Legal
Privacy Policy
Last updated 15 September 2026
The Rights Foundry (“we”) provides a catalog of royalty-free music through a website, a REST API and an MCP connector that AI assistants can use on your behalf. This policy explains what we collect, why, and the choices you have. It applies to therightsfoundry.com, its api and mcp subdomains, and the assets we stream.
What we collect
- Account details: your email address, name, and whether your email is verified. There is no password on your account — you sign in with a code we email you, and we store only a short-lived hash of that code, never the code itself.
- Billing: payment methods are held by Stripe. We store Stripe’s customer and payment-method identifiers, your credit balance and a ledger of credit grants, purchases and usage. We do not store card numbers.
- API usage: for each API key or connected assistant we record request counts, bytes streamed, and which tracks were previewed or downloaded, per day. This is what your credits are charged against and what your dashboard shows.
- Licensing records: which tracks you have licensed, the license type (Stream, Sync or Portable Sync), the date, and the account that licensed them. This is the record of the license granted when you license a track by its id through the API (
POST /v1/tracks/{id}/sync) or through an AI assistant you have connected, and it is what you and we rely on if the license is ever questioned. - Technical data: request logs held by Cloudflare (IP address, user agent, timestamps, status) for security, abuse prevention and debugging, retained for a limited period.
The MCP connector for AI assistants
When you connect an assistant such as Claude or ChatGPT, you sign in with your Rights Foundry account on a page we host and approve the connection. We then issue that assistant its own API key, shown in your dashboard as “MCP · <assistant name>”. Through it the assistant can search and browse the catalog, read track details, read our licensing terms and license a track. It cannot change your account or read your billing details. Searches and licenses made by the assistant are charged to your credits exactly like API calls and appear in your usage. We do not receive your conversations with the assistant, only the catalog queries it sends us. Connections expire after 30 days unless the assistant renews them, and you can revoke one at any time from Connected Assistants in your dashboard.
How we use data
- To provide the service: authenticate you, serve and stream tracks, meter usage and charge credits.
- To bill you and to send transactional email (verification codes, low-balance alerts, receipts) via Brevo.
- To keep the service secure: rate limiting, abuse detection, fraud prevention.
- To improve the catalog and search, using aggregated, de-identified usage.
- To record the licenses granted to you, so that both you and we can prove them later.
We do not sell personal data and we do not use it for advertising.
Who we share it with
- Cloudflare hosts the application, the API, the MCP connector and the audio files.
- Neon hosts our database (United States, us-east-1).
- Stripe processes payments.
- Brevo delivers transactional email.
- An assistant you have connected receives the catalog results for the queries it sends.
- Video and social platforms such as YouTube or TikTok, only when you ask us to clear a channel or a video: we send them the identifiers they need to release or prevent copyright claims on tracks you have licensed, and nothing else.
Each processor acts on our instructions under its own terms. We disclose data where the law requires it.
Retention
Account, billing, license and usage records are kept while your account exists and for as long as required for tax and accounting purposes afterwards. License records are kept for as long as the license lasts. Because our licenses are perpetual, that means we keep the record of each license (the track, the license type, the date, and the name and email of the licensee) even after your account is deleted, so that you or we can prove the license later; everything else about a deleted account is removed. Request logs are kept for a short, fixed period. Revoked assistant connections are deactivated at once and their keys cannot be used again, though a revocation can take up to about a minute to reach every server. A download link already issued to the assistant stays valid until it expires.
Your rights
You can view and change your profile, manage payment methods and revoke API keys or assistant connections from your dashboard. You can ask us to export or delete your account data, subject to records we must keep for legal reasons. Depending on where you live you may have further rights under laws such as the GDPR or the CCPA; we honor them on request.
Security
Traffic is encrypted in transit. Sign-in codes are stored only as a salted SHA-256 hash, expire in ten minutes and work once. API keys and assistant tokens are stored so that a leak of our cache cannot reveal them. Access to production systems is limited to the people who operate the service.
Contact
Questions or requests about this policy: dev@therightsfoundry.com. The Rights Foundry is operated by Audiosocket.