Skip to content
MusicianOS

Privacy Policy

Effective July 9, 2026.

1. Who we are

MusicianOS (“MusicianOS,” “we,” “us”) is a service of Tipping Maples LLC, and operates the MusicianOS Pro+ web platform at muos.app and its artist subdomains ({artist}.muos.app) and any connected custom domains. This policy explains what personal information we collect through the web platform, why, how long we keep it, and how you can ask us to delete it.

Operator/legal entity: Tipping Maples LLC, 4461 County Road 34 NW, Alexandria, MN 56308, USA. Contact for privacy questions: privacy@muos.app TODO: operator — confirm this mailbox exists and is monitored before launch — for copyright notices, counter-notices, abuse reports, and appeals specifically, use legal@tippingmaples.com, which is confirmed monitored (it is the designated DMCA agent’s address; see the DMCA Policy).

2. Which of us is responsible for your data — controller and processor

Data-protection law asks who decides what happens to personal data (the controller) and who merely acts on instructions (the processor). For MusicianOS the answer is different for the app and for the web platform, and the difference is not cosmetic.

The app — Free, Plus, and Pro. Your songs, charts, lyrics, recordings, artwork, annotations, setlists and gigs are written to your device and synchronised through your own private Apple iCloud account, under Apple’s terms and Apple’s encryption.

We are neither the controller nor the processor of that content. We never receive it. We have no server that stores it, no credential that could read it, and no mechanism to produce it, restore it, or delete it — not for you, not for law enforcement, not for a court. Tipping Maples LLC is the vendor of a program that runs on your hardware. That is the whole of our relationship to your library.

For the small amount of data we do determine — crash diagnostics you consent to send, subscription status from Apple, the device list you see in Settings — we are the controller, and this policy governs.

If you want your app data deleted, delete the app and remove it from your iCloud account. There is nothing for us to delete, and we will tell you so rather than pretend to process a request we cannot act on.

The Pro+ web platform — muos.app. When you subscribe to Pro+ and publish to a public artist page, that content is stored on servers we operate. Here we are the controller. This policy governs it, we can access it, we can remove it, and we act on your requests.

Booking enquiries, live audience song requests, tips and their notes are submitted by members of the public through our servers. We are the controller of those too.

3. What we collect

Your music stays iCloud-first. An artist’s song content — charts, lyrics, chords, keys, arrangements, and recordings — lives in their own private iCloud, not on our servers. We do NOT store it. When an artist edits a song in the browser, that change only passes through our servers, encrypted, and is deleted the moment their app applies it; it is never kept. Publishing a song stores only its title, artist, and genre (see “Public listings” below) — never the chart or lyrics.

Artist account data — Sign in with Apple. Artists sign in with Sign in with Apple. We receive Apple’s stable user identifier (sub) and, if the artist chooses to share it, a name and email address. We do not receive or store an Apple password.

The sub identifier is scoped to our developer account, not to you personally, and it does not identify you to anyone else. If you chose Apple’s private-relay email, we never learn your real address.

Disclosure — developer account transfer. MusicianOS transferred from an individual developer account to Tipping Maples LLC on 9 July 2026. Apple’s sub identifier is scoped to the developer team, so it changed. Where a user had previously signed in, we may treat them as a new account. This is Apple’s design, not a data breach, and no personal data was disclosed to anyone.

Fan data — booking requests. When a fan submits a booking inquiry through an artist’s /book page, we collect the requester’s name and email, an optional phone number, event date(s), venue/location, budget, and a free-text message — whichever fields that artist has configured as required or optional.

Fan data — live show requests. When a fan requests a song during an artist’s live show (/live), we collect a requester name and an optional note (which may include a location/table, at the fan’s choice). If the artist has enabled a PIN gate, the PIN itself is not personal data and is not tied to a submitted request afterward.

Fan data — newsletter subscribers. When a fan subscribes to an artist’s newsletter, we collect and store their email address (and subscription status/timestamps) so the artist can send updates. A fan can unsubscribe at any time via the link in any newsletter email; unsubscribing removes their address from that artist’s active list.

Fan data — tips and payments. When a fan tips or pays an artist, payment is processed by the artist’s connected provider (Stripe or Venmo — see subprocessors). We never receive or store full card numbers. We retain a payment record — amount, status, timestamps, and the provider’s reference id — so the artist has a record of the transaction.

Push notification tokens. If an artist enables push notifications in the iOS app, we store the opaque Apple Push Notification service (APNs) device token(s) for their account and their notification preferences, so we can deliver alerts (bookings, live requests, tips, band activity). A token identifies a device, not a person, and is cleared when the artist disables push or signs out.

Aggregate, non-identifying data. Request counts, top-requested songs, and similar tallies are kept indefinitely because they don’t identify any individual fan.

Cookies and sessions. We set a single first-party, HttpOnly session cookie used only to keep an artist signed in to their own account/admin console. We do not use third-party advertising cookies, and we do not sell or share personal information for cross-context behavioral advertising.

Device/browser fingerprinting (Live Show Mode). To let an artist block an abusive or spamming fan from a live request queue, the block feature can key off a device/browser fingerprint in addition to a session or IP address. A fingerprint is tracking technology under GDPR and similar laws, and we treat it as such: it is collected only in the context of an active live session’s moderation tooling, is not used for advertising, and is not linked to a fan’s identity outside that show. For fans in the EU/EEA/UK, fingerprint collection for this purpose relies on TODO: operator — confirm legal basis — likely legitimate interest for abuse prevention, or consent if counsel determines legitimate interest doesn’t hold.

4. Why we collect it, and our lawful basis

  • To operate the account/subscription an artist has with us.
  • To deliver a booking inquiry or live song request to the artist it was addressed to.
  • To prevent abuse of the live request queue (rate limiting, PIN gating, fingerprint-based blocking).
  • To measure aggregate, non-identifying usage of the platform.

We do not use fan-submitted names, messages, or contact details for our own marketing, and we do not sell them to anyone.

For each category of data we hold, our lawful basis under GDPR Art. 6 is:

DataRegimeLawful basis (GDPR Art. 6)
Songs, charts, recordings, annotations in the appNot ours — your device, your iCloud
Content you publish to a public artist pageControllerContract — we cannot host your page without hosting your page
Account: Apple sub, email, handleControllerContract
Subscription statusControllerContract; legal obligation (tax, accounting)
Booking enquiries, audience requests, tipsControllerContract; legitimate interests (operating a platform artists ask us to run)
Copyright notices, counter-notices, abuse reports, strikesControllerLegal obligation — 17 U.S.C. §512 conditions our safe harbor on keeping these records
Audit log of moderation actionsControllerLegal obligation; legitimate interests
Crash diagnosticsControllerConsent

5. How long we keep it — the 30-day retention window

Fan-identifying data — live request names and notes, booking request contact details, and similar fan PII — is retained for 30 days from the relevant event (a live session ending, a booking submission, or an artist account’s deletion), after which it is soft-deleted: it disappears from every artist-facing and public read path immediately and cannot be recovered through the product. A second sweep permanently (hard-)deletes the underlying record 30 days after that.

Aggregate, non-identifying statistics (request counts, top songs, tip totals) are not fan PII and may be kept indefinitely.

This retention window does not apply to the legal records described next — those are kept longer, and for a different reason.

6. Legal records we cannot delete on request

If you send a copyright notice, a counter-notification, or an abuse report, we keep it — including your name and contact details, which the DMCA requires the notice to contain. We keep records of strikes, suspensions and terminations.

We cannot delete these on request, and a deletion request will not erase them. 17 U.S.C. §512(i) conditions our safe harbor on our ability to show we reasonably implemented a repeat-infringer policy, and a record we deleted proves nothing. We retain them for as long as the claim, the account, and any limitation period require. This is a legal obligation under Art. 6(1)(c) and an overriding legitimate interest under Art. 17(3)(b) and (e).

A counter-notification is forwarded to the person who complained, including the name, address, and consent to jurisdiction that §512(g)(3) requires it to contain. That is the statute’s design, not our choice. Do not file one unless you are willing for the complainant to receive it.

See the DMCA Policy and the Repeat Infringer Policy for the full notice, counter-notice, and strikes process these records support.

7. Who we share it with — subprocessors

We do not sell personal data. We do not share it for advertising. We do not use your music, lyrics, or recordings to train machine-learning models.

We use a small set of infrastructure providers (“subprocessors”) to run the platform. None of them are permitted to use fan or artist data for their own purposes. We share data only with these subprocessors, with our professional advisers, and where the law compels us. If you bring your own AI key, your content goes directly to that provider under their terms — we neither proxy it nor keep it.

ProviderRole
VercelApplication hosting, edge/CDN, and serverless functions for the entire web platform.
Neon (Postgres)The public/admin database — site configuration, published song/setlist/gig listings, booking requests, and live-show requests.
Upstash (Redis)Short-lived operational data only: rate limiting, live-session hot state, and edit-presence signals. Not a durable store of personal data.
ResendTransactional email — booking notifications, account emails — sent from one shared, platform-owned account (never per-artist).
AI providersServer-side processing of artist-submitted files/text for the lyric and chord import pipeline. Platform provider keys never reach the browser; artist content is not used to train third-party models beyond that provider's own standard processing terms.
Apple (APNs)Delivery of push notifications (bookings, live requests, tips, band activity) to an artist's registered devices. We send Apple an opaque device token and the notification payload; Apple does not receive fan data beyond what a notification displays.
StripePayment processing for fan tips and payments, when an artist connects a Stripe account. Stripe handles card data directly under its own terms — we never receive or store full card numbers; we retain only a payment-intent record (amount, status, timestamps, Stripe reference).
VenmoAn alternative fan payment/tip method, when an artist connects a Venmo handle. Payment is completed in Venmo under its own terms; we retain only a record that a payment was requested/marked complete.

8. Your rights and choices — deleting your data

Because of the 30-day retention window above, most fan data deletes itself automatically without any action on your part. If you’d like it removed sooner, or want to confirm it’s gone, email privacy@muos.app with the artist’s page you submitted to and roughly when you submitted it, and we’ll locate and delete the record. Artists can request deletion of their own account and all associated data the same way.

Where the law gives you rights — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent — you may also exercise them at legal@tippingmaples.com. We respond within the time the law allows.

Two honest limits:

  • We cannot give you what we do not have. A subject-access request will return your account, your published content, your subscription status, and any moderation records. It cannot return your library, because your library was never ours.
  • Erasure does not reach the legal records in §6.

MusicianOS provides a full export of your library from inside the app, at any time, without asking us. That is the strongest portability guarantee we could give you, and it does not depend on us being reachable, solvent, or willing.

9. International users

MusicianOS is operated from the United States, and the providers in §7 may process data in the United States and other countries. Where we receive personal data from the EEA or UK we rely on the appropriate safeguards. If you are in the EU/EEA/UK, you have rights under GDPR (access, correction, deletion, portability, and objection) — contact us at privacy@muos.app or legal@tippingmaples.com to exercise them.

10. Children's privacy

MusicianOS is not directed to children under 13, and we do not knowingly collect personal information from them. Live show requests and booking inquiries ask for a name and, optionally, contact details or a message — this is not a service designed for children to use unsupervised.

11. Changes to this policy

We’ll update this page when what we collect or how we handle it changes, and update the effective date once one is set.

Questions?

Email privacy@muos.app for general privacy questions, or legal@tippingmaples.com for copyright, moderation, or legal-record matters — see also our Terms of Service, our DMCA Policy, our Repeat Infringer Policy, and our Acceptable Use Policy.