Legal

Privacy Policy

What personal data the Platform collects about you, why, who processes it, and the rights you have over it.

Last updated: July 10, 2026

1. Who this covers

This Privacy Policy explains how MUSO.AI (“Muso”, “we”) handles personal data in connection with the Muso.AI developer platform — the console at platform.muso.ai, the API at api.platform.muso.ai, and the account, key, team, and billing features that come with them (the “Platform”). For Platform personal data, Muso is the controller.

It is important to keep two things separate. This policy governs personal data about you — the account holder, workspace member, or visitor. The music-industry catalog data that the API returns is professional/business information licensed to you under the Data License Agreement, not personal data we collect about you; how you may use that data is governed by that agreement, not this policy.

2. What we collect

We collect only what the Platform needs to run, bill, and stay secure:

  • Account identity — your name and email address, established through Muso Sign-In (login.muso.ai). If you choose a social provider (Google, Facebook, or Apple), that provider passes us the basic profile fields you approve; we never receive your password.
  • Workspace and team data — workspace names, member roles, and invitations you create or accept.
  • Billing data — your plan, credit balance, usage-based charges, and invoices. Card details are entered directly with our payment processor (Stripe) and are never stored on Muso systems; we retain only the tokens, last four digits, and billing metadata Stripe returns.
  • Usage telemetry — metadata about API requests, measured at the gateway: the key used, timestamp, endpoint, response status, and request counts. This drives metering, quotas, invoicing, and abuse prevention. It does not include the personal contents of your end users.
  • Communications — messages you send us (e.g. to legal@muso.ai or support) and your delivery/engagement status for the service emails we send.
  • Technical data — IP address, user agent, and, where enabled, scrubbed error diagnostics used to detect and fix faults.

3. Cookies

The Platform uses only the cookies it needs to function — principally the session cookies that keep you signed in through Muso Sign-In and the console. We do not use advertising cookies or third-party ad-tracking pixels, and we do not sell or share your data for cross-context behavioral advertising.

4. Why we use it

We use personal data to:

  • Provide the Platform — authenticate you, create and manage keys, and serve the console.
  • Bill accurately — meter usage, charge or draw down credits, and produce invoices.
  • Keep the Platform secure — detect abuse, enforce rate limits and the Data License, and investigate suspected breaches.
  • Communicate with you — send transactional and service notices (receipts, low-balance and quota alerts, security and account notices). These are part of the service, not marketing.
  • Meet legal and accounting obligations — tax, financial recordkeeping, and responding to lawful requests.

5. Legal bases

Where the GDPR or UK GDPR applies, we rely on: performance of our contract with you (to provide and bill the Platform); our legitimate interests (to secure the Platform, prevent abuse, and keep basic operational records), balanced against your rights; compliance with a legal obligation (tax and accounting); and, where we ask for it, your consent. You can object to processing based on legitimate interests as described below.

6. Who processes data for us

We share personal data only with the service providers that make the Platform work, each under a data-processing agreement and only for the purpose described. We do not sell personal data. The current list, with each provider’s role and location, is published on the Sub-processors page (linked below).

  • Stripe — payment processing, cards, and invoices.
  • Klaviyo — delivery of transactional and service email on our behalf.
  • Cloudflare — the edge network, CDN, and WAF that front the Platform.
  • Sentry — when enabled, error and performance diagnostics, scrubbed of secrets and message bodies.
  • OVHcloud — the managed infrastructure that hosts the Platform.
  • Muso Sign-In (login.muso.ai) — Muso’s own identity service, which authenticates you and, if you choose one, relays your selected social provider.

7. Where data is processed

The Platform and its core processors operate primarily in the United States. If you access it from the European Economic Area, the United Kingdom, or another region, your personal data will be transferred to and processed in the United States. Where those transfers require a safeguard, we rely on the appropriate mechanism (such as the European Commission’s Standard Contractual Clauses) with the processor concerned.

8. How long we keep it

We keep account and workspace data for as long as your account is active, and for a limited period afterward to honor deletion, resolve disputes, and meet legal obligations. Billing and usage records are retained as long as tax and accounting law requires. When data is no longer needed for these purposes, we delete or anonymize it.

9. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, and withdraw consent. California residents may exercise the rights afforded by the CCPA/CPRA, including the right to know and to delete; because we do not sell or share personal data for cross-context behavioral advertising, there is nothing to opt out of on that basis.

To exercise any of these rights, email legal@muso.ai from your account address. We will verify your request and respond within the time the applicable law allows. Using the Platform on someone else’s behalf does not limit their rights over their own data.

10. How we protect it

We encrypt traffic in transit with TLS, store API keys only as hashes (never in plaintext), scope access to the least privilege each role needs, and separate the systems that hold account data from the data the API serves. No system is perfectly secure, but we treat protecting your data — and preventing leakage of the data the API serves — as a first-order responsibility.

11. Children

The Platform is a professional developer product and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact legal@muso.ai and we will delete it.

12. Changes to this policy

We may update this policy as the Platform evolves. When we do, we revise the “Last updated” date above, and for material changes we provide a more prominent notice. Continuing to use the Platform after an update means you accept the revised policy.

Questions about these terms: legal@muso.ai