Effective date: July 21, 2026 Last updated: August 21, 2026
This Privacy Policy explains how MuseumLog collects, uses, shares, and protects information when you use the MuseumLog mobile application (the “App”).
Data controller: Alex Zhang, operator and data controller for MuseumLog, based in California, United States. Contact: museumlog.app@gmail.com.
Where the App is offered: the App is offered in the United States, in the countries of the European Union / European Economic Area, in the United Kingdom, and in Switzerland. Section 9 describes your rights under the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection (FADP), and the legal bases we rely on.
If you do not agree with this policy, do not use the App.
With your opt-in consent — asked once during onboarding and changeable anytime in Profile → Privacy & Data — we collect product-analytics events through PostHog to understand how the App is used and where it can improve. If you decline (or simply never agree), no analytics events are collected or transmitted, and the App works identically.
When you have opted in, analytics events record what you did, never what you wrote or photographed. Each event carries a fixed event name (for example, that a scan started, completed, or failed) and a limited set of pre-approved, structured properties: platform, app version and build, which part of the App an action started from, the scan mode, which evidence tier identified an artwork, whether you had to correct the result, which type of daily Learn lesson was shown, a coarse duration range (for example “3–10 seconds” rather than an exact timing), a general error category, and small counts such as how many photos you selected. PostHog records the time it receives each event; the App does not attach its own timestamps, and analytics events carry no identifiers linking them to a specific artwork, note, or feedback submission.
Once you sign in, events are associated with your account identifier — the same random identifier your account already has in our database. This means opted-in analytics events are linked to your account, and you can ask us to delete them (Section 8). No other identifying field is ever attached: we do not send your name, your email address, or any profile information to PostHog.
Analytics events never include: your artwork photos or any image data, text read from wall labels, your personal notes, the text of feedback submissions, your location or GPS coordinates, storage links to your photos, authentication tokens, or anything you type in free-form. We have configured PostHog so that it does not record sessions or screens, does not capture screenshots, does not record your network requests or console output, and does not infer your location from your IP address. Your IP address is still processed transiently by PostHog in order to receive the events.
Anything you do before answering the consent question is discarded — it is not stored, not queued, and not sent later. Opting in starts the record from that moment forward; it does not reach back over your earlier activity. If you sign out or delete your account, the analytics identifier on your device is reset.
We do not use third-party advertising SDKs and we do not collect data for cross-app tracking.
We do not use your personal information for third-party advertising, and we do not sell it.
Artwork recognition and content generation are the core function of the App and depend on third-party AI providers. Before your first scan, the App shows a disclosure and asks for your permission; nothing is transmitted to AI providers until you agree, and declining simply leaves the photo unscanned on your device. When you scan an artwork, the photo you submit (a cropped scan image) is transmitted to one or more of the following providers for processing:
| Provider | Purpose | Data sent |
|---|---|---|
| OpenAI (GPT models) | Artwork identification from images — the primary recognition engine | Your scan image(s), including any label/placard photo, and the museum context relevant to the scan |
| Anthropic (Claude models) | Artwork recognition and verification from images; generation and translation of art-history content; daily Learn lessons about artworks you logged; short museum descriptions generated from the museum’s own public website; automated moderation of reviews and replies you publish and of feedback you submit (Section 4.1) | Your scan image; artwork/artist text and context from your logs; the text of reviews, replies, and feedback you submit |
| Google Cloud (Vertex AI) | Image embeddings used to match your scan against known artworks, where visual-matching features are enabled in your build | Your scan image |
When the App generates a short description of a museum, Anthropic’s retrieval tooling fetches that museum’s public website on our behalf; that request contains the museum’s website address only, never your personal data.
Scan images are transmitted to these providers either directly within the processing request or via short-lived signed links to a private, access-controlled storage area. We do not send your name, email, or account details to AI providers with your images.
AI-generated descriptions and lessons about artworks are produced from retrieved sources (such as Wikipedia and museum databases) and may be stored and shown to you and, for shared canonical artworks, to other users. Daily Learn lessons that are instead generated from the visual analysis of your own scan (used when an artwork has no shared reference record) never include your personal notes or your photo itself, are stored keyed to your own log entry, and are shown only to you.
We also use these non-AI service providers and data sources:
| Provider | Purpose | Data sent |
|---|---|---|
| Supabase | Database, authentication, file storage, and serverless functions (our backend) | Account data, user content, photos, usage counters |
| Expo (Expo Application Services) | Delivering app updates and, if you enable notifications, delivering push notifications | Standard technical data (such as IP address) when the App checks for updates; your device’s push token, only if you turn notifications on |
| PostHog | Opt-in product analytics (Section 2.3) | Structured usage events, app/device info, and your account identifier — only after you opt in; never photos, label text, notes, feedback text, location, name, or email |
| Geoapify | Finding museums and art venues near you | Your approximate device coordinates |
| OpenStreetMap (Overpass API) | Fallback nearby-venue lookup | Your approximate device coordinates |
| Apple Maps Server API | Fallback nearby-venue lookup | Your approximate device coordinates |
| Apple App Store (in-app purchases) | Processing payments and verifying purchases (Section 2.2) | Your account identifier, attached to the purchase as its app account token; transaction identifiers. Payment details are handled by Apple under Apple’s privacy policy and never reach us |
| Wikipedia / Wikimedia / Wikidata | Retrieving factual information and public images about artworks and artists | Artwork/artist names only — no personal data |
| Art Institute of Chicago API and other museum open-data sources | Artwork reference data and images | Artwork queries only — no personal data |
| Apple / Google sign-in | Authentication, if you choose those sign-in methods | Handled under Apple’s and Google’s own privacy policies |
Each provider processes data under its own privacy policy. We share only what is needed for the feature you are using.
When you publish a community review or reply, that content becomes visible to other users, and app-store rules require that objectionable content be filtered before it appears. Feedback you submit through the in-app form is delivered privately to us rather than published, but it passes through the same automated check before delivery. In both cases the content is checked automatically before it goes anywhere.
What happens. The check runs in two stages. The first is entirely on our own servers and uses no AI: a list of prohibited terms and simple pattern checks (for example, contact details or links). If that stage is inconclusive, the text is sent to Anthropic for an automated assessment of whether it harasses, threatens, or targets a person, exposes someone’s private information, or is spam.
What is sent. Only the text you submitted, whether it is a review, a reply, or a feedback submission, and — for reviews — the title and artist of the artwork being reviewed, so the assessment can tell that writing about a violent or explicit painting is a description of the artwork. Your name, email address, account identifier, location, and photographs are never sent for moderation.
What we keep. The outcome (publish, hold for review, or do not publish), the categories it matched, a confidence score, and a fingerprint of the text. We do not store the AI system’s reasoning or any free-text explanation about you.
What it can and cannot do. The automated check decides whether one piece of content is published, held, or refused. It cannot restrict, suspend, or ban you — only a human reviewer can do that, and every such decision is recorded. Private notes and unpublished drafts are never moderated and never sent anywhere.
If you disagree. Content that is not published stays in your account and can be edited and resubmitted. To ask a person to look at a decision, email museumlog.app@gmail.com; we will review it manually.
Where the GDPR or UK GDPR applies, we rely on our legitimate interests in keeping shared spaces safe and in meeting app-store obligations (Article 6(1)(f)). This automated check does not produce legal or similarly significant effects concerning you within the meaning of Article 22, and a human decision is available on request as described above.
We share personal information only:
Important note on photos: artwork photos attached to your log are stored in a storage bucket whose URLs are publicly readable. This means anyone who obtains a photo’s URL can view that photo without logging in. Photo URLs are long and randomized, but you should not attach photos you would not want to be publicly accessible.
We do not sell personal information and have not sold personal information in the preceding 12 months. We do not “share” personal information for cross-context behavioral advertising as defined by California law.
You can use the App without creating a named account; in that case we create an anonymous account identifier on your device (Section 1). Because such an account has no email address or sign-in method attached, you cannot recover it on another device and we have no way to contact you about it. We therefore delete inactive anonymous accounts, and everything attached to them, on the following schedule:
Inactivity is measured from your last sign-in. Opening the App refreshes it, so an account you keep using is never removed. If you add a sign-in method — Apple, Google, or email — the account stops being anonymous and these schedules no longer apply; it is then retained like any other account, until you delete it.
Deletion under this schedule removes the same data as an account deletion you request yourself, including the photos you uploaded.
To request deletion, see Section 10.
No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you as required by applicable law.
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent.
If you are in the EU/EEA, the data controller is Alex Zhang, operator and data controller for MuseumLog (contact details in Section 14). We rely on the following legal bases for each processing purpose:
| Processing purpose | Legal basis |
|---|---|
| Creating and operating your account, syncing your data | Performance of a contract |
| Recognizing an artwork from a photo you submit (including sending the photo to the AI providers in Section 4) | Performance of a contract |
| Storing your artwork log, notes, photos, collections, and favorites | Performance of a contract |
| Finding museums near you when you use nearby discovery (with your device location permission) | Performance of a contract — the feature runs only when you invoke it and have granted the permission |
| Reading photo metadata (EXIF location and date) to tag your own log entries | Performance of a contract |
| Personalizing Learn content from your in-app activity | Performance of a contract |
| Security, abuse prevention, and fair-use limits | Legitimate interests (protecting the service and all users; assessment available on request) |
| Essential operational logging | Legitimate interests |
| Optional product analytics (Section 2.3) | Consent — asked during onboarding, off unless you agree, withdrawable anytime via the permanent toggle in Profile → Privacy & Data |
| Responding to support and rights requests; legal compliance | Contract / legal obligation |
You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time (withdrawing is as easy as granting: device permissions can be revoked in iOS Settings — a shortcut is in Profile → Privacy & Data). Withdrawal does not affect processing that already happened.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA country where you live or work. A list of authorities is at edpb.europa.eu.
We are assessing the appointment of an EU representative under GDPR Article 27 and a UK representative under UK GDPR Article 27; if appointed, the representatives’ names and contact details will be published here.
If you are in the United Kingdom, the same rights and legal bases described in Section 9.1 apply under the UK GDPR and the Data Protection Act 2018, with Alex Zhang as controller. You may lodge a complaint with the Information Commissioner’s Office (ICO) — ico.org.uk. Transfers of your data to the United States are protected as described in Section 12, including the UK Addendum / UK extension mechanisms.
If you are in Switzerland, we process your personal data in accordance with the Swiss Federal Act on Data Protection (FADP). You have equivalent rights of access, rectification, erasure, and objection, exercisable via the contact in Section 14, and you may contact the Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch. Transfers abroad rely on the safeguards in Section 12 as recognized for Switzerland.
You have the right to know, delete, correct, and to opt out of sale/sharing. We do not sell or share personal information as defined by the CPRA. We do not discriminate against you for exercising rights.
We will honor applicable rights requests.
To exercise any right, contact museumlog.app@gmail.com. We may need to verify your identity (e.g., confirming control of the account email) before acting on a request. We will respond without undue delay and within the time required by applicable law (for GDPR requests, within one month, extendable for complex requests with notice).
You may delete your account and associated data at any time using Delete Account in the App (Profile → Settings → Account), or by emailing museumlog.app@gmail.com from your account email with the subject “Delete my account.” Deletion removes your profile and user content as described in Section 6. Deleting your account does not cancel an active subscription (manage or cancel it in your Apple ID settings), and purchases tied to the deleted account cannot be transferred to a new account. Refunds are handled by Apple under its policies.
The App is not directed to children, and you must be at least 18 years old to use it (see the Terms of Service). We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, contact museumlog.app@gmail.com and we will delete it.
Our servers and most of our service providers are located in the United States (our primary database is hosted in the AWS us-east-1 region). If you use the App from the EU/EEA, the United Kingdom, or Switzerland, your personal data is transferred to and processed in the United States.
For these transfers we rely on the safeguards recognized under Chapter V of the GDPR for each provider: certification under the EU-U.S. Data Privacy Framework where the provider is certified, and the European Commission’s Standard Contractual Clauses incorporated in our data processing agreement with the provider otherwise. For the United Kingdom we rely on the corresponding UK mechanisms (the UK Extension to the Data Privacy Framework where the provider is certified for it, or the UK International Data Transfer Addendum to the SCCs); for Switzerland, on the Swiss recognition of these mechanisms (including the Swiss-U.S. extension of the Data Privacy Framework where applicable) with the adaptations required by the FDPIC. The per-provider mechanism is listed below and kept current; you can request details at museumlog.app@gmail.com.
| Provider | Role | Transfer safeguard |
|---|---|---|
| Supabase (hosting, database, storage, auth) | Processor | Data processing agreement incorporating the EU Standard Contractual Clauses |
| Anthropic | Processor | Data processing addendum incorporating the EU Standard Contractual Clauses; Anthropic does not train models on API data |
| OpenAI | Processor | Data processing addendum incorporating the EU Standard Contractual Clauses; OpenAI does not train models on API data by default |
| Google Cloud (Vertex AI) | Processor | Certified under the EU-U.S. Data Privacy Framework; Cloud Data Processing Addendum with EU Standard Contractual Clauses |
| Geoapify | Processor | EU-established provider (Geoapify GmbH, Germany) with EU hosting — no third-country transfer by us |
| PostHog (opt-in analytics only) | Processor | Data processing agreement incorporating the EU Standard Contractual Clauses (US hosting) |
Requests to Wikipedia, Wikidata, and museum open-data APIs contain artwork queries only, not your personal data.
We may update this policy from time to time. Material changes will be communicated in the App or by email before they take effect. The “Last updated” date at the top reflects the latest revision. Continued use after changes take effect constitutes acceptance.
Alex Zhang, operator and data controller for MuseumLog museumlog.app@gmail.com
EU representative (GDPR Article 27) and UK representative (UK GDPR Article 27): appointment in progress; details will be published here.