Privacy Policy
Last updated: September 8, 2026
This Privacy Policy explains how Melodin AI, Inc. (“Melodin AI,” “we,” “us”) processes personal data when you use our platform—including artist pages, listening and Following, Stream Time, Studio tools, stem-separation, and related services. It is written to reflect common requirements under the EU/UK General Data Protection Regulation (GDPR) and UK GDPR, alongside globally applicable privacy expectations.
For consumer and direct sign-ups, Melodin AI is typically the controller of the personal data described here. If you are a business and we process personal data on your documented instructions (for example team accounts or API integrations), we may act as a processor; in that case Section 6 (DPA) applies in addition to this Policy.
1. Data controller & contact
Controller: Melodin AI, Inc.
Privacy inquiries: hello@melodinai.com (please use “Privacy Request” in the subject line for GDPR rights requests).
If you are in the European Economic Area (EEA), Switzerland, or the UK, you also have the right to lodge a complaint with your local supervisory authority. A list of EU authorities is available from the European Data Protection Board; in the UK, the ICO (ico.org.uk).
2. Content ownership
We do not claim ownership of your uploads, releases, or separated outputs. Audio files, stems, artist catalog content, and related creative results remain yours, subject to third-party rights (for example labels, publishers, or co-creators) and our limited licence to operate the service as described in our Terms of Service. Processing your content does not transfer intellectual property rights to Melodin AI.
3. Categories of personal data
Depending on how you use Melodin AI, we may process:
- Account data: email address, display name, handle, authentication identifiers, profile metadata you choose to provide, and whether you use the service as a listener and/or artist.
- Artist profile data: public page content, bio, images, release metadata, visibility settings, and follower relationships (who follows whom).
- Transaction data: Stream Time balance, stem credit balance, purchase history, artist listening earnings references, and payment-related references processed by our payment provider (we do not store full card numbers on our servers).
- Audio & creative content: files you upload for release or separation, generated stems, Studio projects, previews, waveforms, and technical derivatives created solely to run the pipeline.
- Usage & technical data: IP address, approximate location derived from IP, device and browser type, timestamps, pages or features used, error logs, security signals, and anti-abuse telemetry. On public artist pages this includes profile views, track plays, and photo opens, shown to the artist as aggregated all and unique visitor counters.
- Communications: messages you send to support and correspondence metadata.
- Copyright / abuse notices: information in DMCA or other infringement reports (see Section 10), which may include identifiers and contact details of claimants.
Important: Audio you upload may contain personal data (for example identifiable voices or spoken information) or third-party content. You are responsible for having a valid legal basis under GDPR (and similar laws) to upload and have us process that audio—including obtaining consent or another basis where voices of other people are concerned.
4. Purposes & legal bases (GDPR Art. 6)
We process personal data only where a lawful basis applies:
- Performance of a contract (Art. 6(1)(b)): to create and maintain your account, run listening and artist-page features, Stream Time and credit purchases, stem separation and Studio tools you request, deliver downloads, and provide customer support tied to the service.
- Legitimate interests (Art. 6(1)(f)): to secure the platform, prevent fraud and abuse, monitor reliability, improve performance, analyse aggregated usage, enforce our Terms, handle copyright complaints, and defend legal claims—balanced against your rights.
- Legal obligation (Art. 6(1)(c)): to comply with tax, accounting, or lawful requests from authorities where applicable.
- Consent (Art. 6(1)(a)): where we rely on consent (for example certain optional communications or non-essential cookies if we introduce them), you may withdraw consent at any time without affecting prior lawful processing.
We do not use your audio to train public-facing generative models for unrelated purposes unless we clearly disclose a separate opt-in programme.
5. Processing of audio (special-category note)
Biometric identification is not a feature of Melodin AI. However, voice recordings can constitute personal data (and in some interpretations, special-category data in certain contexts). You must not upload audio intended to unlawfully identify or surveil individuals. Where required law applies, we rely on your explicit representation that you have authority to submit the audio and, where needed, appropriate consent or another Article 9 GDPR basis.
6. Business customers & Data Processing Agreement (DPA)
If you are a company, organisation, or other legal entity and we process personal data on your behalf (for example your employees’ or end users’ data) through a business plan, API, or custom integration, GDPR Article 28 requires a written Data Processing Agreement alongside these Terms.
How to obtain a DPA: email hello@melodinai.com with “DPA Request” in the subject line, your company name, and a short description of the intended use. We will provide our standard DPA or negotiate an enterprise addendum where appropriate. Until a DPA is executed, do not configure the service to process third-party personal data on behalf of your organisation except as a consumer yourself.
7. Subprocessors & public list
We engage subprocessors to host infrastructure, process payments, deliver email, and provide security and networking. They process personal data only as needed to deliver those services, under contracts that require appropriate safeguards.
A non-exhaustive list of typical categories and example vendors (Stripe, AWS, Cloudflare, and similar) is published at melodinai.com/subprocessors.html. We may update subprocessors over time; we will reflect material changes on that page and, where your agreement requires, provide advance notice or an opportunity to object for enterprise customers.
We do not sell personal data and do not share data for third-party behavioural advertising on this app.
8. International transfers
Melodin AI operates from the United States and may process data there or in other countries. Where we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we implement appropriate safeguards such as the EU Standard Contractual Clauses (and UK Addendum where relevant) or other mechanisms recognised by applicable law.
9. Retention (including audio)
We apply layered retention so you know what to expect:
- Transient processing & pipeline storage: uploads, worker scratch space, intermediate renders, and failed-job artifacts are typically deleted within 24–72 hours after a job reaches a terminal state (completed or failed), unless a shorter period is technically feasible. Some caches may clear sooner.
- Artist releases & Library outputs: tracks and related files you can replay or download are kept until you delete the track or close your account (or we terminate the service for that content under our Terms), subject to the backup rule below.
- Backups: deleted content may persist in encrypted rolling backups for up to approximately 30 days before overwrite, then is removed or irreversibly unlinked from production systems.
- Account & billing records: kept while your account is active and for a period thereafter as required for tax, accounting, fraud prevention, and legal claims (often several years where mandated).
- Security & application logs: typically weeks to months in active storage, longer in aggregated or archived form where needed for integrity and incident response.
- Copyright / DMCA records: notices, counter-notices, and related correspondence may be retained for several years to demonstrate compliance, assert safe-harbor protections, and resolve disputes, limited to what is necessary.
Exact timings can vary slightly by infrastructure and product changes; we will update this Policy if defaults materially change.
10. Copyright, DMCA & your data
Because Melodin AI is a music platform and audio processing service, copyright enforcement intersects with privacy: a valid takedown may result in removal or disabling access to files associated with your account. We process claimant information (names, emails, descriptions) on the basis of legitimate interests and, where applicable, legal obligations to document our response.
For the full notice-and-takedown and counter-notification process under U.S. law, see Section 7 of our Terms of Service (DMCA). Nothing in this Policy limits our right to remove content that violates our Terms or applicable law.
11. Your GDPR rights
Where GDPR/UK GDPR applies, you may have the right to:
- Access your personal data and obtain certain information about processing;
- Rectify inaccurate data;
- Erase data (“right to be forgotten”) where conditions are met;
- Restrict processing in specific cases;
- Data portability for data you provided, where processing is based on contract or consent and is automated;
- Object to processing based on legitimate interests, including profiling that produces legal or similarly significant effects (we do not offer such automated decisions as a default product feature);
- Withdraw consent where processing is consent-based;
- Lodge a complaint with a supervisory authority.
To exercise rights, email hello@melodinai.com from your account email and describe your request. We may need to verify your identity. You may also delete specific tracks or your account where the product provides those controls.
12. Security
We implement technical and organisational measures appropriate to the risk (encryption in transit, access controls, monitoring, and vendor diligence). No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
13. Cookies & local storage
We use essential cookies and local storage for authentication, sessions, and theme preferences. See Cookie settings in your account menu. If we add non-essential cookies, we will update this policy and, where required, obtain consent before use.
14. Children
The service is not directed to children under 13 (or the higher minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it promptly.
15. Automated decision-making
Stem separation and related AI audio tools use automated analysis to produce technical outputs. They do not, by default, make decisions with legal or similarly significant effects about you as a person within the meaning of GDPR Article 22. If that changes, we will update this policy.
16. Changes
We may update this Privacy Policy to reflect product, legal, or regulatory changes. We will post the revised version with a new “Last updated” date. Where required, we will provide additional notice or seek consent.
17. Contact
Privacy questions and requests: hello@melodinai.com
No privacy notice can guarantee outcomes in every court or regulator inquiry. This policy is drafted for transparency and GDPR alignment; Melodin AI does not provide legal advice. Engage qualified privacy counsel for organisational or high-risk processing.