MOuseios

MOuseios Terms of Service & Privacy Policy

Last updated: 7 August 2026 · Effective version: 2026-08-07

This document covers privacy. The licence grant, acceptable use, warranties and disclaimers, limitation of liability, indemnification, arbitration and class-action waiver, governing law, DMCA, and termination are in the End User License Agreement. Which document do I need?

This document explains how Mouseios, Inc. (“MOuseios,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you use the MOuseios mobile application, related website pages, account deletion tools, optional cloud generation features, optional model improvement features, paid features, subscriptions, credits, and related services that link to this Policy (collectively, the “Service”). MOuseios is a sketch-to-image creative application that lets you draw on a canvas and generate images using artificial intelligence models, with most creative processing occurring on your device unless you use specific server-side features described in this Policy. MOuseios does not currently offer or make available our goods or services outside of the U.S., nor do we monitor the behavior of any data subjects outside of the U.S. The Service is not directed to children under 13, and you must be at least 13 years old to use the Service.

Scope. At launch, access from the European Economic Area and the United Kingdom is intended to be geo-excluded, and we will publish a separate EU/UK privacy notice before offering the Service in those locations. This Policy is written for our current U.S.-only operations and does not address rights or legal bases that may apply if we later offer the Service in the European Economic Area, the United Kingdom, or other jurisdictions outside the United States. If our practices change or if we expand the Service to additional jurisdictions, we will update this Policy as required by applicable law.

1. Who We Are and How to Contact Us

1.1 Operator and contact

Mouseios, Inc. is the operator of the MOuseios Service. For privacy questions, requests, or complaints, you may contact us at . Our current mailing address is 9431 Haven Ave, Suite 100 PMB 1048, Rancho Cucamonga, CA 91730, USA. We may provide additional contact methods in the Service, on our website, or in app-store listings.

2. Personal Information We Collect

2.1 Account identity

We collect account identity information when you sign in to the Service using Google or Apple sign-in. This information may include your Firebase user ID, email address, display name, and, for Google sign-in, profile photo URL, as provided by your sign-in provider. If you use Apple’s Hide My Email feature, we may receive and use the private-relay email address associated with your account. We use this information to create and authenticate your account, associate your account with server-side records, apply your settings, process account deletion, support paid features, and protect the Service from abuse.

2.2 Sketch and drawing data

We collect and process sketches and drawing information when you use the Service to draw. This information may include the shape of your strokes, x and y positions on the canvas, color, tool type, brush size, stroke count, drawing duration, capture time, and related sketch metadata. Depending on your device and input tool, the Service may also capture pen, finger, or stylus dynamics, such as pressure, tilt, orientation, per-point timing, velocity, rhythm, and related drawing signals. By default, your sketches, prompts, generated images, and related creative content are stored in the app’s private storage on your device and are not transmitted to us unless a specific server-side feature described below applies.

2.3 Prompts and generation data

We collect prompts, tags, and generation metadata when you use the Service to generate images. Prompts and tags are the words or labels you provide to guide a generation. Generation metadata may include the model version, prompt and negative prompt, random seed, step count, guidance scale, image-to-image strength, whether generation ran on device or in the cloud, and inference duration. We use this information to provide the Service, render your gallery, reproduce or improve results, operate optional cloud generation if you choose to use it, and support model improvement only as described in Section 5.

2.4 Device, diagnostic, and in-app analytics data

We collect device and technical information to operate, secure, and improve the Service. This information may include device manufacturer and model, operating system version, app version, coarse session context, network type, battery level, thermal state, and similar technical signals. We use Firebase Crashlytics to receive crash and stability reports, which may include crash stack traces, technical diagnostics, device model, operating system, app version, and a Crashlytics installation identifier. We do not intentionally include your sketches, prompts, generated images, pen dynamics, email address, or Firebase user ID in Crashlytics reports. We also use TelemetryDeck GmbH, Germany, for in-app analytics. TelemetryDeck receives anonymized behavioral events only, such as app feature interactions and coarse usage events; Mouseios salts and hashes user identifiers before transmission to TelemetryDeck, and TelemetryDeck does not receive drawing content, prompts, generated images, or pen, finger, or stylus dynamics.

2.5 Approximate region

We collect approximate region information when the Service contacts our servers. Our infrastructure provider may derive an approximate country or region from your network connection, including your IP address. We do not collect GPS location or precise location for ordinary Service operation. We use approximate region information to apply the correct privacy defaults, maintain records of your choices, and protect the Service.

2.6 Purchases and subscriptions

We collect purchase and subscription information if you buy a subscription, credits, or other paid features. This information may include your Spark balance, trial or promotional grants, redemptions, purchase events, subscription status, transaction or event identifiers, product purchased, and related account identifiers. Purchases made in the iOS or Android app are processed by Apple or Google, and web purchases may be processed by Stripe, with subscriptions managed through RevenueCat. Payment card details entered at web checkout go directly to Stripe, and we do not receive or store your full payment information.

2.7 Cookies and similar technologies

The Service does not use marketing or advertising cookies, retargeting pixels, or similar tracking technologies. On our website and Pro page, we may use strictly necessary browser storage for Firebase Authentication and a RevenueCat subscriber cache needed to provide account, checkout, and subscription-management functionality. We use Plausible Insights OÜ, Estonia, on a hosted plan for cookieless website analytics served first-party from the Mouseios domain; Plausible does not use cookies or personal identifiers and provides aggregate traffic and referrer metrics. If we later add advertising, retargeting, or similar tools, we will update this Policy and provide any notices or choices required by applicable law before using them.

3. How the On-Device Default Works

3.1 On-device default

MOuseios is designed to be on-device first. Your sketches, pen or stylus dynamics, prompts, generated images, and generation metadata ordinarily remain in the app’s private storage on your device. This local creative content is not available to us unless you use a feature that sends it to our servers or to a service provider acting on our behalf. Uninstalling the app removes local app data stored on your device, although uninstalling the app does not necessarily delete server-side account records or cancel subscriptions.

3.2 Server-side features

Certain features require or may involve server-side processing. These include sign-in, model-improvement settings, model-improvement contributions if enabled, optional cloud generation if used, crash and stability reporting, purchase and credit ledger records, abuse prevention, and account deletion. We describe these server-side features in this Policy so that you can understand when your information leaves your device.

4. Pen, Finger, and Stylus Dynamics Are Not Used to Identify You

4.1 Drawing dynamics

The Service may collect pen, finger, or stylus dynamics as part of your drawing activity, including pressure, tilt, orientation, timing, velocity, rhythm, and related per-point drawing signals. We use these signals to help the Service understand the drawing process, support generation quality, and, if model improvement is enabled, improve our models. We do not use pen, finger, or stylus dynamics to identify you, authenticate you, recognize you, verify your identity, or create an identity template about you. We also do not collect retina or iris scans, fingerprints, voiceprints, or scans or records of hand or face geometry for identity recognition.

4.2 Not biometric information

Mouseios does not treat pen, finger, or stylus dynamics as biometric identifiers or biometric information because we do not use those signals to identify, authenticate, verify, or recognize a person or to create an identity template about a person. If we materially change our practices and begin using drawing signals to identify, authenticate, verify, or recognize a person, we will update this Policy and provide any notice or consent required by applicable law before doing so.

5. AI Model Improvement and Training

5.1 Model improvement setting

The Service includes a model-improvement setting called “Help improve our models.” When this setting is enabled, the Service may upload examples of your work so we can evaluate, train, fine-tune, test, secure, and improve MOuseios models and related systems. A model-improvement contribution may include your input sketch, generated image, raw ink strokes, pen or stylus dynamics, associated prompt, tags, generation metadata, device information, and a record of the applicable setting and consent text version at the time of contribution. When technically feasible, Mouseios de-identifies or removes account identifiers, email addresses, and other directly identifying information from model-improvement contributions before using them for model improvement; where removal is not technically feasible, we limit the information used to what is reasonably necessary for the disclosed model-improvement purposes. We use model-improvement contributions to improve image generation quality, safety systems, abuse prevention systems, model evaluation, and related product performance.

5.2 Training opt-out

You may opt out of future model-improvement contributions at any time in Settings → Privacy by turning off “Help improve our models.” Turning off this setting stops future contributions from being uploaded for model improvement. If you delete your account or request deletion of your data, we delete stored server-side model-improvement contributions associated with your account, subject to backup rotation and legal retention exceptions described in this Policy. Opting out or deleting your account does not undo model training that already occurred while your setting allowed contributions, and we do not attempt to reconstruct individual contributions from trained models or use trained models to identify you.

5.3 De-identified statistics

We may retain aggregated, de-identified, or anonymized statistics derived from model-improvement contributions if those statistics no longer identify you or your work. We maintain de-identified data in de-identified form and do not attempt to re-identify it except as permitted by law to test whether our de-identification measures work. We do not sell your model-improvement contributions. We do not use your creative content for model improvement unless the model-improvement setting allows that use at the time of contribution.

6. Optional Cloud Generation

6.1 Cloud generation requests

Some devices, versions, or paid features may offer optional cloud generation. If you use cloud generation, the Service sends your prompt and conditioning input, such as your sketch, to our servers or private inference backend so that the requested image can be generated and returned to you. Cloud generation requests require account identity for authentication, attribution, abuse prevention, rate limiting, and service integrity. Using cloud generation does not, by itself, add your work to the model-improvement training corpus.

6.2 Separation from training

Cloud generation is separate from the “Help improve our models” setting. We process cloud generation inputs to provide the generation you requested, operate the Service, prevent abuse, and maintain security. We retain cloud generation request data only as long as needed to produce and deliver your result and to operate the Service, including short-term abuse prevention, unless a longer period is required by law, security needs, or another lawful retention purpose. If cloud generation becomes unavailable in some versions or regions, this section applies only when cloud generation is offered and used.

7. How We Use Personal Information

7.1 Core service uses

We use account identity information to authenticate you, create and maintain your account, gate access to the Service, associate your account with settings and purchase records, support account deletion, and protect the Service from abuse. We use sketches, prompts, generated images, and generation metadata to let you draw, generate images, manage your gallery, reproduce results, and use the Service’s creative features. We use approximate region information to apply the correct privacy defaults and maintain a record of your choices. We use purchase and credit information to process purchases, maintain Spark balances, prevent duplicate grants, reconcile transactions, support refunds and chargebacks, and comply with tax, accounting, and fraud-prevention obligations.

7.2 Diagnostics and legal uses

We use diagnostic information to diagnose crashes, improve stability, maintain quality, and secure the Service. We use device and technical information to operate model performance features, support compatibility, apply rate limits, detect abuse, and maintain app integrity. We use model-improvement contributions only when the model-improvement setting allows that use. We use information as necessary to comply with law, enforce our terms, protect our rights, respond to legal process, prevent fraud, and support a merger, acquisition, financing, reorganization, bankruptcy, or similar corporate transaction.

8. How We Disclose Personal Information

8.1 Service providers

We disclose personal information and other service-related information to service providers that help us operate the Service. Google and Firebase may process account identity, authentication records, consent settings, contribution metadata, consent receipts, crash reports, and device integrity information. Cloudflare may process edge server traffic, object storage, approximate-region detection, rate limiting, model files, and model-improvement contributions if you participate. RevenueCat may process subscription and purchase management information, and Stripe may process payment details and billing information for web checkout. TelemetryDeck GmbH may process anonymized in-app behavioral events after Mouseios salts and hashes user identifiers before transmission; TelemetryDeck does not receive drawing content, prompts, generated images, or pen, finger, or stylus dynamics. Plausible Insights OÜ provides cookieless website analytics on a hosted plan served first-party from the Mouseios domain and processes aggregate traffic and referrer metrics without cookies or personal identifiers. Apple and Google may process in-app purchases as independent platform providers under their own terms and privacy policies. Some service providers may process information in the United States, the European Union, or other jurisdictions where they or their subprocessors operate.

8.2 Legal and cloud disclosures

We may disclose prompts, sketches, and related request data to our private cloud inference backend when you use optional cloud generation. We may disclose information when required by law, legal process, or government request, or when we believe disclosure is necessary to protect rights, safety, security, users, or the Service. We may disclose information in connection with a corporate transaction, subject to appropriate safeguards and applicable law. We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising.

9. Your Choices and Controls

9.1 Model improvement opt-out

You can opt out of future model-improvement contributions by opening Settings → Privacy and turning off “Help improve our models.” This opt-out stops future uploads for model improvement, but it does not undo training that already occurred while your setting allowed contributions. You can delete your account in the app by going to Settings → Delete Account. If you cannot access the app, you can email from the email address associated with your Google or Apple sign-in account with the subject “MOuseios account deletion request.”

9.2 Local data and subscriptions

You can uninstall the app to remove local app data stored on your device. Uninstalling the app does not automatically delete server-side account records if those records exist, and deleting your account does not automatically cancel active subscriptions. You must cancel subscriptions through the channel where you purchased them, such as Apple ID settings, Google Play subscriptions, or the web subscription portal linked from your purchase receipt. You may also contact us at to ask privacy questions or submit requests.

10. Account Deletion and Data Deletion

10.1 Server-side deletion

When you delete your account in the app, we delete the server-side account data we maintain for your account, including your authentication account, model-improvement consent setting, stored model-improvement contributions, contribution metadata, and credit ledger records, subject to exceptions described in this Policy. Stored model-improvement contributions may include contributed sketch images, generated images, raw strokes, pen pressure, tilt, timing, and related metadata if those contributions were uploaded while the model-improvement setting allowed it. We may retain purchase, subscription, transaction, tax, accounting, refund, chargeback, fraud-prevention, legal, and security records for the period required or permitted by law. Residual copies in encrypted backups, if any, are purged on our providers’ standard backup-rotation schedules. See the account-deletion page for step-by-step instructions.

10.2 Limits of deletion

Deleting your account removes stored server-side contributions, but it does not un-train models that were already trained while your settings allowed contributions. A trained model does not store your contributions in a retrievable form, and we do not attempt to reconstruct or identify individual contributions from trained models. Sketches and generated images stored only on your device are not stored by us and are removed by uninstalling the app or deleting them locally through available app functions. Account deletion cannot be undone once completed.

11. Data Retention

11.1 Account and training retention

We retain account identity information for as long as your account exists, unless a longer period is required or permitted for legal, security, fraud-prevention, accounting, dispute-resolution, or compliance purposes. We retain your model-improvement setting and consent receipt while your account exists so that we can record and honor your choice. We retain model-improvement contributions for as long as reasonably useful for model development, evaluation, safety, or improvement, unless you opt out, delete your account, or request deletion in a manner that requires earlier deletion of stored contributions. We retain cloud generation request data only as long as needed to produce and deliver your result and operate the Service, including short-term abuse prevention, unless a longer period is required for legal, security, or dispute purposes.

11.2 Diagnostics and transaction retention

We retain Crashlytics and diagnostic reports for the limited period needed for stability analysis and Service quality. We retain purchase and credit ledger records while your account exists and, after deletion, only to the extent and for the period needed for tax, accounting, refund, chargeback, fraud-prevention, legal, or compliance obligations. We may retain aggregated, de-identified, or anonymized data without time limit if it no longer identifies you or your work. We delete, anonymize, or de-identify personal information when it is no longer reasonably needed for the purposes described in this Policy.

12. U.S. State Privacy Rights

12.1 State privacy rights

Depending on your state of residence and our legal obligations, you may have rights to request access to personal information we process about you, request correction of inaccurate personal information, request deletion of personal information, request a portable copy of personal information, opt out of certain processing, and appeal a decision regarding a privacy request. The exact scope of these rights varies by state and may be subject to exceptions. We do not sell personal information, share personal information for cross-context behavioral advertising, or use personal information for profiling that produces legal or similarly significant effects. If our practices change in a way that gives you additional opt-out rights, we will update this Policy and provide any required mechanisms.

12.2 Exercising rights

To request access to your data, or to otherwise exercise your privacy rights, you may use the in-app controls described in this Policy or contact us at . We may need to verify your request by matching the information you provide with information associated with your account. If you use Apple Hide My Email, we may need the private-relay email address associated with your account to locate and verify the account. An authorized agent may submit a request on your behalf by email, and we may require verification of the request and the agent’s authority as permitted by law.

13. Children’s Privacy and COPPA

13.1 Age screening and COPPA position

The Service is not directed to children under 13, and you must be at least 13 years old to use the Service. We may use age-screening or other reasonable measures to support this requirement. We do not knowingly collect personal information from children under 13. Because the Service is not directed to children under 13 and we do not knowingly collect personal information from children under 13, our current position is that the Children’s Online Privacy Protection Act does not apply to the Service. If we learn that we have collected personal information from a child under 13 without legally sufficient parental consent, we will delete that information as required by law and may suspend or terminate the account.

13.2 Parent or guardian requests

Parents or guardians who believe a child under 13 has provided personal information to us may contact us at . We may request information needed to locate the account and verify the request. We do not knowingly sell or share personal information of children or teens for cross-context behavioral advertising. If we later offer features directed to children or knowingly collect information from children under 13, we will update our practices to comply with COPPA and any other applicable children’s privacy laws before doing so.

13.3 Rights of teenagers and minors

Some U.S. states define a “minor” or “child” for data privacy purposes as an individual under 16, 17, or 18 years of age, or require parent or legal guardian consent for certain processing involving minors. If you reside in a state that sets a higher applicable minor threshold and you are under that threshold, you may use the Service only if your parent or legal guardian has reviewed this Policy and consented to your use of the Service on your behalf. By using the Service, you represent that you are at least 13 years old and, if you are under an applicable higher minor threshold in your state, that you are using the Service with valid consent from your parent or legal guardian. If we learn that a child under 13 or another minor under an applicable state threshold is using the Service without valid parental or guardian consent, we may suspend or terminate that account and delete associated personal information.

14. Security

14.1 Security measures

We use reasonable technical, organizational, and administrative measures designed to protect personal information in light of its nature, sensitivity, and our business operations. We protect data in transit using HTTPS/TLS. We also use account authentication, access controls, service-provider controls, diagnostic monitoring, abuse-prevention measures, and other safeguards appropriate to the Service. No security measure is perfect, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed without authorization.

14.2 Incident notices

If we experience a security incident that triggers legal notification obligations, we will provide notices as required by applicable law. U.S. breach notification requirements vary by state and may depend on the type of information involved, whether the information was encrypted, and whether misuse is likely. We may also take steps to investigate, remediate, preserve records, notify service providers, cooperate with law enforcement, and protect users and the Service. You are responsible for maintaining access to the email address and sign-in method associated with your account.

15. Third-Party Services and Platforms

15.1 Third-party services

Your use of Google sign-in, Apple sign-in, Apple App Store purchases, Google Play purchases, Stripe checkout, and other third-party services, and the Service’s use of in-app or website analytics providers such as TelemetryDeck and Plausible, may be subject to those third parties’ own terms and privacy policies. We receive certain information from these services to operate the Service, authenticate your account, manage purchases, reconcile transactions, support account deletion, and understand aggregate Service usage.

15.2 Third-party limitations

Although we select third-party services that we believe maintain acceptable privacy and security measures, we cannot guarantee the privacy practices, security measures, systems, or legal compliance of those third parties. We are not responsible for the privacy practices of third-party services that operate as independent controllers or independent businesses. You should review the privacy policies and settings of the third-party services you use with MOuseios.

16. Changes to This Policy

16.1 Policy updates

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date and provide additional notice or obtain consent where required by applicable law. If we materially change how we use personal information collected under a prior version of this Policy, we will handle that change in accordance with applicable law and our commitments to users. Your continued use of the Service after an updated Policy becomes effective means that the updated Policy applies to your use of the Service from that point forward, subject to your non-waivable rights under applicable law.

17. Contact Information

17.1 Contact and deletion requests

If you have questions about this Policy or our privacy practices, please contact us at . If you want to delete your account and can access the app, the fastest method is to use Settings → Delete Account. If you cannot access the app, email us from the email address associated with your Google or Apple sign-in account with the subject “MOuseios account deletion request.” If you used Apple Hide My Email, please use or include the private-relay address so that we can locate and verify your account.