Accounts, published work & products
Privacy Policy
Version 0.2-draft, September 19, 2026. This describes what Maru collects, where it is stored, who else sees it, and how to have it deleted.
Draft — pending legal review
These documents were written by the team that runs the service and have not been reviewed by a lawyer. They describe what the product actually does today, and they are the terms we will operate under, but they may change materially once counsel has read them.
Version 0.2-draft · September 19, 2026
1. Who handles your data
Maru is operated by [Operator legal name], which is the controller of the data described here. Questions and requests go to hello@maruaudio.com.
2. What we collect
- Account information. When you sign in with a third-party provider (such as Google), we receive basic profile details — typically your name, email address, and avatar — to create and identify your account.
- Your creator work. The projects you create and every saved revision of them: source files, presets, project settings, listing text, tags and cover artwork, and the samples and other files you upload. Also your original brief and your agent conversations, which stay private to you.
- Purchases and product access. Products acquired, order and provider references, prices, product-license snapshots, receipts, fulfillment status, and account entitlements. Our payment provider processes payment details; we do not store your complete card number.
- Transactional messages. Delivery information for account, receipt, access, and support messages, including whether a message was accepted, delivered, failed, or suppressed.
- Applications and inquiries. If you apply to work with us or contact us about a collaboration, we collect what you send — resume, interests, location, experience, preferred role, contact details, message text and any supporting material. These are private and visible only to you and authorized staff.
- Basic usage and diagnostic data. Log data, error reports, and counts such as how many times a public module page was viewed, used to keep the Service running and to improve it.
3. Where it lives
Maru runs on Cloudflare. Account rows, project rows, revision manifests and small source files are stored in Cloudflare D1 (our SQL database). Larger files — uploaded samples, build artifacts, generated audio, images — are stored as objects in Cloudflare R2 (our object storage). Both are operated by Cloudflare on our behalf under their terms.
File bodies in D1 and R2 are stored by their content digest: two identical files are stored once and shared by every revision and every fork that refers to them. This matters for deletion — see section 7 and the fork rule in the Terms.
4. What is public
New modules you create in Studio are created as public, and you can change that at any time from the Share control. While a project is public or unlisted, anyone who can open it can play it, read its latest saved source, fork it and embed it, and your profile lists your public work. Your unsaved edits, your brief, your agent conversations, your private projects and your revision history are not shown to other users. The Terms set this out in full.
5. How we use it
We use the information above to:
- Provide, maintain, and secure the Service.
- Save your work and associate it with your account.
- Serve public pages, embeds, forks and profiles.
- Understand how products and preview tools are used and improve them.
- Process acquisitions, provide receipts, assign product access, support redownloads, and resolve payment or account issues.
- Review applications and inquiries, respond to your messages, and act on reports and takedown requests.
We do not sell your personal information, and we do not share it with advertisers.
6. Sharing
We share data only with the service providers that help us operate Maru — hosting and storage (Cloudflare), authentication, payment and transactional-email providers — and where required by law or needed to protect the Service, our users, or our rights. These providers process data on our behalf under their own terms.
7. Deletion, and exactly what it removes
You can delete your creator data from your account settings, or by writing to hello@maruaudio.com from the address on your account. Either way we aim to complete it within 30 days.
Deletion removes:
- your projects and every revision of them, including private and archived projects;
- their dependent rows — uploaded assets, preview sessions, export records, agent conversations and messages, release records and rate-limit events;
- the R2 objects those rows name and that nothing else refers to; and
- your profile and account record.
Deletion does not remove:
- Forks other people already took of your public work, or the shared content-addressed file bodies those forks still depend on. A fork is its owner’s project. What does go is the attribution: the fork stops naming you as the original. See the fork rule.
- Records we are required to keep — purchase and tax records, security and abuse logs, and anything under a legal hold.
- Copies outside our control: search-engine caches, archives, embeds, and anything a visitor downloaded while your work was public.
- Backups, which expire on their own schedule rather than being edited. Deleted data can persist in a backup for a period after deletion and is not restored to the live service.
Known limitation, stated plainly. We delete the R2 objects that your database rows name. Because storage is content-addressed and keys are shared, we do not delete an object that a surviving fork still refers to, and an object whose last naming row was lost by an earlier bug would not be reached by this pass. Reclaiming those is a background sweep we have not built yet.
8. Retention
We keep your data for as long as your account is active or as needed to provide the Service, fulfill purchases, resolve disputes, and meet legal, tax, accounting, and security obligations. Data created inside preview tools may be reset or removed as those tools evolve; do not treat preview project storage as your only copy.
9. Security
We take reasonable measures to protect your data, but no method of transmission or storage is completely secure. Preview tools are provided without warranty; please do not store sensitive or irreplaceable project data in them.
10. Your choices
You may request access to, correction of, export of, or deletion of your personal data by contacting us at hello@maruaudio.com. Depending on where you live you may have additional rights under local law, and we will honor them where they apply. You can also change any project’s visibility, or stop using the Service, at any time.
11. Children
Maru is not for people under 13, or under the higher minimum age your local law may set. We do not knowingly collect data from them. If you believe a child has created an account, write to us and we will remove it.
12. Changes to this policy
We may update this policy. When we do, we will revise the version and date above.
13. Contact
For any privacy question, deletion request, or report, contact us at hello@maruaudio.com.
See also our Terms & Conditions.