Privacy
Privacy Policy
Medlock Music Technologies respects your privacy. This policy explains what information P.A.C.E. by Medlock handles, why it is used, and the choices available to you.
Effective date: September 6, 2026
Information we collect
Depending on how you use the service, we may handle:
- Account information, including your email address and authentication identifiers.
- Profile information such as your display name, instrument, skill level, and practice goal.
- Practice information including session duration, pitch readings, detected notes or likely chords, tuning measurements, stability scores, and generated coaching reports.
- Repertoire information you choose to provide, including owned or permitted audio, video, and MIDI files; loop selections; file metadata; ownership confirmations; and generated analysis results.
- Optional lesson-reminder details, such as your chosen schedule, time zone, notification method, and reminder destination.
- Subscription information such as plan status, Stripe customer and subscription identifiers, billing-period dates, and cancellation status.
- Messages and information you choose to send when requesting support.
- Lyric passages and songwriting context you deliberately share with P.A.C.E. Coach when asking for creative help.
- Technical usage and performance information, such as visited page paths, referring pages, general browser and device information, approximate geographic region, website performance measurements, and security or abuse signals. For guest coaching limits, an IP address is transformed into a one-way, secret-keyed hash; P.A.C.E. does not use that hash to identify you by name.
Cookies, browser storage, and analytics
P.A.C.E. uses essential cookies to keep accounts signed in, protect guest coaching limits, preserve security state, and complete requested account and billing flows. Blocking these cookies may prevent parts of the service from working.
Browser local or session storage may remember First Look details, unfinished lyric drafts, workspace preferences, playback choices, and short-lived recovery information. Clearing browser storage removes device-local information, but it does not delete account data or reset server-enforced usage limits.
Vercel Analytics and Speed Insights help us understand page use and website performance. Our product events are limited to allow-listed categorical details; we do not intentionally place lyrics, transcripts, profile text, private recordings, or raw error messages in those events.
Lyrics and songwriting drafts
Lyrics drafts autosave in the local storage of the browser and device where you write them. They are not account cloud storage. When you ask P.A.C.E. Coach about the selected lyric passage, that passage and its songwriting frame may be sent to OpenAI's Realtime service so the Coach can respond.
Coach lyric revisions are shown as proposals. P.A.C.E. does not apply a proposed change to the local draft unless you approve it in the Lyrics workspace.
When you use Rhyme Lab, the single rhyme word you enter may be sent to Datamuse to return an expanded dictionary of perfect, near, and multisyllabic rhymes. P.A.C.E. does not send your lyric draft or account identity with that lookup.
Microphone and audio processing
Live pitch detection, tuner measurements, and Note Detection estimates use your device microphone with your permission. These musical measurements are calculated in your browser. Note Detection estimates one isolated note or likely chord at a time; it does not prove the exact fingering or physical position used.
When you connect P.A.C.E. Coach, the application also sends a microphone audio track to OpenAI's Realtime service over a WebRTC connection so the Coach can listen and respond conversationally. The application may also provide derived musical information such as a detected note or likely chord, frequency, tuning difference, stability, practice results, and relevant saved coaching context. P.A.C.E. does not intentionally save the raw live microphone stream as an account recording. Under its default API data controls, OpenAI states that abuse-monitoring logs may retain customer content for up to 30 days, unless longer retention is required by law or reasonably necessary to protect its services or others. OpenAI also states that API content is not used to train its models unless the API customer opts in.
When you import owned or permitted audio, video, or MIDI into Repertoire Lab, the source file and generated results are stored in private Supabase Storage buckets. P.A.C.E. uses short-lived signed links rather than making those files public.
When you request a Repertoire tool such as stem separation, transposition, or translation to Tabs / Staff, the selected media, loop settings, and related profile context may be sent to our protected analysis worker on Modal. Generated audio and notation results may be saved privately to your account so you can use them in the practice workspace.
How we use information
- Provide authentication, profiles, practice history, pitch graphs, subscription access, and AI coaching.
- Personalize reports using your instrument, skill level, goal, and practice measurements.
- Protect the service, enforce plan limits, troubleshoot errors, and prevent misuse.
- Respond to support, privacy, billing, and legal requests.
How we disclose information
We disclose information to the service providers described below only as needed to operate, secure, support, and improve requested features; to process billing; or to comply with law and protect users, the service, and others. We may also disclose information in connection with a merger, financing, acquisition, or sale of business assets, subject to appropriate confidentiality and legal requirements.
P.A.C.E. does not sell personal information for money and does not use private practice content for third-party targeted advertising.
Service providers
We use third-party providers to operate the service. These currently include Supabase for authentication, database, and private file storage; OpenAI for Realtime voice processing and AI-generated coaching; Modal for Repertoire audio and music analysis; Datamuse for single-word Rhyme Lab lookups; Stripe for hosted checkout and subscription billing; Cloudflare Turnstile for bot and abuse protection; Resend and, when enabled, Twilio for lesson reminders; and Vercel for hosting, web analytics, and performance monitoring. Those providers process information under their own terms and privacy notices.
Payment-card details entered in Stripe Checkout are processed by Stripe. The application stores subscription identifiers and status information, but it does not intentionally store full payment-card numbers.
Data retention and deletion
Account, profile, saved-session, report, and subscription records are retained while needed to provide the service, comply with legal obligations, resolve disputes, and protect the platform. You may delete individual saved sessions through the dashboard where that feature is available.
Logged-in members may use the self-service account deletion controls available under Dashboard → Membership / Security. Deleting an account removes its active private Repertoire source files and generated results along with its saved P.A.C.E. account data. Members with an unfinished Stripe subscription may either wait until the subscription has fully ended or explicitly authorize P.A.C.E. to cancel it immediately as part of account deletion. Immediate cancellation ends paid access at once and does not automatically issue a refund for unused subscription time. You may also contact pacebymedlock@gmail.com for assistance. Payment, tax, security, fraud-prevention, dispute, and other records may be retained where required for legitimate business or legal purposes. Limited copies may also remain temporarily in provider backups until those backups cycle out under the provider's retention process.
Data location and transfers
P.A.C.E. and its service providers may process information in the United States and other locations where they operate. Those locations may have data-protection rules different from the place where you live.
Security
We use reasonable technical and organizational safeguards, including authenticated access and database access controls. No internet service can guarantee absolute security, so protect your password and notify us if you believe your account has been compromised.
Children
The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information, please contact us so we can review and remove it. A parent or legal guardian should review and consent to use by an older minor where required by law.
Your choices and contact
You can update profile information in your dashboard, delete saved sessions where supported, and manage or cancel a paid subscription through the Stripe billing portal. Questions or privacy requests—including requests to access, correct, or delete account information—may be sent to pacebymedlock@gmail.com.
We may need to verify your identity before fulfilling a request. Some information may be retained when required for billing, fraud prevention, security, disputes, or legal compliance. If a law where you live provides additional privacy rights, you may exercise them through the same contact method.
Changes to this policy
We may update this policy as the service, providers, or legal requirements change. The current version will be posted here with a revised effective date. We will provide additional notice when a material change requires it.