Privacy Policy
Last updated: August 3, 2026
This policy describes how MusicPulse processes your personal data, in accordance with Regulation (EU) 2016/679 (“GDPR”) and the French Data Protection Act of 6 January 1978 as amended. It applies to www.musicpulse.app, the application and related communications.
1. Data controller
The data controller is Pierre-Albert Benlolo, sole proprietor, SIREN 522 424 209, 27 B rue Singer, 75016 Paris, France. Given the size of the business, no data protection officer has been appointed; any data request may be sent via the site's contact form, which is the dedicated point of contact.
2. Data we collect
Account data: email address, display name, password (hashed), verification status, language, Google identifier where you sign in with OAuth. Content: audio files you submit, associated metadata (title, artist, genre, BPM, lyrics where applicable), analysis results, vault files, information entered in the release passport (including your collaborators' names, whom you undertake to inform). Usage data: actions performed in the Service, credit consumption, technical logs (IP address, browser type, timestamps) and audience measurement. Billing data: Stripe customer and subscription identifiers, transaction history; card data is processed exclusively by Stripe and never transmitted to us. Your fans' data: email addresses collected through your smart links; you are the controller of these contacts, MusicPulse acting as a processor hosting them on your behalf. Communications: messages exchanged via the contact form or by email.
Product usage data: when you are logged in, we record which features of the dashboard you open and interact with (feature name and timestamps only, no content). This first-party data is tied to your account, stored on our servers and used solely to understand which features are used and to improve the service (legitimate interest). It involves no cookie and no third party.
3. Purposes and legal bases
Provision of the Service, account and credit management — performance of the contract (Art. 6(1)(b) GDPR). Payment processing and invoicing — performance of the contract and legal accounting and tax obligations (Art. 6(1)(b) and (c)). Analysis of your audio files and content generation by our processing providers — performance of the contract. Service improvement and audience measurement — legitimate interest (Art. 6(1)(f)), with your consent where non-essential trackers are used. Service emails (verification, alerts, digests) — performance of the contract; commercial communications to users — legitimate interest, with the right to object at any time (unsubscribe link). Fraud prevention and security — legitimate interest. Responses to requests from authorities — legal obligation.
4. Outreach to artists
As part of business development, MusicPulse occasionally sends prospecting emails to artists whose professional address they themselves made public (notably in their Spotify biography). This processing is based on legitimate interest (business-to-business prospecting) and follows these principles: limited volumes, content relevant to the artist's activity, clear identification of the sender, and a one-click unsubscribe link in every message, the exercise of which is final. Unsubscribed addresses are kept on a suppression list for the sole purpose of honouring that choice. You may also exercise your rights as described in section 8.
5. Recipients and processors
Your data is processed by the following providers, each for the stated purpose: Supabase, Inc. (database and file hosting, European Union region — Ireland); Railway Corp. (application hosting, United States); Stripe Payments Europe, Ltd. (payments); Resend, Inc. (email delivery); Google LLC (audio analysis and generation — Gemini API); Anthropic, PBC (analysis and generation — Claude API); OpenAI, LLC (ancillary processing); Suno, Inc. (music generation); KIE (video generation); Meta Platforms Ireland Ltd. (only if you use the advertising campaign service); as well as services providing access to public streaming-platform data. No data is sold to third parties; none of these providers is permitted to use your content to train its models.
6. Transfers outside the European Union
Some providers are established in the United States. The corresponding transfers are governed by an adequacy decision (EU-US Data Privacy Framework) where the provider is certified, and otherwise by the European Commission's standard contractual clauses, supplemented where appropriate by additional measures. A copy of the applicable safeguards may be requested via the contact form.
7. Retention periods
Account data and content: for the life of the account, then deleted within a maximum of thirty (30) days after account deletion, subject to legal obligations. Billing documents: ten (10) years (accounting obligation). Technical and security logs: up to twelve (12) months. Prospecting: data of prospects who have not responded is deleted no later than three (3) years after the last contact; suppression lists (unsubscribes) are kept indefinitely for objection purposes only. Audience measurement data: kept in aggregated form.
8. Your rights
You have the rights of access, rectification, erasure, restriction, portability, objection (including to prospecting, without giving reasons), and the right to withdraw consent at any time where processing is based on it. You may also give instructions regarding your data after death (Art. 85 of the French Data Protection Act).
These rights are exercised via the site's contact form or by post to the controller's address, together with proof of identity where there is reasonable doubt. You will receive a reply within one (1) month, extendable by two (2) months for complex requests.
If you consider that your rights are not respected, you may lodge a complaint with the CNIL (French data protection authority): www.cnil.fr — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
9. Automated processing and audio content
Your audio files are analysed by signal processing run by us and by models provided by Google and Anthropic through their business APIs. These providers acquire no rights in your works and do not use them to train their models. The results (analyses, scores, recommendations) are decision-support tools and produce no automated legal effect concerning you within the meaning of Article 22 GDPR.
10. Security
We implement appropriate technical and organisational measures: encryption in transit (TLS), encryption at rest with our hosts, per-user access partitioning at database level (row-level security), private file storage with time-limited signed URLs, least-privilege administration access, logging, and minimisation of data entrusted to providers. In the event of a data breach likely to result in a high risk to your rights, you will be informed in accordance with Articles 33 and 34 GDPR.
11. Minors
The Service is not intended for children under fifteen (15), the age of digital consent in France. If you believe a child under fifteen has provided us with data without joint consent of a holder of parental authority, contact us to have it deleted.
12. Cookies and trackers
The use of cookies and similar technologies is described in the Cookie Policy, accessible from the footer. You can change your choices at any time via the “Manage my cookies” link.
13. Changes
This policy may be updated to reflect changes to the Service or the legal framework. In the event of substantial change, account holders will be informed by email or notification. The date of last update appears at the top of the page.