MusetteEarly access

Privacy

What we hold, and what we don’t.

Musette is an early-access product used by a small number of UK families. This page describes what the software actually does today, in plain English. If something isn’t settled yet, we say that instead of guessing.

Last updated August 2026

Who we are

Musette is a small independent early-access product built and run by its founder in the UK. It is not yet a company with a filing cabinet of policies, and we’re not going to pretend otherwise. You can reach us from inside the app: Settings → Feedback & requests. That includes privacy questions and deletion requests.

Your account and household

  • Your email address and password (or your Google sign-in), held by our authentication provider. We never see or store your password ourselves.
  • A display name if you enter one, and the name you give another adult you invite.
  • Your household: which adults are in it (one or two), who owns it, and whether you told us you parent together or across two homes.
  • Your children’s first names and year groups, exactly as you type them. We ask for these so messages can be matched to the right child.
  • Invitations you create for another adult: the invite link’s token, an optional email address you typed, and whether it was accepted.

A household can be one adult or two. Where there are two, both see the same school items, the same “get ready” lists and the same children — that is the point of sharing. Neither adult can see the other’s email address in full: it is masked in the app.

The school messages you send it

You can paste text, add a screenshot or photo, or add a PDF letter. Here is what happens to each:

  • Uploaded files are processed in memory and then discarded. We do not save the image or PDF bytes anywhere — there is no file storage in this product at all.
  • The full text of what you send is not stored either. What we keep is the structured result: the items found, plus a short quote (a “source snippet”) for each item so you can see where it came from.
  • Source snippets are visible only to the two adults in your household inside the app. They are never included in calendar output.
  • We store a one-way fingerprint (a hash) of what you sent so that sending the same letter twice doesn’t create duplicate items. The hash cannot be turned back into the message.
  • We record housekeeping about each submission: which household, which adult, whether it was text, an image or a PDF, how many items came out, how long it took, and a generic error code if it failed.

How the AI part works

To turn a school message into a tidy list, Musette sends the content you submitted to a third-party AI model through the Lovable AI gateway (currently Google’s Gemini models). That means the content leaves our system to be processed by that provider. We cannot truthfully claim it is processed only on your device, or that no third party ever sees it — so we don’t.

  • We send only the content you chose to submit, plus your children’s names and year groups so the item can be matched to the right child.
  • We treat school content as untrusted data: instructions hidden inside a message cannot make the app do anything.
  • We do not store the prompt we sent or the raw response we got back. We store the validated result.
  • We record how many tokens a request used, so we can watch cost and quality. No content is recorded with it.
  • We do not control how the AI provider handles data under Lovable’s gateway terms. If your school messages are sensitive beyond ordinary school admin, don’t send them.

Calendar sync

If you connect your calendar, we create a private subscription link. The link contains a secret that only you ever see: we store a hashed version, so we cannot reconstruct your link. Anyone holding that link can read your approved school dates, so treat it like a password — and you can revoke and replace it in Settings at any time.

  • Only approved, dated items appear in the feed. Ignored, deleted and sample items never do.
  • Privacy mode, if you switch it on, sends deliberately vague titles so nothing revealing sits in a shared calendar.
  • We count how often the feed is fetched, to stop abuse, and record when it was last fetched.
  • If you leave a household, your subscription link is revoked automatically.

Email forwarding

Forwarding school emails to Musette is not switched on. There is no live inbound address, nothing is receiving your mail, and the endpoint is disabled in the code. When we turn it on, we’ll say so clearly in the app first.

Analytics

We measure how the product is used so we can improve it. It is coarse and internal. We do not sell data, we do not run advertising, and there are no third-party advertising or social tracking scripts in the app.

  • What we record: counts and coarse labels — sessions, which screen you entered on, device type (phone/tablet/desktop), how you first arrived (campaign tags and referring site), which buttons were pressed, how many items an extraction produced, and whether a plan preference was chosen.
  • What we never record in analytics: school message content, source snippets, child names, event titles, email addresses, calendar links or secrets, uploaded files, or anything from your browser storage.
  • Analytics rows are linked to your household and user id so we can tell whether real families are getting value. They are visible only to the founder, in an internal dashboard.
  • Sessions from our own preview environment are excluded so we don’t contaminate real numbers.

Feedback you send us

When you use Feedback & requests, we store the category you chose, the message you typed and the coarse screen name you were on. We deliberately do not attach school content, child names, event titles, screenshots, source snippets or anything from your session. The founder reads these to support you — that’s the whole point — and they are kept separate from analytics.

Where it all lives

The app and its database run on managed cloud infrastructure (Supabase for the database and authentication, Cloudflare for serving the app, and the Lovable AI gateway for extraction). We haven’t yet published a formal subprocessor list or a confirmed set of hosting regions, so we’re not going to state one here. Ask us and we’ll tell you what we know.

How long we keep things

Your account, your household, your children and your school items stay until you ask us to delete them. Duplicate-detection fingerprints are used on a rolling 30-day window for the “same letter twice” check. We have not yet set fixed retention clocks for internal housekeeping records like analytics rows and ingestion logs. Rather than promise a period we don’t enforce in code, we’ll tell you honestly: they persist for now, and deleting your account removes the records tied to you.

Deleting, correcting, and asking questions

You can edit or delete individual items, children, invites and calendar links yourself at any time. For your whole account, go to Settings → Feedback & requests and choose Delete my account and data. That raises a real request with the founder, who will confirm by email and carry it out. We do that by hand at this stage rather than giving you a one-tap button that might quietly break the household for anyone else in it — and we won’t pretend a request is instant deletion when it isn’t.

You can also ask what we hold about you, ask us to correct it, or object to how we use it, through the same route.

Children

Musette is for parents and carers, not children. Accounts are for adults. The only information we hold about a child is the first name and year group you type in, plus the school items you choose to add.

Changes

This is an early-access product and this page will change as the product does. If something material changes about what we collect, we’ll tell the beta families directly. The early access terms sit alongside this.