Privacy Policy

Last updated 6 August 2026

This policy covers the AINSOF music agent — the connector you add at https://mcp.ainsof.io — and this website. AINSOF is operated by Or Chausha AINSOF, a sole proprietorship registered in Israel. Contact: info@ainsof.io

What the agent can reach

The agent has twelve tools. Nine are read-only — they do not change your files, accounts or systems. We do keep the request log described under “What we record”. Most of these tools only search our own music catalogue and return results. Two reach outside it: analyze_video measures a video you link to, and search_by_reference works out what record you named. Both are described in full below.

Three do more than read. score_my_video — if you give it a link to a video, it downloads that video, renders a copy with our music mixed onto it, and gives you a link to the copy. get_upload_link — if the video is on your own machine instead, it hands back a one-time address you upload it to; the file goes straight from your machine to our storage and never passes through the conversation. feedback — it stores one line about how an answer landed, which the agent sends only when you have actually said something about a result. Video is described separately below, in full, because it is the part of this service that handles something of yours.

If you tell us an answer was wrong

When you react to something we returned — "none of these fit", "that one is perfect" — the agent may send that reaction to us through feedback. We store the sentence you said, which tool it was about, and the track or brief it concerned, so that the people who choose and tag the music can see where we are getting it wrong. We store nothing else from the conversation. The ordinary request log may associate the feedback call with an AINSOF key identifier, client application and pseudonymous caller hash, as described below. Nothing is sent unless you actually said something about a result, and you can tell the agent not to send feedback at all.

The agent cannot:

It receives only what you send it in a request — a written brief, a video length, a reference link, a track ID, or a link to a video you have asked it to score.

If you send us a video

Nothing here happens unless you ask for it yourself. Two tools reach a video, and only when you hand them one: score_my_video, which puts music on it, and analyze_video, which only measures it. analyze_video downloads the video, reads its length, frame rate and cuts, and deletes the temporary copy from our processing machine in the same operation. It renders nothing and returns only the numbers it measured. If you used an AINSOF upload link, the storage original remains available for the score step until that link's two-hour window ends. When you call score_my_video:

What we record

We keep a log of requests. We do this to run the service, to enforce fair-use limits, and to know how the catalogue is being used.

WhatWhy
The search text or link you sentTo run the search, and to improve matching
The video link you asked us to score, and what we measured from it (length, frame rate, shot count)To run the render, and so a repeat request re-uses the same work instead of downloading your video twice
Which tool was called, and whenService operation and troubleshooting
Track IDs returned or requestedTo know which cues are in demand
Which AINSOF listen, view or download link was requested or openedTo understand which links people choose and to troubleshoot delivery. This records the link event, not proof that playback or a download completed.
Client application name and user-agent stringCompatibility and support across Claude, Gemini, Grok, Cursor, ChatGPT and other MCP clients
CountryLicensing territory
A pseudonymous SHA-256 hash derived from your IP addressRate limiting and request grouping. The raw IP itself is not stored in the AINSOF application log. This hash is pseudonymous data, not anonymous data.

If you hold an API key, we also hold the name and email address you gave us when the key was issued, and a one-way hash of the key. We never store the key itself — it is shown once and cannot be recovered.

What we do not do Where it is held

Request logs and the catalogue are held on Supabase infrastructure in the European Union (Frankfurt, eu-central-1). Search requests are processed by systems we operate. Neither your brief nor your video is ever sent to an external AI service — the matching and the mixing run on our own hardware.

Who else handles it

These are the only parties who see any part of a request, and each sees it solely to deliver the service you asked for:

WhoWhat reaches them
Supabase — hosting, database and audio storage Everything described above. EU (Frankfurt).
Netlify — the address mcp.ainsof.io runs through Every request passes through it on the way to us. Netlify is a global network, so a request may be handled outside the European Union before it reaches our systems in Frankfurt.
GitHub Pages — serves AINSOF listen and video watch pages When you open one of those pages, your browser connects to GitHub directly, so GitHub sees your IP address. Nothing about your search reaches it.
Apple, Deezer, Spotify and YouTube Only if you search by reference. To work out what record you named, we send that link or that "artist — title" to them from our server, through each one's own public or authorised interface — Apple's and Deezer's published search APIs, Spotify's API under our registered application, and YouTube's oEmbed endpoint, which returns a video's title and channel name and no audio. Your own browser is not involved and your IP is not passed on. An ordinary written brief never reaches them.

Each of these acts on our instructions and for no purpose of its own. We use no advertising network, no analytics provider and no data broker.

How we reach anything that is not ours

We take nothing from a platform that the platform does not offer. Every request we make to someone else's service goes through that service's own published or authorised interface, and where a platform does not permit something, we do not do it by another route — we refuse and say so.

How long we keep it

Request logs are kept for as long as they are useful for operating and improving the service. Account details for API-key holders are kept while the key is active, and removed on request.

Your rights

Email info@ainsof.io and we will tell you what we hold about you, correct it, or delete it. If you hold a key, we will revoke it and remove the associated record. We will answer within 30 days.

What we never collect

AINSOF does not collect, solicit or process payment card data, health information, government identifiers, or any access credentials, passwords or API keys for other services. An AINSOF key is stored only as a one-way hash, as described above. We do not request location data. We do not read, reconstruct or infer your chat history — the agent sees only the brief, link or track ID you send with a request.

Support

For any question, request or complaint about this policy or the service, contact info@ainsof.io. We answer within two business days.

Children

AINSOF is a professional music licensing service and is not directed at children under 16.

Changes

If this policy changes we will update the date at the top of this page. Material changes will be communicated to active key holders by email.

Questions about anything here — including exactly what a given tool sends or receives — go to info@ainsof.io. We would rather answer than have you guess.