Privacy Policy
Last updated: 7 September 2026
1. Introduction
MusicToPiano ("we", "our") respects your privacy. This policy explains what data we collect, why, and how we protect it. We comply with the EU General Data Protection Regulation (GDPR).
2. Data We Collect
Account Information
- Email address (for login, receipts, and account recovery)
- Name (optional, for personalization)
- Password (bcrypt-hashed, never stored in plain text)
Audio and Scores
- Audio files you upload (stored in Cloudflare R2, encrypted at rest)
- Generated scores, MIDI files, and arrangements
Usage Data
- Pages visited, features used, songs uploaded (for product improvement)
- IP address (for security and rate limiting, not stored permanently)
Payment Data
- Processed entirely by Stripe — we never see or store your card details
3. How We Use Your Data
- To provide the Service (transcription, score generation, playback)
- To manage your account and subscription
- To send transactional emails (welcome, receipts, password reset)
- To improve the Service (aggregate analytics, always anonymized)
4. Legal Basis (GDPR)
- Contract: Processing necessary to deliver the Service you signed up for
- Legitimate interest: Security, fraud prevention, product improvement
- Consent: Non-essential cookies (analytics) — you can opt out
5. Data Sharing
We do NOT sell your data. We share only with:
- Stripe — payment processing (card data never touches our servers)
- Cloudflare — CDN, DDoS protection, file storage (R2)
- Google — OAuth sign-in and anonymous analytics (with consent)
- Resend — transactional email delivery
6. Data Retention
Audio and scores are kept until you delete them or delete your account. Account data is kept while your account is active. Deleting your account removes ALL data permanently, including R2 files, within 24 hours.
7. Your Rights (GDPR)
You have the right to: access your data, rectify inaccuracies, delete your account ("right to be forgotten"), restrict processing, object to processing, and data portability. To exercise any right, contact [email protected] or use the in-app account deletion in Settings.
8. Security
All traffic uses HTTPS/TLS. Passwords are bcrypt-hashed. Sessions use HttpOnly, SameSite cookies with Secure flag in production. Data at rest is encrypted by our providers (Cloudflare R2, PostgreSQL).
9. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect data from children under 13.
10. Contact
Data Protection inquiries: [email protected]
