Effective date: September 1, 2026
Version: 2.0
Part of: the Muza Privacy Notice (appmuza.com/info/privacy) and the Terms of Service (appmuza.com/info/terms)
Company details. In this document, "Company", "we", "us" and "our" refer to:
Legal name: ONCREATE LTD, a limited liability company organized under the laws of Ukraine
Registered address: 31V Serhiia Podolynskoho Street, Dnipro, 49069, Ukraine
Privacy requests: [email protected]
1. Purpose of this page and how to read it
Muza is built on top of third-party infrastructure, AI models, data sources, software development kits (SDKs) and business tools. This page identifies the categories of third-party services we rely on and names the principal providers currently used or that may be used within each category, so that you can understand who may process data in connection with the Service and under which terms. It supplements the Privacy Notice, which describes what data is processed, why and on what legal basis.
Please read the following carefully:
- Providers change. We add, replace and remove providers, models, SDKs and integrations regularly, for quality, cost, availability, security, legal and product reasons. A provider named here may not be in use at any given moment, and a provider within a listed category may be used before this page is updated. We update this page periodically and, where a change involves a new category of recipient or a materially different kind of processing, we update the Privacy Notice.
- Current information in the App. Where the law or an App Store Provider requires it, the App tells you, at the point where you enable a feature (for example a consent screen before cloud AI processing or face and voice features), which categories of providers are involved at that time. The App and this page together are the current source of that information.
- What providers receive. Providers receive only the data needed for their role. AI Providers receive the Inputs needed for a request (for example a photo, video, audio clip, prompt or brand description), but not your email address, account credentials or payment details; they may see names and other details contained in the Inputs themselves. Files are passed to providers through links to our cloud storage that are not publicly listed and expire after a short period. Analytics, attribution and advertising providers receive usage events and identifiers, not the content of your files.
- Their terms apply to them. Each provider processes data under its own privacy terms and under our contract with it. Links to provider terms are given for convenience; the current versions are published on the providers' own websites and may change without our involvement. Where a provider offers a setting to prevent the use of customer content for training AI models, we use it.
- Locations. Unless otherwise noted, providers are located in, or process data mainly in, the United States and the European Union; some infrastructure and model providers also operate data centers in Asia and other regions. Transfers are protected as described in Section 9 of the Privacy Notice.
- No additional obligations. This page is informational. It does not create obligations beyond those in the Terms of Service and the Privacy Notice, and, to the maximum extent permitted by law, we are not responsible for the practices, availability or security of third-party services, as explained in Section 10 of the Terms of Service.
2. Hosting, infrastructure, content delivery and security
| Provider | Role | Data | Terms |
| Google Cloud / Firebase (Google LLC and affiliates) | Authentication (email, Apple and Google sign-in), Realtime Database and Cloud Firestore (account, profile, projects index, characters, chat history, cached social data), Cloud Storage (uploads, synced files, brand assets), Cloud Functions (social growth back end), Cloud Messaging (push notifications), Remote Config (feature settings), App Check (App integrity) | Account and profile data, Your Content uploaded for cloud features, identifiers, push tokens | firebase.google.com/support/privacy, policies.google.com/privacy |
| Our own servers (the Company's back end at appmuza.com and related domains), hosted with infrastructure providers such as OVHcloud, Google Cloud and other hosting providers, in data centers located in the European Union, the United States and Asia | Accounts, devices, Subscriptions and Credits, promo codes, support requests, catalogs of Muza Content, AI request routing and task management, generation results | Account data, purchase records, Credit ledger, request logs, Inputs and Outputs in transit and temporary storage | Muza Privacy Notice; hosting providers act as our processors under their data processing terms (for example ovhcloud.com/en/personal-data-protection) |
| Cloudflare | Content delivery network, DNS, traffic security, bot protection and performance for the Website and our services | IP address, request metadata, security cookies on the Website | cloudflare.com/privacypolicy |
| Other infrastructure providers (object storage, databases, queues, monitoring, logging and backup services) | Operating and securing the Service | Technical data and, where necessary, Your Content in encrypted storage or backups | Their respective terms |
3. App distribution, sign-in and platform services
| Provider | Role | Data | Terms |
| Apple (Apple Inc. and affiliates) | App Store distribution, in-app purchases and subscriptions (StoreKit), Sign in with Apple, push notifications (APNs), App Attest and DeviceCheck, on-device frameworks (Vision, Core ML, Speech, Image Playground), SKAdNetwork and AdAttributionKit | Purchase confirmations, sign-in identity, device tokens, aggregated attribution values | apple.com/legal/privacy |
| Google (Google LLC and affiliates) | Google Play distribution and Google Play Billing (where the App is distributed through Google Play), Google Sign-In, Google Play services and on-device components such as ML Kit and MediaPipe | Purchase confirmations, sign-in identity, device tokens; ML Kit usage metrics may be reported to Google | policies.google.com/privacy, developers.google.com/ml-kit/terms |
| Other app distribution platforms that we may use in the future | Distribution and billing | Purchase confirmations | Their respective terms |
4. AI Providers (cloud generation and transformation)
AI Features are delivered through third-party AI infrastructure, model-hosting platforms, aggregators and model providers. Which provider handles a request depends on the feature and model you select and on our routing at the time; routing may change at any time without notice. Providers currently used or that may be used include:
| Provider | Typical role | Retention of Inputs and Outputs at the provider | Terms |
| Replicate | Hosting of image, video and audio models from multiple developers | Inputs, results and logs of API requests are deleted shortly after completion under the provider's terms | replicate.com/privacy |
| fal.ai | Hosting of image and video models | Under the provider's terms | fal.ai/privacy |
| OpenAI | Language models (AI Assistant, SMM Team, analysis and text generation), image generation and editing, speech recognition, website analysis | API inputs and outputs are not used for training under the provider's API terms; limited retention for abuse monitoring, then deletion | openai.com/policies/privacy-policy |
| Google (Gemini API and Vertex AI) | Multimodal language models, image generation, music generation | Under the provider's API terms for paid services, prompts and outputs are not used to improve Google products; limited retention for abuse monitoring | ai.google.dev/gemini-api/terms, policies.google.com/privacy |
| ElevenLabs | Text-to-speech, voice library, voice-related features, speech recognition | Under the provider's terms | elevenlabs.io/privacy-policy |
| Stability AI | Image generation, erasing, inpainting and outpainting | Under the provider's terms | stability.ai/privacy-policy |
| Luma AI | Image generation and stylization with character references | Under the provider's terms | lumalabs.ai/legal/privacy-policy |
| Segmind | Hosting of image and video models and workflows | Under the provider's terms | segmind.com/privacy |
| MuAPI | Hosting of selected image and video effects | Under the provider's terms | muapi.ai |
| Together AI | Hosting of selected models | Under the provider's terms | together.ai/privacy |
| Anthropic, Mistral AI, xAI, Amazon Web Services (Bedrock), Microsoft (Azure AI) and other AI infrastructure or model providers that we may use | Language, image, video or audio models | Under the provider's terms | Their respective terms |
Model developers. The providers above host or provide models developed by Black Forest Labs (FLUX), Google (Gemini, Imagen, Lyria), OpenAI (GPT, gpt-image, DALL·E, Whisper), ByteDance (Seedance, Seedream, SeedEdit, Dreamina), Kuaishou (Kling), MiniMax (Hailuo, MiniMax Speech and Music), Alibaba (Qwen, Wan), Runway (Gen-4), Ideogram, Recraft, Bria, Stability AI, Luma AI, Meta (MusicGen), TencentARC (PhotoMaker), ElevenLabs and other developers whose models we may add. Unless stated on this page, models are run on the infrastructure of the AI Provider listed above, and the model developer does not itself receive your data. Where we use a model through the developer's own API, that developer is an AI Provider for the purposes of the Privacy Notice.
Retention. Most AI Providers delete request data immediately after processing or within a limited period (typically up to 30 days) for abuse monitoring and reliability. The applicable period is stated in each provider's terms and may change; we do not control it.
5. Data Providers (Social Growth Features)
Providers currently used or that may be used include:
| Provider | Role | Data | Terms |
| Apify | Retrieval of publicly available profile, post, hashtag and trend data from social platforms, and rendering of public web pages, at your request | Social media handles you enter (yours and Reference Accounts), public profile and post data, website URLs | apify.com/privacy-policy |
| ScrapeCreators | Username lookup and suggestions while you type a handle | Partial handles and public avatars of matching accounts | scrapecreators.com |
| Official platform APIs (for example the Instagram Graph API of Meta Platforms) | Retrieval of public data of business and creator accounts through official interfaces, where available | Handles and public profile data | Platform terms (for example facebook.com/privacy/policy) |
| Other public data providers, web crawling services and search APIs that we may use | Retrieval of publicly available information at your request | Public information only | Their respective terms |
Muza is not affiliated with Meta, Instagram, Threads, TikTok, X, YouTube, LinkedIn, Pinterest or any other platform. We never receive or ask for your platform passwords.
6. Analytics, crash reporting, attribution, advertising and product tools
We use, or may use, the following tools and SDKs in the App and on the Website. On iOS, identifiers used for tracking across other companies' apps and websites are accessed only with your permission in the App Tracking Transparency prompt; in the EU, EEA, UK and Switzerland, analytics and marketing identifiers are used only with your consent where the law requires it.
| Provider | Role | Data | Terms |
| Google Analytics for Firebase, Firebase Crashlytics and Firebase Performance Monitoring | Product analytics, crash reporting and performance monitoring | Usage events, device and app information, installation identifiers, crash data | firebase.google.com/support/privacy |
| Amplitude, Mixpanel or similar product analytics tools | Product analytics and funnel analysis | Usage events, device information, pseudonymous identifiers | amplitude.com/privacy, mixpanel.com/legal/privacy-policy |
| RevenueCat, Adapty or similar subscription infrastructure | Subscription and purchase management, receipt validation, subscription analytics | Purchase and Subscription status, transaction identifiers, App Store account tokens, installation identifiers | revenuecat.com/privacy, adapty.io/privacy |
| Sentry, Bugsnag or similar error monitoring tools | Error and stability monitoring | Crash and error data, device information | Their respective terms |
| AppsFlyer, Adjust or similar attribution platforms | Install attribution, deep links (for example AppsFlyer OneLink), measurement of campaign performance, uninstall measurement | Device identifiers (IDFA only with your permission, IDFV), installation identifier, IP-derived location, events such as installs, paywall views and purchases, push token for uninstall measurement | appsflyer.com/legal/privacy-policy, adjust.com/terms/privacy-policy |
| Meta (Meta Business Tools and Facebook SDK) | Measurement and optimization of our advertising on Facebook and Instagram, aggregated event measurement, deferred deep links | App events (installs, paywall views, purchases with amounts), device identifiers subject to your permission, IP address | facebook.com/privacy/policy |
| Apple Ads (Apple Search Ads), Google Ads, TikTok for Business, AppLovin, Unity Ads, Snap, X Ads and other advertising networks and measurement partners | Measurement, attribution and optimization of our advertising campaigns; on-device or aggregated conversion measurement where available | Attribution tokens, conversion events, device identifiers subject to your permission | Their respective terms (for example searchads.apple.com/privacy, policies.google.com/privacy, applovin.com/privacy) |
| Google User Messaging Platform or another consent management platform | Collecting and storing consent choices in the App where required | Consent choices, installation identifier | Their respective terms |
| Website analytics and tag management (Google Analytics, Google Tag Manager, Meta Pixel, TikTok Pixel, Microsoft Clarity, Hotjar or similar) | Website analytics, session insights and marketing measurement, subject to cookie consent | See the Cookie Policy | See the Cookie Policy |
7. Communications, support and business tools
Providers currently used or that may be used include:
| Provider | Role | Data | Terms |
| SendPulse | Transactional emails (for example receipts, security notices, account emails) and, with your consent where required, marketing emails and newsletters | Email address, name, delivery and engagement data | sendpulse.com/legal/privacy-policy |
| Our own support systems (the Company's servers and API) | Handling in-app support requests, feedback, surveys and forms | Support communications, account and transaction identifiers, device details | Muza Privacy Notice |
| Firebase Cloud Messaging, Apple Push Notification service and, where used, OneSignal or similar | Push notifications and Live Activities | Push tokens, notification content and delivery data | firebase.google.com/support/privacy, apple.com/legal/privacy, onesignal.com/privacy |
| Google Workspace, Microsoft 365, Slack, Notion, Jira and similar business tools | Internal collaboration, ticketing and record keeping | Support correspondence and internal records | Their respective terms |
| Legal, accounting, tax and payment reconciliation services | Compliance and financial administration | Transaction records | Their respective terms |
8. Payments (direct purchases on the Website or other direct channels)
| Provider | Role | Data | Terms |
| Stripe | Payment processing for purchases made directly on the Website | Payment details (collected directly by the processor), billing address, transaction data | stripe.com/privacy |
| Paddle, PayPal, Apple Pay, Google Pay and other payment processors that we may use | Payment processing and, where applicable, merchant of record | Payment details (collected directly by the processor), billing address, transaction data | Their respective terms |
Payment processors act as independent controllers for the payment transaction itself. We do not store your full payment card details.
9. Content libraries, stock media and on-device components
Providers and components currently used or that may be used include:
| Provider | Role | Data | Terms |
| Unsplash | Stock photo search and download | Search terms, technical data | unsplash.com/privacy, unsplash.com/license |
| Pexels | Stock photo and video search and download | Search terms, technical data | pexels.com/privacy-policy, pexels.com/license |
| GIPHY | GIF and sticker search | Search terms, technical data | giphy.com/privacy, giphy.com/terms |
| Other stock, font, music and sound libraries that we may integrate | Search and download of licensed media | Search terms, technical data | Their respective terms |
| Google ML Kit and MediaPipe, Apple Vision, Core ML, Speech and Image Playground, TensorFlow Lite, PyTorch, OpenCV and other on-device frameworks and models | On-device analysis, editing, segmentation, speech recognition and generation | Processed on your device; for speech recognition in some languages Apple may process audio on its servers under Apple's terms; some SDKs may report usage metrics to their developers | apple.com/legal/privacy, developers.google.com/ml-kit/terms |
| Open-source software libraries and SDKs included in the App | Application functionality | No data is sent to the libraries' authors; notices are available in the App (Settings > Legal > Open Source Licenses) | Their respective licenses |
10. Questions
If you have questions about a provider on this page, or want to know which provider processed a specific request of yours, contact [email protected].