Your art, your wall, your business.
Effective 28 August 2026 · Applies to the Wall Muse app for iPhone and iPad and to wallmuse.tv
Wall Muse is built to need as little of your data as possible. There are no accounts, no advertising, no tracking across apps, and no analytics profiles. This page describes the small amount of information the app does handle, in plain language.
The short version
- Photos you hang travel directly from your phone to your TV over your home network. They never touch our servers.
- When you create artwork with words, your prompt (and reference photo, if you attach one) is sent to our server and passed to an image generation service just long enough to paint the piece. We do not store prompts, reference photos, or the artwork.
- We count how many artworks you create against your allowance using an anonymous, random identifier. It is not your name, email, Apple Account, or advertising ID.
- We never sell or share your information for advertising.
What never leaves your home
Hanging a photo is a local affair. Wall Muse prepares the image on your device and sends it straight to your Samsung Frame TV over your Wi‑Fi network. Your photo library is only accessed when you pick a photo, using Apple’s picker, and your photos are stored only on your device. Wall Muse asks for Local Network permission solely to find and talk to your TV.
What is sent when you paint with words
Creating artwork uses our generation service, which runs on Cloudflare. When you ask for a piece, the app sends:
- your prompt and chosen style;
- a reference photo, only if you attached one to guide the piece;
- a random device identifier (see below);
- if you subscribe to Pro or bought a Booster, your App Store purchase receipt, so the service can verify your allowance.
Our server forwards the prompt, style and any reference photo to Google’s Gemini API, which creates the image and returns it to your device. We use Google’s paid API, which under Google’s terms does not use your prompts or images to train its models. Our server keeps no copy of your prompt, reference photo, or the finished artwork; they pass through in memory and are gone when the piece arrives on your phone.
The one thing we do store
To run the free and Pro allowances, our server keeps a counter of how many artworks have been created by your device this period. The counter is keyed by a cryptographic hash of a random identifier your app generated on first launch. From our side it is a meaningless string with a number next to it: it contains nothing about who you are, and we cannot connect it to you. Counters expire on their own after the period they cover.
Purchases
Payments are handled entirely by Apple; we never see your payment details. To verify a Pro subscription or Booster, the app presents its App Store receipt (a signed transaction) to our server, which checks Apple’s signature and reads only what it needs: the product purchased and its validity. We also use RevenueCat, a subscription infrastructure service, to keep subscription status reliable across reinstalls and devices. RevenueCat receives purchase information (product, price, dates) tied to an anonymous identifier, not your name or email. Their privacy policy is at revenuecat.com/privacy.
This website
wallmuse.tv is a static site served by Cloudflare. It sets no cookies and runs no analytics or trackers. Cloudflare processes visitor IP addresses transiently to serve and secure the site, as any host does. Fonts are served by Google Fonts, which receives the standard request data involved in loading a font file.
What we do not do
- No selling of personal information, and no sharing for advertising or cross-app tracking.
- No profiles: we could not build one if we wanted to; there is nothing to build it from.
- No reading of your photo library beyond the photos you explicitly pick.
Children
Wall Muse is not directed at children under 13, and we do not knowingly collect personal information from them. There are no accounts, so there is nothing for a child to sign up to.
Your choices and rights
- You can use the photo-hanging side of Wall Muse without ever sending anything to our servers.
- You can decline Local Network or photo permissions at any time in iOS Settings; the related features simply switch off.
- Deleting the app deletes your library and your device identifier; the anonymous usage counter on our side expires on its own and can no longer be associated with anything.
- Depending on where you live (for example under the GDPR or the Australian Privacy Act), you may have rights to access or delete personal information. Given how little we hold, the honest answer is usually that there is nothing to retrieve, but write to us and we will help: hello@wallmuse.tv.
Changes
If Wall Muse ever needs to handle more data than described here, this policy will be updated first and the effective date above will change. Material changes will be called out in the app’s release notes.
Contact
Wall Muse is made by Xavier Muhlebach. Questions about this policy: hello@wallmuse.tv.