This policy covers the AINSOF music agent — the connector you add at https://mcp.ainsof.io — and this website. AINSOF is operated by Or Chausha AINSOF, a sole proprietorship registered in Israel. Contact: info@ainsof.io
What the agent can reach
The agent has twelve tools. Nine are read-only — they do not change
your files, accounts or systems. We do keep the request log described under
“What we record”. Most of these tools only search our own music catalogue and
return results. Two reach outside it: analyze_video measures a
video you link to, and search_by_reference works out what record you named.
Both are described in full below.
Three do more than read. score_my_video — if you give it
a link to a video, it downloads that video, renders a copy with our music mixed onto
it, and gives you a link to the copy. get_upload_link — if the video is on
your own machine instead, it hands back a one-time address you upload it to; the file
goes straight from your machine to our storage and never passes through the
conversation. feedback — it stores one line about how an answer landed,
which the agent sends only when you have actually said something about a result.
Video is described separately below, in full, because it is the part of this service
that handles something of yours.
When you react to something we returned — "none of these fit", "that one is perfect" —
the agent may send that reaction to us through feedback. We store the
sentence you said, which tool it was about, and the track or brief it concerned, so
that the people who choose and tag the music can see where we are getting it wrong.
We store nothing else from the conversation. The ordinary request log may associate
the feedback call with an AINSOF key identifier, client application and pseudonymous
caller hash, as described below. Nothing is sent unless you actually said something
about a result, and you can tell the agent not to send feedback at all.
The agent cannot:
It receives only what you send it in a request — a written brief, a video length, a reference link, a track ID, or a link to a video you have asked it to score.
If you send us a video
Nothing here happens unless you ask for it yourself. Two tools reach a video, and only
when you hand them one: score_my_video, which puts music on it, and
analyze_video, which only measures it. analyze_video downloads
the video, reads its length, frame rate and cuts, and deletes the temporary copy
from our processing machine in the same operation. It renders nothing and returns
only the numbers it measured. If you used an AINSOF upload link, the storage original
remains available for the score step until that link's two-hour window ends. When
you call score_my_video:
We keep a log of requests. We do this to run the service, to enforce fair-use limits, and to know how the catalogue is being used.
| What | Why |
|---|---|
| The search text or link you sent | To run the search, and to improve matching |
| The video link you asked us to score, and what we measured from it (length, frame rate, shot count) | To run the render, and so a repeat request re-uses the same work instead of downloading your video twice |
| Which tool was called, and when | Service operation and troubleshooting |
| Track IDs returned or requested | To know which cues are in demand |
| Which AINSOF listen, view or download link was requested or opened | To understand which links people choose and to troubleshoot delivery. This records the link event, not proof that playback or a download completed. |
| Client application name and user-agent string | Compatibility and support across Claude, Gemini, Grok, Cursor, ChatGPT and other MCP clients |
| Country | Licensing territory |
| A pseudonymous SHA-256 hash derived from your IP address | Rate limiting and request grouping. The raw IP itself is not stored in the AINSOF application log. This hash is pseudonymous data, not anonymous data. |
If you hold an API key, we also hold the name and email address you gave us when the key was issued, and a one-way hash of the key. We never store the key itself — it is shown once and cannot be recovered.
What we do not do
Request logs and the catalogue are held on Supabase infrastructure in the
European Union (Frankfurt, eu-central-1). Search requests are processed
by systems we operate. Neither your brief nor your video is ever sent to an external AI
service — the matching and the mixing run on our own hardware.
These are the only parties who see any part of a request, and each sees it solely to deliver the service you asked for:
| Who | What reaches them |
|---|---|
| Supabase — hosting, database and audio storage | Everything described above. EU (Frankfurt). |
Netlify — the address mcp.ainsof.io runs through |
Every request passes through it on the way to us. Netlify is a global network, so a request may be handled outside the European Union before it reaches our systems in Frankfurt. |
| GitHub Pages — serves AINSOF listen and video watch pages | When you open one of those pages, your browser connects to GitHub directly, so GitHub sees your IP address. Nothing about your search reaches it. |
| Apple, Deezer, Spotify and YouTube | Only if you search by reference. To work out what record you named, we send that link or that "artist — title" to them from our server, through each one's own public or authorised interface — Apple's and Deezer's published search APIs, Spotify's API under our registered application, and YouTube's oEmbed endpoint, which returns a video's title and channel name and no audio. Your own browser is not involved and your IP is not passed on. An ordinary written brief never reaches them. |
Each of these acts on our instructions and for no purpose of its own. We use no advertising network, no analytics provider and no data broker.
How we reach anything that is not oursWe take nothing from a platform that the platform does not offer. Every request we make to someone else's service goes through that service's own published or authorised interface, and where a platform does not permit something, we do not do it by another route — we refuse and say so.
oembed, the endpoint YouTube publishes so other sites can
embed its videos; it returns the video's title and channel name. That is the
entire extent of our contact with YouTube.Request logs are kept for as long as they are useful for operating and improving the service. Account details for API-key holders are kept while the key is active, and removed on request.
Your rightsEmail info@ainsof.io and we will tell you what we hold about you, correct it, or delete it. If you hold a key, we will revoke it and remove the associated record. We will answer within 30 days.
What we never collectAINSOF does not collect, solicit or process payment card data, health information, government identifiers, or any access credentials, passwords or API keys for other services. An AINSOF key is stored only as a one-way hash, as described above. We do not request location data. We do not read, reconstruct or infer your chat history — the agent sees only the brief, link or track ID you send with a request.
SupportFor any question, request or complaint about this policy or the service, contact info@ainsof.io. We answer within two business days.
ChildrenAINSOF is a professional music licensing service and is not directed at children under 16.
ChangesIf this policy changes we will update the date at the top of this page. Material changes will be communicated to active key holders by email.