Privacy Policy
Last Updated: June 2026 | Effective Date: June 9, 2026
1. Introduction
Patchline Inc. ("Patchline," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered music business platform and related services (collectively, the "Services").
2. Information We Collect
2.1 Information You Provide
- Account information (name, email, company details)
- Music catalog data and metadata
- Contract and rights information
- Communication preferences
- Payment and billing information
2.2 Automatically Collected Information
- Usage data and analytics
- Device and browser information
- IP addresses and location data
- Cookies and similar tracking technologies
2.3 Analytics and User Journey Data
To improve our Services and provide you with a better experience, we collect and analyze:
- User Interactions: Button clicks, feature usage, and navigation patterns
- Page Views: Pages visited, time spent on each page, and scroll depth
- Chat Messages and Feedback: Your conversations with our AI agents (including Aria, Scout, and Strands), thumbs up/down feedback, tool actions, and related context to provide personalized assistance, debug failures, evaluate response quality, and improve AI-assisted music business workflows
- Operation Success/Failure: Whether specific actions (uploads, exports, API calls) succeeded or failed to help us identify and fix issues
- Attachment Manifests: File names, asset IDs, S3 object references, MIME types, and other technical metadata for uploaded or referenced files so we can route, audit, and troubleshoot AI-assisted workflows
- Session Data: Login times, session duration, device type, browser, and operating system
- Error Tracking: Technical errors and crashes to improve platform stability
Your Control: You can opt out of analytics collection at any time by emailing privacy@patchline.ai or using account privacy controls where available. After your opt-out is processed, we will only collect essential data required for platform operation, security, legal compliance, and service delivery.
Advertising Measurement: Where enabled, we use Google Analytics and Google Ads tags to measure visits, campaign performance, and subscription conversions so we can understand whether our ads led to a paid Patchline subscription. We configure Google Ads personalization as denied by default and use these tags for measurement and attribution, not personalized advertising or remarketing. We honor browser Global Privacy Control signals and explicit analytics opt-outs.
Data Retention: Product analytics may be retained on shorter operational schedules. AI conversation records, attachment manifests, feedback, and related audit logs may be retained longer where needed for security, legal compliance, customer support, product improvement, and training-eligible evaluation workflows.
2.4 AI Processing Data
Our AI agents may process your music business data to provide automated workflows, insights, and recommendations. This includes analyzing contracts, catalog and rights metadata, communication patterns, industry trends, uploaded or imported audio files, and audio-analysis outputs.
To provide features such as catalog search, playlist matching, sonic similarity, metadata extraction, quality review, and visual analysis, we may create, store, display, and use derivative technical representations of your music, including fingerprints, spectrograms, embeddings, feature vectors, MIDI or transcription outputs, tempo, key, mood, genre, energy, and similar analysis outputs.
We may also use these derivative technical representations and audio-analysis outputs, where permitted by our agreements with contracted analysis providers, to train, evaluate, tune, and improve Patchline-developed non-generative analysis models, such as vocal presence and characteristics, genre, mood, instrument, key, tempo, energy, valence, and arousal classifiers that produce metadata describing your content. These models do not synthesize, generate, reproduce, identify, or imitate music, sound recordings, vocals, or artist likeness. You can exclude your account from this default analysis-model improvement use through account privacy controls where available or by emailing privacy@patchline.ai.
We may use eligible chat interactions, prompts, feedback, tool inputs and outputs, workflow outcomes, catalog and rights metadata, business documents, product telemetry, and de-identified or aggregated outputs to evaluate, train, tune, reinforce, and improve Patchline's AI business assistants, search systems, recommendation systems, safety systems, and related product models. By default, we do not use your audio recordings, stems, masters, compositions, musical works, vocals, artist likeness, or derivative audio or music features extracted from them, including spectrograms, fingerprints, embeddings, feature vectors, or MIDI transcriptions, to train generative AI models that create music, sound recordings, voices, or artist likenesses. This restriction applies to Patchline and to every subprocessor acting on our behalf, and cannot be waived by operational necessity.
If Patchline introduces a creator research, raw-audio foundation-model fine-tuning, generative music/audio training, voice or likeness, or similar program beyond the default non-generative analysis-model improvement uses described above, that program will require your separate, explicit, affirmative, and revocable opt-in consent. Acceptance of this Privacy Policy, acceptance of our Terms, or continued use of the Services does not enroll you in any such program.
2.5 AI Assistants, MCP Connectors, and Third-Party LLM Clients
Patchline offers an AI assistant, Aria, which is accessible directly in our Services and through Model Context Protocol (MCP) connectors in third-party AI clients such as Anthropic's Claude (Claude Code, Claude Desktop, Claude for Work). When you authorize one of these clients through our OAuth 2.0 flow (AWS Cognito with PKCE):
- The third-party client (for example, Anthropic, PBC) receives an access token for your authenticated Patchline account and the OAuth scopes authorized during the connection flow.
- Each tool invocation is authenticated against your account, scoped to your user, governed by Patchline permissions and MCP tool metadata, and written to a structured audit log.
- Inputs you send through the client, and outputs returned by Aria tools, transit the client's infrastructure subject to its own privacy policy and terms. Patchline does not control the retention or secondary use of those messages inside the third-party client.
- You can revoke access at any time from the third-party client's connector settings, or by contacting privacy@patchline.ai.
When Aria answers your requests, prompts and responses are processed by large language models hosted on Amazon Web Services Bedrock (including Anthropic Claude models) and, in limited cases, Google GenAI. Prompts may include your catalog metadata, artist data, and chat content to generate the requested output. We export LLM trace data (prompts, tool calls, latency, and errors) to our observability provider for debugging and quality monitoring. Trace data may contain the content of your prompts and tool outputs, is access-controlled, and is retained on an operational schedule.
2.6 AI Research, Reinforcement Learning, and Creator AI Research Opt-In
We continuously improve Aria and related AI business assistants through evaluation, fine-tuning, and reinforcement learning. The following describes what we may and may not use for those purposes:
- Eligible for AI research and training: your chat interactions with Aria, prompts, thumbs up/down feedback, tool inputs and outputs, tool success/failure signals, workflow outcomes, catalog and rights metadata, business documents, de-identified product telemetry, and aggregated usage metrics.
- Eligible for product search, matching, and non-generative analysis-model improvement: derivative technical representations of music, such as spectrograms, fingerprints, embeddings, feature vectors, and audio-analysis model outputs from Patchline-developed analyzers and contracted third-party analysis providers, subject in each case to the applicable provider agreement, may be used to provide, evaluate, train, tune, and improve catalog search, sonic matching, recommendations, deduplication, metadata quality, vocal presence and characteristics, genre, mood, instrument classification, and related user-requested features. You can exclude your account from future analysis-model training and evaluation datasets through account privacy controls where available or by emailing privacy@patchline.ai.
- Raw-audio foundation model fine-tuning requires opt-in: Patchline does not fine-tune foundation audio models, including embedding, captioning, transcription, music-generation, or voice models, directly on your audio recordings, stems, masters, compositions, or vocals except where you have separately opted in through an explicit, written, revocable consent mechanism. Derivative technical representations and metadata outputs described in Section 2.4 are not raw audio and are governed by the analysis-model improvement controls above.
- Not used for generative music, audio, voice, or artist-likeness model training without separate opt-in consent: your audio recordings, stems, masters, compositions, musical works, vocals, artist likeness, and derivative audio or music features derived from them, consistent with Section 2.4.
- Optional creator programs: if we offer a Creator AI Research Program or similar opt-in opportunity, we will disclose the categories of content involved, training or evaluation purposes, participating model providers, retention period, withdrawal process, and any compensation, credit, or commercial terms before you opt in.
- Opt-out: you can exclude your account from AI-improvement and training-eligible datasets at any time by emailing privacy@patchline.ai or using account privacy controls where available. This opt-out applies to future training and evaluation runs. Removing your data from models that have already been trained is not always technically feasible; we will document this limitation in our response to any erasure request and will exclude your data from all future model versions.
- Governance: access to training-eligible data is role-restricted, reviewed, and logged. We do not sell or license training-eligible data to third parties for their independent model training.
3. How We Use Your Information
- Provide and improve our Services
- Process transactions and manage subscriptions
- Customize AI agents to your specific workflows
- Analyze user behavior to identify bugs, improve features, and optimize user experience
- Evaluate and improve AI systems using eligible interaction data, feedback, and de-identified or aggregated data, subject to opt-out and governance controls
- Operate optional creator research or model-training programs only where a user separately and affirmatively opts in
- Generate analytics and insights
- Communicate updates and support
- Ensure platform security and prevent fraud
- Comply with legal obligations
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your data only in these circumstances:
- Service Providers: With trusted partners who assist in operating our Services
- Legal Requirements: When required by law or to protect rights and safety
- Business Transfers: In connection with mergers or acquisitions
- With Consent: When you explicitly authorize us to share information
4.1 Subprocessors
We engage the following categories of subprocessors to operate the Services. Each is bound by a written data-processing agreement and is required to maintain security standards at least as protective as ours.
- Amazon Web Services, Inc. — cloud hosting, object storage (including the bucket where your uploaded audio files are stored), database services, identity, and large language model inference (Bedrock). Region: United States.
- Anthropic, PBC — large language model inference via AWS Bedrock, and, where you authorize a Claude MCP connection, direct delivery of Aria tool inputs and outputs.
- Google LLC — supplemental generative AI inference; website analytics, campaign measurement, and Google Ads conversion tracking where enabled.
- Stripe, Inc. — payment processing, subscription billing, Connect payouts, and tax reporting.
- Audio analysis provider — receives audio files you upload (directly or via Aria) to extract tempo, key, energy, mood, and genre features. The provider is contractually prohibited from using your audio to train generative music or audio models.
- Streaming and composition intelligence provider — supplies artist, song, and playlist data on demand; results are cached in our systems.
- Error and crash reporting provider — receives technical diagnostics, including stack traces and request metadata.
- Product analytics provider — event routing and product usage analytics.
- LLM observability provider — stores prompts, tool calls, and traces for debugging and evaluation.
An up-to-date list of subprocessors with specific vendor names and processing regions is available on request at privacy@patchline.ai.
5. Marketplace & Storefront Data
When you use the Patchline Music Store as a seller or buyer, additional data may be collected and shared:
- Seller Data: Seller identity and payment information is shared with Stripe for payment processing. Seller store information (name, profile, listed content) is publicly visible on storefronts.
- Buyer Data: Buyer email and purchase information is shared with the seller for order fulfillment. Payment details are processed by Stripe and not stored by Patchline.
- Copyright and Rights Complaints: DMCA submissions, counter-notifications, voice, likeness, publicity, trademark, endorsement, privacy, contractual, and other rights complaints may include claimant identity, contact details, affected person or rights holder, URLs, descriptions, evidence, consent documents, rights documentation, signatures, IP address, user agent, review notes, uploader responses, and review outcomes. We store this information for legal compliance, rights enforcement, fraud prevention, dispute handling, and repeat-infringer or repeat-rights-violator analysis, and may share it with affected parties, uploaders, sellers, buyers, payment providers, counsel, authorities, or service providers as needed to evaluate, resolve, defend, enforce, or comply with the complaint.
- Transaction Records: Purchase history, revenue data, and payout information are retained for tax reporting and dispute resolution.
- AI Content Labels: If content is marked as AI-generated, this label is publicly visible on the storefront.
6. Data Security
We implement enterprise-grade security measures including:
- Encryption in transit using TLS 1.2 or higher for all connections to the Services and to our subprocessors.
- Encryption at rest using AES-256 for data stored in object storage and our databases.
- AWS infrastructure that uses SOC 2-audited services, combined with Patchline-managed controls aligned to SOC 2 criteria. Patchline has not yet completed its own SOC 2 Type II audit.
- OAuth 2.0 with PKCE for third-party AI client connections that require user authentication, with access tokens scoped to the authenticated user and revocable at any time.
- Per-invocation authentication and authorization for every Aria tool call, with each invocation written to an audit log.
- Internal security reviews, vulnerability remediation, and enterprise security review preparation.
- Role-based access controls, multi-factor authentication for administrative access, and least-privilege provisioning.
- Secure data backup and disaster recovery.
7. Your Rights and Choices
You have the right to:
- Access and download your data
- Correct or update information
- Delete your account and associated data
- Opt out of analytics and usage tracking by contacting privacy@patchline.ai or using account privacy controls where available
- Request exclusion from AI-improvement or training-eligible datasets by contacting privacy@patchline.ai
- Opt-out of marketing communications
- Control AI processing preferences, including deciding whether to participate in any optional Creator AI Research Program
- Export your data in standard formats
- Request deletion of your chat history at any time
7A. Legal Bases for Processing (EEA / UK / Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract (Art. 6(1)(b)) — to provide the Services you request, including AI assistant features, catalog management, playlist targeting, storefront, and payments.
- Legitimate interests (Art. 6(1)(f)) — to secure the Services, prevent fraud, debug failures, measure product usage, and improve AI response quality. You may object at any time by contacting privacy@patchline.ai.
- Consent (Art. 6(1)(a)) — for optional analytics, marketing communications, and any processing activity where consent is required by applicable law, including any opt-in program that would use musical works or derivative audio or music features for model training beyond providing the Services. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — to retain transaction, tax, DMCA, rights complaint, and audit records.
International transfers out of the EEA, UK, or Switzerland rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum.
7B. California Privacy Rights (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, disclose, and retain about you.
- Request deletion of personal information we have collected from you.
- Correct inaccurate personal information.
- Opt out of the “sale” or “sharing” of personal information.
- Limit the use and disclosure of sensitive personal information.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We use Google Ads conversion tracking for measurement and attribution, with ad personalization disabled by default, and we honor Global Privacy Control signals and explicit opt-outs as opt-out-of-sharing requests where required. To exercise any of your California rights, email privacy@patchline.ai. We will not discriminate against you for exercising these rights.
8. Data Retention
We retain your information for as long as necessary to provide Services and comply with legal obligations. Durable AI conversation ledgers, audit logs, and related records may be retained for legal, safety, security, support, and governance purposes, including up to seven years where appropriate. You may request deletion at any time, subject to legal holds, dispute records, security obligations, and other legal requirements.
9. International Data Transfers
Your information may be processed in the United States. We ensure appropriate safeguards are in place for international transfers in compliance with applicable laws.
10. Children's Privacy
Our Services are not intended for users under 18 years of age, and we do not knowingly collect information from children.
Patchline is a business-to-business platform for music industry professionals and is not directed to children. We do not knowingly collect personal information from anyone under the age of 13, consistent with the Children's Online Privacy Protection Act (COPPA). If we learn we have collected personal information from a child under 13, we will promptly delete it. If you believe we may have collected such information, contact privacy@patchline.ai.
11. Updates to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or through the Services. Material updates may require renewed acceptance before continued use of the Services. However, no update to this Privacy Policy, no continued-use mechanism, and no general account consent will enroll your music, audio, vocals, artist likeness, or derivative music/audio features into generative AI training or raw-audio foundation-model fine-tuning; that requires a separate affirmative opt-in.
12. Contact Us
For questions about this Privacy Policy or our data practices:
Email: privacy@patchline.ai
Address: Patchline Inc.
Brooklyn, NY
For privacy requests, data subject access requests (DSAR), or questions about our subprocessors and AI data flows, contact our Privacy Team at privacy@patchline.ai. We will respond within the timeframes required by applicable law — within 30 days under the GDPR and UK GDPR, and within 45 days under the CCPA / CPRA, in each case extendable once where permitted by law.