Musterv0.9 BETASign in with GitHub

PRIVACY POLICY · DRAFT

Privacy Policy

What Muster stores, which other companies handle your data on the way, and how to have it deleted.

Draft — pending legal reviewThis page describes what Muster actually does today, so you can decide with the facts in front of you. It has not been reviewed by a lawyer and is not yet a binding agreement. The final version will replace it and carry a date.

What Muster stores

  • From GitHub sign-in: your GitHub id, name, email and avatar, to identify you on the account.
  • From the repositories you connect: repository names and the text of merged pull requests — title, description, commits, and the diff only where you turned diff reading on.
  • What Muster produces: release drafts, the excerpts that prove each line, and an audit record of every publication with who approved it.
  • Usage: the model, tokens and cost of each generation, shown to you under Usage and cost.
  • Billing: the Stripe customer and subscription identifiers. Card details stay at Stripe.
  • A session cookie, used only to keep you signed in. It is not readable by scripts on the page.

Who else handles it

  • GitHub — the source of the pull requests. Muster reads through the GitHub API and writes nothing back.
  • OpenRouter — pull request text is sent to OpenRouter, which routes it to the language model that writes the draft. Their retention rules are theirs; read them before connecting a private repository.
  • Stripe — payments and invoices for paid plans.
  • Slack and your email provider — only if you turn those destinations on, using the credentials you provide, and only to deliver a published release or a test.

What is public

Only what a person on your account approves and publishes: the changelog page and its RSS and JSON feeds, with the pull request references cited in each entry. Coverage, cost, ignored pull requests and internal notes never appear there.

Deleting your data

The account owner can delete the account from Settings. Access ends at once and published changelogs go offline. The audit log of past publications is kept, because it is the record that a publication happened and who approved it; the deletion screen lists what stays and why.

Still to be defined

  • The legal entity responsible for your data.
  • How long pull request text and generation records are kept after a release is published.
  • How to request a copy of your data, and the legal basis for each use.

Contact

Questions about these pages: contato@defina-o-email.invalid