DRAFT — must be reviewed by a lawyer before publishing. Replace every
{{PLACEHOLDER}}. Check it against what the shipped app and cloud actually collect before publishing — this draft describes the design as of v0.9.
monody Privacy Policy
Last updated: {{DATE}}
BlazeApps LLC, {{ADDRESS}} ("we") is the data controller for the personal data described here. Contact: support@monody.ai.
What we collect and why
| Data | When | Why (legal basis) |
|---|---|---|
| Email address, password hash, account creation date | You create an account | To run your account and send service emails (contract) |
| Plan, subscription status, Paddle customer and subscription ids | You buy a plan | To unlock what you paid for (contract) |
| AI prompts, the relevant project state (track names, notes, device settings — not your audio files), and the assistant's replies | You use the AI assistant | To perform the request (contract) |
| AI usage records: time, model, token counts, credits used | Every AI request | Metering, fraud prevention, billing (contract, legitimate interest) |
| App version, operating system, IP address, request logs | The app talks to our servers | Security, debugging, update checks (legitimate interest) |
We do not collect your audio recordings or project files: projects stay on your computer. The app does not include advertising or third-party tracking. Card details are collected by Paddle, never by us.
Who processes it
- Paddle.com (Merchant of Record) — payments, invoicing, tax, refunds. Paddle is an independent controller for payment data; see https://www.paddle.com/legal/privacy.
- Anthropic — runs the AI model that answers assistant requests. Prompts and project state are sent through our servers; under Anthropic's commercial API terms they are not used to train models. {{VERIFY current Anthropic retention terms before publishing}}
- Render — hosts our servers and database ({{REGION}}).
- {{EMAIL_PROVIDER}} — sends account emails (sign-in, password reset).
Some of these providers are outside your country (including the United States); transfers rely on Standard Contractual Clauses or equivalent safeguards.
How long we keep it
Account data: while your account exists, then deleted within 30 days of closure (except what we must keep for tax/accounting — handled by Paddle). AI prompts and replies: we do not store their content beyond processing the request {{or: N days for abuse review — decide}}; usage records (no content): 24 months. Server logs: 30 days.
Your rights
Under the GDPR (EU/UK) and Turkey's Personal Data Protection Law No. 6698 (KVKK) you can ask for access to, correction of, deletion of, or a copy of your personal data, object to processing based on legitimate interest, and withdraw consent where processing relies on it. Write to support@monody.ai; we answer within 30 days. You can also complain to your data protection authority (in Turkey: Kişisel Verileri Koruma Kurumu, https://www.kvkk.gov.tr).
Security
Passwords are stored as salted hashes; connections use TLS; license tokens are signed. No system is perfectly secure — tell us about vulnerabilities at support@monody.ai.
Children
monody is not directed at children under 16, and we don't knowingly collect their data.
Changes
We'll post changes here and, for material ones, notify you by email or in the app.