The short version:

  • We collect your username, email, and content you create. We also log basic technical data (IP, browser type) for security.
  • We do not sell your data. We do not advertise. We do not track you across other websites.
  • We share data only with the providers that power the service: Cloudflare (file storage), OpenRouter (AI inference), Resend (email), Fly.io (hosting), and PostHog (product analytics).
  • You can access, correct, export, or delete your data at any time by visiting your account settings or emailing us.
  • If you are in the EU or UK, the full rights and legal bases are covered in Sections 2 and 6 below.

This summary is for convenience only. The full policy below is the legally binding document.

Privacy Policy

Effective Date: April 28, 2026  ·  Last Updated: July 1, 2026

This Privacy Policy describes how Strange Bytes LLC ("we", "us", or "our") collects, uses, and shares information when you use the Museris.com services (the "Service").

1. Information We Collect

We collect the following categories of personally identifiable information ("PII") when you register for or use the Service:

  • Account information — username and email address, provided by you at signup.
  • User-generated content — any content you create and upload through the Service, including associated media files.
  • API credentials — client credentials created when you connect an app to Museris Cloud.
  • Usage data — token quota consumption associated with your account when you use the Museris Cloud inference service.
  • Technical data — IP address, browser type, and request metadata collected automatically in server logs when you access the Service.
  • Product analytics — pages visited, feature interactions, device and browser information, and an internal account identifier when signed in.

✗  We do not knowingly collect information from anyone under the age of 13.

✗  We do not collect sensitive or special-category data — no health, biometric, racial or ethnic origin, political, religious, or sexual orientation data.

✗  We do not use your content to train AI models. Inference requests are routed to OpenRouter for processing; their data practices are governed by OpenRouter's privacy policy.

2. Legal Basis for Processing

We process your personal data only where we have a valid reason to do so:

  • Performance of a contract — processing necessary to provide the Service you have signed up for: creating and maintaining your account, authenticating your session, sending transactional emails (verification, password reset), enforcing your token quota, and routing inference requests to OpenRouter on your behalf.
  • Legitimate interests — processing necessary for our legitimate interests in operating a secure and reliable service: collecting server logs for security monitoring, diagnosing technical issues, and protecting against abuse. We only rely on this basis where those interests are not overridden by your rights and freedoms.
  • Legitimate interests — understanding aggregate product usage so we can improve usability, diagnose failed user journeys, and prioritize features. Analytics collection is limited to the Service and is not used for advertising or cross-site tracking.

Providing your username and email address is a contractual requirement. Without this information we are unable to create your account or provide the Service. All other data (user-generated content, usage data) is collected only as a direct result of your use of specific Service features.

3. How We Use Your Information

We use the information we collect to:

  • Operate, maintain, and provide the features of the Service.
  • Authenticate your identity and secure your account.
  • Send transactional emails such as email verification and password reset messages.
  • Track and enforce your token quota for the inference service.
  • Diagnose technical problems and maintain server security.
  • Understand feature usage and improve the Service.
  • Communicate material changes to this Privacy Policy or the Service.

4. Information Shared with Third Parties

We do not sell, rent, or trade your data. We share information only with the infrastructure providers that power the Service:

Cloudflare R2

File storage

Stores avatar images and other uploaded assets. Receives file content and associated metadata.

OpenRouter

AI inference routing

Receives your prompts and model selection when you use Museris Cloud. Subject to OpenRouter's own privacy policy.

Resend

Transactional email

Delivers account-related emails (verification, password reset). Receives your email address for this purpose only.

Fly.io

Cloud hosting

Hosts the API server. Server logs containing IP addresses and request metadata are stored on Fly.io infrastructure.

PostHog

Product analytics

Processes page views, feature interactions, device information, and an internal account identifier. We do not send account email addresses or usernames.

We may also disclose information if required by law, court order, or to protect the rights, property, or safety of Strange Bytes LLC, our users, or the public.

Business transfers. If Strange Bytes LLC is involved in a merger, acquisition, or sale of all or a portion of its assets, your personal data may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Service before your personal data becomes subject to a different privacy policy.

Third-party links. The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies when you leave our Service.

5. International Data Transfers

Strange Bytes LLC and the third-party service providers listed in Section 4 are based in the United States. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States, which may have data protection laws that differ from those in your country.

We take steps to ensure appropriate safeguards are in place for these transfers, including relying on processors that participate in recognized data transfer frameworks or have executed Standard Contractual Clauses where applicable.

6. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data. To exercise any of these rights, contact us at privacy@museris.com.

Access

Request a copy of the personal data we hold about you.

Rectification

Request correction of inaccurate data. You can update your username and email directly in your account settings.

Erasure

Request deletion of your account and associated personal data ("right to be forgotten").

Restriction

Request that we limit processing of your data in certain circumstances, such as while a correction request is pending.

Data portability

Request a structured, machine-readable copy of personal data you have provided to us.

Right to object

Object to processing based on our legitimate interests. We will cease unless we can demonstrate compelling overriding grounds.

Withdraw consent

Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.

Lodge a complaint

Where available in your jurisdiction, you have the right to lodge a complaint with your local data protection authority.

We will respond to verifiable requests within 30 days. We do not charge a fee for reasonable requests. To protect your data, we may ask you to verify your identity before fulfilling a request. We will not disclose personal data to any person who cannot be verified as the account holder.

7. Data Retention

We retain your account data and user-generated content for as long as your account is active. Upon account deletion, personal data is removed from active systems within 30 days; any residual copies in backups are purged on the backup rotation schedule.

Server logs containing technical data (IP addresses, request metadata) are generated and stored by our infrastructure providers as a normal part of operating internet services. We do not independently control log rotation for these systems; retention is governed by each provider's standard practices. See Section 4 for the list of infrastructure providers.

8. Cookies, Tracking, and Do Not Track

We use session cookies strictly necessary to maintain your authenticated session. Product analytics uses browser local storage rather than an analytics cookie to recognize repeat visits. We do not use advertising cookies, third-party advertising networks, or cross-site tracking.

Some web browsers transmit "Do Not Track" (DNT) signals. Because there is no accepted technical standard for responding to DNT signals, the Service does not alter its behavior based on them. Analytics is limited to activity within the Service and is not used to track you across other websites.

9. Security and Data Breaches

We use industry-standard measures to protect your information, including encrypted connections (HTTPS), password hashing, and protected API credential storage. We limit access to personal data to personnel and systems that require it to operate the Service. No method of transmission over the Internet is completely secure; we cannot guarantee absolute security.

We have procedures in place to detect, investigate, and respond to personal data breaches. Where we are legally required to do so, we will notify affected users and the relevant supervisory authority of a breach without undue delay.

10. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

11. Changes to This Policy

If we make material changes to this Privacy Policy, we will post a prominent notice on the Service before the changes take effect. The updated policy will identify a new effective date. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact privacy@museris.com