Privacy Policy

Effective Date: September 10, 2026Last Updated: September 10, 2026

This Privacy Policy describes how Misu Labs AB ("Misu", "we", "us", or "our"), registered in Sweden, collects, uses, stores, and shares personal data when you use the Misu platform at misu.agency (the "Platform").

We are the data controller for personal data processed in connection with your account and use of the Platform, as defined under the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679).

If you have questions about this policy or wish to exercise your data rights, contact us at: legal@misu.agency

1. What Data We Collect

We collect personal data in the following categories:

1.1 Account and Identity Data

  • Name, email address, and password (or third-party login credentials)
  • Company or brand name
  • Role within your organisation
  • Profile settings and preferences

1.2 Billing and Payment Data

  • Subscription plan, billing cycle, and payment history
  • Payment card details — collected and processed directly by our payment processor (Stripe); Misu does not store full card numbers
  • VAT or tax identification number (where provided)
  • Invoicing address

1.3 Uploaded Content

  • Product images, photographs, and visual assets you upload to the Platform
  • Brand guidelines, colour palettes, typography, and style references
  • Campaign briefs, creative direction notes, and project descriptions
  • Reference images used for style or composition guidance

Where Uploaded Content contains identifiable individuals (for example, a product photograph featuring a person), that content may constitute personal data. You are the data controller for such content and are responsible for the lawful basis on which you uploaded it.

1.4 AI Training Data

  • Product images used to train custom AI models (LoRA fine-tunes) on the Platform
  • Training outputs and model weights associated with your account

We do not use your Uploaded Content or Trained Models to train AI for any other brand, customer, or general-purpose model.

1.5 Generated Content Metadata

  • Prompts, settings, and parameters used in generations
  • Output images, videos, and edited assets and their metadata
  • Generation job logs (model used, credit cost, timestamp, status)

1.6 Usage and Technical Data

  • IP address, browser type, operating system, and device identifiers
  • Pages visited, features used, and session duration
  • API call logs and error logs
  • Performance and diagnostic data

1.7 Communications Data

  • Email correspondence with our team
  • Support requests and their content
  • Managed plan communications via dedicated Slack channel
  • Booking requests for Real Human Model talent

1.8 Integration Data

When you connect third-party platforms (Shopify, Meta, Google, TikTok, Snapchat, LinkedIn), we receive:

  • OAuth access tokens and connection status
  • Product catalogue data synced from Shopify
  • Analytics event data from connected marketing platforms

1.9 Real Human Model Likeness Data

The following applies to Real Human Model data:

  • Likeness data for Real Human Models is collected directly from the individual under a separate written agreement with Misu
  • Misu processes this data solely for the purpose of operating the Talent feature within the Platform
  • Brands that generate content using Real Human Model characters do not receive access to the underlying likeness training data — they receive only the Generated Content outputs
  • Real Human Models have the right to withdraw consent, subject to the terms of their individual agreement with Misu

2. Legal Basis for Processing (GDPR)

We process personal data under the following legal bases:

Processing ActivityLegal Basis (GDPR Art. 6)
Providing the Platform and managing your accountArt. 6(1)(b) — Performance of a contract
Processing subscription billing and paymentsArt. 6(1)(b) — Performance of a contract
Delivering the Managed ServiceArt. 6(1)(b) — Performance of a contract
Running LoRA training on your Uploaded ContentArt. 6(1)(b) — Performance of a contract
Sending transactional emails (account, billing, security)Art. 6(1)(b) — Performance of a contract
Detecting and preventing fraud, abuse, and security incidentsArt. 6(1)(f) — Legitimate interests
Improving Platform features, models, and performanceArt. 6(1)(f) — Legitimate interests
Keeping records as required by tax and accounting lawArt. 6(1)(c) — Legal obligation
Sending marketing and product update emailsArt. 6(1)(a) — Consent (withdrawable at any time)
Analytics and usage tracking (non-essential cookies)Art. 6(1)(a) — Consent (cookie banner)

For processing that relies on legitimate interests, you may object at any time (see Section 7).

3. How We Use Your Data

We use the data we collect to:

  • Provide and operate the Platform — including account management, generation jobs, training pipelines, campaign management, and asset library
  • Process billing — subscriptions, credit purchases, invoicing, and tax reporting
  • Deliver the Managed Service — assigning Creative Directors, managing briefs, delivering assets
  • Operate the AI model agency — processing booking requests, confirming talent usage, and delivering generations using Platform Talent
  • Maintain and improve the Platform — fixing bugs, improving generation quality, developing new features
  • Ensure security — detecting abuse, fraud, and unauthorised access
  • Communicate with you — account notifications, billing updates, support responses, product news (where consented)
  • Meet legal obligations — tax records, responding to lawful requests from authorities

We do not sell your personal data. We do not use your Uploaded Content, Trained Models, or Generated Content to train general-purpose AI models offered to third parties.

4. Sub-Processors and Third Parties

To deliver the Platform, we share data with the following categories of sub-processors. All sub-processors are contractually bound to process data only on our instructions and in accordance with GDPR requirements.

4.1 Infrastructure and Authentication

  • Supabase (Database, authentication, storage) — EU / US
  • Vercel (Application hosting and CDN) — US / Global

4.2 AI Generation and Training

  • FAL.AI (Image/video generation, editing) — US
  • Replicate (LoRA product model training and inference) — US
  • Anthropic (AI agent services) — US
  • OpenAI (Ad copy generation, analysis, enhancement) — US

Data shared with AI providers: Prompts, generation parameters, and Uploaded Content used as inputs for generation or training jobs. We share the minimum data necessary for each operation. We maintain data processing agreements with each AI provider.

4.3 Observability and Analytics

  • Braintrust (LLM call tracing, cost tracking, prompt versioning) — US

4.4 Marketing Platform Integrations (User-Activated)

When you choose to connect these platforms, data is exchanged:

  • Shopify (Product catalogue, image push)
  • Meta (OAuth token, campaign assets)
  • Google (OAuth token, campaign assets)
  • TikTok (OAuth token, campaign assets)
  • Snapchat (OAuth token, campaign assets)
  • LinkedIn (OAuth token, campaign assets)

You connect these integrations voluntarily. Disconnecting an integration via your account settings ends data exchange.

4.5 Payments

  • Stripe (Payment processing, subscription management) — US / EU

4.6 Legal Disclosures

We may disclose personal data to law enforcement, courts, or regulatory authorities where required by applicable law or a valid legal process. Where permitted, we will notify you before complying.

5. International Data Transfers

Several of our sub-processors are located in the United States or operate globally. When we transfer personal data from the European Economic Area (EEA) to countries without an EU adequacy decision, we rely on:

  • Standard Contractual Clauses (SCCs) (Commission Implementing Decision (EU) 2021/914), incorporated into our data processing agreements with each recipient
  • EU-US Data Privacy Framework where the recipient is certified

A list of our sub-processors and the applicable transfer mechanisms is available on request at legal@misu.agency.

6. Data Retention

We retain personal data for as long as necessary for the purposes described in this Policy, or as required by law.

Data CategoryRetention Period
Account and identity dataDuration of account + 30 days after closure
Billing and payment records7 years (tax/accounting legal obligation)
Uploaded ContentDuration of account, or until you delete it
Trained ModelsDuration of account, or until you delete the product
Generated ContentDuration of account, or until you delete the asset
Generation and usage logs12 months rolling
Support and communications3 years from last interaction
Real Human Model likeness dataDuration of the individual's agreement with Misu

After the applicable retention period, data is securely deleted or anonymised.

7. Your Rights Under GDPR

If you are located in the EEA, UK, or Switzerland, you have the following rights regarding your personal data:

  • Right of Access (Art. 15) — You can request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16) — You can ask us to correct inaccurate or incomplete data.
  • Right to Erasure (Art. 17) — You can ask us to delete your data in certain circumstances (e.g., where we no longer need it, or where you withdraw consent). Deletion requests will be honoured within 30 days, subject to legal retention obligations.
  • Right to Restriction (Art. 18) — You can ask us to restrict processing in certain circumstances while a dispute is resolved.
  • Right to Data Portability (Art. 20) — You can request your data in a structured, machine-readable format for transfer to another service, where processing is based on contract or consent.
  • Right to Object (Art. 21) — You can object to processing based on legitimate interests. We will stop unless we demonstrate compelling legitimate grounds.
  • Rights Related to Automated Decision-Making (Art. 22) — The Platform does not make legally significant automated decisions about you. If this changes, we will update this Policy and provide appropriate rights.
  • Right to Withdraw Consent — Where processing is based on consent (e.g., marketing emails, non-essential cookies), you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at legal@misu.agency. We will respond within 30 days. We may ask you to verify your identity before processing a request. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

EU/EEA supervisory authority: Integritetsskyddsmyndigheten (IMY)

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on the Platform and landing site.

Current status: as of the date above, only Strictly Necessary and Functional cookies described below are active (e.g. session authentication and interface preferences). Analytics and Marketing cookies are not currently in use. This section will be updated, and a cookie consent banner introduced, before any such cookie becomes active.

8.1 Types of Cookies

CategoryPurposeConsent Required
Strictly necessarySession management, authentication, securityNo
FunctionalUser preferences, language, UI settingsNo
AnalyticsUsage statistics, feature performance (e.g. platform analytics)Yes
MarketingConversion tracking via Meta, Google, TikTok, Snapchat pixelsYes

8.2 Cookie Consent

Because only Strictly Necessary and Functional cookies are currently active, no cookie consent banner is presented at this time — these categories do not require consent under GDPR/ePrivacy. Once Analytics or Marketing cookies are activated, a cookie consent banner will be introduced on the landing site, letting you accept all, reject non-essential, or customise your choices before any non-essential cookie is set, with preferences changeable at any time via a cookie settings link in the footer.

8.3 Third-Party Pixels

Where you consent to marketing cookies, pixels from Meta, Google, TikTok, Snapchat, and/or LinkedIn may be active on the landing site. These providers process data under their own privacy policies. We recommend reviewing those policies if you have concerns.

9. AI-Specific Disclosures

9.1 LoRA Product Training

When you upload product images and initiate a training run, those images are sent to Replicate's API to fine-tune a custom AI model (LoRA). The resulting model weights are stored in your account and used solely to generate images of your product. Your product training data is not used to improve Replicate's general models beyond what is permitted under Replicate's data processing terms.

9.2 AI Agent Processing

When you use the Canvas, Wardrobe, or Generate Director features, your prompts and brand context are sent to Anthropic's Claude API and/or OpenAI's API for processing. These interactions may be routed through Braintrust for tracing and cost management where enabled. Prompts and outputs may be retained for debugging and quality purposes in accordance with each provider's data processing agreement.

9.3 AI-Generated Content and Real Persons

The Platform can generate synthetic images and videos featuring the likenesses of Real Human Models from the Talent roster. These generations are AI-produced and do not reflect the actual views, statements, or activities of the real person. Users are responsible for complying with applicable laws and platform policies on AI-generated content, including advertising standards and social media disclosure requirements.

9.4 EU AI Act Transparency

In accordance with Article 50 of Regulation (EU) 2024/1689 (EU AI Act), Misu will implement technically feasible measures to mark or disclose AI-generated content where required by law, particularly for synthetic content featuring real human likenesses. Where such obligations impose requirements on you as the downstream user, we will notify you in advance.

10. Children's Data

The Platform is intended for use by businesses and professionals aged 18 and over. We do not knowingly collect personal data from individuals under 18. If you believe a minor has created an account, please contact us at legal@misu.agency and we will delete the account promptly.

11. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. These include:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and role-based permissions within the Platform
  • Authentication security via Supabase Auth
  • Regular security reviews and vulnerability assessments
  • Sub-processor contractual security obligations

No system is entirely secure. If you become aware of a security incident involving your account, contact us immediately at legal@misu.agency.

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Art. 33–34.

12. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email and/or by displaying a prominent notice in the Platform at least 30 days before the changes take effect. The "Last Updated" date at the top of this page reflects the most recent revision.

Your continued use of the Platform after the effective date of an updated Policy constitutes acceptance of the changes. If you do not accept the updated Policy, you may close your account before the effective date.

13. Contact and Data Protection

For privacy-related questions, data subject requests, or complaints:

Misu Labs AB

Skeppsbron 38, 111 30 Stockholm, Sweden

legal@misu.agency