Draft: not yet reviewed by a lawyer
Privacy policy
Last updated: October 7, 2026
Uncommon Ear is a free website for finding CC0 music and sound effects. You can browse, search, and download without an account. Connecting an AI assistant over MCP needs a free account. This page lists every piece of personal data the site handles, where it lives, and how long it stays.
Who we are
Uncommon Ear (uncommonear.com) is run by Magic Factory, LLC, a Delaware limited liability company. In this policy, "we" means Magic Factory, LLC. We decide why and how your personal data is used, which makes us the controller of it.
Questions about this policy go to legal@uncommonear.com.
The short version
- If you only browse, search and play tracks, we do not ask for or store anything about you. Our hosting provider still sees technical request data, described below.
- If you sign in, we store your email address and the collections you make, with the tracks and notes in them.
- If you connect an AI assistant over MCP, we also store the permission you gave it, and a log of each tool call it makes as you: which tool, when, and the search text. We delete the search text after 90 days and the rest after 400 days. We never store your IP address in that log.
- If you call the JSON API with an API key, we also store the key's name and a one-way hash of it, and keep the same kind of log for each call: which route, when, and the search text, with the same 90-day and 400-day limits. We never store the key itself or your IP address.
- We do not show ads, sell your data, or use tracking cookies. The only cookies we set are the sign-in cookies described below.
- You can delete your account yourself, at any time, from the account menu.
What we collect, where it lives, and for how long
This table covers everything the site stores about you or receives from your browser, as of the date above.
Email address, when you sign in or create an account
- Where
- Our database (Cloudflare D1), in the account record, stored in lowercase
- Why
- To identify your account and send your sign-in link
- How long
- Until you delete your account
- Who processes it
- Cloudflare (database host)
Account ID, creation date, and plan (free or Pro)
- Where
- Same account record
- Why
- To run your account
- How long
- Until you delete your account
- Who processes it
- Cloudflare
Google account ID, only if you choose Continue with Google
- Where
- Same account record
- Why
- To recognize you when you sign in with Google again
- How long
- Until you delete your account
- Who processes it
- Cloudflare; Google, while you sign in
Session cookie named ue_session, set when you sign in. It is HttpOnly, Secure, SameSite=Lax, and lasts 30 days. Our database holds only a one-way hash (SHA-256) of the cookie value, with its creation and expiry times.
- Where
- Your browser (cookie); our database (hash)
- Why
- To keep you signed in
- How long
- Cookie: 30 days at most, or until you sign out. Database row: removed when you sign out or delete your account, and in any case deleted within a day after it expires.
- Who processes it
- Cloudflare
Google sign-in cookie named ue_google_oauth, holding a random state value and a one-time verifier
- Where
- Your browser (cookie)
- Why
- To complete Google sign-in securely
- How long
- 10 minutes, and cleared when sign-in finishes
- Who processes it
- Not sent to anyone else
Sign-in link records: a one-way hash (SHA-256) of the link token, the email address you typed, an expiry time, when the link was used, and, when an AI assistant sent you to sign in, the page to return to
- Where
- Our database
- Why
- To check that a sign-in link is real, single-use, and under 15 minutes old
- How long
- The link stops working after 15 minutes or one use. A daily clean-up deletes the record within about a day after the link expires or is used, and deleting your account removes it immediately.
- Who processes it
- Cloudflare
Sign-in rate-limit counters: a count per hour, keyed by your email address (lowercase) and by your IP address, both stored as plain text, not hashed
- Where
- Our database
- Why
- To stop people from flooding an address with sign-in emails (legitimate interest in security)
- How long
- Kept 48 hours, then removed by the daily clean-up. The counter for your email address is also deleted immediately when you delete your account.
- Who processes it
- Cloudflare
Collections, when signed in: each collection's name and settings, the track IDs in it, the notes and change notes you type, and the date each track was added
- Where
- Our database
- Why
- To keep your collections on every device and build your credit block
- How long
- Until you delete the collection or your account
- Who processes it
- Cloudflare
Saved tracks and notes from before collections existed, when you saved them while signed in: track ID, your note, and the date you saved it. We copied them into a collection named My Favorites the first time you opened your collections, and we kept the original rows.
- Where
- Our database
- Why
- To keep what you saved, and so the copy can be redone if something goes wrong
- How long
- Until you delete your account
- Who processes it
- Cloudflare
Saved tracks from older versions of the site, if you saved any while signed out (local storage, keys uncommon-ear:saved and uncommon-ear:import-offered). The site no longer reads or writes them.
- Where
- Your browser only
- Why
- Nothing; they are left over from an older version
- How long
- Until you clear your browser data. We never received them unless you added them to an account.
- Who processes it
- Nobody; they stay on your device
Theme choice, light or dark (local storage, key ue-theme)
- Where
- Your browser only
- Why
- To remember your choice
- How long
- Until you clear your browser data
- Who processes it
- Nobody; it stays on your device
Download counts: one number per track, and the time of the latest download. No IP address, no account, and no browser details are stored with it.
- Where
- Our database
- Why
- To see which tracks are used
- How long
- Kept; the counts are not personal data
- Who processes it
- Cloudflare
Rate-limit counters for MCP and the JSON API, which share one allowance: your account ID with a call count per minute and per day, plus a call count per month for Pro accounts (free accounts: 20 calls per minute and 300 per day; Pro accounts: 60 calls per minute and 20,000 per month). We read your plan (free or Pro) from your account record to apply the right limit. No IP address.
- Where
- Our database
- Why
- To block bursts and abuse, and to apply the limit for your plan (legitimate interest in security)
- How long
- Minute and day counts are kept 48 hours; the monthly count is kept 40 days. The daily clean-up then removes them
- Who processes it
- Cloudflare
MCP sign-in grant records, created when you select Allow for an AI assistant: your account ID and email address (the email address is encrypted), the assistant's name, the permission granted (mcp:read, which lets it search, look up, and find similar tracks), and creation and expiry times. Access and refresh tokens are stored only as one-way hashes. During the consent step, we also keep a short-lived record that ties the consent form to your account.
- Where
- Cloudflare Workers KV
- Why
- To let the assistant act as you without asking you to sign in on every call, and to keep that access limited
- How long
- The access token lasts 1 hour. The grant, with its refresh token, expires 30 days after you select Allow, and the assistant then asks you to sign in again. The consent-step record lasts 10 minutes. Cloudflare removes expired records, and a daily clean-up removes any left behind. Deleting your account revokes every grant immediately, and Remove under Connected assistants in the account menu revokes one.
- Who processes it
- Cloudflare
MCP client registration records, created when an assistant registers itself with us: the assistant's client ID, name, redirect addresses, and registration date. They hold no personal data about you.
- Where
- Cloudflare Workers KV
- Why
- To know which assistant is asking for access
- How long
- 90 days after the assistant last renewed it. An assistant that is still in use renews it.
- Who processes it
- Cloudflare
MCP usage log: one row for each tool call your assistant makes after you sign in. A row holds the row ID, your account ID, the assistant's client ID and name, the tool name, whether the call succeeded, an error code if it failed (rate limited, not found, invalid, or internal), how long it took in milliseconds, the number of results, the search text (first 200 characters, search tool only), and the time. It does not hold your IP address, the track results, or the credit lines returned.
- Where
- Our database
- Why
- Security and support, to understand how the service is used, and to find gaps in the catalog (for example, searches that return no results)
- How long
- We delete the search text 90 days after the call and the whole row after 400 days, in the daily clean-up. Deleting your account deletes your rows immediately.
- Who processes it
- Cloudflare
API keys, when you create one in the account menu: the key's name, its first 8 characters, a one-way hash (SHA-256) of the key, and its creation, last-used, and revoked times. The key itself is shown once, when you create it, and is never stored.
- Where
- Our database
- Why
- To let a script call the API as you, and to let you tell your keys apart and revoke them
- How long
- Until you delete your account. Revoked keys stay as records, and a revoked key stops working at once.
- Who processes it
- Cloudflare
API usage log: one row for each call a script makes to the JSON API with your key. A row holds the row ID, your account ID, the ID of the key used, the route (search, track, or similar tracks), whether the call succeeded, how long it took in milliseconds, the number of results, the search text (first 200 characters, search route only), and the time. It does not hold the key or the Authorization header, your IP address, the track results, or the credit lines returned. Calls with a missing or invalid key are not recorded, because they have no account.
- Where
- Our database
- Why
- Security and support, to understand how the API is used, and to find gaps in the catalog
- How long
- We delete the search text 90 days after the call and the whole row after 400 days, in the daily clean-up. Deleting your account deletes your rows immediately.
- Who processes it
- Cloudflare
Bot check (Cloudflare Turnstile), shown in the sign-in dialog. Your browser loads a script from challenges.cloudflare.com, and sends Cloudflare browser and network signals. When you submit your email, our server sends Cloudflare the check result and your IP address to confirm it.
- Where
- Cloudflare
- Why
- To stop automated sign-ups (legitimate interest in security)
- How long
- Set by Cloudflare. See Cloudflare's privacy policy.
- Who processes it
- Cloudflare
Sign-in email: the message goes to the address you typed, from sign-in@uncommonear.com, with your one-time link. Our logs record a message ID, never your address or the link.
- Where
- Cloudflare Email Service, then your email provider
- Why
- To deliver your sign-in link
- How long
- Set by Cloudflare and your email provider
- Who processes it
- Cloudflare
Request logs: both our Workers run with Cloudflare's observability turned on, which records requests and our own log lines (for example a message ID after a sign-in email, or an error). Requests can include IP address, URL, and browser details.
- Where
- Cloudflare
- Why
- To keep the site running and find faults (legitimate interest)
- How long
- Set by Cloudflare, not by us
- Who processes it
- Cloudflare
Fonts: your browser requests fonts from fonts.googleapis.com and fonts.gstatic.com, which are run by Google. Google receives your IP address and browser details with the request.
- Where
- Why
- To show the site's typefaces
- How long
- Set by Google. See Google's privacy policy.
- Who processes it
Reports you send us, such as a takedown request: your name, contact details, and what you write
- Where
- Our email inbox
- Why
- To review and answer the report
- How long
- As long as needed to handle it and keep a record of what we decided
- Who processes it
- Our email provider
Audio files and previews load from media.uncommonear.com, which is hosted on Cloudflare. Those requests are ordinary web requests, so Cloudflare sees them as described in the request logs row.
The catalog, the audio, and your account data are stored on Cloudflare's services: R2 for files, D1 for the database, and Workers KV for the sign-in records of connected AI assistants.
What we do not do
- We do not run ads or load advertising scripts.
- We do not sell your personal data or share it for advertising.
- We run no analytics scripts and set no tracking cookies today. The site loads no third-party scripts except the Cloudflare Turnstile check, and only when you open the sign-in dialog.
- We do not store passwords. You sign in with an emailed link or with Google.
Signing in with Google
If you choose Continue with Google, we ask Google for the openid and email scopes. Google sends us your Google account ID and your verified email address. We do not receive your name, picture, contacts, or anything else from your Google account. Google's own privacy policy covers what Google does when you sign in.
Why we may use your data
If you live in the European Economic Area or the United Kingdom, the law asks us to name a legal basis for each use. In plain words:
- Contract: we use your email, account record, session, collections, and the MCP sign-in grant to give you the account and the assistant access you asked for.
- Legitimate interest: we use the rate-limit counters, the bot check, request logs, and the MCP and API usage logs to keep the site secure and working, to support you, and to understand how the service is used. We think this is a small, expected use of your data. You can object by writing to us.
- Legal obligation: we may keep or share data if the law requires it.
Who handles your data
Cloudflare hosts the site, runs our database and file storage, sends the sign-in email, and provides the bot check. Google receives requests for fonts, and handles your sign-in if you choose Google. Your email provider handles the sign-in email after we send it. We do not share your data with anyone else, except when the law requires it.
International transfers
Cloudflare runs a global network, so your data can be processed in countries other than your own, including the United States. Where the law requires it, Cloudflare and Google rely on approved transfer terms.
Your choices and rights
- Delete your account: open the account menu and choose Delete account. This removes your account record, sessions, collections and their notes, any saved tracks from before collections existed, API keys, and your MCP and API usage log rows. It also removes the sign-in link records and the email rate-limit counter for your address, immediately. Counters keyed by IP address are kept 48 hours, then removed by the daily clean-up. The rate-limit counters keyed by your account ID are removed by the same clean-up, within 48 hours or, for the monthly count, within 40 days. Deleting your account revokes every grant immediately, so AI assistants lose access at once.
- Remove an assistant's access: open the account menu, choose Connected assistants, and choose Remove next to the assistant. Signing out of the website does not end MCP access.
- Sign out: choose Sign out in the account menu. It ends your session and clears the cookie.
- Access and export: email legal@uncommonear.com and we send you a copy of the data we hold about you. There is no self-service export yet.
- Correct your data: email us. To change the email address on your account, write to us from the old address.
- Browser data: clear the site's local storage and cookies in your browser at any time. That removes your theme choice, your sign-in cookie, and any leftover saved tracks from older versions of the site.
Depending on where you live, the law may also give you the right to object to a use, restrict a use, move your data to another service, withdraw consent you gave, or complain to your data protection authority. This includes GDPR and UK GDPR rights, and rights in some US states under laws such as the California Consumer Privacy Act. We do not sell or share personal data for advertising, so there is nothing to opt out of. We answer requests within one month, and we may ask you to confirm you own the email address first. We will not treat you worse for using any of these rights.
Children
Uncommon Ear is not directed at children under 13. In the European Economic Area and the United Kingdom, do not create an account if you are under 16, or under the age of digital consent in your country if that is lower, unless a parent or guardian agrees. If you think a child has given us personal data, write to legal@uncommonear.com and we delete it.
Coming later
Paid Pro accounts, with payments handled by a payment provider, and product analytics are planned but not live. We will update this policy, and change the date at the top, before either launches.
Changes to this policy
When we change this policy, we change the date at the top.
Contact
Write to legal@uncommonear.com.