Last Updated: August 17, 2026
SoundDeal ("we," "us," or "our") operates the SoundDeal platform. This Privacy Policy explains how we collect, use, and protect your information.
Who we are. The data controller for the personal information described in this policy is Songs About Sound, LLC, 5777 W Century Blvd, Ste 1600, Los Angeles, CA 90045. You can reach us about anything in this policy at support@sounddeal.com.
Account Information: When you create an account, we collect your email address and password (stored in hashed form).
Payment Information: When you purchase a plan, payment is processed by Stripe. We do not store your credit card number, expiration date, or CVC.
Uploaded Contracts: When you submit a contract for analysis, the document text is processed by our AI analysis engine. The original uploaded file is deleted from our file storage once the analysis completes successfully; see Section 6 for what happens when an analysis fails. The extracted text is used to generate your analysis output and, for supported deal types, structured deal terms. These derived items are stored in your account so you can revisit your results. Your analysis output can quote or paraphrase passages from your contract — that is what makes a red flag or a redline useful — so the analysis we retain may contain excerpts of the original document.
A note on embeddings: Earlier versions of this policy said we store embeddings (numerical representations) of your contract to improve future analyses. We no longer do this. Contributions from user contracts to our retrieval corpus are switched off, and the reference material our analysis engine retrieves from is a curated corpus we maintain — not other users' contracts. If we ever re-enable user contributions, it will be opt-in and this policy will be updated first.
Analysis Results: Your analysis reports (deal health scores, red flags, benchmarks, negotiation briefs) are stored in our database so you can access your analysis history.
Structured Deal Terms: For supported deal types, we extract structured fields from your contract (such as advance amounts, royalty rates, term lengths, territory, and similar financial terms) and store them in your account. These fields may also be included in our anonymized benchmark dataset if you have opted in (see Section 4A).
Usage Data: We collect basic usage data including pages visited, features used, analysis count, and timestamps.
Cookies: We use essential cookies for authentication and session management. We do not use advertising or third-party tracking cookies.
We use your information to:
We do NOT:
We use the following third-party services to operate SoundDeal. This is the complete list of sub-processors that may handle personal data on our behalf:
Changes to this list. If we add or replace a sub-processor that handles personal data, we will update this section and the "Last Updated" date above before the change takes effect, and we will notify account holders by email where the change is material.
SoundDeal maintains an industry benchmark dataset built from anonymized deal terms (such as advance amounts, royalty rates, points, term lengths, territory scope, and similar non-identifying financial fields) extracted from contracts analyzed through the Service. This dataset powers the market comparisons and negotiation guidance shown to all users.
User-contributed data: When you upload a contract, you may opt in to including anonymized deal terms in our benchmark dataset by checking the consent box on the analysis page. Opting in is voluntary and not required to use the Service. If you do not opt in, your deal terms will not be included in benchmark calculations.
Pre-cleared sources: A portion of the benchmark dataset originates from pre-cleared sources, including management company databases where the rights holders have authorized anonymized aggregation through their representation, distribution, or licensing agreements. Where SoundDeal relies on legitimate interest as a basis for processing such data, we have determined that our interest in producing accurate industry benchmarks does not override the rights and freedoms of data subjects, given the anonymized and aggregated nature of the data.
What is included: Only specific structured fields are included — for example, deal type, advance amount, royalty rate, term length, territory, and similar non-identifying terms. Personally identifying information such as party names, signatures, and the original contract text are NOT included in the benchmark dataset.
How it is used: Benchmark statistics are computed from groups of records and never reveal the terms of any single contract or party. Aggregated statistics may be displayed to other users, included in product features, used to improve our analysis models, referenced in SoundDeal marketing, and licensed or made available as anonymized industry statistics.
Withdrawing consent: You may withdraw consent at any time by contacting support@sounddeal.com. Withdrawal covers all of your contributed analyses, past and future, not only the ones you upload afterwards: we remove your contributed deal terms from the dataset, so they are excluded from every subsequent benchmark calculation. What we cannot do is un-publish arithmetic — benchmark figures already computed and displayed before your withdrawal are not retroactively recalculated. We action withdrawal requests within a reasonable timeframe.
SoundDeal offers a connector based on the Model Context Protocol ("MCP") that allows AI assistants you use — such as Anthropic's Claude — to access SoundDeal on your behalf.
Two ways an assistant can reach your account. There are exactly two, and they differ in how permission is granted. Both are listed on your Connected Apps page, which is the complete picture of what can reach your account.
1. OAuth — per-connection consent. This is how Claude and other interactive MCP clients connect. Access is possible only after you sign in to SoundDeal and explicitly approve the connection on our consent screen, which identifies the application and lists each permission it is asking for. Permissions are granular and separately granted: benchmarks:read (aggregate market data, which reveals nothing about your contracts), analyses:read (the analyses stored in your account, including contract contents), and analyses:write (running new analyses using your plan's allowance). An application that later asks for a permission you did not grant must prompt you again.
2. API key — an all-or-nothing credential you mint yourself. A SoundDeal API key sent as a bearer token also works against the connector, and this path has no consent screen — because there is no third party to consent to. You create the key yourself and choose what to give it to. A key used this way is all-or-nothing: it carries the equivalent of all three permissions above against your own account, and it does not expire on its own. Treat one like a password. See Section 4C for how keys are stored and revoked.
Revoking access. You can disconnect any OAuth-connected application at any time from your Connected Apps page. Disconnecting invalidates that application's access and refresh tokens server-side, so its next request fails immediately rather than continuing until a token expires, and it must ask for your permission again to reconnect. Revoking one application does not affect any other, and does not affect your API keys — those are revoked separately at Developer API.
What data is accessed. Depending on the permissions in force, a connected AI assistant may: retrieve aggregate market benchmark statistics (which contain no individual contract data); retrieve the results of contract analyses stored in your account; submit contract text or files for analysis, which are processed and stored in the same way as contracts you upload through our website; and generate negotiation briefs from your stored analyses. Analyses created through the connector or the API are never added to the benchmark dataset — the opt-in described in Section 4A is offered only on our website's upload page, and analyses submitted through any other interface default to not contributing.
What the AI assistant provider sees. When you use SoundDeal through an AI assistant, the content of your requests and our responses passes through that assistant's platform (for example, Anthropic's systems when using Claude). That data is handled under the AI assistant provider's own privacy policy and terms, which are separate from ours. We encourage you to review the privacy practices of any AI assistant you connect to SoundDeal.
Aggregate data protections. Benchmark statistics returned through the connector are computed from multiple contracts and are never returned for samples small enough to identify an individual deal. The connector does not provide access to any other user's contracts, analyses, or account data.
Security. OAuth connector access uses the OAuth 2.1 authorization standard. We store only cryptographic hashes of access credentials, never the credentials themselves. OAuth access tokens expire after one hour, refresh tokens rotate on each use, and a refresh chain expires no more than 60 days after you first authorized it. API keys, by contrast, do not expire — they remain valid until you revoke them.
Audit and retention. Requests made through the connector are logged (including IP address, the tool invoked, and timestamps) for security, abuse prevention, and service improvement, consistent with the logging described elsewhere in this policy. Analyses created through the connector are retained under the same retention terms as analyses created on our website.
Your controls. You may disconnect any AI assistant from your Connected Apps page or from the assistant's own connector settings. Disconnecting stops all future access; data already shared with the AI assistant provider remains subject to that provider's policies.
If you use the SoundDeal API, you create API keys yourself from the Developer API page. A key is a credential that acts on your account, and anyone holding it can do what the key permits without any further sign-in.
How keys are stored. We store only a SHA-256 hash of each key, never the key itself. The full key is shown to you once, at creation, and cannot be retrieved afterwards — if you lose it, revoke it and create another. We also store a short non-secret prefix (for example sd_live_a1b2) so you can tell your keys apart in a list.
What a key can access on the REST API. Keys carry scopes, and a request is refused unless the key positively holds the required one: analyze:write submits contracts for analysis and consumes the key's allowance; analyses:read lists and fetches analyses and jobs belonging to your account; logs:read reads that key's own audit log entries. A key created without an explicit scope list receives analyze:write and analyses:read, but not logs:read.
What a key can access on the MCP connector. The same key sent as a bearer token to our MCP connector is not scoped in the same way: it grants the full set of account permissions described in Section 4B — reading your analyses and running new ones — without a consent screen. This is deliberate, because you are the one who minted the key and chose where to use it, but it means a key given to a third party is a broader grant than an OAuth connection to that same third party would be.
Revoking a key. You can revoke any key at any time from the Developer API page, or by calling DELETE /api/v1/keys. Revocation takes effect immediately for both the REST API and the MCP connector. Your active keys are also listed on your Connected Apps page alongside your OAuth connections, so you can see everything holding access to your account in one place.
Key usage logging. API requests are logged with the key used, the endpoint called, IP address, and timestamps, for security, abuse prevention, and billing. These logs are retained under the audit-log retention described in Section 6.
We use industry-standard security measures including encrypted connections (HTTPS) and encryption of stored data. Every credential we hold is stored as a one-way hash, never in a form we could read back: your password, your API keys (Section 4C), and OAuth access and refresh tokens (Section 4B) are all hashed. This means we cannot tell you what your own key or password is — only replace it.
However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
While your account is open we retain your analyses, extracted deal terms, and account settings so the Service works. Two things have their own short clocks:
Deleting your account. You can delete your account yourself from your account settings. When you do, you are signed out immediately and every credential connected to your account — OAuth connections and API keys alike — stops working at once.
The 30-day window. For 30 days after the request, your account is closed but recoverable: contact us within that period and we can restore it. After 30 days everything listed below is permanently deleted by an automated job, and cannot be recovered by us or by you.
Permanently deleted after 30 days: your account record, your contract analyses and their scores and red flags, your extracted deal terms, negotiation briefs, linked songs, imported income data, notification settings and history, your API keys, your OAuth connections and tokens, and your account activity log.
What we keep, and why. Three things survive account deletion. This is the complete list:
If you would rather withdraw a benchmark contribution than delete your whole account, Section 4A explains how — you do not have to close your account to do it.
You have the right to:
To exercise any of these rights, contact us at support@sounddeal.com. You can disconnect apps and see what holds access to your account yourself, at any time, from your Connected Apps page.
California Residents (CCPA): You have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information.
UK and EU Residents (UK GDPR / EU GDPR): If you are a resident of the United Kingdom or the European Economic Area, you have additional rights including the right to data portability and the right to lodge a complaint with your local data protection authority. The legal basis for processing your account data and contract analyses is the performance of our contract with you. The legal basis for including pre-cleared deal data in our benchmark dataset is legitimate interest, balanced against your rights as described in Section 4A. The legal basis for including your contributed deal data is your explicit consent.
The Service is not intended for users under 18 years of age. We do not knowingly collect information from minors.
The Service is operated from the United States, and the sub-processors listed in Section 4 process data in the United States. If you access the Service from outside the US, your information — including any contract you submit — is transferred to and processed in the US.
If you are in the United Kingdom or the European Economic Area, this is a transfer to a third country. Where a transfer is not covered by an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) as the transfer mechanism, entered into with the relevant sub-processor. You can request details of the safeguards in place for a particular transfer at support@sounddeal.com.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the Service.
Privacy questions, rights requests, and complaints all go to the same place — you do not need a special form or subject line.
Email: support@sounddeal.com
Post: Songs About Sound, LLC, 5777 W Century Blvd, Ste 1600, Los Angeles, CA 90045
If you are in the UK or EEA and you are not satisfied with how we have handled your request, you have the right to complain to your local data protection authority.