Legal
Privacy policy
This policy explains what personal data Melody Studio collects through this website, why it is collected, who it is shared with, how long it is kept and what you can ask us to do about it.
1. Who is responsible
Melody Studio is the data controller for the personal data described here — meaning we decide what is collected and why.
For anything in this policy, including the requests described in section 8, write to info@melodyspatial.com.
2. What we collect, and why
We collect only what a specific feature needs. Nothing on this site is collected speculatively, and none of it is used to build a profile of you.
When you send an enquiry
The contact form asks for the kind of work, your name, your email address, and — optionally — a location, a timeline and a description of the project. All of it is stored so we can answer you, and a copy is emailed to the studio.
Legal basis: steps taken at your request before entering a contract, and our legitimate interest in responding to people who contact us.
When you create an account
An account exists for one purpose: downloading the files attached to a project. We store your email address and, if you set a password, a one-way hash of it — never the password itself, and there is no way to read it back.
If you sign in with Google instead, we receive from Google the email address, name and profile picture on that account, along with the identifier Google uses for it. We do not receive your Google password and have no access to anything else in your Google account.
Legal basis: performance of a contract — you asked for an account in order to access files.
When you download a file
We record which file was downloaded, by which account, and when. This is how we know the drawings and specifications we publish are being used, and by whom, since they are licensed rather than public.
Legal basis: our legitimate interest in knowing how licensed material is distributed.
While you are signed in
So that you can see where your account is signed in and sign a lost or borrowed device out remotely, we keep a short record of each active session: a random session identifier, a rough description of the browser and operating system (“Chrome on Windows”), the time it started, the time it was last used, and a truncated IP address — the final part is discarded, so it identifies roughly which network you are on and not which connection you are.
Legal basis: our legitimate interest, and yours, in the security of your account.
When you submit any public form
To stop automated abuse, the enquiry and registration endpoints count recent requests per IP address. That counter lives in memory for the length of its window and is never written to a database or a log we keep.
Legal basis: our legitimate interest in keeping the site usable and free of spam.
3. Cookies and browser storage
This site sets no analytics, advertising or tracking cookies. There is no third-party tag manager, no advertising pixel and no cross-site tracking of any kind. What it does store is the following, and only this:
| Name | Kind | Purpose | Lifetime |
|---|---|---|---|
authjs.session-token | Cookie | Keeps you signed in. Set only after you sign in, and readable only by the server — not by any script on the page. | 30 days |
authjs.csrf-token, authjs.callback-url | Cookie | Security and routing for the sign-in process itself — they stop a sign-in being forged from another site. | The browser session |
ai-studio-consent | Local storage | Remembers your answer to the cookie notice so you are not asked again. Deliberately not a cookie: kept in your browser, it is never transmitted to us. | Until you clear it |
ai-studio-loaded | Session storage | Notes that the opening animation has already played, so it does not play again on every page. | Until the tab closes |
The sign-in cookies are strictly necessary — the site cannot keep you signed in without them — which is why they are not subject to the consent notice. To remove them, sign out.
4. Who else processes your data
We use a small number of service providers to run the site. They act on our instructions, under contract, and may not use your data for their own purposes.
- Our hosting provider — serves the site and keeps short-lived server logs, which ordinarily include IP addresses.
- Our database provider — stores the enquiries, accounts and download records described above.
- Our file storage provider — holds the images and downloadable files published on the site.
- Resend — delivers the notification email when you send an enquiry. It processes the name, address and message you submitted.
- Google — only if you choose to sign in with Google, and only then. Google's own privacy policy governs what Google does with the fact that you signed in.
- Our session store — holds the device records in section 2 for as long as they live.
If you tap the WhatsApp button, WhatsApp opens with a message ready to send. Nothing is sent until you send it, and from that point the conversation is subject to WhatsApp's own terms and privacy policy as well as this one.
We do not sell personal data, and we do not share it for anyone else's marketing.
5. Where your data is held
Our providers may store or process data outside the country you are in, including in the United States. Where that happens, the transfer is covered by the safeguards those providers offer for international transfers — standard contractual clauses approved by the European Commission, or an equivalent mechanism. You can ask us which provider handles what, and we will tell you.
6. How long we keep it
- Enquiries — kept while we are in conversation and for as long as the project may reasonably resume. Ask and we will delete yours.
- Accounts — kept until you ask us to close the account, at which point the account and its download history are deleted.
- Download records — deleted with the account they belong to.
- Session records — expire automatically 30 days after sign-in, and are deleted immediately when you sign out or revoke the device.
7. How it is protected
- Passwords are stored only as a one-way hash, computed with a deliberately slow algorithm designed to resist being cracked in bulk.
- The sign-in cookie is marked
HttpOnly, so no script on the page can read it, and is sent only over an encrypted connection in production. - Downloadable files are not public. Their real storage addresses are never rendered into the page; every download passes through a route that checks you are signed in first.
- The administration area is restricted to the studio's own accounts, and every action there re-checks that permission rather than trusting the page it came from.
- You can review the devices signed in to your account, and sign any of them out, from your account page.
No system is perfectly secure. If a breach ever affects your data and poses a risk to you, we will tell you and the relevant supervisory authority, as the law requires.
8. Your rights
Under the GDPR and equivalent laws you may ask us to do any of the following, free of charge:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct anything inaccurate or incomplete.
- Erasure — have it deleted, where we have no overriding reason to keep it.
- Restriction — have us hold it but stop using it, while a dispute is resolved.
- Portability — receive what you gave us in a machine-readable format, or have it sent elsewhere.
- Objection — object to processing we base on legitimate interests, including at any time to direct marketing.
- Withdrawal of consent — where we rely on consent, withdraw it. That does not undo what was lawful beforehand.
Write to info@melodyspatial.com. We will respond within one month. There is no automated decision-making or profiling on this site, so the rights that concern those do not arise.
If you think we have handled your data badly, you may complain to your national data protection authority — in Spain, the Agencia Española de Protección de Datos (aepd.es). We would rather you came to us first.
9. Children
This site is meant for professional and commercial use and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
10. Changes to this policy
When the site changes what it collects, this page changes with it, and the date at the top is updated. Where a change materially affects you, we will say so rather than rely on you noticing.