Privacy policy
MCP Music Studio is maintained by Xule Lin. This policy describes the hosted service at music-studio.linxule.com (also available at mcp-music-studio.linxule.workers.dev) and the optional local server. Updated September 26, 2026.
Playing and editing music
The hosted MCP server receives the arguments sent by your MCP client: notation or code, titles, playback settings, and reference or harmony questions. It processes those arguments to provide the requested tool result. Playback does not save your composition in the service's share database. A local installation processes playback locally.
Short pieces may be included in a self-contained browser link. The link contains the composition in an encoded, not encrypted, form. Creating this link does not upload a local composition. Opening it sends the URL and its contents to the hosted service; the URL can also appear in browser history, host conversation records, previews, and infrastructure logs. Anyone you give the link to can decode or play it. Do not put secrets or sensitive information in music code or titles.
Music synthesis, editing and recording run in your browser or MCP host. Audio and MIDI exports are created there and handed to that host or downloaded to your device; the Music Studio server does not receive the exported audio or MIDI. Your MCP host has its own data policies. Using “Send to chat” sends your current edited music to that conversation. The widget can also send playback/error status to the host so the assistant knows whether a pattern worked.
Creating a stored share
The separate create-share-link tool, or an explicit POST /share request, uploads the supplied piece and its playback settings to Cloudflare Workers KV. Anyone holding the resulting link can view and play it without an account. Links are not private storage or authentication, and the service asks search engines not to index player pages.
Stored shares expire 30 days after creation. Creating an identical share again refreshes that period. Older versions of the server also created these shares automatically for long playback inputs; those existing links retain their expiry. Expiry does not remove copies held by recipients, conversations, browser history or caches. There is no account-based share library or self-service deletion control. Contact the maintainer to request removal; do not post a sensitive link in a public issue.
Reference search and browser dependencies
search-music-docs sends your query and selected library to Context7. Results are cached for 24 hours under a hash of the query. The cached result may itself contain parts of the query. Other guide and harmony tools do not use this search service.
The players load scripts, fonts or samples as needed from unpkg, jsDelivr, GitHub/GitHub Pages, and, for the corresponding sample feature, shabda.ndre.gr and cdn.freesound.org. These providers receive normal network request information such as your IP address and user agent. The hosted service runs on Cloudflare. These providers process requests under their own policies, including Cloudflare's privacy policy and GitHub's privacy statement.
Usage information and retention
To understand compatibility and usage, the hosted service records MCP method/tool names, guide topics or the selected documentation library, requested resource identifiers, and a coarse client label. For clients it does not recognize, it also records up to 200 characters of the user-agent header. These analytics do not intentionally include scores, pattern code, search queries or full conversations. Cloudflare Analytics Engine currently retains these events for up to three months.
Cloudflare processes network metadata and operational logs to provide and protect the service. Request URLs, including music embedded in query strings, may appear in those logs. Cloudflare Workers Logs currently retain logs for up to seven days, depending on the plan. Share rate-limit records use the request IP address and expire with a one-hour window. The service does not use these records for advertising or to train an AI model.
Widgets store a bounded list of playback identifiers and timestamps in browser local storage to avoid replaying music when a host rebuilds the view. They keep at most 300 entries, not the composition itself; these entries remain until evicted or browser/site data is cleared. Your browser, MCP host, Context7 and sample/CDN providers can have separate retention policies.
Contact and choices
You can use the local server, avoid opening hosted browser links, and refrain from using reference search or creating stored shares. Local playback can still load browser dependencies from the providers above. Clear your browser's site data to remove playback-memory entries.
For privacy questions, access or removal requests, contact Xule Lin through the project support channel. If your request includes sensitive material, ask for a private contact channel first instead of posting that material publicly.