Privacy Policy

Last Updated: August 17, 2026

1. Introduction

SoundDeal ("we," "us," or "our") operates the SoundDeal platform. This Privacy Policy explains how we collect, use, and protect your information.

Who we are. The data controller for the personal information described in this policy is Songs About Sound, LLC, 5777 W Century Blvd, Ste 1600, Los Angeles, CA 90045. You can reach us about anything in this policy at support@sounddeal.com.

2. Information We Collect

Account Information: When you create an account, we collect your email address and password (stored in hashed form).

Payment Information: When you purchase a plan, payment is processed by Stripe. We do not store your credit card number, expiration date, or CVC.

Uploaded Contracts: When you submit a contract for analysis, the document text is processed by our AI analysis engine. The original uploaded file is deleted from our file storage once the analysis completes successfully; see Section 6 for what happens when an analysis fails. The extracted text is used to generate your analysis output and, for supported deal types, structured deal terms. These derived items are stored in your account so you can revisit your results. Your analysis output can quote or paraphrase passages from your contract — that is what makes a red flag or a redline useful — so the analysis we retain may contain excerpts of the original document.

A note on embeddings: Earlier versions of this policy said we store embeddings (numerical representations) of your contract to improve future analyses. We no longer do this. Contributions from user contracts to our retrieval corpus are switched off, and the reference material our analysis engine retrieves from is a curated corpus we maintain — not other users' contracts. If we ever re-enable user contributions, it will be opt-in and this policy will be updated first.

Analysis Results: Your analysis reports (deal health scores, red flags, benchmarks, negotiation briefs) are stored in our database so you can access your analysis history.

Structured Deal Terms: For supported deal types, we extract structured fields from your contract (such as advance amounts, royalty rates, term lengths, territory, and similar financial terms) and store them in your account. These fields may also be included in our anonymized benchmark dataset if you have opted in (see Section 4A).

Usage Data: We collect basic usage data including pages visited, features used, analysis count, and timestamps.

Cookies: We use essential cookies for authentication and session management. We do not use advertising or third-party tracking cookies.

3. How We Use Your Information

We use your information to:

  • Provide and operate the Service
  • Process your contract analyses
  • Manage your account and subscription
  • Process payments through Stripe
  • Send transactional emails (receipts, account notifications)
  • Improve the Service, including improving the accuracy of our analysis methodology and benchmark dataset
  • Compute aggregated industry benchmarks (using anonymized data from users who have opted in and from pre-cleared sources — see Section 4A)
  • Comply with legal obligations

We do NOT:

  • Sell or rent your personal data to third parties
  • Send marketing emails without your consent
  • Send the text of your uploaded contracts to third-party AI providers for the purpose of training their models
  • Share the text of your contracts with other users
  • Include your deal terms in our anonymized benchmark dataset unless you have opted in or your data comes from a pre-cleared source (see Section 4A)

4. Third-Party Services (Sub-processors)

We use the following third-party services to operate SoundDeal. This is the complete list of sub-processors that may handle personal data on our behalf:

  • Anthropic (Claude API) — AI contract analysis. Your contract text is sent to Anthropic to produce your analysis. Anthropic's commercial terms state that inputs and outputs sent through the API are not used to train their models. Anthropic does retain API inputs and outputs for a limited period for trust-and-safety and abuse-detection purposes, and may retain them longer where required to investigate a policy violation or comply with law. See Anthropic's own privacy policy for their current retention periods. Processing: United States.
  • Voyage AI — Generates embeddings used for retrieval-augmented analysis. Embedding inputs are not used to train Voyage's models. Processing: United States.
  • Cloudflare R2 — Temporary file storage during contract upload. See Section 6 for how long uploaded files persist. Processing: United States.
  • Cloudflare Turnstile — Bot protection on sign-up. Receives your IP address and browser signals. It is not an advertising or cross-site tracking product. Processing: global edge network.
  • Neon / Postgres — Database hosting. This is where your account, analyses, and structured deal terms are stored. Processing: United States.
  • Vercel — Application hosting. Processing: United States, with requests served from a global edge network.
  • Vercel Analytics and Speed Insights — Aggregate page-view and page-performance measurement. Cookieless, and not used for advertising or cross-site tracking. Processing: United States.
  • Sentry — Error monitoring. When something breaks, Sentry receives a diagnostic report: what failed, where in our code, and the URL being requested. If you were signed in, the report carries your account's numeric ID — not your name, not your email address — so we can tell whether a fault is affecting one account or everyone. Cookies, request bodies, authorization headers, and IP addresses are stripped from these reports before they are sent, which means your session credentials and the text of your contracts do not reach Sentry. Processing: United States.
  • Stripe — Payment processing. Stripe receives your payment details directly; we never see or store your card number. Processing: United States.
  • Resend — Transactional email delivery (receipts, password resets, account notifications). Receives your email address and the message contents. Processing: United States.

Changes to this list. If we add or replace a sub-processor that handles personal data, we will update this section and the "Last Updated" date above before the change takes effect, and we will notify account holders by email where the change is material.

4A. Anonymized Benchmark Dataset

SoundDeal maintains an industry benchmark dataset built from anonymized deal terms (such as advance amounts, royalty rates, points, term lengths, territory scope, and similar non-identifying financial fields) extracted from contracts analyzed through the Service. This dataset powers the market comparisons and negotiation guidance shown to all users.

User-contributed data: When you upload a contract, you may opt in to including anonymized deal terms in our benchmark dataset by checking the consent box on the analysis page. Opting in is voluntary and not required to use the Service. If you do not opt in, your deal terms will not be included in benchmark calculations.

Pre-cleared sources: A portion of the benchmark dataset originates from pre-cleared sources, including management company databases where the rights holders have authorized anonymized aggregation through their representation, distribution, or licensing agreements. Where SoundDeal relies on legitimate interest as a basis for processing such data, we have determined that our interest in producing accurate industry benchmarks does not override the rights and freedoms of data subjects, given the anonymized and aggregated nature of the data.

What is included: Only specific structured fields are included — for example, deal type, advance amount, royalty rate, term length, territory, and similar non-identifying terms. Personally identifying information such as party names, signatures, and the original contract text are NOT included in the benchmark dataset.

How it is used: Benchmark statistics are computed from groups of records and never reveal the terms of any single contract or party. Aggregated statistics may be displayed to other users, included in product features, used to improve our analysis models, referenced in SoundDeal marketing, and licensed or made available as anonymized industry statistics.

Withdrawing consent: You may withdraw consent at any time by contacting support@sounddeal.com. Withdrawal covers all of your contributed analyses, past and future, not only the ones you upload afterwards: we remove your contributed deal terms from the dataset, so they are excluded from every subsequent benchmark calculation. What we cannot do is un-publish arithmetic — benchmark figures already computed and displayed before your withdrawal are not retroactively recalculated. We action withdrawal requests within a reasonable timeframe.

4B. AI Assistants and Connector Access (MCP)

SoundDeal offers a connector based on the Model Context Protocol ("MCP") that allows AI assistants you use — such as Anthropic's Claude — to access SoundDeal on your behalf.

Two ways an assistant can reach your account. There are exactly two, and they differ in how permission is granted. Both are listed on your Connected Apps page, which is the complete picture of what can reach your account.

1. OAuth — per-connection consent. This is how Claude and other interactive MCP clients connect. Access is possible only after you sign in to SoundDeal and explicitly approve the connection on our consent screen, which identifies the application and lists each permission it is asking for. Permissions are granular and separately granted: benchmarks:read (aggregate market data, which reveals nothing about your contracts), analyses:read (the analyses stored in your account, including contract contents), and analyses:write (running new analyses using your plan's allowance). An application that later asks for a permission you did not grant must prompt you again.

2. API key — an all-or-nothing credential you mint yourself. A SoundDeal API key sent as a bearer token also works against the connector, and this path has no consent screen — because there is no third party to consent to. You create the key yourself and choose what to give it to. A key used this way is all-or-nothing: it carries the equivalent of all three permissions above against your own account, and it does not expire on its own. Treat one like a password. See Section 4C for how keys are stored and revoked.

Revoking access. You can disconnect any OAuth-connected application at any time from your Connected Apps page. Disconnecting invalidates that application's access and refresh tokens server-side, so its next request fails immediately rather than continuing until a token expires, and it must ask for your permission again to reconnect. Revoking one application does not affect any other, and does not affect your API keys — those are revoked separately at Developer API.

What data is accessed. Depending on the permissions in force, a connected AI assistant may: retrieve aggregate market benchmark statistics (which contain no individual contract data); retrieve the results of contract analyses stored in your account; submit contract text or files for analysis, which are processed and stored in the same way as contracts you upload through our website; and generate negotiation briefs from your stored analyses. Analyses created through the connector or the API are never added to the benchmark dataset — the opt-in described in Section 4A is offered only on our website's upload page, and analyses submitted through any other interface default to not contributing.

What the AI assistant provider sees. When you use SoundDeal through an AI assistant, the content of your requests and our responses passes through that assistant's platform (for example, Anthropic's systems when using Claude). That data is handled under the AI assistant provider's own privacy policy and terms, which are separate from ours. We encourage you to review the privacy practices of any AI assistant you connect to SoundDeal.

Aggregate data protections. Benchmark statistics returned through the connector are computed from multiple contracts and are never returned for samples small enough to identify an individual deal. The connector does not provide access to any other user's contracts, analyses, or account data.

Security. OAuth connector access uses the OAuth 2.1 authorization standard. We store only cryptographic hashes of access credentials, never the credentials themselves. OAuth access tokens expire after one hour, refresh tokens rotate on each use, and a refresh chain expires no more than 60 days after you first authorized it. API keys, by contrast, do not expire — they remain valid until you revoke them.

Audit and retention. Requests made through the connector are logged (including IP address, the tool invoked, and timestamps) for security, abuse prevention, and service improvement, consistent with the logging described elsewhere in this policy. Analyses created through the connector are retained under the same retention terms as analyses created on our website.

Your controls. You may disconnect any AI assistant from your Connected Apps page or from the assistant's own connector settings. Disconnecting stops all future access; data already shared with the AI assistant provider remains subject to that provider's policies.

4C. API Keys

If you use the SoundDeal API, you create API keys yourself from the Developer API page. A key is a credential that acts on your account, and anyone holding it can do what the key permits without any further sign-in.

How keys are stored. We store only a SHA-256 hash of each key, never the key itself. The full key is shown to you once, at creation, and cannot be retrieved afterwards — if you lose it, revoke it and create another. We also store a short non-secret prefix (for example sd_live_a1b2) so you can tell your keys apart in a list.

What a key can access on the REST API. Keys carry scopes, and a request is refused unless the key positively holds the required one: analyze:write submits contracts for analysis and consumes the key's allowance; analyses:read lists and fetches analyses and jobs belonging to your account; logs:read reads that key's own audit log entries. A key created without an explicit scope list receives analyze:write and analyses:read, but not logs:read.

What a key can access on the MCP connector. The same key sent as a bearer token to our MCP connector is not scoped in the same way: it grants the full set of account permissions described in Section 4B — reading your analyses and running new ones — without a consent screen. This is deliberate, because you are the one who minted the key and chose where to use it, but it means a key given to a third party is a broader grant than an OAuth connection to that same third party would be.

Revoking a key. You can revoke any key at any time from the Developer API page, or by calling DELETE /api/v1/keys. Revocation takes effect immediately for both the REST API and the MCP connector. Your active keys are also listed on your Connected Apps page alongside your OAuth connections, so you can see everything holding access to your account in one place.

Key usage logging. API requests are logged with the key used, the endpoint called, IP address, and timestamps, for security, abuse prevention, and billing. These logs are retained under the audit-log retention described in Section 6.

5. Data Security

We use industry-standard security measures including encrypted connections (HTTPS) and encryption of stored data. Every credential we hold is stored as a one-way hash, never in a form we could read back: your password, your API keys (Section 4C), and OAuth access and refresh tokens (Section 4B) are all hashed. This means we cannot tell you what your own key or password is — only replace it.

However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

6. Data Retention and Account Deletion

While your account is open we retain your analyses, extracted deal terms, and account settings so the Service works. Two things have their own short clocks:

  • Uploaded contract files: Deleted from file storage as soon as your analysis completes successfully. If an analysis fails partway through, the uploaded file can remain in storage until an automated sweep removes it, within 24 hours.
  • Embeddings of your contract: Not stored — see Section 2.

Deleting your account. You can delete your account yourself from your account settings. When you do, you are signed out immediately and every credential connected to your account — OAuth connections and API keys alike — stops working at once.

The 30-day window. For 30 days after the request, your account is closed but recoverable: contact us within that period and we can restore it. After 30 days everything listed below is permanently deleted by an automated job, and cannot be recovered by us or by you.

Permanently deleted after 30 days: your account record, your contract analyses and their scores and red flags, your extracted deal terms, negotiation briefs, linked songs, imported income data, notification settings and history, your API keys, your OAuth connections and tokens, and your account activity log.

What we keep, and why. Three things survive account deletion. This is the complete list:

  • Payment records. Held by Stripe, our payment processor, to meet tax and financial-regulation requirements. These are not stored in our own database, and deleting your SoundDeal account does not remove them from Stripe.
  • Security audit logs. Records of API and connector requests — which credential was used, which endpoint, IP address, and timestamps — are retained for security and abuse investigation. Your user ID is erased from them, so what remains is request metadata that is no longer linked to you.
  • Benchmark contributions you opted in to. If you opted in under Section 4A, those deal terms are kept — but every link back to you is erased: your user ID, the connection to your analysis, the counterparty name, and every free-text field are removed, leaving only the numbers (advance, royalty rate, term length, and similar). They stop being your personal data, and the published benchmark figures they contributed to stay accurate. Deal terms you did not opt in to are deleted outright along with everything else.

If you would rather withdraw a benchmark contribution than delete your whole account, Section 4A explains how — you do not have to close your account to do it.

7. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your analysis history
  • Withdraw consent for your data to be included in the anonymized benchmark dataset (see Section 4A)
  • Opt out of non-essential communications

To exercise any of these rights, contact us at support@sounddeal.com. You can disconnect apps and see what holds access to your account yourself, at any time, from your Connected Apps page.

California Residents (CCPA): You have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information.

UK and EU Residents (UK GDPR / EU GDPR): If you are a resident of the United Kingdom or the European Economic Area, you have additional rights including the right to data portability and the right to lodge a complaint with your local data protection authority. The legal basis for processing your account data and contract analyses is the performance of our contract with you. The legal basis for including pre-cleared deal data in our benchmark dataset is legitimate interest, balanced against your rights as described in Section 4A. The legal basis for including your contributed deal data is your explicit consent.

8. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect information from minors.

9. International Users and Data Transfers

The Service is operated from the United States, and the sub-processors listed in Section 4 process data in the United States. If you access the Service from outside the US, your information — including any contract you submit — is transferred to and processed in the US.

If you are in the United Kingdom or the European Economic Area, this is a transfer to a third country. Where a transfer is not covered by an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) as the transfer mechanism, entered into with the relevant sub-processor. You can request details of the safeguards in place for a particular transfer at support@sounddeal.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the Service.

11. Contact

Privacy questions, rights requests, and complaints all go to the same place — you do not need a special form or subject line.

Email: support@sounddeal.com

Post: Songs About Sound, LLC, 5777 W Century Blvd, Ste 1600, Los Angeles, CA 90045

If you are in the UK or EEA and you are not satisfied with how we have handled your request, you have the right to complain to your local data protection authority.