Privacy
Last updated 9 October 2026
In short: your recordings stay on your device, and anything that syncs is encrypted there first, with a key we never have. There are no accounts, adverts, analytics or tracking.
Who we are
Music Momentos is run by Lunamonkey, the controller of any personal data the service handles. Contact us through www.lunamonkey.co.uk.
On your device
Your ideas (recordings, chords, notes, tags and edit history), your settings and your library's secret key are kept in your browser's storage on your device. They stay there until you delete them or clear the site's data. See Cookies and storage for exactly what's stored.
The microphone is only used while it's switched on in the app: for recording, the level meter, the tuner and auto-record. Sound is processed in your browser. Nothing is sent anywhere as you play.
What reaches our server
Only when cloud sync runs, and only encrypted. Your browser encrypts each idea (its audio and everything about it) with AES-256-GCM before uploading it, using a key that never leaves your devices. Our server stores:
- the encrypted data, which we can't read or play;
- each idea's random id, the time it was last edited, and the size of the stored data;
- a one-way fingerprint (a SHA-256 hash) of your library's access token, to keep libraries apart, and when it last synced.
It stores no name, email address or account. Your recovery code is the only key to your library: we don't have it and can't recover it.
Share links
Sharing an idea uploads a separate encrypted copy with its own key. The key is in the part of the link after the #, which browsers never send to servers, so we can't open shared copies either. Notes and tags aren't included. Anyone you give the link to can play and save the idea until you revoke it.
Server logs and abuse limits
Like any website, our hosting receives your IP address when your browser connects. We use it briefly, in memory, to limit how many requests one address can make, and our hosting provider keeps standard technical logs for security and reliability. We don't use it to identify or track you.
Who processes data for us
The site, the API and the encrypted storage are hosted by Microsoft Azure (Static Web Apps, Functions and Blob Storage). The site loads nothing from any other company: its fonts and code are served from our own domain.
How long we keep things
- Deleted ideas wait in Recently Deleted for 30 days, then are deleted from your devices and the server.
- Inactive libraries: if no device syncs a library for 30 days, its encrypted cloud copy is deleted. Copies on your devices aren't affected.
- Safety net: if our storage's protection against accidental deletion is switched on, deleted encrypted data can stay recoverable by us for a limited time (no more than 30 days) before it's gone for good.
Why we're allowed to
We handle this data to provide the service you've chosen to use, and in our legitimate interests in keeping it secure and working (UK GDPR Article 6(1)(b) and (f)).
Your rights
You can delete any idea, or all of them, from within the app, and clearing the site's data in your browser removes everything on that device. Because everything we store is encrypted and isn't linked to who you are, we usually can't tell which data is yours, but if you have a question or want to use your rights under UK data protection law (to access, correct or erase data, or to object), contact us. You can also complain to the Information Commissioner's Office at ico.org.uk.
Changes
If this policy changes, we'll update this page and the date at the top.