co-muse Legal · Privacy
Privacy policy

Small tool, small footprint.

Last updated: 2 July 2026

co-muse ("we") is a quoting and booking tool for tattoo studios, operated from the EU and available at co-muse.xyz. This policy explains what we store, why, and what your rights are — whether you run a studio on co-muse or you're a client getting a quote from one.

What we store, and why

What we don't do

Retention

Studio data lives as long as the studio's account does. Webhook event records used for payment idempotency are pruned after 90 days, and expired unpaid quotes are removed once their validity window lapses — both by an automatic daily sweep. When a studio's account is deleted (write to privacy@co-muse.xyz), its rate card, memory, quotes and bookings go with it; payment records at Stripe follow Stripe's retention rules.

Your rights

Under the GDPR (and equivalent laws), you can ask for a copy of your data, ask us to correct it, or ask us to delete it. Clients can direct requests either to their studio (the controller of their booking data) or to us. Write to privacy@co-muse.xyz and we'll respond within 30 days.

Security

All traffic is encrypted in transit (TLS). Studio access tokens are stored hashed. Deposits are computed server-side so prices can't be tampered with, and payment webhooks are signature-verified. If we ever suffer a breach affecting your data, we'll notify affected studios without undue delay.

Changes

If this policy changes materially, we'll note it here with a new date and flag it in the studio console. Continued use after a change means you accept the updated policy.