MuninnMuninn

Privacy

What Muninn stores, where it lives, and what never happens to it. Last updated October 1, 2026.

What Muninn stores

Your inventory: the places, shelves, bins, and items you create, any photos you attach to them, optional details you choose to track (like value or serial numbers), and your account email and display name. If an import is bigger than your plan, the part waiting for Plus is kept too, until you add it or remove it. That’s the list.

Where it lives

In your household’s own database, hosted on Supabase, and in a local copy on each signed-in device so the app works offline. Access is restricted at the database level to your household’s members — row-level security enforced by the server, not just by the app.

The website and the app’s pages are served by Vercel, which keeps ordinary server logs (the address a request came from, and what it asked for). The emails that confirm an account or reset a password are sent through Resend, which sees your email address and that message.

The AI assistant

When you use Muninn AI — asking a question, importing items from a photo, or asking it to sort a list you pasted — the text of your question, the relevant inventory snapshot, and any photo you submit are sent to Anthropic, which runs the Claude models that produce the answer. The snapshot is your place, bin and item names together with their notes, their tags, and the values of any optional fields you have turned on — so if you record what something cost or where you bought it, that goes too. If you never use the AI features, nothing is ever sent.

Importing a spreadsheet sends nothing unless you ask: Muninn matches its columns on your device. If you tap Match columns with Muninn AI, it sends a little more, and only a little: the column names and the first five rows of the file, so Muninn can work out which column holds the item name and which holds the box. The rest of the file never leaves your device — it is read and turned into bins and items here.

If you ask Muninn to sort a list you pasted, the whole list goes to Anthropic — every line, as you typed it — so Muninn can work out where everything goes. Pasting a list without asking Muninn to sort it reads it on your device and sends nothing.

One feature uses a second company. Removing the background from a bin’s photo happens on your own device and sends nothing. But if you ask Muninn to redraw the photo as a clean picture, that one photo and the name of the kind of bin go to xAI, which runs the image model that draws it. Nothing else about your household goes with it. xAI is also Muninn’s stand-in: if Anthropic’s service were out for a long stretch, questions and photos could be switched to xAI’s models instead, and what is sent would be exactly the same.

Anthropic states that by default it does not train its models on what is sent through its API, and that it deletes those requests and answers within 30 days, apart from what it must keep to enforce its usage policy or to comply with the law. xAI states that it does not train its models on API inputs or outputs, and that they are stored encrypted for 30 days for abuse auditing and then deleted. Those are their terms rather than ours, and they can change — the current policies are at privacy.claude.com and docs.x.ai.

If you buy label packs

The shop hands money off straight away. Checkout runs on Stripe: your card is typed on Stripe’s own page and never reaches Muninn. Stripe takes your name, email and shipping address, and we read the order back from Stripe to ship the parcel.

The postage is bought through Pirate Ship, which gets your name, shipping address and email address to print the label and to email you the tracking number once the parcel is on its way.

Muninn keeps no orders table of its own. When a pack’s code is claimed, we record which household claimed it beside the Stripe order it came from, so the pack’s bins stay with that household and a refund can take them back. Nothing about your card is part of that. If you never buy anything, none of this applies to you.

If you buy Muninn Plus

In the iPhone or iPad app, Muninn Plus is bought through Apple. Apple handles the payment and holds the billing relationship; we never see your card. On this website it is bought by card through Stripe, which takes the payment and keeps your card, your billing details and your email address as our payment processor; we never see your card there either. To know that a household has Plus, we use RevenueCat, a purchase-processing service: it receives the App Store receipt, or the Stripe subscription, together with your Muninn account identifier (a random ID, not your name or email), and tells our server which household to unlock and until when. That is the only thing stored about the purchase in Muninn: the plan, its expiry, and whether it came from the App Store or a card.

What never happens

  • No ads, and no data sold or shared for advertising.
  • No tracking across other apps or websites.
  • No analytics profile of you — Muninn doesn’t watch how you use it.
  • No access to your contacts, location, or anything not listed above.

What Muninn counts, and what it never reads

To decide what to build, Muninn sometimes counts things across all households — how many use a particular bin type, how many turn on an optional field like Value, how often bins end up labeled. Counts only, never individual records, and only where enough households share an answer that no single one can be picked out.

Never mined, and never sold. Your item names, notes, tags, photos and values are never read to improve Muninn, never used for advertising, and never sold or handed to anyone. Nobody here reads them and nothing counts them. The one time they leave your household is when you ask Muninn AI a question — then the relevant ones go to the AI company that answers it, as described above, and nowhere else.

Crash reports

If Muninn crashes in your browser, it sends us a short technical report so we can fix it: the error message, where in the code it happened, which page you were on (the address only, never its contents), and your browser type. No name, no email, no account id travels with it. Reports are kept for 30 days, readable only by us, then deleted automatically.

If you tell us why you left

When Plus ends, or when you delete your account, Muninn may ask one optional question: what made you cancel or leave. If you answer, we keep the answer you tapped, any words you added, where you were asked, and the month — with no name, email, account or household attached. Skipping it keeps nothing.

Your data is yours

Export everything at any time — spreadsheet, printable report, or JSON — from Settings → Export. Delete your account from Settings (Danger zone → Delete my account); your membership and personal data are removed, and a household is deleted entirely when its last member leaves. Photos are also copied each night to a private backup we keep with Cloudflare, so one lost by mistake can be put back; a deleted photo stays in that backup for 30 days, then is deleted from it too.

Questions

Ask anytime — the support page has contact details.

If you email support@askmuninn.com, your message is received and stored by our email provider. We may use Anthropic’s Claude to help draft a reply — under the same terms as the AI assistant above — and a person reads every reply before it is sent. Ask us to delete your messages and we will.