Legal
Privacy Policy
What we collect, why we need it, who helps us process it and what you can ask us to do with it. We collect as little as we can and we never sell it.
Last updated
On this page
The short version
- We collect what we need to sell you a license, deliver it, keep it working and help you: mainly your email, payment details handled by Stripe, and a scrambled ID of the PC your license is tied to.
- No analytics, no ad trackers, no tracking cookies on this website.
- We never sell your data and we only share it with the services listed below.
- You can ask to see, correct or delete your data at any time.
1. Who is responsible for your data
The controller of your personal data is MUSA. Contact us about anything in this policy at [email protected].
2. What we collect
When you buy
- Your email address.
- Your name, billing country and payment status, which Stripe collects to process the payment. We see the last four digits and type of your card, never the full number.
- What you bought, when and for how much.
When you log in and use MUSA
- The email you log in with and the status of your license.
- A device fingerprint: a one way scrambled value made from identifiers of your Windows installation. We use it only to tie your license to one PC. It cannot be turned back into the original identifiers.
- Your IP address, the MUSA version and build, and the time of each license check or update check.
MUSA does not upload your gameplay, your screen, your files or its run logs. The logs stay on your PC unless you choose to send them to us.
When you ask for help
- Your Discord username and the messages you send us.
- Emails you send us.
- Log files and screenshots you choose to share. Logs can include your PC's general setup, game settings and what the bot did during a run.
When you visit this website
- Our hosting provider Cloudflare processes your IP address, browser type and the pages you request, to deliver the site and protect it from attacks.
- We do not use analytics tools, advertising trackers or tracking cookies. See our Cookie Policy.
3. Why we use it and our legal basis
| What we do | Data used | Legal basis (GDPR) |
|---|---|---|
| Take payment and deliver your access | Email, payment details, order | Performing our contract with you, Art. 6(1)(b) |
| Log you in and keep your license working | Email, license, device fingerprint, IP, version | Performing our contract, Art. 6(1)(b) |
| Deliver updates | Version, IP | Performing our contract, Art. 6(1)(b) |
| Help you when something goes wrong | Discord username, messages, logs you send | Performing our contract, Art. 6(1)(b) |
| Stop account sharing, fraud and abuse | License, device fingerprint, IP, order | Our legitimate interest in protecting our service and paying customers, Art. 6(1)(f) |
| Keep accounting and tax records | Order and payment records | Legal obligation, Art. 6(1)(c) |
| Keep the website running and secure | IP, browser data | Our legitimate interest in a secure, working site, Art. 6(1)(f) |
| Email you about your plan, price or terms changes | Performing our contract, Art. 6(1)(b) |
We do not send marketing emails.
Our license system automatically refuses to log in a license on a second PC. This is part of the license you bought and has no legal or similarly significant effect on you. If it blocks you by mistake, contact us and a person will look at it.
4. Who we share it with
We share data only with the service providers we need to run MUSA. They process it on our instructions under data processing agreements, except where noted.
| Provider | What for | Where |
|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing and fraud checks | Ireland (EU), with transfers to the US |
| Cloudflare, Inc. | Website hosting, security and our license server | Global network, US company |
| Airtable (Formagrid, Inc.) | License and order database | United States |
| Discord, Inc. | Our community and support chat. Discord is its own controller for your Discord account. | United States |
We may also disclose data if the law requires it, for example to tax authorities or in response to a valid court order.
5. Transfers outside the EU
Some providers above are based in the United States. Where a provider is certified under the EU US Data Privacy Framework, transfers rely on the European Commission's adequacy decision. Otherwise they rely on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the relevant safeguards.
6. Cookies
This website does not use tracking or analytics cookies. The details are in our Cookie Policy.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- correct data that is wrong or incomplete;
- delete your data, where we no longer need it or have no other legal reason to keep it;
- restrict how we use your data in certain situations;
- receive the data you gave us in a common machine readable format, or have it sent to someone else;
- object to processing we base on legitimate interests.
To use any of these rights, email [email protected] from the email address linked to your purchase. We reply within one month. It is free, unless a request is clearly unfounded or excessive. We may ask you to confirm your identity first.
If you delete data we need to run your license, such as your email or device fingerprint, we will not be able to keep your license working.
8. Complaints
If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to a data protection authority. In Croatia that is the Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr. If you live in another EU country, you can also contact the authority there.
9. How we protect it
We use encrypted connections everywhere, keep access to customer data limited to the people who need it, store only a scrambled device fingerprint instead of raw hardware identifiers, and rely on providers with strong security practices. No system is perfectly secure, but if a breach ever puts your data at risk, we will tell you and the authorities as the law requires.
10. Children
MUSA is not meant for children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We update this policy when what we do with data changes. The date at the top shows the current version. If a change significantly affects you, we will email you before it applies.
12. Contact
Email [email protected] with any privacy question.
