Where your data actually goes
Short version: nowhere. Everything happens in your browser, on your machine. This page is the long version, because a promise you cannot check is not worth much.
Your export is never uploaded
Your export is opened by the browser itself, the same way it would open a file you double-click. Reading it, merging services, finding duplicates, repairing dates, searching and exporting all happen on your machine. No part of the archive is sent anywhere. Open your browser's network tab while you use it and you will see the page load, and then nothing.
There is exactly one exception, it is optional, and it is never on by default: if you ask us to tag your photos with AI, those photos are sent to be described. That is the only thing that ever leaves, and the next section is about it.
The one exception: AI tagging
Tagging reads a picture and writes a sentence about what is in it. That needs a model, and models do not run in a browser tab. So there are two ways to do it, and you choose before anything happens.
On your own machine
Point Muletto at a model running on your own computer, or an API account you already hold. With a local model nothing leaves the device at all, and there is nothing to pay. This route will always exist.
Using our credits
For people who do not want to install anything. You buy credits, and each photo you tag is sent to be described. Only the picture - never the archive, the file list, the dates or the messages.
What happens to the picture
It is held for the moment it takes to describe it, then dropped. It is not written to disk, not logged, and never used to train anything. No description or filename is kept after the reply is sent back to you.
No account, ever
A credit code identifies a balance, not a person. No email, no sign-up, nothing tying the pictures to you. Everything else in Muletto stays free and needs no code at all.
Some things are kept, on your device
Reading a large export takes time, and working out which photos are near-duplicates takes longer. Doing that again every visit would be a poor trade, so the results are kept - in your browser's own storage, on your own disk.
What is kept
The list of what is inside your export, the dates and places read out of it, and the results of any analysis. Plus a reference to each archive, so it can be reopened without asking you to find it again.
What is not kept
Copies of your photos, videos or messages. A reference to an archive is a pointer to the file already on your disk, not a second copy of it. Move or delete the archive and Muletto will tell you it is gone.
Who can read it
This browser, on this machine, for this site. Not us, not another site, not another profile. It is the same storage a web app uses to remember your settings.
Getting rid of it
One button. "Forget this library" in the sidebar clears everything Muletto has kept, immediately. Clearing site data in your browser does the same.
Work you can take with you
Browser storage belongs to the browser, and it can be cleared - by you, or by the browser needing room. Anything that took real effort can be written out to a file you keep. It holds the results only: no photos, no messages, not even file names. Feed it back next year alongside a fresh export and everything that still applies is recognised, because results are filed against the contents of each file rather than its name.
Nothing happens in the background
There is no telemetry, no analytics and no crash reporting. Nothing is sent while you are not looking, and nothing is sent because you opened a page. The only request Muletto ever makes with your data in it is one you started, for photos you picked, on a screen that told you the cost first.