Last updated 27 September 2026
Muridian (“we”, “us”) operates Muridian at muridian.xyz (the “Service”). This policy explains what we collect, why, who we share it with, and what control you have over it.
Muridian is a connector: it gives an AI assistant you already use the ability to research and publish on social networks, and to read your own business metrics. Questions go to letin1672@gmail.com.
Nothing you store in Muridian is sent to an AI provider by us. We operate no model, we have no AI provider as a subprocessor, and we do not train anything on your data or use it to improve any model.
Your own AI assistant is the exception, and it is your choice. Muridian exposes your workspace over the Model Context Protocol so that a client you connect — Claude, ChatGPT, or any other MCP client — can read and act on it. When you connect one and it calls a tool, the data that tool returns is sent to that client and is then governed by that provider’s privacy policy, not this one. You choose which client to connect, which permissions to grant it, and you can disconnect it at any time in Settings. We show you every connected app and when it was last used.
Account information. Your email address, and your name and profile picture if Google provides them at sign-in. Authentication is handled by Supabase Auth. We never receive or store a password.
Connected social accounts. If you connect an X account we store its numeric account id, its username, the permissions you granted, and access and refresh tokens. Both tokens are encrypted at rest with AES-256-GCM using a key held outside the database.
Connected TikTok account. If you connect a TikTok account we store the account identifier TikTok issues for it (its open_id), the scopes you granted, and the access and refresh tokens — both encrypted at rest the same way. Alongside them we store the profile information TikTok makes available, the account statistics it reports, and metadata and statistics for the public videos TikTok returns for that account. Section 4 lists those fields.
Your workspace. Everything you or your AI assistant saves: research you keep, accounts you track, notes on how you write and who you write for, experiments, drafts, scheduled posts, and your own published posts. Saved research includes a copy of the post text and metrics as they were when you saved it, so it survives the original being deleted.
Performance history. Periodic snapshots of your own follower count and of how your posts performed. We capture these because the platforms will tell you a figure now and will not tell you what it was three weeks ago — the history only exists because we wrote it down.
Connected business accounts. If you connect them, we store credentials for your Stripe account, Google Search Console properties, Vercel projects and Supabase projects, encrypted the same way as above, together with daily snapshots of what they report. Section 4 describes exactly what we read from each.
Usage records. A ledger of research reads and published posts, so we can show you what you have used and settle any question about it later. Counts of calls made to the Service and to third-party APIs, used for rate limiting.
Payment information. Your subscription is processed by Stripe. We store a Stripe customer identifier, a subscription identifier and a status. We never receive or store your card number.
Technical data. Server and application logs. These are automatically redacted before they are written: tokens, keys, secrets and account identifiers are replaced with a placeholder rather than recorded.
We do not sell your data, we do not share it for advertising, and we do not use it to build a profile of you for anyone else’s purposes.
Every connection is optional, granted by you, and revocable in Settings. Each one is described below by exactly what it can reach.
X. Read and publish permission on your account, plus the ability to stay connected without re-authorising. We read public posts you search for, your own posts and their metrics, and we publish and delete posts when you ask. We do not read your direct messages, and we do not follow, like or repost.
TikTok. Read-only. We request permission to read your basic profile, your profile details, your account statistics and your list of videos, and we use them only to show you account and public-video analytics. We do not access your direct messages, your drafts or your private videos, and we do not publish, edit or delete videos. We read no account other than the one you connected.
The profile statistics TikTok reports can include your follower count, following count, total likes and public-video count, along with your display name, avatar, bio, profile link and verification flag.
The public-video data we read can include each video’s description or title, its publish time, its duration, its cover image and share URLs, and its view, like, comment and share counts — where TikTok makes those fields available. We record these repeatedly over time so that performance history exists at all; TikTok reports a figure now and will not tell you what it was last month.
Disconnecting TikTok deletes the stored TikTok credentials and the TikTok-specific analytics data — the account snapshots and the video records — rather than leaving them behind. Switching the connection to a different TikTok account does the same for the account you replaced.
YouTube. Read-only. Muridian uses YouTube API Services, and we request only the youtube.readonly permission. We read your own channel’s id, title, handle and thumbnail, and its subscriber, view and video counts; and for each of your uploads its title, publish time, duration, thumbnail, privacy status, and its view, like and comment counts. We record those counts repeatedly so that you can see how each video performed over time. We use this data only to show you your own channel’s performance inside Muridian. We do not upload, edit or delete videos, read comments or messages, read any channel other than yours, or share YouTube data with anyone else. We do not store or read cookies or other information on your device for YouTube.
We re-check with YouTube every day that you still authorise Muridian, and re-read each stored video’s details at least every 30 days, deleting any video that no longer exists. You can revoke Muridian’s access at any time by disconnecting YouTube in Settings, or through the Google security settings page. Either way we delete all YouTube data we stored for that channel. By connecting YouTube you agree to the YouTube Terms of Service, and Google’s handling of your data is governed by the Google Privacy Policy.
Reddit. Read-only. We request only the identity and history permissions, and read only your own account: your username, account id and karma, and the posts you submitted — for each, its title, subreddit, link, publish time, whether it is a text or NSFW post, and its score, comment count and upvote ratio. We keep at most your 100 most recent posts. We never store post bodies, never read other users’ content, subreddits, comments, votes or messages, and never post, comment, vote or message. Reddit data is shown only to you in Muridian. It is not sent to any AI model — including Muridian’s own chat and any AI assistant you connect — and it is never sold, shared, used for advertising, or used to train any model.
We re-check your posts against your Reddit history every day and delete any post you deleted, that was removed, or that is no longer among your 100 most recent. If that check cannot run for 48 hours, stored titles and links are removed anyway; if your account cannot be confirmed for two days, everything stored for it is deleted. Disconnecting Reddit in Settings revokes our access with Reddit and deletes everything stored for that account immediately. You can also revoke access on Reddit at reddit.com/prefs/apps, after which we delete the data on our next check.
Google Search Console. Read-only. We request only webmasters.readonly for Search Console. We read aggregate search performance — queries, pages, clicks, impressions, click-through rate and average position — for the properties you choose to connect. This data is aggregated and anonymised by Google before we see it; it does not identify any individual searcher, and we never present it as though it does.
Stripe (your own account). Read-only. We read subscriptions, customers, invoices, charges and refunds in order to calculate revenue, subscriber counts, churn and failed payments. We never write to your Stripe account and we never move money. We store the derived figures — not copies of your customers’ records. Your connected Stripe account is kept entirely separate from the Stripe account that bills you for Muridian.
Vercel. Read-only. We read your project’s deployment history and its Web Analytics aggregates: visitor and page-view counts grouped by page, referrer and campaign. Vercel’s analytics are aggregate-only, so this contains no individual visitor, no session and no identity.
Supabase. Read-only, and narrower than it sounds. We run a fixed, unchangeable set of queries against PostgreSQL’s own system catalogs to read database size, table sizes, row estimates and index health, plus Supabase’s security and performance advisor findings. We do not read the contents of your tables. There is no way to ask Muridian to do so: the query set is fixed in code and cannot be extended by you, by us, or by an AI assistant.
Bluesky, Hacker News and GitHub. We search these on your behalf using our own service credentials. Your identity is not sent to them; only your search terms are.
Muridian’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Search Console and YouTube data we receive is:
Signing in with Google uses Google’s standard sign-in and gives us your email address and basic profile only. It grants no access to any other Google service.
We use a small number of processors, each for one job:
Beyond those, data goes only where you have directed it: to a network you connected, and to the AI client you connected. We may also disclose data if required by law, or as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.
You can access, correct, export or delete your data. Most of it is visible in the app and through your connected assistant. Deleting your account deletes everything associated with it — workspace, history, ledgers, connections and credentials — and is available in Settings. It is immediate and cannot be undone.
Depending on where you live you may also have the right to object to or restrict processing, to data portability, and to complain to a supervisory authority. Write to letin1672@gmail.com and we will respond within the period the law requires, and in any case within 30 days.
All third-party credentials are encrypted at rest with AES-256-GCM, using a key that is never stored in the database. Database access is restricted per-account at the database level, and the columns holding credentials are not readable by the application’s browser client at all. Logs are redacted before they are written.
No system is perfectly secure. If a breach affects your data we will notify you and any relevant authority as the law requires.
Our processors operate in the United States and elsewhere; using the Service involves transferring your data internationally, under the safeguards those processors provide.
Muridian is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact letin1672@gmail.com and we will delete it.
If we change this policy materially we will update the date at the top and email you before the change takes effect. Continuing to use the Service after that means you accept the revised policy.
Contact: letin1672@gmail.com