← Back to home

Privacy Policy

Last updated: 2 October 2026

The short version: TinyMuse works without a sign-up. The photo you choose is sent to make the creation you asked for and is not kept by us or used to train AI. Your creations are stored only on your device. We keep a pseudonymous credit balance so your subscription and credits work across the phones you link.

This Privacy Policy explains how Orango Labs Ltd ("we", "us", "our") handles information in the TinyMuse mobile application (the "App"). By using the App, you agree to this policy.

1. Information stored on your device

The following is created and stored only on your device:

We cannot access this data, and it is removed if you delete the App. Linking another device (Section 5) copies only the account key, not your creations or baby details.

2. Information we receive automatically

Like almost all internet services, our servers automatically process limited technical information to deliver content and keep the service secure, such as your device's IP address, device type and the time of a request. This is used only to operate, secure and troubleshoot the service. To prevent abuse we keep daily request counters keyed by a one-way hash (for example, of an IP address when redeeming a device-link code).

3. Purchases, subscriptions and AI credits

TinyMuse Pro and credit packs are processed by Apple (App Store) or Google (Google Play). We never receive your payment card details. We use RevenueCat to confirm purchases using a pseudonymous account identifier (a one-way hash of your account key), so the App can unlock Pro and add credits. Their handling of your information is governed by their own privacy policies.

To run credits, our servers store a one-way hash of that identifier with your credit balance, a one-way hash identifying your Pro subscription (so credits follow it and each period is credited once), the store transaction IDs of credit packs already added, and a record of each generation (template, credits charged, status and the provider's job reference). These records never contain your photos or the generated results.

4. How creations are made

When you start a creation, the App sends the photo(s) you chose to our Cloudflare service, which passes them through OpenRouter to the AI provider for that template, solely to create what you asked for:

We do not store your photos, generated images or videos in our databases or file storage. Results are returned to the App and saved on your device until you delete them or save them to your photo library. Only submit a photo if you are the child's parent or guardian, or otherwise have permission to use it.

5. Your account and linked devices

TinyMuse has no sign-in. On first launch the App creates a random account key on your device; our servers only ever see it to verify requests and store a one-way hash of it. It is not linked to your name, email address or phone number.

If you choose "Link another device", the App shows a single-use QR code that expires after five minutes. We store a one-way hash of the code and your account key encrypted with that code, and delete these records within a day of expiry. Scanning the code moves the second device to the same account, so both share Pro and credits.

6. What we do not do

7. Children's privacy

TinyMuse is intended for parents and caregivers, who are adults, and is not directed to children. A parent or caregiver may submit a child's photo as described above; that processing is limited to fulfilling the adult's request, and the photo is not retained by us.

8. Data retention and deletion

Content on your device stays until you delete it or uninstall the App. Server logs are kept only as long as needed for operation and security. Photos and results are not retained by our servers. Hashed credit and generation records are kept while your credits may still be used, and device-link records are deleted within a day of expiry. To ask us to delete your credit records, contact us at the email below.

9. Security

We take reasonable technical measures to protect the App and our servers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Your rights

Depending on where you live, you may have rights under laws such as the GDPR or CCPA. To make a request about your credit data, contact us at the email below and we will respond as required by applicable law.

11. Changes to this policy

We may update this policy from time to time and will revise the "Last updated" date above.

12. Contact us

Questions about privacy? Email us at support@orangolabs.com.