product. Your continued use of Muze CMO after an update means you accept the revised policy.
Contact
Questions, requests, or concerns about privacy? Email us at hello@muzecmo.com.