MELD

Privacy Policy

Last updated 4 September 2026

This covers meldliveapp.com: MELD Master, MELD Jam, MELD Studio, MELD Social and the messaging that goes with it, and the sign-up forms. The short version: we ask for an email address only when you offer one, we do not use analytics cookies or third-party trackers, and the only audio that ever reaches us is a track you deliberately post.

Added 1 September 2026: likes, comments, reposts and a count of how many times a post has been played. The sections below say what each one stores. Nothing about audio, mastering, recording or jamming changed.

This page changed on 30 August 2026, and one change is material. Until then nothing you recorded was ever uploaded, because there was nowhere for a recording to go. Posting a track now uploads that recording, so that other people can play it — a feed of tracks nobody can hear is not a feed. Everything else is unchanged: mastering, recording and jamming still happen entirely on your own machine. The section below says exactly what is uploaded and when.

Your audio, and what happens to it

The free MELD Master render never uploads your audio. The file you choose is read by the page in your browser, processed on your own machine, and saved back by your browser. It does not reach us.

The paid server render would upload it, and it is not switched on. That path exists in the code: your browser would be given a short-lived signed link and would upload the file to Cloudflare R2, our server would render it there and hand back a download. It is disabled — every attempt is refused — and no audio has been uploaded through it. We are describing it here anyway, because a privacy promise that is only true until a setting changes is not a promise. If it is ever enabled, the upload happens only when you choose a paid render, the input is deleted when the render finishes, and the output is deleted the moment its download link is issued. The free render never uploads anything, whatever else is switched on.

Posting a track

When you post a track to MELD Social, that recording is uploaded. This is the only thing MELD uploads in the ordinary course of using it, and it happens only when you choose to post. The file goes from your browser straight to our storage at Cloudflare R2 on a short-lived signed link; it does not pass through the rest of our systems on the way. We hold it so that the people you have allowed can press play.

Who can play it is checked every single time, not once. A post is public, friends only, or private, and the audio follows that setting at the moment somebody presses play — not at the moment they loaded the page. Narrow a post to friends, or make it private, and anybody outside that is refused from then on, including anybody who kept the link.

Your own posts also play from the copy already in your browser, which is why you can hear your own track back before anything is uploaded and even if uploading is switched off. That copy is yours and is never sent anywhere.

A recording may be reduced in size before it is uploaded. A long take is resampled — fewer channels, a lower sample rate — so that it fits; the page tells you when it has done this. The original on your machine is never altered. A take too long even for that is not uploaded at all, and only plays on your own device.

You can delete a post, and the audio goes with it. Delete is on your own posts in the feed and takes two presses, because it cannot be undone: it removes the row and the file from our storage together. Setting a post to private is the softer option — it stops anybody else playing it immediately while the post stays yours.

Cloud save and sharing a mix by link (Studio plan)

Two paid Studio buttons upload audio, and only those two. Save to cloud uploads the lanes of an arrangement so you can open it on another device; Share by link uploads the finished mix so somebody with the link can play it. Both go from your browser straight to our storage at Cloudflare R2 on a short-lived signed link, on the press of that button and at no other time. A shared mix plays from a link that is minted per visit and expires; delete the link, or the project, and the audio is removed with it. Nothing else in the Studio — recording, arranging, effects, the drum machine and synthesiser, importing your own sounds, exporting stems — sends audio anywhere.

Your takes and any sounds you import stay in your own browser's storage, on that device. They are not copied to us, and they are not synced between your devices unless you use Cloud save, which is the button described above. The practical consequence is worth knowing: clearing your browser's site data for MELD deletes them, and they will not be on your phone because you recorded them on your laptop.

Sending a track to a friend in a message does not upload anything. What travels is the card — the name, the length, what you played it on and a link to your profile.

Jamming

MELD Jam is audio only. There is no camera. It used to offer video; the camera, the video panes and everything that drove them were removed on 4 September 2026, so a jam now asks your browser for the microphone and nothing else. Your browser asks permission before using it, and you can refuse or revoke that at any time.

We do not record MELD Jam sessions. Audio travels between the two participants — directly where both networks allow it, and otherwise through a relay, described under Who else is involved below. Either way it is encrypted in transit and it does not come to us: we do not record, store or listen to any session, and nothing from a jam is uploaded to MELD. This is equally true of a jam you started by inviting somebody directly: a private room is private from us as well.

Recording both people exists, and it is opt-in on BOTH sides. There is a switch in the jam room, off by default, called Record both of us. Turning it on does not only change what your browser captures — it changes which room you are put in, so you are only ever matched with somebody who has turned it on as well. Two people choose it separately, before they meet; there is no way to be recorded by somebody who chose it when you did not, because you are never in the same room. While it runs both of you see a red indicator, and either of you can stop it, which stops it for both. The recording is made in the browser and MELD never receives it.

With that switch off, which is the default, your own playing is captured and nothing else during the playing part of a session, so that a take you liked is not lost when the three minutes are up. It is your microphone only. The other person's audio is not captured, by you or by us. A red indicator shows while it is running whichever mode you are in, it stops before the cool-down, and when the session ends you choose what happens to the take: send it to MELD Studio, download it, or discard it. If you do nothing, it goes when you close the page.

If you invite somebody to jam, we store who invited whom and a one-time code, for fifteen minutes, so that both browsers can find the same room. Then it is deleted. Only the two people named on an invite can open it; a forwarded link does not work. Nobody can send you an invite who could not already send you a message, so blocking somebody also stops them inviting you.

What we collect

If you use a sign-up form: your email address, and — only if you type them — your name and what you play. We store one record per address and whether the email was sent. Records from the MELD Jam beta also hold the access key that was issued; keys are no longer needed or issued.

If you ask to reset your password: we store a one-hour, single-use code for that account — hashed, so what is in our database cannot be turned back into the link that was emailed to you. It is deleted when it is used or when it expires. Asking is answered the same way whether or not there is an account with that address, so the form cannot be used to find out who is registered here.

If you email us: your message and address, read by a person in order to answer you and kept as ordinary correspondence.

If you create a MELD Studio account: your email address and your password. The address also goes on the MELD updates list, which is occasional email about what is new. The sign-up form says so above the button, every email carries a one-click unsubscribe, and unsubscribing does not touch your account. If you had unsubscribed before, creating an account does not put you back on — you stay off it. The password is never stored — what we keep is a scrypt hash with a salt unique to your account, which cannot be reversed back into your password. We also store which plan you are on. You do not need an account to record, export, or master; it exists only so your work can follow you once cloud save is built.

If you post a track to MELD Social: the track name, how long it is, what you played it on, your profile name and handle, and — this is the part that changed — the recording itself. The audio section above says where it goes and who can play it.

A post can also carry a caption and a source label. The caption is a line you write about the track when you post it. It is optional, it is yours, and it is shown to exactly the people the post is shown to. The source label says which MELD tool the track came out of — MELD Studio, MELD Master, or a jam — and it is recorded only when the button you pressed knows the answer. It is never guessed: a post that did not say shows no label. Neither is added to posts made before these existed.

Who can see each post is set on the post, as public, friends only, or private, and you can change it afterwards. The switch on your account page, Show my posts to everyone, decides what a new post starts as; it is a default, not a rule about all of them. Changing a post's own setting takes effect immediately, for the card and for the audio.

If you like, comment on, or repost something: we store that you did it, and when. A comment stores its text and, if you added a GIF, the address of that image on GIPHY's servers rather than a copy of it — the same way a GIF in a message is stored. A repost stores only a pointer to the original post: the track, the audio and the permission all stay with whoever made it, which is why a post narrowed to friends disappears from every repost of it at the same moment. Deleting a post deletes its likes, its comments and every repost of it.

We count how many times a post has been played, and that is all we count. There is no record of who played it. The number is a single total on the post; to stop one person's refresh inflating it we hold a short-lived key in memory for an hour, which is never written to disk and is discarded when the server restarts. We chose a count that can occasionally be slightly wrong over a list of who listened to what.

If someone likes or comments on your post we store a notification so you can see it later. Your account page has a switch for each: turned off, the thing is never recorded at all, so switching it back on later does not hand you a pile of things you missed. A friend request, an unread message and a jam invitation are not stored as notifications — they are read live from the request, the message and the invitation themselves, and stop appearing the moment you deal with them.

A public post has a link, and that link previews. From 4 September 2026 every post has a page of its own at /p/<id>, and when that link is pasted somewhere — a message, Instagram, Discord — the other service fetches the page to build a preview card. For a public post that card carries the track name, your display name and handle, your caption if you wrote one, and your profile picture. That is the point of it: a link to your music should look like your music. A post that is not public gets no such card. A preview is fetched by strangers, usually by machines with no sign-in, and is then cached and copied by other companies' servers — so a friends-only or private post produces exactly the same generic MELD preview that a post which does not exist produces. The two are deliberately identical, because a different answer would confirm the post is there. The same applies to your profile page, which is public and previews with your name, handle and picture.

What your profile page shows about you. It was redesigned on 4 September 2026 and now shows more, so here is exactly what: your name, handle, picture, the location you typed if you typed one, the month you joined, the tracks you have published, a total of how many times they have been played, how many connections you have, and the instruments you have actually posted with. That last one is read off your own posts, not from a field you filled in — nothing there is a claim you did not make by posting.

Who can see your connections. This changed on the same day and it is worth being plain about. On your own profile you see your own connections by name. On somebody else's profile, if you are signed in, you see the people you both know — which can only ever be people you are already connected to yourself, so it tells you nothing new about anyone. You never see a list of somebody else's connections, and nobody sees a list of yours: there is no request a browser can make that returns another person's connections, and a test fails if one is ever added. A signed-out visitor sees no names at all. What everyone can see is the number of connections an account has, which has been on the profile since it existed.

If you upload a profile picture: we store the image and its type in our database, and serve it to anyone who can see your profile or a message you sent. Replacing it replaces what we hold.

If you message someone: the text, and when it was sent. We store whether the recipient has opened the conversation — that is what puts the second tick on your message, and the sender is told that it was read, never when. A GIF is stored as the address of an image on GIPHY's servers, not as a copy of it; a track is stored as the card, not the recording. Messages are not end-to-end encrypted and we are able to read them. We would rather say that than let the word private imply something it does not.

While you have MELD open: people you are connected to can see whether you are online, away or offline, and the person you are typing to can see that you are typing. Typing is not stored anywhere — it is passed straight through to that one person and forgotten. The online indicator comes from having a page open and from recent activity on it, and it goes when you close the tab.

If you turn on notifications: your browser gives us a subscription — an address at your browser vendor's push service and two keys used to encrypt what we send. We store those so we can reach you when MELD is not the window you are looking at. Turning notifications off, or clearing your browser data, ends it, and we delete a subscription as soon as the push service tells us the device is gone.

If you simply visit: we count page views on our own server. There is no tracking pixel and no third-party analytics.

To count returning visitors without identifying anyone, we compute a one-way hash of your IP address, your browser's user-agent string, a secret, and the current date. The date is included deliberately: the same person produces a completely different value tomorrow, so these records cannot be joined together into a history of any individual. Your IP address itself is never written down. We keep these counts for about four months.

What we do not collect

Who else is involved

Running the site requires a few providers. They are listed because they necessarily handle something.

How long we keep things

Account records are kept while the account exists. Ask us to close it and the record and its password hash are deleted; a signed-in session is discarded the moment you sign out, and in any case after two weeks of not being used.

A posted track's audio is kept while the post exists. Setting the post to private stops anybody else playing it; removing the post and the file is something to ask us for. Messages are kept until an account is closed. Push subscriptions are kept until you turn notifications off or the push service tells us the device is gone. Nothing about typing is kept at all.

Sign-up records are kept until you unsubscribe or ask us to delete them. Unsubscribing marks the record so we stop emailing you; ask us and we will remove it entirely. Visit counts are kept about four months. Correspondence is kept as ordinary business records.

Your choices

Security

The site is served over HTTPS and sign-up records live in a password-protected database. Access keys issued during the MELD Jam beta are still stored so an old one still works; they are never shown on any dashboard or included in any export.

Account passwords go through scrypt with a random salt unique to each account, so what is stored cannot be turned back into your password, and two people who pick the same password do not get the same stored value. We never see your password after you type it and we cannot recover it for you. A failed sign-in says only that the email and password did not match — never which of the two was wrong, because that would turn the form into a way of asking whether someone has an account here. No system is perfectly secure, and we will not pretend otherwise.

Children

The site is not directed at children under 13, and we do not knowingly collect their information. If you believe a child has given us an address, write to us and we will delete it.

Changes

This policy may be updated. The date at the top reflects the most recent revision. If a change materially affects people on our list, we will say so in an email rather than only editing this page.

Contact

Questions, deletion requests, anything else: support@meldliveapp.com