Who is responsible#
AHigh Lab inc. (NEQ 1149545080), a Québec company, operates the Canada Muse service. Our privacy officer (responsable de la protection des renseignements personnels) is the person with highest authority in the company, reachable at privacy@museai.ca. Every request under “Your rights” goes there and is answered within 30 days.
What we collect#
Account and billing: email, name, username, a modern password hash (argon2id — never the password itself), language, organization and plan. Payment runs on Stripe's hosted checkout: we never see or store your card number. Sign-in attempts are logged with IP address for security. Your workspace, isolated per tenant: conversations with your assistant and the memory built from them, files you upload or it creates, email received or forwarded to your Muse address including attachments, SMS relayed through your connected Twilio, your client records, and pages you build.
Voice#
Audio is transcribed and immediately discarded — we do not store recordings. Only the text transcript remains in your workspace. Transcription is performed by OpenAI Whisper.
What we don't do#
No tracking without your yes — museai.ca and app.museai.ca load no analytics and set no advertising cookies until you accept the cookie banner. If you accept, two Google tools load. Google's ad tag (Google Ads) sets first-party cookies to measure whether an ad click led to a sign-up. Google Analytics sets first-party cookies to count visits and show which pages are read — in aggregate, under a random identifier, not your name. Ad personalization is switched off for both, so your visit is not used for remarketing or an ad profile. Decline, or withdraw later from “Cookie preferences” at the bottom of museai.ca, and nothing loads — the cookies already set are deleted. Your choice itself is kept in one cookie (muse_consent) for six months. Separately, if you arrive from one of our ads, the click identifier Google puts in the link (gclid) is kept on your account when you sign up, and used for exactly one thing: telling Google Ads, after the fact, that a click led to a confirmed sign-up, a free trial or a first payment — the identifier, the event name, its time and amount, nothing else about you. No sale or rental of personal information. No pooling of data across tenants. And no training of shared AI models on your content — that's architectural (your own database), not a setting you have to find.
Why we use it#
To provide the service you asked for, process payments, secure accounts, meter usage against your credits, answer support, and meet legal obligations. Anything else gets separate consent. Two automated behaviours you should know about — a human decides everything with legal or significant effect: inbound email failing authentication (DMARC) or matching spam rules is filtered automatically and may not reach your assistant; and if credit enforcement is enabled, a depleted balance can pause paid features until you top up.
Who processes data for us#
Hosting is on AWS in Canada (ca-central-1) — databases, files, email. Disclosed exceptions: content delivery uses AWS's global edge network, and certain components (some model inference, TLS certificates, transactional email) operate from AWS US regions. To answer you, your messages are processed by frontier-model providers over their business APIs: Anthropic, OpenAI (also embeddings and voice transcription), and — when routed or chosen — xAI and other providers your configuration enables. Our default providers do not use API content to train their models under the terms we use; optional providers you explicitly enable are governed by their own terms. ElevenLabs synthesizes your assistant's voice from reply text. Simli renders the avatar. Stripe processes payments. With your consent only, Google measures whether an ad led to a sign-up (Google Ads) and how the site is visited (Google Analytics). Web searches your assistant runs are sent to search providers as queries. Connections you make — Google, Microsoft, Twilio, Zapier, your cloud — run under your own agreements, with credentials stored encrypted (KMS) and used only on your instruction.
If you connect a Google account#
Canada Muse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: we request the narrowest scopes that do the job, one at a time and only when you reach for the feature — Calendar to read and write the events you ask for; Gmail send-only to send the mail you ask us to send, never read access to your inbox; Contacts read-only to fill your client book with names and email addresses; Drive limited to files the app itself creates. We do not use Google user data for advertising, do not sell or transfer it, and do not use it to develop, improve or train generalized AI or machine-learning models. No one here reads your Google data except at your explicit request for a specific item, or where security or the law requires it. Tokens are encrypted (KMS) in your own tenant, never returned to your browser, and used only on your instruction. Disconnecting from the Integrations page revokes the token at Google and deletes our copy — you can also revoke at myaccount.google.com/permissions.
If you use the Muse browser extension#
The Muse extension for Chrome (and other Chromium browsers) is optional. It sends nothing on its own: when you click “Share this page with Captain” (or press its shortcut), it reads the visible text, title and address of that one tab — never form fields, passwords, cookies or page code — and sends it to your own workspace. Addresses are stored without query strings or fragments. Sign-in, payment, banking and account-security pages are refused by default. A shared page stays readable by your assistant for 24 hours (the last 20 are kept), and each share is logged with a fingerprint of its content, never the content itself. If you enable it for a site in Integrations, the extension can also fill in a reply you approved (you click Send on the real page) or, only during a 15-minute window you start, open and read the specific pages you allowed. To connect, the extension receives a device token from your workspace; it is stored in your browser, only its fingerprint is kept on our side, and you can disconnect any browser from Integrations at any time. The extension has no analytics, shows no ads, and its data is never sold or used to train models.
Where it lives, where it travels#
Your data is stored in Canada. Answering your requests involves processing in the United States by the model providers above — we say this plainly because Law 25 requires the assessment and you deserve the fact. We bind subprocessors to protect your data and process it only for us.
How long we keep it#
Workspace data is kept while your account is active — that persistence is the product. After closure or on a verified request, account and workspace data are deleted within 30 days, except what the law makes us keep: billing records (tax law, 7 years) and the minimal trace proving the deletion. A free start that never adds a card is paused after 7 days and deleted, assistant and data alike, 30 days after signup — we tell you twice before. Security logs are kept 12 months. Backups roll off within 35 days.
Security#
Encryption in transit everywhere (TLS). Integration credentials encrypted at rest with managed keys (KMS). Passwords hashed with argon2id. Strict tenant isolation: your own database with row-level security, per-tenant credentials, service tokens scoped to your tenant. Staff access is limited to operating and supporting the service. We keep a confidentiality-incident register; if an incident presents a risk of serious injury we notify the Commission d'accès à l'information and affected persons without delay, as Law 25 requires.
Your rights#
Write to privacy@museai.ca to: access what we hold about you, rectify it, withdraw consent, have your data deleted, receive the computerized personal information you provided in a structured commonly-used format (portability), or complain. We answer within 30 days. You may also complain to the Commission d'accès à l'information (Québec) or the Office of the Privacy Commissioner of Canada.
If you're a client of one of our customers#
If your courtier, host or service provider uses Canada Muse, they are responsible for your information and we process it on their behalf — including anything you submit through a form on a page they built, which is stored in their workspace and delivered to them. We route requests we receive to them, and help them answer. Their pages should carry their own privacy notice.
Children#
The service is for adults and businesses. It is not directed at minors under 14 and we do not knowingly collect their information.
Changes & contact#
This policy is dated, prior versions stay available, and material changes are announced by email and in the product before they take effect. Effective 2026-07-29 — this first complete policy replaces the earlier summary. Questions: privacy@museai.ca.
Write to hello@museai.ca. A human reads every message.