Back to the catalog

Draft: not yet reviewed by a lawyer

Privacy policy

Last updated: October 7, 2026

Uncommon Ear is a free website for finding CC0 music and sound effects. You can browse, search, and download without an account. Connecting an AI assistant over MCP needs a free account. This page lists every piece of personal data the site handles, where it lives, and how long it stays.

Who we are

Uncommon Ear (uncommonear.com) is run by Magic Factory, LLC, a Delaware limited liability company. In this policy, "we" means Magic Factory, LLC. We decide why and how your personal data is used, which makes us the controller of it.

Questions about this policy go to legal@uncommonear.com.

The short version

  • If you only browse, search and play tracks, we do not ask for or store anything about you. Our hosting provider still sees technical request data, described below.
  • If you sign in, we store your email address and the collections you make, with the tracks and notes in them.
  • If you connect an AI assistant over MCP, we also store the permission you gave it, and a log of each tool call it makes as you: which tool, when, and the search text. We delete the search text after 90 days and the rest after 400 days. We never store your IP address in that log.
  • If you call the JSON API with an API key, we also store the key's name and a one-way hash of it, and keep the same kind of log for each call: which route, when, and the search text, with the same 90-day and 400-day limits. We never store the key itself or your IP address.
  • We do not show ads, sell your data, or use tracking cookies. The only cookies we set are the sign-in cookies described below.
  • You can delete your account yourself, at any time, from the account menu.

What we collect, where it lives, and for how long

This table covers everything the site stores about you or receives from your browser, as of the date above.

  • Email address, when you sign in or create an account

    Where
    Our database (Cloudflare D1), in the account record, stored in lowercase
    Why
    To identify your account and send your sign-in link
    How long
    Until you delete your account
    Who processes it
    Cloudflare (database host)
  • Account ID, creation date, and plan (free or Pro)

    Where
    Same account record
    Why
    To run your account
    How long
    Until you delete your account
    Who processes it
    Cloudflare
  • Google account ID, only if you choose Continue with Google

    Where
    Same account record
    Why
    To recognize you when you sign in with Google again
    How long
    Until you delete your account
    Who processes it
    Cloudflare; Google, while you sign in
  • Session cookie named ue_session, set when you sign in. It is HttpOnly, Secure, SameSite=Lax, and lasts 30 days. Our database holds only a one-way hash (SHA-256) of the cookie value, with its creation and expiry times.

    Where
    Your browser (cookie); our database (hash)
    Why
    To keep you signed in
    How long
    Cookie: 30 days at most, or until you sign out. Database row: removed when you sign out or delete your account, and in any case deleted within a day after it expires.
    Who processes it
    Cloudflare
  • Google sign-in cookie named ue_google_oauth, holding a random state value and a one-time verifier

    Where
    Your browser (cookie)
    Why
    To complete Google sign-in securely
    How long
    10 minutes, and cleared when sign-in finishes
    Who processes it
    Not sent to anyone else
  • Sign-in link records: a one-way hash (SHA-256) of the link token, the email address you typed, an expiry time, when the link was used, and, when an AI assistant sent you to sign in, the page to return to

    Where
    Our database
    Why
    To check that a sign-in link is real, single-use, and under 15 minutes old
    How long
    The link stops working after 15 minutes or one use. A daily clean-up deletes the record within about a day after the link expires or is used, and deleting your account removes it immediately.
    Who processes it
    Cloudflare
  • Sign-in rate-limit counters: a count per hour, keyed by your email address (lowercase) and by your IP address, both stored as plain text, not hashed

    Where
    Our database
    Why
    To stop people from flooding an address with sign-in emails (legitimate interest in security)
    How long
    Kept 48 hours, then removed by the daily clean-up. The counter for your email address is also deleted immediately when you delete your account.
    Who processes it
    Cloudflare
  • Collections, when signed in: each collection's name and settings, the track IDs in it, the notes and change notes you type, and the date each track was added

    Where
    Our database
    Why
    To keep your collections on every device and build your credit block
    How long
    Until you delete the collection or your account
    Who processes it
    Cloudflare
  • Saved tracks and notes from before collections existed, when you saved them while signed in: track ID, your note, and the date you saved it. We copied them into a collection named My Favorites the first time you opened your collections, and we kept the original rows.

    Where
    Our database
    Why
    To keep what you saved, and so the copy can be redone if something goes wrong
    How long
    Until you delete your account
    Who processes it
    Cloudflare
  • Saved tracks from older versions of the site, if you saved any while signed out (local storage, keys uncommon-ear:saved and uncommon-ear:import-offered). The site no longer reads or writes them.

    Where
    Your browser only
    Why
    Nothing; they are left over from an older version
    How long
    Until you clear your browser data. We never received them unless you added them to an account.
    Who processes it
    Nobody; they stay on your device
  • Theme choice, light or dark (local storage, key ue-theme)

    Where
    Your browser only
    Why
    To remember your choice
    How long
    Until you clear your browser data
    Who processes it
    Nobody; it stays on your device
  • Download counts: one number per track, and the time of the latest download. No IP address, no account, and no browser details are stored with it.

    Where
    Our database
    Why
    To see which tracks are used
    How long
    Kept; the counts are not personal data
    Who processes it
    Cloudflare
  • Rate-limit counters for MCP and the JSON API, which share one allowance: your account ID with a call count per minute and per day, plus a call count per month for Pro accounts (free accounts: 20 calls per minute and 300 per day; Pro accounts: 60 calls per minute and 20,000 per month). We read your plan (free or Pro) from your account record to apply the right limit. No IP address.

    Where
    Our database
    Why
    To block bursts and abuse, and to apply the limit for your plan (legitimate interest in security)
    How long
    Minute and day counts are kept 48 hours; the monthly count is kept 40 days. The daily clean-up then removes them
    Who processes it
    Cloudflare
  • MCP sign-in grant records, created when you select Allow for an AI assistant: your account ID and email address (the email address is encrypted), the assistant's name, the permission granted (mcp:read, which lets it search, look up, and find similar tracks), and creation and expiry times. Access and refresh tokens are stored only as one-way hashes. During the consent step, we also keep a short-lived record that ties the consent form to your account.

    Where
    Cloudflare Workers KV
    Why
    To let the assistant act as you without asking you to sign in on every call, and to keep that access limited
    How long
    The access token lasts 1 hour. The grant, with its refresh token, expires 30 days after you select Allow, and the assistant then asks you to sign in again. The consent-step record lasts 10 minutes. Cloudflare removes expired records, and a daily clean-up removes any left behind. Deleting your account revokes every grant immediately, and Remove under Connected assistants in the account menu revokes one.
    Who processes it
    Cloudflare
  • MCP client registration records, created when an assistant registers itself with us: the assistant's client ID, name, redirect addresses, and registration date. They hold no personal data about you.

    Where
    Cloudflare Workers KV
    Why
    To know which assistant is asking for access
    How long
    90 days after the assistant last renewed it. An assistant that is still in use renews it.
    Who processes it
    Cloudflare
  • MCP usage log: one row for each tool call your assistant makes after you sign in. A row holds the row ID, your account ID, the assistant's client ID and name, the tool name, whether the call succeeded, an error code if it failed (rate limited, not found, invalid, or internal), how long it took in milliseconds, the number of results, the search text (first 200 characters, search tool only), and the time. It does not hold your IP address, the track results, or the credit lines returned.

    Where
    Our database
    Why
    Security and support, to understand how the service is used, and to find gaps in the catalog (for example, searches that return no results)
    How long
    We delete the search text 90 days after the call and the whole row after 400 days, in the daily clean-up. Deleting your account deletes your rows immediately.
    Who processes it
    Cloudflare
  • API keys, when you create one in the account menu: the key's name, its first 8 characters, a one-way hash (SHA-256) of the key, and its creation, last-used, and revoked times. The key itself is shown once, when you create it, and is never stored.

    Where
    Our database
    Why
    To let a script call the API as you, and to let you tell your keys apart and revoke them
    How long
    Until you delete your account. Revoked keys stay as records, and a revoked key stops working at once.
    Who processes it
    Cloudflare
  • API usage log: one row for each call a script makes to the JSON API with your key. A row holds the row ID, your account ID, the ID of the key used, the route (search, track, or similar tracks), whether the call succeeded, how long it took in milliseconds, the number of results, the search text (first 200 characters, search route only), and the time. It does not hold the key or the Authorization header, your IP address, the track results, or the credit lines returned. Calls with a missing or invalid key are not recorded, because they have no account.

    Where
    Our database
    Why
    Security and support, to understand how the API is used, and to find gaps in the catalog
    How long
    We delete the search text 90 days after the call and the whole row after 400 days, in the daily clean-up. Deleting your account deletes your rows immediately.
    Who processes it
    Cloudflare
  • Bot check (Cloudflare Turnstile), shown in the sign-in dialog. Your browser loads a script from challenges.cloudflare.com, and sends Cloudflare browser and network signals. When you submit your email, our server sends Cloudflare the check result and your IP address to confirm it.

    Where
    Cloudflare
    Why
    To stop automated sign-ups (legitimate interest in security)
    How long
    Set by Cloudflare. See Cloudflare's privacy policy.
    Who processes it
    Cloudflare
  • Sign-in email: the message goes to the address you typed, from sign-in@uncommonear.com, with your one-time link. Our logs record a message ID, never your address or the link.

    Where
    Cloudflare Email Service, then your email provider
    Why
    To deliver your sign-in link
    How long
    Set by Cloudflare and your email provider
    Who processes it
    Cloudflare
  • Request logs: both our Workers run with Cloudflare's observability turned on, which records requests and our own log lines (for example a message ID after a sign-in email, or an error). Requests can include IP address, URL, and browser details.

    Where
    Cloudflare
    Why
    To keep the site running and find faults (legitimate interest)
    How long
    Set by Cloudflare, not by us
    Who processes it
    Cloudflare
  • Fonts: your browser requests fonts from fonts.googleapis.com and fonts.gstatic.com, which are run by Google. Google receives your IP address and browser details with the request.

    Where
    Google
    Why
    To show the site's typefaces
    How long
    Set by Google. See Google's privacy policy.
    Who processes it
    Google
  • Reports you send us, such as a takedown request: your name, contact details, and what you write

    Where
    Our email inbox
    Why
    To review and answer the report
    How long
    As long as needed to handle it and keep a record of what we decided
    Who processes it
    Our email provider

Audio files and previews load from media.uncommonear.com, which is hosted on Cloudflare. Those requests are ordinary web requests, so Cloudflare sees them as described in the request logs row.

The catalog, the audio, and your account data are stored on Cloudflare's services: R2 for files, D1 for the database, and Workers KV for the sign-in records of connected AI assistants.

What we do not do

  • We do not run ads or load advertising scripts.
  • We do not sell your personal data or share it for advertising.
  • We run no analytics scripts and set no tracking cookies today. The site loads no third-party scripts except the Cloudflare Turnstile check, and only when you open the sign-in dialog.
  • We do not store passwords. You sign in with an emailed link or with Google.

Signing in with Google

If you choose Continue with Google, we ask Google for the openid and email scopes. Google sends us your Google account ID and your verified email address. We do not receive your name, picture, contacts, or anything else from your Google account. Google's own privacy policy covers what Google does when you sign in.

Why we may use your data

If you live in the European Economic Area or the United Kingdom, the law asks us to name a legal basis for each use. In plain words:

  • Contract: we use your email, account record, session, collections, and the MCP sign-in grant to give you the account and the assistant access you asked for.
  • Legitimate interest: we use the rate-limit counters, the bot check, request logs, and the MCP and API usage logs to keep the site secure and working, to support you, and to understand how the service is used. We think this is a small, expected use of your data. You can object by writing to us.
  • Legal obligation: we may keep or share data if the law requires it.

Who handles your data

Cloudflare hosts the site, runs our database and file storage, sends the sign-in email, and provides the bot check. Google receives requests for fonts, and handles your sign-in if you choose Google. Your email provider handles the sign-in email after we send it. We do not share your data with anyone else, except when the law requires it.

International transfers

Cloudflare runs a global network, so your data can be processed in countries other than your own, including the United States. Where the law requires it, Cloudflare and Google rely on approved transfer terms.

Your choices and rights

  • Delete your account: open the account menu and choose Delete account. This removes your account record, sessions, collections and their notes, any saved tracks from before collections existed, API keys, and your MCP and API usage log rows. It also removes the sign-in link records and the email rate-limit counter for your address, immediately. Counters keyed by IP address are kept 48 hours, then removed by the daily clean-up. The rate-limit counters keyed by your account ID are removed by the same clean-up, within 48 hours or, for the monthly count, within 40 days. Deleting your account revokes every grant immediately, so AI assistants lose access at once.
  • Remove an assistant's access: open the account menu, choose Connected assistants, and choose Remove next to the assistant. Signing out of the website does not end MCP access.
  • Sign out: choose Sign out in the account menu. It ends your session and clears the cookie.
  • Access and export: email legal@uncommonear.com and we send you a copy of the data we hold about you. There is no self-service export yet.
  • Correct your data: email us. To change the email address on your account, write to us from the old address.
  • Browser data: clear the site's local storage and cookies in your browser at any time. That removes your theme choice, your sign-in cookie, and any leftover saved tracks from older versions of the site.

Depending on where you live, the law may also give you the right to object to a use, restrict a use, move your data to another service, withdraw consent you gave, or complain to your data protection authority. This includes GDPR and UK GDPR rights, and rights in some US states under laws such as the California Consumer Privacy Act. We do not sell or share personal data for advertising, so there is nothing to opt out of. We answer requests within one month, and we may ask you to confirm you own the email address first. We will not treat you worse for using any of these rights.

Children

Uncommon Ear is not directed at children under 13. In the European Economic Area and the United Kingdom, do not create an account if you are under 16, or under the age of digital consent in your country if that is lower, unless a parent or guardian agrees. If you think a child has given us personal data, write to legal@uncommonear.com and we delete it.

Coming later

Paid Pro accounts, with payments handled by a payment provider, and product analytics are planned but not live. We will update this policy, and change the date at the top, before either launches.

Changes to this policy

When we change this policy, we change the date at the top.

Contact

Write to legal@uncommonear.com.