Privacy Policy

Effective July 12, 2026

Musaica is designed to help reciprocal museum members find nearby participating museums and maintain a wallet pass (Apple Wallet on iOS, Google Wallet on Android). This policy explains what information the apps, website, and pass signing service use.

Information You Provide

The app asks for membership details such as member name, home institution, membership level, expiration date, and reciprocal program affiliations. These details are stored on your device and are sent to Musaica's pass signing service only when the app needs to create or refresh your Wallet pass.

Location

Musaica uses device location to sort museums near you and choose which museums should be loaded into your wallet pass. The app sends selected museum IDs to the signing service; it does not send raw latitude, longitude, or a precise location fix.

On Android you may optionally allow location access "all the time" so the home-screen widget and your Google Wallet pass can keep showing the nearest museums as you travel. These background updates are computed entirely on your device — a single geofence and a periodic check recompute the nearby list when you have moved; your coordinates are never sent to Musaica's servers. Declining leaves the app fully functional: the list, widget, and pass then refresh whenever you open the app.

Address Search, Maps, and Directions

If you search for an address to anchor the nearby list, your search text is sent to the platform's mapping service to find matching places. The museum detail page may show a map, and when you are within walking distance the app may request a walking route using your current position as the origin — the same information any directions request carries. On iOS these requests go to Apple (MapKit) and are handled under Apple's privacy policy; on Android they go to Google (Google Maps, address autocomplete, and directions) and are handled under Google's privacy policy. None of them go to Musaica's servers.

Wallet Pass Signing

To create a signed wallet pass, Musaica sends membership details, a stable pass serial number, selected museum IDs, and any visit marks or ratings for those selected museums to the pass signing service which uses that information to produce the pass and does not require a user account. On Android, the resulting pass content is delivered to your Google Wallet through Google's Wallet service and is then handled by Google under its terms and privacy practices; on iOS the pass is added to Apple Wallet on your device.

Visit Journal, Marks, and Ratings

Visit dates and private notes, along with marks such as want to visit and star ratings, are stored on your device. On iOS, if iCloud key-value syncing is enabled for your Apple ID, Apple may sync those values across your devices according to Apple's iCloud terms and privacy practices. Musaica's service does not receive your journal entries. On Android, marks and ratings stay on the device.

Data Correction Reports

If you choose to report incorrect institution information, Musaica sends the institution and dataset version, the categories and corrections you enter, any evidence link you provide, and the app platform and version to Musaica's reporting service. Reports do not include your device location. If you report an incorrect institution location, the report includes the completed address and map coordinate that you explicitly select.

The app creates a reporting-only random installation identifier so retries can be recognized and basic abuse limits can be applied without requiring an account. The service transforms that identifier with a secret keyed hash before storing it and does not retain the identifier sent by the app. Report content and editorial outcomes are retained as needed to improve the dataset, prevent duplicate work, and maintain an audit trail.

Camera and Photo Library

On iOS, if you choose, you may attach membership proof to your museum memberships. This may ask for permission to use the camera or for access to selected photos in your photo library. Photos so supplied are stored on your device and may be synced across multiple devices according to Apple's iCloud terms and privacy practices. The photographs are never sent to Musaica's servers.

Website

The public website and app API are served by Musaica. Musaica does not add website analytics, advertising trackers, or cookies on these pages. Our hosting provider may process request metadata such as IP address, user agent, and request URL to provide hosting, security, and delivery.

Data Retention

Membership details and app state remain on your device unless needed to sign a wallet pass. Wallet signing remains stateless and Musaica does not create user accounts. Voluntarily submitted correction reports are stored as described above. Operational logs may be retained by the hosting provider for security, debugging, and abuse prevention.

Third-Party Services

Contact

For privacy questions, contact support@musaica.app.