Privacy Policy

Effective: 23 September 2026

This Privacy Policy applies to the Musairec app for mobile devices and web browsers, together with any related services operated by Musairec, LLC (collectively, the “Application”). Musairec, LLC is referred to as the “Service Provider”. Musairec is a music-recording app that lets you record audio ideas, transcribe them to MIDI, separate stems, and generate AI-assisted musical suggestions.

Data Controller

Musairec, LLC acts as the Data Controller responsible for the processing of your personal data.

For data protection inquiries and to exercise your rights, please contact the Data Controller using the details above.

What information the Application collects and how it is used

Using the Application requires an account, so the information below is associated with one unless stated otherwise. We use the information we collect to provide and improve the Application, as described below. Where permitted by law, and only with your consent where required, we may send you service notices and marketing communications.

Information you provide:

  • Account information — your email address and, depending on the sign-in method (email and password, email link, Google, or Apple), a unique user identifier and any name or profile photo you choose to share.
  • Your content — audio recordings you make or import and content derived from them (waveforms, MIDI transcriptions, detected chords, key and tempo, tags, titles, notes, and any files you attach to notes, such as images, documents, or audio).
  • Content submitted for processing — recordings you choose to separate into stems are uploaded to our servers and processing providers. For AI suggestions, the MIDI transcription of your recording (notes and timing, not the audio) is uploaded instead.
  • Support communications — information you send us when you contact us.
  • Website sign-ups — if you sign up with your email on our website, we store the email address you submit, when you submitted it, and which part of the site it came from, and use it to send you product updates and to grant the early-supporter perk. Signing up does not make you a Front Row member; Front Row is purchased in the Application. You can unsubscribe or ask us to remove your address at any time at privacy@musairec.app.

Information collected automatically

The Application may automatically collect the type of device or computer you use, a device or installation identifier, your IP address (via server logs), your operating system and browser type, your app version, crash and diagnostic data, and information about how you use the Application. The Application does not collect precise location data, does not use advertising identifiers, and does not include third-party advertising or cross-app tracking.

Usage analytics are optional and switched off until you turn them on. If you enable them, the Application records which screens you open, an app-instance identifier generated by Firebase, and standard app-lifecycle events, using Google Analytics for Firebase. It never sends your audio, transcriptions, or the contents of your recordings and notes. Advertising identifiers and ad-personalisation signals are disabled permanently on every platform, whether or not you enable analytics.

Crash and error reporting. We collect diagnostic reports when something goes wrong, so we can find and fix it. On the iOS and Android apps this uses Firebase Crashlytics. The browser version does not — Crashlytics has no web version — and sends reports to our own servers instead, where they are stored in Google Cloud Logging and deleted after 30 days. If you are signed in, a report is linked to your account. Error messages and stack traces are produced by the software rather than written by you, but they can incidentally include text being processed at the time. Crash and error reporting is on by default and is not covered by the usage-analytics setting.

On-device vs. cloud processing

To be clear about what leaves your device:

  • On your device only (no upload): MIDI transcription, instrument and sound tagging, chord detection, and waveform generation are performed locally using bundled machine-learning models.
  • Sent to our servers: Stem separation requires your audio to be uploaded to our backend and AI processing providers, processed, and returned to you. AI musical suggestions upload the MIDI transcription of your recording, not the audio. Cloud backup and sync also transmit your content and related metadata; new accounts may include a limited period of cloud sync, during which recordings you save are backed up automatically.

How the Application uses Artificial Intelligence (AI)

The Application uses machine-learning models to provide music features:

  • On-device AI transcribes your audio to MIDI, detects chords, and tags instruments and sounds, without uploading your audio.
  • Server-side AI performs stem separation and generates musical suggestions. For stem separation your recording is uploaded to our backend and to our AI processing provider, processed, and the result returned to you; for suggestions, only the MIDI transcription of your recording is uploaded.
  • We do not use your recordings or content to train generalized AI models, and we do not use them for advertising.

Where the GDPR applies, we rely on one or more lawful bases:

  • Contract performance — to provide the features you request, including account, subscriptions and purchases, sync, stem separation, and AI suggestions.
  • Consent — where required, for example for optional usage analytics or optional communications. You may withdraw consent at any time without affecting prior processing; turning analytics off stops collection from that point on.
  • Legitimate interests — to keep the Application secure, prevent fraud and abuse, detect and fix crashes and errors so the Application stays reliable, and improve core functionality, balanced against your rights. You can object to processing based on legitimate interests — see Your GDPR rights below.
  • Legal obligation — to comply with applicable law.

Automated decision-making and profiling

We do not use your personal data for solely automated decision-making that produces legal or similarly significant effects about you. The AI features generate creative musical output at your request and do not make decisions about you.

Cookies and similar technologies

Our website sets a small number of cookies that are strictly necessary to run it: an app-integrity check (reCAPTCHA, via Firebase App Check) so the site can accept sign-ups without abuse, a cookie remembering your light or dark theme, and a cookie remembering your cookie choice (kept for six months). These are set without asking, because the site does not work correctly without them.

We also use Google Analytics on this website. Those cookies are set only if you accept them. You are asked on your first visit, nothing analytics-related loads until you choose, and you can change your mind at any time via Cookie settings in the footer. We do not use advertising cookies or ad pixels. In the browser version of the Application, analytics storage is used only if you have enabled usage analytics.

Third parties and service providers

We do not sell your personal information. We share information only with service providers that process data on our behalf under contractual obligations, with payment providers, or as required by law. We require any third party with whom we share user data to provide the same or equal protection of that data as stated in this Policy. Where the GDPR applies, we enter into Data Processing Agreements under Article 28 with providers that process personal data on our behalf.

The Application relies on the following third-party services, each with its own privacy policy:

  • Google Firebase — authentication, cloud database (Firestore), file storage, crash reporting on the iOS and Android apps only (Crashlytics), app-integrity checks (App Check), and — only if you turn it on — usage analytics (Google Analytics for Firebase).
  • Google — sign-in.
  • Google Cloud Platform — the servers that perform stem separation and generate AI suggestions. Your recording is uploaded, processed and returned to you. It also hosts the servers that receive browser error reports and the Cloud Logging service that stores them.
  • Modal — alternative cloud GPU infrastructure that may be used to generate AI suggestions. Stem separation is not processed by Modal.
  • RevenueCat — subscription and entitlement management, acting as our data processor. We share your account identifier and email; RevenueCat also receives your purchase history and technical information about your device or browser (such as device type, operating system, browser, language, time zone, screen size and, in the browser version, the page you are on) to process and manage your subscription.
  • Apple, Google Play, and Stripe — payment processing for in-app purchases and subscriptions. We do not receive or store your full payment card details.

We may also disclose information as required by law (such as to comply with a subpoena or similar process); when we believe in good faith it is necessary to protect our rights or the safety of others, or to investigate fraud; and in connection with a merger, acquisition, or sale of assets, in which case we will notify you of any change in how your information is handled.

International data transfers

We operate globally, and our service providers may process and store your information in countries other than your own, including the United States. Where we transfer personal data outside the EEA or the UK, we rely on an appropriate mechanism under GDPR Chapter V, such as an adequacy decision or the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable). Countries outside the EEA may not provide the same level of protection; where required, we apply appropriate safeguards.

Your opt-out rights

Usage analytics can be turned on or off at any time in the app, under Settings → Data & privacy (“Help improve Musairec”). It is off unless you enable it, you are asked once when you first set the app up, and turning it off stops analytics collection from that point on.

Analytics cookies on our website are separate, and are set only if you accept them. Use Cookie settings in the footer of any page to accept or reject them, or to change a choice you made earlier.

You can stop all further collection from your device by uninstalling the Application. Uninstalling stops the app from collecting new data, but it does not automatically delete information already transmitted to us or to third parties. To delete that data, use the in-app tools or contact us at privacy@musairec.app.

Data retention and managing your information

You can delete your account directly from the Account settings in the app. To receive a copy of your data, email privacy@musairec.app.

  • We retain your account information, content, and processing records for as long as your account is active.
  • When you delete your account, your data is retained for 30 days and then permanently deleted. Signing back in within 30 days cancels the deletion.
  • Recordings you move to Trash are deleted automatically after 60 days, or sooner if you empty the Trash.
  • If your paid plan, trial, or any included cloud-sync period ends, your cloud copy stays downloadable for 30 days, is retained for a further 60 days, and is then deleted. Recordings and files stored on your device are not affected.
  • Server logs, including IP addresses and error reports, are kept for 30 days. Crash reports are retained by Firebase Crashlytics for 90 days, and usage-analytics data by Google Analytics for Firebase for two months, Google’s defaults. Website sign-ups are kept until you unsubscribe or ask us to remove them.
  • We may retain limited information for longer where required to comply with law, resolve disputes, or enforce our agreements; subscription and billing records held by RevenueCat and Stripe are kept as required for tax and dispute purposes.

Children’s privacy

The Application is not intended for children under 16 years of age, or where a higher age of digital consent is established under applicable law (and not below 13 in any case). The Service Provider does not knowingly collect personal information from children below the applicable age. If we discover that a child has provided personal information, we will delete it. If you are a parent or guardian and believe your child has provided us with personal information, contact privacy@musairec.app.

How your information is kept secure

We implement physical, electronic, and procedural safeguards to protect the information we process, including encryption in transit, authentication, access controls limited to authorized personnel, and app-integrity checks. No security system can prevent all breaches, so we cannot guarantee absolute security.

Data breach notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as required by applicable law. Where the breach is likely to result in a high risk to you, we will also notify you without undue delay.

Your GDPR rights

Under the GDPR you have the rights of access, rectification, erasure, restriction, data portability, objection (including an absolute right to object to direct marketing), and withdrawal of consent. You also have the right to lodge a complaint with your local Data Protection Authority (contacts at edpb.ec.europa.eu; in the UK, the ICO at ico.org.uk).

Your California privacy rights (CCPA/CPRA)

If you are a California resident, you have the rights to know, delete, and correct your personal information, to opt out of the sale or sharing of personal information for cross-context behavioral advertising, to limit the use of sensitive personal information, and to non-discrimination. We do not sell or share your personal information as those terms are defined under California law. To exercise these rights, contact privacy@musairec.app; you may use an authorized agent.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, where required, seek your consent to material changes. Previous versions are available on request at privacy@musairec.app. This Privacy Policy is effective as of 23 September 2026.

How to contact the Data Controller

For any privacy questions or to exercise your rights, contact Musairec, LLC at privacy@musairec.app. We will respond within one month of receiving your request, extendable by up to two months where necessary due to complexity or volume, as permitted by applicable law.