Privacy Policy

Last updated: 20 February 2025

Information We Collect

When you use Mastermind Music we collect and store the following information:

  • Account information — your name, email address, and profile picture as provided by Clerk, our authentication provider.
  • OAuth tokens — access and refresh tokens for any music platforms you choose to connect (Spotify, Tidal).
  • Music library metadata — track titles, artist names, album names, playlists, genres, BPM, key, and platform IDs that you import or create within the service.
  • Usage data — server logs including IP addresses, request timestamps, and API endpoints accessed.

We do not collect passwords (authentication is handled entirely by Clerk), payment information, or audio files.

How We Use Your Information

  • Organising, analysing, and enriching your music library metadata.
  • Cross-platform track matching — identifying the same track across Spotify, Tidal, Bandcamp, Beatport, SoundCloud, and MusicBrainz.
  • Importing and exporting playlists between connected platforms.
  • Providing personalised library statistics and insights.
  • Improving the service and fixing bugs.

Third-Party Services

Mastermind Music integrates with the following third-party services. Each receives only the data necessary to perform its function:

  • Clerk — authentication and session management. Receives your email, name, and profile picture.
  • Spotify — track search, audio features, and playlist management. Receives search queries and playlist data when you use Spotify features.
  • Tidal — track search and playlist management. Receives search queries and playlist data when you use Tidal features.
  • Bandcamp, Beatport, SoundCloud — track matching and metadata lookup. Receives search queries containing track titles and artist names.
  • MusicBrainz — open metadata enrichment. Receives track titles and artist names for metadata lookup.
  • Neon (PostgreSQL) — cloud database. Stores all application data described above.
  • Vercel — hosting and serverless compute. Processes all web requests.

Data Storage & Security

  • All data is transmitted over HTTPS. We do not support unencrypted connections.
  • OAuth tokens are stored server-side in our database — they are never exposed to the browser.
  • We do not store passwords. Authentication is delegated entirely to Clerk.
  • All database queries use parameterised statements to prevent SQL injection.
  • API endpoints are protected by rate limiting and security headers (CSP, HSTS, X-Frame-Options).

Cookies

Mastermind Music uses only essential cookies set by Clerk for session management. We do not use tracking cookies, advertising cookies, or any third-party analytics cookies.

Your Rights & Controls

  • Disconnect platforms — you can disconnect any connected music platform at any time from your settings. This revokes the stored OAuth tokens.
  • Data export — you can request a copy of all data we hold about you by contacting us.
  • Account deletion — you can request deletion of your account and all associated data by contacting us at the address below.

Data Retention

We retain your data for as long as your account is active. If you request account deletion, we will delete all your personal data and music library metadata within 30 days. Server logs are retained for up to 90 days for security and debugging purposes.

Children's Privacy

Mastermind Music is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.

Changes to This Policy

We may update this privacy policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.

Contact

If you have questions about this privacy policy or want to exercise your data rights, contact us at: privacy@mastermindmusic.net