Privacy Policy
Effective date: May 5, 2026
Epic Music Space (βEMS,β βwe,β βusβ) collects and processes personal information when you use the Service. This Privacy Policy explains what we collect, how we use it, who we share it with, and the rights you have over it. It applies to everyone who visits epicmusicspace.com or uses our APIs.
1. What we collect
- Account information β email, password hash, display name, avatar, role, and (for artists) studio username, bio, banner.
- Content β songs, cover art, posts, comments, messages, licenses, and metadata you upload.
- Payment information β handled by Stripe. We never see full card numbers; we store Stripe customer + Connect IDs and a transaction history.
- Usage information β log entries (IP, user-agent, referer), play counts, AI score events, search queries, and behavior events used to personalize recommendations.
- Cookies β strictly-necessary session cookies, plus optional analytics cookies you control via the cookie banner.
2. How we use it
- To operate the Service: serve your feed, process payments, deliver licenses, send notifications.
- To prevent fraud + abuse: rate limiting, BotID checks, moderation queues, audit logs.
- To improve the Service: aggregate analytics, AI scoring, recommendation personalization.
- To comply with legal obligations: tax reporting, DMCA, court orders, sanctions screening.
We do not sell your personal information. We do not use your music content to train third-party AI models without your explicit opt-in.
3. Who we share with
- Stripe β payment processing, payouts, tax forms.
- Mux β video transcoding + delivery.
- Supabase β file storage + database hosting.
- Vercel β application hosting + edge delivery.
- Resend β transactional email delivery.
- Sentry / PostHog β error tracking + product analytics.
- Law enforcement β only when compelled by valid legal process.
Each subprocessor is bound by a data-processing agreement and processes your data only on our instructions. Contact privacy@epicmusicspace.com for the current subprocessor list.
4. Your rights
Depending on where you live, you may have the right to:
- Access β get a copy of the personal information we hold about you.
- Correct β update inaccurate information.
- Delete β request deletion (we retain financial records where required by law).
- Port β receive your data in a machine-readable format.
- Object / restrict β opt out of profiling for personalization.
- Withdraw consent β for any processing based on consent.
To exercise these rights, sign in and visit your profile settings or email privacy@epicmusicspace.com. We respond within 30 days.
5. California (CCPA / CPRA)
California residents have the right to know what personal information we collect, the right to delete, the right to correct, and the right to opt-out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. To submit a verifiable consumer request, see Section 4.
6. Europe (GDPR / UK GDPR)
Our legal bases for processing are: contract (operating the Service for you), legitimate interests (security + abuse prevention + improving the Service), legal obligation (tax + DMCA), and consent (optional cookies + marketing emails). Data may be transferred to the US under Standard Contractual Clauses. You have the right to lodge a complaint with your local data-protection authority.
7. Retention
We retain account and content data while your account is active. After deletion we retain (a) anonymized usage logs for up to 13 months, (b) financial records for 7 years where required by tax law, and (c) abuse-prevention signals for as long as needed to defend the Service. Read messages are pruned at 30 days; unread at 90 days.
8. Security
We use HTTPS everywhere, hash passwords with bcrypt at cost 12, encrypt connected-account tokens at rest, and run rate limits + BotID + signature verification on webhooks. No system is impenetrable; in the event of a qualifying breach we will notify you and authorities as required by law.
9. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact us at privacy@epicmusicspace.com and we will delete it promptly.
10. Cookies
See our cookie banner on first visit. Strictly-necessary cookies cannot be disabled; analytics cookies are opt-in.
11. Changes
Material changes to this Policy will be announced on the Service or by email. The effective date at the top is updated whenever we change this Policy.
12. Contact
Privacy questions or requests: privacy@epicmusicspace.com.