Privacy
What RigMuse stores, where it stores it, who else can see it, and how to get rid of it. Written from the code, not from a template.
Last updated 27 September 2026.
Who runs this. RigMuse is operated by All4 Agency, in Italy.RigMuse is operated by its owner. Registered at . Company number . VAT . Questions about anything on this page, or a request about your data: . Support phone: . To ask about anything on this page, or about your own data, use the account you signed up with — your profile corrects and deletes it without going through anyone.
The short version
- No trackers, no advertising. The only visit counting is Cloudflare’s Web Analytics, which counts page views without cookies (details below). Nothing else on this site reports your visit. That is why there is no cookie banner.
- One cookie, and only once you sign in: the one that keeps you signed in.
- Designs you make are private unless you publish them yourself. Many never leave your browser at all.
- You can delete your account yourself, from your profile, and it takes your files with it.
What is stored, and where
Your account
| Name, email address, plan | Needed to have an account at all. Your name is shown beside any comment you write; your email address never is. |
|---|---|
| Profile photo | Optional. If you add one it is public — it appears next to your comments, at an address anyone can open. |
| Password | Stored only as a scrypt hash. We cannot read it. |
| Google sign-in | If you use it, Google gives us your email address, name and picture, and we keep the tokens Google issues, encrypted. |
| Facebook Page connection | Optional, and only if you use Share → Facebook or Instagram in the studio, or Publish on the Social page. We keep the names of the Pages and Instagram accounts you connected and the access token Meta issues for each Page, encrypted, until you disconnect them from the same sheet or delete your account. We never see your Facebook password. |
| YouTube channel connection | Optional, and only if you use Share → YouTube in the studio, or Publish a video post on the Social page. We keep the channel's name and picture and the lasting permission Google issues to upload to it, encrypted, until you disconnect it from the same sheet or delete your account. We never see your Google password. |
| Sessions | One row per signed-in browser, so you stay signed in. Expires after seven days of not being used. |
Your designs
This is the part worth reading carefully, because designs live in two different places and the difference matters.
| In your browser only | Every design you open in the studio is kept in this browser's own storage. Signed out, that is the only copy — we have no access to it, and clearing your browser data destroys it. |
|---|---|
| In your account | When you are signed in, each design is kept in your account as you work: the layered file, a small preview image, and what the studio adds to it — its motions, its 3D stage, the characters, places and props in it with their reference photos, and its sound — so it opens complete on your other devices. Private to you. |
| Your uploads | Only the pictures you add with Uploads in the studio. Each is kept in your account, private to you, with a small preview, and counts toward your plan's storage, so you can use it in any design on any device. Deleting one in the same tab removes it from your account; the designs you put it in keep their own copy. |
| Shared with people you invite | Only if you invite them. The people you add can open the design — to view it, or to edit it and save it back — and see each other's names. An invitation is one email we send to the address you type. If you open the design's link to "anyone with the link", anybody holding the link can view it, without an account, until you close it again. While you have a shared design open, the people on it — and anyone signed in who opens it through its open link — see that you are there, where your pointer is on the page and which layer you have selected; that passes through our server as it happens and is not stored. Somebody who opens it only through the link appears to the others as a number, not by name, and their own pointer is shown to nobody. |
| An AI assistant you connect | Only if you connect one — by pressing Connect in ChatGPT or Claude and allowing it on the page RigMuse shows, or by giving an assistant a personal token from the MCP page. Then the assistant can see the design you have open in the studio — its layers, its words and a picture of the page — and change it, while that page is open; each change is one step you can undo. It can also put new designs in your gallery and, when you ask it to, post to the Facebook and Instagram pages you connected to RigMuse. When a design it makes names a picture on a website that will not let your browser read it directly, our server fetches that one picture for you and hands it straight to your studio — the website sees our server, not you, and nothing is kept. What it reads passes through our server to your assistant as it happens and is not stored. What your assistant then does with it is between you and that assistant's maker. Disconnect it, or revoke the token, on the MCP page and it stops. A connection keeps a record of which app you connected and when, until you disconnect it. |
| Published to the community | Only if you choose it. Publishing copies the whole layered file to a public address anyone can open and download. You can unpublish it again. |
Things you write
Comments are public, under your display name. Reactions and saved items are private to your account. Notifications are generated by the site itself. On the Social page, what you write about your business, the logo, colours and photos you add there (kept small, and never sent to the writing assistant) and every post in your calendar are kept in your account, private to you, until you delete them or the account. A design made for a post is a design like any other: in your gallery and your account. The design rules you keep from the studio's Design chat are kept in your account the same way; the conversation itself stays in this browser.
Security records
We keep a short record of things that look like attacks on accounts: a failed sign-in, a rate limit, a wrong admin key, and each use of a personal API token. Each entry holds the time, what happened, and the IP address it came from. It exists so that if something happens to your account there is something to look at. It is capped at roughly 20,000 entries and older ones fall off the end.
What never reaches us
RigMuse no longer asks you for AI provider keys; a key you saved in an earlier build stays in your browser only and is never read. The projects on the Storyboard page also stay in your browser (the characters and photos you add inside a studio design travel with that design, above). If you use a browser extension or a local tool with RigMuse, we see nothing of it.
Who else is involved
| Cloudflare | Sits in front of the site and stores the files. Handles every request, so it sees your IP address. Files are stored in the European Union. If “Remove background” is set to use the cloud model, the one layer you are cutting out is sent to Cloudflare for that; it is deleted straight after and the studio tells you which model ran. Cloudflare also counts visits for us (Cloudflare Web Analytics): a small script it adds to each page reports which page was opened, the site you came from, your browser and device type, your country and how fast the page loaded. Cloudflare says this uses no cookies or local storage and does not follow you from site to site. |
|---|---|
| Only if you choose “Continue with Google”. Google then knows you signed in to RigMuse. | |
| Google Gemini | Only if you press Enhance, Design or Rebuild or write in the Design chat in the studio, or Plan, Write again, Make design or Design all on the Social page. The picture of your design and the words you typed for it — in the Design chat, the conversation, the words and places of the layers on the page, what you wrote about your business and the design rules you keep there; on the Social page, what you wrote about your business, your notes for the month, the words of the pages you linked there (our server opens those pages itself when you press Plan or Write again, the way any visitor would), your posts and the words printed on the templates chosen for them — are sent to Google’s Gemini API to write captions, a plan, or the words on a design. We use Google’s free tier, whose terms let Google keep what is sent and use it to improve its products — so put nothing private in a caption or a brief you send that way. The buttons do nothing until you press them. |
| Tavily (web search) | Only if you write in the studio’s Design chat and the answer needs a fact from the web — a fixture, a date, a price. The few search words the assistant chose (for example “Morocco next match September 2026”) go to Tavily, which searches the web and sends back the pages it found. Nothing else goes: not your design, your account or your messages. |
| fal.ai | Only if you use image generation. Your prompt and any reference image you attach are sent to fal.ai (Features and Labels, Inc.), which runs the model. We ask fal not to keep the request, and the finished image is returned to your browser rather than stored on fal’s servers; where a file does land there it expires within an hour. fal’s terms let it use anonymised or aggregated data derived from what is sent to improve its services. |
| Stripe | Only if you buy a plan. Stripe takes the payment and receives your email and card details directly — RigMuse never sees your card number. No payment code runs on this site. |
| Meta (Facebook, Instagram) | Only if you connect a Facebook Page and post a design from the studio or the Social page. The design you post and its caption go to Meta, which publishes them on your Page or Instagram account under its own terms. For that, the picture sits at a public, unguessable address on our storage so Meta can fetch it — from the moment you post or schedule it until the post is up, or until you unschedule it — and is removed then. |
| Google (YouTube) | Only if you connect a YouTube channel and send a video from the studio or the Social page. The video, its title and its description go to Google, which publishes them on your channel under its own terms; a video scheduled from the Social page is sent at once and YouTube keeps it private until its time. The file passes through our server and is deleted there once YouTube has it. |
| Poly Haven | Only if you open Props → Library, the HDRI tab of a 3D stage’s Light, or the Build card’s walls, floors and materials in the studio. Your browser asks Poly Haven (polyhaven.com) directly for its lists of free 3D models, HDRIs (the light of real places) and materials, their pictures and the files of the pieces you place, the materials you give a wall or a floor, or the place you light a stage with, so Poly Haven sees your IP address. Nothing of your designs is sent to it. |
| Our own server | A single machine we rent, in Europe. |
That is the whole list. Apart from Cloudflare’s visit counter above there is no analytics provider, no advertising network, no session recorder, no chat widget, and no other third-party font or script loaded on the main app.
Cookies
One, set only when you sign in, holding the token that keeps you signed in. It is removed when you sign out. Cloudflare may set its own cookie to tell people from bots. Nothing here is used to follow you anywhere, which is why you are not being asked to consent to anything.
Your browser also keeps preferences on your own device — your theme, your last view, your saved items. That is storage on your machine, not something we hold.
How long we keep it
Until you delete it. We do not expire designs, comments or accounts on a timer, and rather than invent a retention period we do not enforce, we would rather say plainly that removal is in your hands. The exceptions are the ones with real limits: sessions expire after seven days, download links expire in five minutes, and security records fall off after about 20,000 entries.
What you can do
| See what we hold | Your profile shows your account; the Designs view lists your files. For anything else, ask — the operator block at the top of this page says how. |
|---|---|
| Correct it | Name and photo from your profile, at any time. |
| Delete your account | From your profile, yourself. It removes your designs and their previews, anything you published, your photo, your comments, your API tokens and your sign-in records. It cannot be undone. |
| Take a copy | Designs download one at a time from the studio. We do not yet have a one-click export of everything — ask, and we will put it together by hand. |
| Object or complain | Ask us first. You can also complain to the data protection authority of the country you live in — every EU country has one, and yours can act on a complaint about a service based in another. |
Deleting your account does not reach designs saved only in your browser — those are yours and always were. Clear your browser data for this site to remove them.
Why we are allowed to hold it
To give you the service you asked for (your account, your files) — that is the contract between us. To keep the service standing (the security records) — that is our legitimate interest in not being broken into, and yours in the same. Where the law requires records of a sale, to comply with it. We ask for nothing on the basis of consent, because we collect nothing that needs it.
Children
RigMuse is not intended for anyone under 16.
Changes
If what this page says about your data changes in a way that matters, the date at the top changes and signed-in members are told inside the app.
The operator block at the top is the exception: it is kept as a record we edit, not as text in the page, so that a company name or a contact address can be corrected the day it changes rather than the day someone remembers to publish it. Its date is its own, and it is not carried in the site's source history the way the rest of this page is.