Draft pending review — this text has not yet been reviewed by a lawyer and may change before launch.
Privacy Policy
Last updated: October 6, 2026
This policy explains which personal data My Music Loft (https://mymusicloft.com) processes, why, for how long, with which providers and what rights you have. It applies to people who create an account and to people who open a public link or an artist page without an account. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR").
1. Data controller
Andrea Biagioni, sole proprietorship, VAT number 02033800471, registered office at Piazza Papa Giovanni XXIII 6, 51100 Pistoia (PT), Italia.
For any privacy question and to exercise your rights: info@mymusicloft.com. No Data Protection Officer has been appointed, as one is not required for this processing.
2. What data we process
Account
- your email address, used to sign in and to receive service messages;
- the name you choose, your username (if you set one) and the public links you add to your profile;
- your password, if you set one, stored only as a salted hash (scrypt): nobody can read it;
- preferences (for example chord notation), plan, storage used, creation date.
Content you upload
- audio files, separated tracks (stems), artwork, artist page photos, sheet music;
- titles, descriptions, lyrics and chords, credits, notes, folders and projects;
- data we derive from your files to make them work in the app: duration, waveform, estimated tempo and key.
If you enter other people's names or email addresses in credits, in your musicians list or in invitations, we process them on your behalf and only to show them where you put them or to send the invitation: make sure you are allowed to.
Collaboration
When you invite someone to a project we keep the invitation email (if you give one), who invited, the role and the invitation status; for members, their role on each project or track.
Plays and visits on public links and artist pages
When someone opens a public link or an artist page, to give the person sharing it aggregate statistics we record: date and time; device type (phone, tablet, computer); the referrer, reduced to the name of the site the visit came from (for example "Instagram"), with no path or parameters; the country, derived from the IP address using a database installed on our own server, without sending the address to anyone; for artist pages also which link was clicked or which track was played. To avoid counting the same person twice we compute a daily fingerprint (a truncated hash of IP address, browser and a secret value that changes every day): it is pseudonymous data, and fingerprints from different days cannot be linked to each other without knowing the address. The IP address is not stored, and no cookies are used to count plays. Owners are not counted.
Sign-in and security
- sign-in codes and links sent by email (stored only as a hash, valid for 15 minutes);
- open sessions, with start and last-use time, to show you your signed-in devices;
- the number of failed code or password attempts and anti-abuse counters (per email, account or IP address): in those counters the key is stored only as a hash.
Payments
If you subscribe, payments go through Stripe. We keep your Stripe customer ID, your plan and subscription status, and receipt data. Card details are seen and stored only by Stripe, never by us.
Technical data
- web server logs, which may contain IP address, date, requested page and browser;
- error reports and performance data sent to Sentry: the page or feature involved (with secret link codes removed), browser and operating system, and only the internal ID of your account if you are signed in. No email, no name, no IP address, no form contents.
3. Why we process it and on what legal basis
- Providing the service (account, sign-in, uploading and processing files, sharing, collaboration, subscription, service emails): performance of a contract (Art. 6(1)(b) GDPR).
- Tax and accounting obligations on payments: legal obligation (Art. 6(1)(c)).
- Security, abuse prevention and fixing errors (attempt limits, logs, Sentry, backups): legitimate interest in keeping the service safe and working (Art. 6(1)(f)).
- Play and visit statistics for people who share: our legitimate interest, and that of the person sharing, in knowing in aggregate and minimised form how their content is played (Art. 6(1)(f)). You can object by writing to us.
We do not sell data, run ads, build profiles or make automated decisions about you.
4. Providers that process data
We use these providers, appointed as processors (Art. 28 GDPR):
- IONOS SE (Germany): server hosting the application and database.
- Backblaze, Inc. (United States), with data in the EU Central region data centre (Amsterdam, the Netherlands): storage of uploaded files and backups.
- Resend (Plus Five Five, Inc., United States): sending service emails (sign-in, notices, invitations). It receives your address and the message content.
- Stripe (Stripe Payments Europe, Ltd., Ireland, and group companies in the United States): payments and the subscription portal. For payment data Stripe also acts as an independent controller, under its own policy.
- Sentry (Functional Software, Inc., United States), with data stored in the EU region (Germany): error reporting and performance monitoring.
5. Transfers outside the European Union
Backblaze, Resend, Stripe and Sentry are, or belong to, US companies: some data may be processed in the United States. Transfers rely on the EU–US adequacy decision (EU-U.S. Data Privacy Framework) for certified companies and in any case on the European Commission's standard contractual clauses included in each provider's data processing agreement. You can ask us for a copy of these safeguards.
6. How long we keep it
- account and content: as long as you keep your account. If you delete it, files and data are removed from the service immediately and from backups within 30 days. What you uploaded to other people's projects stays with them, without your name;
- sign-in codes and links: valid for 15 minutes, then deleted at the next clean-up (every 6 hours);
- sessions: 30 days from sign-in, or until you sign out;
- failed sign-in attempts: reset after 7 days without errors; anti-abuse counters: at most 24 hours plus clean-up time;
- plays and visits: 13 months, to allow year-on-year comparison;
- closed invitations and ownership transfer proposals: one month;
- interrupted uploads: 24 hours;
- «Export my data» archives: 24 hours after they are ready, then deleted;
- artist page names (
/@name) of a deleted account: kept reserved, on their own and with no link to you, for 12 months, so that people with the old link do not land on someone else's page; - database backups: 30 days;
- error reports on Sentry: at most 90 days;
- web server logs: 14 days;
- payment data and receipts: 10 years, as required by Italian tax law (Art. 2220 of the Civil Code).
7. Your rights
You can at any time ask to access, correct or delete your data, restrict its processing, receive it in a machine-readable format (portability) and object to processing based on legitimate interest (Articles 15–22 GDPR).
- you can do many of these yourself in Settings: edit your name, username and links, sign out other devices, export your data (a ZIP archive with your original files and your data in JSON, once every 24 hours, via an emailed link valid for 24 hours) and delete your account (confirmed with an emailed code);
- for anything else write to info@mymusicloft.com from your account's address. We reply within one month.
If you opened a public link without an account, the statistics contain neither your IP address nor your name: the daily fingerprint is pseudonymous data that does not identify you on its own. You can still exercise your rights, including the right to object, by writing to us.
If you believe the processing breaks the law, you can lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of the EU country where you live or work.
8. Cookies and browser storage
We only use technical tools that are necessary for the service to work. That is why we do not ask for consent and there is no banner.
ml_session: session cookie that keeps you signed in; lasts 30 days, not readable by scripts;ml_link_…: if you open a password-protected link and enter the right password, remembers that you unlocked that link so it does not ask again; one per link, lasts until the link expires and at most 30 days, not readable by scripts, and does not contain the password;ml_locale: remembers the language you picked; set only when you pick one, lasts one year;ml-sidebar: remembers whether you collapsed the sidebar; set only when you collapse or expand it, lasts one year;- browser local storage (
localStorage): the player queue, the track mix, display preferences, your chosen sign-in method, the page to return to after an invitation. It stays on your device and is not sent to us; - if you install the app, the browser keeps a copy of pages, your library and artwork to open them faster and offline.
We do not use profiling, analytics or third-party cookies.
9. Children
You must be at least 14 years old to create an account. To take out a paid subscription you must be of legal age or have the consent of a parent or guardian.
10. Security
Encrypted connections (HTTPS), passwords stored as hashes, unguessable secret links and codes, server access limited to the controller, daily backups. No system is 100% secure: if we discover a breach affecting you, we will tell you as the law requires.
11. Changes
If we change this policy in a significant way we will tell you by email or in the app before the changes apply. The date at the top shows when it was last updated. This English version is a translation: if the two differ, the Italian version prevails.