Privacy policy
Small tool, small footprint.
Last updated: 2 July 2026
co-muse ("we") is a quoting and booking tool for tattoo studios, operated from the EU and
available at co-muse.xyz. This policy explains what we store, why, and what
your rights are — whether you run a studio on co-muse or you're a client getting a quote from one.
What we store, and why
- Studio accounts. Studio name, sign-in email (when email verification is on),
your rate settings, and the pricing memory the tool learns from the hours you log. This is the
product working as intended.
- Quotes and bookings. The size/style factors behind each quote, the computed
price, and — when a booking is made — the client name and email the client or studio entered,
the appointment time, and the deposit amount. Studios need this record to run their bookings;
clients need it as proof of what was quoted and paid.
- Payments. Deposits are processed by Stripe. Card numbers
never touch our servers — we store only Stripe's references (session and payment identifiers),
the amount, and its paid/refunded state. Stripe's own
privacy policy applies to the checkout.
- Design reads. When a studio submits a reference image for an AI read, the image
is sent to Anthropic's Claude API to extract sizing factors and is not used by us for anything
else. We cache the extracted factors (not judgements about people) to avoid re-billing repeat reads.
- Operational logs. Standard server logs (IP address, request path, timing) kept
briefly for security and debugging — rate limiting, abuse prevention, incident forensics.
What we don't do
- No advertising, no tracking pixels, no analytics cookies. The only browser storage we use is a
session token so a studio stays signed in.
- We never sell or share data with third parties beyond the processors named above
(Stripe for payments, Anthropic for design reads, our hosting provider).
- Client emails are used for booking confirmations and proformas — never marketing.
Retention
Studio data lives as long as the studio's account does. Webhook event records used for payment
idempotency are pruned after 90 days, and expired unpaid quotes are removed once their validity
window lapses — both by an automatic daily sweep. When a studio's account is deleted (write to
privacy@co-muse.xyz), its rate card, memory, quotes and bookings go with it;
payment records at Stripe follow Stripe's retention rules.
Your rights
Under the GDPR (and equivalent laws), you can ask for a copy of your data, ask us to correct it,
or ask us to delete it. Clients can direct requests either to their studio (the controller of their
booking data) or to us. Write to privacy@co-muse.xyz and we'll respond within 30 days.
Security
All traffic is encrypted in transit (TLS). Studio access tokens are stored hashed. Deposits are
computed server-side so prices can't be tampered with, and payment webhooks are signature-verified.
If we ever suffer a breach affecting your data, we'll notify affected studios without undue delay.
Changes
If this policy changes materially, we'll note it here with a new date and flag it in the studio
console. Continued use after a change means you accept the updated policy.