Privacy Policy
Last updated July 25, 2026
Effective Date: August 24, 2023
This policy describes how Black Toast Music LLC ("Company," "we," "us," or the "Company") collects, aggregates, stores, safeguards and uses the data and information (including non-public personal information, or "NPI") provided by users through our website, www.blacktoastmusic.com (the "Site"), as well as information collected by us through other means, including by email, over the phone, or in offline communications. This Site is operated by the Company and has been created to provide information about our company, products, and services (together, the "Services").
We take your privacy and the security of your information seriously.
This policy explains what information we collect and how we use it, the choices you can make about the way your information is collected and used, and how we protect personal information electronically and physically.
This policy is incorporated into and a material term of your registration and/or use of Company's products and services, including our website, www.blacktoastmusic.com. By using the Site or Services, you consent to the practices set forth in this Privacy Policy.
Information We Collect
Information You Provide to Us
Company collects information from you when you choose to provide it to us through the Site or through any other means. This may include when you create an account on the Site, register or request products or services, request information from us, sign up for newsletters or our email lists, use our Site, or otherwise contact us.
The information we collect may include your name, address, email address, telephone or mobile phone number, information relating to your employment or professional activities and financial account information. You may be required to provide certain personal and/or business information to apply for and receive Company products and/or services.
Information We Automatically Collect
We may use cookies or other technologies to automatically collect certain information when you visit our Site or interact with our emails. We may automatically collect non-personal information such as your browser type, operating system, software version, and Internet Protocol (IP) address. We also may collect information about your use of the Site, including the date and time of access, the areas or pages that you visit, the amount of time you spend using the Site, and whether you open, forward, or click-through emails.
You may adjust your browser or operating system settings to limit this tracking or to decline cookies, but by doing so, you may not be able to use certain features on the Site. Please note that our system may not respond to Do Not Track requests or headers from some or all browsers.
Cookies, Pixel Tags/Web Beacons, and Other Technologies
Our Site is advertisement-free. We neither collect nor utilize your data for advertising purposes. We do not authorize any third parties to utilize your data for advertising on our platform. We, as well as third parties that provide content or other functionality on our Services, may use cookies, pixel tags, local storage, and other technologies to automatically collect information through your use of our Services.
How We Use Information We Collect
Company uses the data and information you provide in a manner that is consistent with this Privacy Policy and applicable law. If you provide personal data for a certain reason, we may use the personal data in connection with the reason for which it was provided. For instance, if you contact us by email, we will use the personal data you provide to answer your question or resolve your problem.
Company may also use your personal data and other personally non-identifiable information collected through the Site to help us improve the content and functionality of the Site or Services, to better understand our users and to improve the Site and Services. If at any time you wish not to receive any future marketing communications, please contact us as indicated below.
Sharing of Information We Collect
Company is not in the business of selling your information. There are, however, certain circumstances in which we may share your personal data with certain third parties without further notice to you: agents, consultants and third-party service providers (to perform specific business-related functions); business transfers (in the event of a corporate sale, merger, reorganization, dissolution, or similar event); related companies (our corporate affiliates and subsidiaries for purposes consistent with this Privacy Policy); and where required by law or in the good faith belief that such action is necessary.
Links to Other Websites
The Site may have links to third-party websites, which may have privacy policies that differ from our own. We are not responsible for the practices of such sites, nor does any such link imply that Company endorses or has reviewed the third-party site. We suggest contacting those sites directly for information on their privacy policies.
Children and Minors
Company does not knowingly collect personal data from minors under the age of 18. If you are under the age of 18, please do not submit any personal data through the Services. If you have reason to believe that a minor under the age of 18 has provided personal data to Company, please contact us, and we will endeavor to delete that information from our databases.
Data Security
We have taken certain physical, administrative, and technical steps to safeguard the information we collect from and about our customers and Site visitors. While we make reasonable efforts to help ensure the integrity and security of our network and systems, we cannot guarantee our security measures. Therefore, you should take special care in deciding what information you send to us via email.
Access to Your Personal Information
To keep your personal data accurate, current, and complete, please contact us as specified below. We will take reasonable steps to update or correct personal information in our possession that you have previously submitted via the Services.
Information for EEA Users
Individuals located in the European Economic Area (EEA) have certain rights in respect of their NPI, including the right of access, rectification, restriction, opposition, erasure and data portability. Where possible, we rely on user consent as a lawful basis for processing personal data and obtain such consent in compliance with applicable laws.
Company has designated a Data Protection Officer to assist with data privacy and data protection issues. You may contact the Data Protection Officer by emailing help@blacktoastmusic.com.
If You Have Questions
If you have any questions about this Privacy Statement or the practices described herein, you may contact us at help@blacktoastmusic.com.
Changes to This Statement
Company reserves the right to revise this Privacy Policy at any time. When we do, we will post the change(s) on the Site. This Privacy Policy was last updated on the date indicated above. Your continued use of the Site and the Services after any changes or revisions to this Privacy Policy shall indicate your agreement with the terms of such revised Privacy Policy.
---
ChatGPT, Codex, and connected AI services — staging legal draft
Staging-only draft for counsel review. This section is not approved production privacy language.
Connected AI services
If you choose to connect Black Toast Music to ChatGPT, Codex, or another supported AI service, we process your Black Toast Music account and authorization information to establish and secure that connection. Depending on your role, this may include your user identifier, organization and membership identifiers, current permissions, approved OAuth scopes, consent and session records, and the status of your account and acceptance of our terms.
The AI service processes the prompts and instructions you provide and sends authorized requests to Black Toast Music. We return only the catalog, playback availability, download status, or staff workflow information needed to answer the request. Embedded components may separately receive short-lived playback or download delivery information that is not included in the AI model's visible tool result. Your prompts, tool requests, and our responses are therefore processed by both Black Toast Music and the connected AI service under each provider's applicable terms and privacy notices.
Catalog, playback, and downloads
We process catalog search terms, selected tracks, queue order, and playback or download requests to provide the features you ask for. Playback uses short-lived, origin-bound authorization. We do not expose media stream or storage addresses to the AI model. The connected service's embedded App and host may receive short-lived addresses to play or deliver authorized files. Downloads are available only when your current organization membership, catalog entitlement, and request-specific permissions allow them. We may recheck those conditions while a request is processed and before a download is made available.
Download records may include the requesting account, organization and membership, selected tracks, requested formats, operation status, device or request information, and delivery metadata. Download outputs are scheduled to expire after 90 days, and individual ready links are short-lived. Counsel note: replace or qualify this sentence after engineering proves file, metadata, backup, and audit deletion behavior.
Staff changes and audit
Authorized staff may use connected AI services to prepare catalog changes. A proposed change does not alter catalog data until an authorized user reviews the exact proposal and separately confirms it. We maintain security and audit records for connected-service activity, which may include the user, organization, client, scopes, tool, request, sanitized input, summarized result, status, and error information. We redact credentials and sensitive media or download addresses from these records.
Service providers
We use service providers to operate and protect these features. OpenAI processes conversations, connected tool requests and responses, embedded App content, component-only playback or download delivery metadata, and connection credentials when you use ChatGPT or Codex. Sentry may process sanitized error and performance information for security and reliability. Our hosting, database, storage, and delivery providers process data as needed to run the service. Counsel note: name or link all required subprocessors and describe controller/processor roles, international transfers, retention, and user controls under the final agreements.
Choices, revocation, and deletion
You can disconnect Black Toast Music from the connected AI service and revoke consent. Revocation prevents new authorized requests but may not immediately delete records we must retain for security, legal, licensing, or audit purposes, or conversation data controlled by the AI service. Contact [approved privacy contact] to request access, correction, or deletion. We will explain any information we must retain and the applicable retention period.