Privacy Policy

Last updated: 11 August 2026

Information We Collect

When you use Mastermind Music we collect and store the following information:

  • Account information — your name, email address, and profile picture as provided by Clerk, our authentication provider.
  • OAuth tokens — access and refresh tokens for any music platforms you choose to connect (Spotify, Tidal).
  • Music library metadata — track titles, artist names, album names, playlists, genres, BPM, key, and platform IDs that you import or create within the service.
  • Usage data — server logs including IP addresses, request timestamps, and API endpoints accessed.
  • Desktop app analytics and crash reports — see the dedicated section below, including how to turn them off.

We do not collect passwords (authentication is handled entirely by Clerk), payment information, or audio files.

Desktop App Analytics & Crash Reporting

The Mastermind desktop application sends usage analytics and crash reports to PostHog, our EU-hosted analytics provider, so we can see which features are used and find and fix problems. This is on by default, and you can turn it off at any time in Settings → Privacy & Data inside the app — the first launch shows a notice with the same one-click switch. Turning it off stops all collection immediately.

What is sent while it is on:

  • A random device identifier — generated on your machine, not derived from any hardware or personal detail.
  • App version, operating system, and feature-usage events — for example “analysis started” or “a sign-in failed”, with timing information.
  • Crash reports — the error type and a stack trace that has been scrubbed on your machine before sending: file-system paths, which on Windows include your account name, are removed, and any file name that is not part of our own program (for example a music file) is replaced with a placeholder.

What is never sent: your audio files, track titles or artist names from your library, file or folder paths, search queries, or anything you type. Screen recording is off in all normal builds.

How We Use Your Information

  • Organising, analysing, and enriching your music library metadata.
  • Cross-platform track matching — identifying the same track across Spotify, Tidal, Bandcamp, Beatport, SoundCloud, and MusicBrainz.
  • Importing and exporting playlists between connected platforms.
  • Providing personalised library statistics and insights.
  • Improving the service and fixing bugs.

Third-Party Services

Mastermind Music integrates with the following third-party services. Each receives only the data necessary to perform its function:

  • Clerk — authentication and session management. Receives your email, name, and profile picture.
  • Spotify — track search, audio features, and playlist management. Receives search queries and playlist data when you use Spotify features.
  • Tidal — track search and playlist management. Receives search queries and playlist data when you use Tidal features.
  • Bandcamp, Beatport, SoundCloud — track matching and metadata lookup. Receives search queries containing track titles and artist names.
  • MusicBrainz — open metadata enrichment. Receives track titles and artist names for metadata lookup.
  • Neon (PostgreSQL) — cloud database. Stores all application data described above.
  • Vercel — hosting and serverless compute. Processes all web requests.
  • PostHog (EU region) — desktop app analytics and crash reports, as described above. Receives the random device identifier and usage/crash events; hosted in the EU.
  • Sentry — server-side error monitoring for the web application. Receives error details from our servers when something breaks.
  • Chatwoot (self-hosted) — our support chat, hosted by us at support.mastermindmusic.net. Receives your messages and, when signed in, your account email so we can reply.

Data Storage & Security

  • All data is transmitted over HTTPS. We do not support unencrypted connections.
  • OAuth tokens are stored server-side in our database — they are never exposed to the browser.
  • We do not store passwords. Authentication is delegated entirely to Clerk.
  • All database queries use parameterised statements to prevent SQL injection.
  • API endpoints are protected by rate limiting and security headers (CSP, HSTS, X-Frame-Options).

Cookies

The Mastermind Music website uses only essential cookies set by Clerk for session management, plus a cookie from our self-hosted support chat if you open it. We do not use advertising cookies or third-party ad trackers. The desktop application's analytics (described above) are not cookies and have their own off switch in the app.

Your Rights & Controls

  • Disconnect platforms — you can disconnect any connected music platform at any time from your settings. This revokes the stored OAuth tokens.
  • Data export — you can request a copy of all data we hold about you by contacting us.
  • Account deletion — you can request deletion of your account and its associated data by contacting us at the address below. Contract and signature records are kept separately and are not deleted with your account — see Contract & Signature Records below.
  • Object to processing — where we rely on legitimate interests (for example, the IP address and user agent held in a signature record), you can object to that processing by contacting us at the address below.

Data Retention

We retain your data for as long as your account is active. When you request account deletion, your account is deactivated and your data taken out of use straight away, and permanently removed from our production systems within 30 days — including, on request, the analytics identity described above. Server logs are retained for up to 90 days for security and debugging purposes. Note that your music library itself lives on your own computer and is never in our hands to delete. Contract and signature records are the one exception to this timeline — see the section below.

Contract & Signature Records

If you sign the closed-beta non-disclosure agreement, we keep a record of that agreement separately from the rest of your account: your identity (name and email), the IP address and browser/device details used at signing, timestamps for each step, and the signed document itself.

We keep the identity fields because we need them to perform the contract — they are how we know who agreed to what. We keep the IP address and user agent under our legitimate interest in being able to establish and defend the agreement if it is ever disputed. We hold these records for around seven years, in line with contract limitation periods.

These records exist to evidence that the agreement was made, so they are the one exception to the deletion timeline described above: deleting your account does not delete a signature record we hold on you. Everything else covered by this policy — your library, your OAuth tokens, your usage data — follows the deletion process as normal.

Children's Privacy

Mastermind Music is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.

Changes to This Policy

We may update this privacy policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.

Contact

If you have questions about this privacy policy or want to exercise your data rights, contact us at: privacy@mastermindmusic.net

Privacy Policy | Mastermind Music