Privacy
Privacy
What this instance stores, why, and what it never does.
What we don't do
No advertising. No tracking pixels, no third-party analytics, no cross-site identifiers. Nothing you do here is profiled to sell you something, and no data is sold or shared with a data broker — there is no business model here that would want it.
Your content is not used to train anyone's model.
What is stored
Your account — a username, a password hash or passkey, and an email address if you gave one. Signing in with Google stores the email and name Google returns, nothing else.
Your mail — this instance runs an SMTP server, so messages sent to and from your address are stored here in order to be an inbox at all. They are readable by you, and by whoever operates the instance, in the same way any mail server works.
What you make — posts, blogs, files, contacts, calendar entries, stored records. Private unless you make them public.
Your credits — a balance and a transaction history, so charges can be explained.
Operational logs — requests, errors and IP addresses, kept short-term to run the service and stop abuse.
Agents and third parties
Some tools reach outside this instance, and when they do, the request goes to that provider: web search to Brave, places and travel time to Google, image generation and most model calls to Atlas Cloud, with Anthropic for the premium model tier. Those requests carry the query, not your identity.
A question you ask the agent is sent to a model provider to be answered. If that matters for something you are about to ask, it is worth knowing before you ask it.
Tokens and connected agents
A personal access token, or a client you signed in through the MCP
authorization flow, acts as you: it reaches the same tools and the same
data. Revoke either at /token. Anything an agent did
with a token is attributed to your account, which is why
mail_send is available only to a signed-in account and never
to an anonymous caller.
Deleting things
Delete individual items — a file, a record, a post, a contact — with the tool or page that made them. To close an account and remove what it holds, mail the operator of the instance. On micro.mu that is admin@micro.mu.
Self-hosting
Mu is one Go binary and the source is public. Run your own instance and none of the above involves us at all: the data is on your disk, and you are the operator this page is describing.







