Privacy pages are easy to write and easy to get wrong, especially the one page whose entire job is being trusted. So here is the plain version of how Muse actually handles your data, with the two real exceptions named rather than buried.
Muse was built local-first. No account gates it, no server holds a copy of your library, and nothing about using the app day to day requires an internet connection. That much is true without qualification. Two specific features do reach the network, and the rest of this page is about exactly what they do and when they run.
No account, no sign-in, no cloud
Muse does not ask for an email address or a password when you open it for the first time. There is no account to create and no login screen to come back to if you forget one. What you save lives as ordinary files on your Mac, inside a folder called Muse Library that you can open in Finder like any other folder, alongside a small local database that holds titles, tags and which collections things belong to.
That is a genuine structural difference from a lot of the category. A web-based bookmark manager or a moodboard tool routes your saves through its own servers because that is how the product works: your library lives in their database, and you reach it by signing in. Muse's library lives on your disk. Move to a different Mac tomorrow and you would copy a folder across, not migrate an account.
Any collection can be written out as ordinary folders and files at any point, including after the 30-day trial ends. Getting your files back out never depends on buying the app.
Where does the built-in AI actually run?
On your Mac. Muse tags what you save automatically, reads any text it finds inside images so a screenshot of an invoice is searchable by typing part of the invoice, and pulls the dominant colours out of every picture. All three run using models installed with the app, and none of them need a network connection to work. There is no upload step, because there is nothing to upload to.
The optional Pro AI pack adds one more layer: search by meaning rather than by keyword, so a query like "quiet room with warm light" can return pictures that were never tagged with any of those words. Installing it downloads a set of model files once, and after that it also runs entirely on your Mac.
So what actually reaches the network?
Two features, and both are opt-in. Neither is needed to use Muse for saving, organising or finding things.
Muse Vision is a reverse image search. Point it at a picture and ask it to find visually similar images from around the web, and it sends that one image to a web visual-search service to run the search. It only happens when you invoke it on a specific picture, never as something running in the background.
The second is the optional Claude features. Add your own Anthropic API key in Settings, and certain writing and tagging tasks can run through Claude instead of on-device. That data goes to Anthropic under your own account, not to us, and it stays off unless you turn it on and supply the key yourself.
On-device by default: your library, its tags, its text and its colours. Two named exceptions when you choose to use them: Muse Vision sends one picked image to a visual-search service, and the optional Claude features send data to Anthropic under your own key.
How does the browser extension fit in?
The extension only does anything if the Muse app is open and running on the same Mac. When you save a page, an image or a link, it hands that one item to the app over a loopback connection, an address that only your own computer can reach and that never travels over the public internet. It does not read your browsing history, your passwords or anything on a page you have not chosen to save.
What Muse tells us, and what it does not
The app records a small number of anonymous events: the app was opened, a trial started, a trial expired, a licence was activated. Those go to a self-hosted analytics server we run ourselves, purely so we know roughly how many people are using Muse and whether trials convert. They carry no identifier tied to you and no detail about what you actually save. What is in your library, its titles, its tags, its images, stays out of that reporting entirely.
So, is Muse private?
By the definition that matters: no account, no cloud copy of your library, and the AI Muse ships with running on your own machine. That covers everything most people mean when they ask. The honest answer also names the two places the line moves, because a privacy page that hides them is not worth reading. Muse Vision and the optional Claude features are both opt-in, both named here, and neither is required to get value out of the app.
The full detail, including data retention and your rights, is in Muse's own privacy policy. Read it if you want the complete picture. This page is the short version, written to be precise rather than reassuring.
Frequently asked
Do I need an account to use Muse?
Does Muse send my images or screenshots anywhere?
What does Muse Vision actually do, and can I avoid it?
Can the browser extension see my browsing history?
What does Muse's usage analytics actually record?
A library that stays exactly where you put it
Free for 30 days. Then $29 once, and it is yours.