This policy covers only the optional MusicBook Pro Agent Collaboration MCP and its ChatGPT plugin. It gives a complete account of the current tool inputs, outputs, purposes, recipients, retention and user controls. The separate MusicBook Pro app privacy policy covers local app features such as recording, transcription, camera import, private iCloud sync and Apple's in-app purchase system. Those features are not available to the MCP and are not MCP inputs.
Purpose and user choice
Agent Collaboration helps a musician work with songwriting content already stored in MusicBook Pro on their Mac. It is off by default and available only in the Mac app. The user deliberately enables library reading, new-Idea creation, new-Setlist creation, or a combination, and chooses a time limit or Until turned off. A permitted action does not require a second MusicBook Pro confirmation on every call. The user may expire or disconnect access at any time.
The MCP can search or fetch approved Songs, Drafts, Ideas, Projects and Setlists, and can create only a new Idea or Setlist when the corresponding permission is enabled. It cannot edit or delete an existing item, access generic files or source code, run shell/database commands, fetch protected lyrics, or access media, recordings, temporary transcripts, credentials or recovery data.
Data collected and used by each tool
| Tool | Input collected | Output returned | Purpose |
|---|---|---|---|
pair_mac |
A short-lived device connection code generated inside MusicBook Pro for Mac. | Whether the Mac was paired. | Connect the authenticated MusicBook Pro account to that Mac. This is an app device code, not an account password, MFA/OTP code, API key or payment credential. |
get_collaboration_context |
No tool input. | The user's local songwriting brief; read/create permission states; access expiry; aggregate counts of Songs/Drafts, Ideas, Projects and Setlists. | Let the provider respect the user's current scope and writing instructions. |
search |
A music-library keyword or phrase, limited to 200 characters. | Matching private item references, user-supplied titles and MusicBook Pro deep links. | Find approved content in the user's own MusicBook Pro library. |
fetch |
One opaque item reference returned by search. |
That item's reference, title, private deep link, JSON-encoded songwriting text/music metadata, item type and—only when needed for safe Setlist creation—a Song revision token. OpenAI's isolated samples also carry a reviewSample flag. |
Read the single requested Song, Draft, Idea, Project or Setlist and preserve current revisions. |
create_idea |
An idempotency UUID, title, creative text and optional artist, writing notes, language code, Project reference or related Song reference/revision. | The new private item's UUID, type, title, local source label and whether the same idempotent request was already completed. | Save one new songwriting Idea. It cannot change an existing item. |
create_setlist |
An idempotency UUID, Setlist name, optional rehearsal/performance notes, ordered Song UUIDs and an explicit list of matching Song-ID/current-revision-token pairs. | The new private item's UUID, type, name, local source label and whether the same idempotent request was already completed. | Save one new revision-validated Setlist. It cannot change an existing Setlist or Song. |
The fetch creative payload is limited by item type. Song/Draft data may contain user-entered lyrics/chords, artist, keys, capo, tempo, time signature, genre, tags, duration, tuning, musical/performance notes, language, checklist, material type and library links. Idea data may contain title, text and notes. Project data may contain its name and Idea links. Setlist data may contain its name, notes and ordered Song entries with title, artist, key/capo, duration and transition notes. Item/revision references and local timestamps may be included to preserve current library relationships and prevent stale writes.
Restricted and sensitive data
No MusicBook Pro MCP tool asks for or is intended to receive health or medical records, biometric identifiers or templates, government identifiers such as social security numbers, payment-card or other PCI data, passwords, account credentials, MFA/OTP codes, API keys, authentication tokens, precise location, raw audio/video/photos, microphone/camera/speech data or a full ChatGPT/Claude conversation history.
Tool fields are purpose-limited to songwriting and personal music-library content. Do not place restricted personal, authentication or payment data in titles, lyrics, notes or search queries. MusicBook Pro does not need that data to provide Agent Collaboration.
Recipients and processing
- The selected provider, such as OpenAI: receives the tool call input and the tool output needed to answer the user's request. MusicBook Pro does not receive the user's full provider conversation.
- Cloudflare: hosts the authenticated relay and may process ordinary network and security data such as IP address and request headers under Cloudflare's policies. The MusicBook Pro gateway relays approved request content without a creative-library database or raw-content request logging.
- Auth0: hosts OAuth login and may process the login identifier, account credentials on Auth0's hosted page, tokens and security events under Auth0's policies. The MusicBook Pro gateway receives only the Auth0 subject identifier and granted scopes from the access token; it does not receive the user's password.
- The user's Mac: receives authenticated tool requests, reads only enabled library data and stores a newly created Idea or Setlist locally when permitted.
Music by Lars does not sell this data, use it for advertising, tracking or profiling, or create a developer-controlled copy of a user's creative library.
Retention
- For normal accounts, approved request content remains in the MusicBook Pro gateway only in memory until a response or timeout, normally no longer than 25 seconds. It is not written to a creative-content database or raw-content log.
- Active Mac routing state remains only while connected and is discarded on disconnect or service restart. A pairing code expires after ten minutes or first successful use. A signed reconnect token remains in the Mac Keychain until revoked or replaced.
- A newly created Idea or Setlist is stored in the user's MusicBook Pro library until the user deletes it under the app's normal retention rules. The local, backup-excluded activity list stores provider, action, item name and time—but not lyrics or raw tool input—and gives the user Open and Undo controls.
- OpenAI's reviewer account can access only fictional samples. Review-created Ideas and Setlists exist only in volatile gateway memory and may disappear when the service restarts.
- Auth0, Cloudflare and the selected provider retain their own account, security, service or conversation data under their policies and the user's account settings.
User controls and deletion
On Mac, the user can independently disable library reading, Idea creation or Setlist creation; set a short manual duration; select Until turned off; or use Disconnect All. Expiry and disconnection stop access immediately. Users can inspect the local activity list, open or undo an agent-created item, and delete library content through MusicBook Pro. Contact Music by Lars to request deletion of a MusicBook-specific Auth0 login. Provider-side conversations and account data must be controlled or deleted through that provider.
OpenAI model-improvement controls
On a personal ChatGPT account, open Profile → Settings → Data Controls and turn off Improve the model for everyone to exclude new personal-workspace conversations from model training under OpenAI's current policy. OpenAI states that ChatGPT Business, Enterprise, Edu and API inputs and outputs are not used for model training by default. Feedback submissions may include the related conversation. See OpenAI's official data-control guide.
Contact
For privacy questions or requests concerning MusicBook Pro, contact Music by Lars at musicbylars.com/index.php/contact.