Privacy, in plain English

What we hold, and what we don’t.

Musette is an early-access product used by a small number of UK families. This page describes what the software actually does today, in plain English. If something isn’t settled yet, we say that instead of guessing.

Last updated August 2026

Musette / trust

Less kept. More explained.

  • Uploaded school files are discarded
  • Optional photos stay private
  • No advertising or social trackers

Plain-English facts about the product as it works today.

Who we are

Musette is a small independent early-access product built and run by its founder in the UK. It is not yet a company with a filing cabinet of policies, and we’re not going to pretend otherwise. You can reach us from inside the app: Settings → Feedback & requests. That includes privacy questions and deletion requests.

Your account and household

  • Your email address and password (or your Google sign-in), held by our authentication provider. We never see or store your password ourselves.
  • A display name if you enter one, and the name you give another adult you invite.
  • Your household: which adults are in it (one or two), who owns it, and whether you told us you parent together or across two homes.
  • Your children’s first names and year groups, exactly as you type them. We ask for these so messages can be matched to the right child.
  • Invitations you create for another adult: the invite link’s token, an optional email address you typed, and whether it was accepted.

A family can be one adult or several. Each adult only sees the children shared with them, along with those children’s school items, the same “get ready” lists and the same children — that is the point of sharing. Neither adult can see the other’s email address in full: it is masked in the app.

The school messages you send it

You can paste text, add a screenshot or photo, or add a PDF letter. Here is what happens to each:

  • Uploaded school files are processed in memory and then discarded. We do not save the image or PDF bytes anywhere. (The only files we ever store are the optional profile photos described below.)
  • The full text of what you send is not stored either. What we keep is the structured result: the items found, plus a short quote (a “source snippet”) for each item so you can see where it came from.
  • Source snippets are visible in the app only to adults who can see that child. They are never included in calendar output.
  • We store a one-way fingerprint (a hash) of what you sent so that sending the same letter twice doesn’t create duplicate items. The hash cannot be turned back into the message.
  • The same is true of the per-item duplicate check. It compares a keyed code, made with a secret unique to your household and held in a separate vault, so even someone holding a copy of our database could not work out from those codes that “Avery — Year 6 trip — £50” exists.
  • We record housekeeping about each submission: which household, which adult, whether it was text, an image or a PDF, how many items came out, how long it took, and a generic error code if it failed.

How the AI part works

To turn a school message into a tidy list, Musette sends the content you submitted to a third-party AI model through the Lovable AI gateway (currently Google’s Gemini models). That means the content leaves our system to be processed by that provider. We cannot truthfully claim it is processed only on your device, or that no third party ever sees it — so we don’t.

  • We send only the content you chose to submit, plus your children’s names and year groups so the item can be matched to the right child.
  • We treat school content as untrusted data: instructions hidden inside a message cannot make the app do anything.
  • We do not store the prompt we sent or the raw response we got back. We store the validated result.
  • We record how many tokens a request used, so we can watch cost and quality. No content is recorded with it.
  • We do not control how the AI provider handles data under Lovable’s gateway terms. If your school messages are sensitive beyond ordinary school admin, don’t send them.

Calendar sync

If you connect your calendar, we create a private subscription link. The link contains a secret that only you ever see: we store a hashed version, so we cannot reconstruct your link. Anyone holding that link can read your approved school dates, so treat it like a password — and you can revoke and replace it in Settings at any time.

  • Only approved, dated items appear in the feed. Ignored, deleted and sample items never do.
  • New calendar links hide the details by default: entries say “School event” and give the date, nothing more. Including your child’s name, amounts and notes is a choice you make deliberately, and you can change it later.
  • Entries never carry a location, and never carry the original school wording.
  • We count how often the feed is fetched, to stop abuse, and record when it was last fetched.
  • If you leave a household, your subscription link is revoked automatically.

Optional photos of your children and yourself

You can add a photo to a child or to your own name so it is instantly obvious who an item is about, and who is handling it. Photos are entirely optional — initials work exactly the same everywhere.

  • Photos are stored privately. There is no public link: the app hands out a temporary, expiring link only after checking you are in that household.
  • Every photo is rebuilt as a small square image before it is stored, and we check and strip camera metadata such as location on our side too. We do not keep the original file or its file name.
  • Photos are never sent to the AI that reads school messages, and we do no face detection, face recognition or any other inference on them.
  • Photos never appear in analytics, calendar output or anything shared outside your household.
  • You can remove a photo at any time in Children or Settings. Removing a child removes its photo too.
  • Your own photo belongs to your account, not to a household. If you leave a household, the other adult stops seeing it — we don’t delete it. If you ask us to delete your account (still a manual request), your photo is deleted with it.

Email forwarding

Forwarding school emails to Musette is not switched on. There is no live inbound address, nothing is receiving your mail, and the endpoint is disabled in the code. When we turn it on, we’ll say so clearly in the app first.

Analytics

We measure how the product is used so we can improve it. It is coarse and internal. We do not sell data, we do not run advertising, and there are no third-party advertising or social tracking scripts in the app.

  • What we record: counts and coarse labels — sessions, which screen you entered on, device type (phone/tablet/desktop), how you first arrived (campaign tags and referring site), which buttons were pressed, how many items an extraction produced, and whether a plan preference was chosen.
  • What we never record in analytics: school message content, source snippets, child names, event titles, email addresses, calendar links or secrets, uploaded files, or anything from your browser storage.
  • Analytics rows are linked to your household and user id so we can tell whether real families are getting value. They are visible only to the founder, in an internal dashboard.
  • Sessions from our own preview environment are excluded so we don’t contaminate real numbers.

Feedback you send us

When you use Feedback & requests, we store the category you chose, the message you typed and the coarse screen name you were on. We deliberately do not attach school content, child names, event titles, screenshots, source snippets or anything from your session. The founder reads these to support you — that’s the whole point — and they are kept separate from analytics.

Where it all lives

The app and its database run on managed cloud infrastructure (Supabase for the database and authentication, Cloudflare for serving the app, and the Lovable AI gateway for extraction). We haven’t yet published a formal subprocessor list or a confirmed set of hosting regions, so we’re not going to state one here. Ask us and we’ll tell you what we know.

How long we keep things

Your account, your household, your children and your school items stay until you ask us to delete them. Duplicate-detection fingerprints are used on a rolling 30-day window for the “same letter twice” check.

The school’s own wording does not stay forever, though — a nightly job clears it out on a schedule we actually enforce in code:

  • The short quote kept with each item (the “source snippet”) is cleared after 30 days. The item itself — what it is, when it is, who it’s for — stays.
  • Wording held on tonight’s jobs and prep steps is cleared after 30 days.
  • Pending “is this the same thing?” comparisons are cleared after 90 days.
  • The change history behind an item keeps only what changed after 180 days, not the old wording.

We have not yet set fixed retention clocks for internal housekeeping records like analytics rows and ingestion logs. Rather than promise a period we don’t enforce in code, we’ll tell you honestly: they persist for now, and deleting your account removes the records tied to you.

Deleting, correcting, and asking questions

You can edit or delete individual items, children, invites and calendar links yourself at any time. For your whole account, go to Settings → Feedback & requests and choose Delete my account and data. That raises a real request with the founder, who will confirm by email and carry it out. We do that by hand at this stage rather than giving you a one-tap button that might quietly break the household for anyone else in it — and we won’t pretend a request is instant deletion when it isn’t.

You can also ask what we hold about you, ask us to correct it, or object to how we use it, through the same route.

Children

Musette is for parents and carers, not children. Accounts are for adults. The only information we hold about a child is the first name and year group you type in, plus the school items you choose to add.

Changes

This is an early-access product and this page will change as the product does. If something material changes about what we collect, we’ll tell the beta families directly. The early access terms sit alongside this.