Privacy Policy

    Last updated: 27 August 2026

    This policy explains what personal data Raag Finder collects, why, who it is shared with, how long it is kept, and the choices you have. It applies to raagfinder.com and all related features. Read it alongside our Terms of Use and Cookie Policy.

    1. Who we are

    The data controller is Workolo Entertainments (PAN AUNPG2336E), 191/6, Lamech Street, Janaki Nagar, Valasaravakkam, Chennai 600087, Tamil Nadu, India, phone +91-4443300011. Privacy queries: admin@workolo.com.

    2. What we collect

    a. Account and profile data

    • Email address and an encrypted password hash (held by our authentication provider — we never see your password).
    • Full name, avatar image, age group, country of residence, nationality, occupation, talents and languages you speak, if you choose to provide them in your profile.
    • Connect directory details: your city, a short "looking for" line, and whether you appear in the member directory at all.
    • Whether your account holds administrator privileges.

    b. Audio and analysis data

    • Microphone recordings made through the Listen feature and files you Upload, and the trimmed excerpt you confirm for analysis.
    • Separated stems (vocal, accompaniment and lead-instrument tracks) derived from your audio.
    • Analysis outputs: detected tonic, swaras, phrases, note timeline, raag matches, confidence scores and AI reasoning; the tonic you confirm or correct; and any raag you mark as the correct one.
    • The name you give a recording, and reports you generate from it.
    • A cryptographic fingerprint (hash) of your audio file, used to recognise a repeat upload and avoid charging you for the same work twice.
    • The result of the copyright screening run on your recording, retained so a block can be explained or disputed.
    • Whether the headphone check passed on your device (a pass/fail flag only — the test tone and the microphone audio used for it are processed in your browser and are not stored or sent to us).
    • Your privacy setting for each analysis (public when run on a free credit, private by default when run on a paid credit).

    c. Payments and credits

    • Credit balance and ledger entries (purchases, deductions, rewards and gifts).
    • Order records: reference code, amount, currency (Indian Rupees via PhonePe, or US Dollars via PayPal), status, timestamps and the payment gateway's transaction reference.
    • For orders that are never paid: the automated re-check history, the time the order was flagged as "payment not completed", and any administrator note or closure record. Closed orders are hidden from your purchases but retained.
    • Invoice and receipt records containing your name and email. We never receive or store card, UPI, PayPal or bank credentials — those are handled by the payment provider.

    d. Community contributions

    • Comments and replies, forum topics and replies, mood suggestions, votes on moods and on raag predictions, suggested performance/explanation video links, and public analyses you choose to share.

    e. Connect requests and private messages

    • Connect requests you send or receive, including the introductory message, status, credit used and timestamps.
    • Chat messages exchanged after a request is accepted — text, voice notes recorded in the app, and attached images or PDF documents (up to 5 MB each) — visible only to the two members involved.
    • Which discussion and chat threads you have read, used to show you unread counts.

    f. Technical and analytics data

    • A randomly generated device identifier stored in your browser, and a hashed browser/device fingerprint, used to count unique devices rather than page loads.
    • IP address at the time of a visit, used to derive an approximate country and for abuse prevention and security logging.
    • Coarse device details such as browser, operating system, screen size and timezone; first-seen and last-seen timestamps.
    • Server, error and security logs.

    g. Support chat

    • The name and email address you give when starting a chat, and — for visitors who are not signed in — the one-time code sent to that address and the fact that it was verified.
    • The full transcript of the conversation, including anything you paste or attach.
    • Queue position, wait time and handling time, used to manage the queue and measure responsiveness.
    • Whether the chat came from a signed-in member or a guest, and the page from which it was opened.

    Support replies are written by our administrator, who may use an AI assistant to draft suggested wording before a human sends it. Please do not paste passwords, card details or banking one-time codes into chat.

    h. Moderation records

    • Flags you raise against another member, a public analysis, a comment or a Connect approach, and flags raised against you, together with the reason given.
    • Records of blocks, account closures and their reasons, which are archived rather than erased so repeat abuse can be identified.

    We do not knowingly collect government identifiers, financial account numbers, health data or other sensitive categories, and you should not upload them.

    3. Why we use it, and our legal basis

    • To provide the Service — run analyses, store and show your results, operate credits, and deliver invoices. Basis: performance of our contract with you.
    • To operate community features — display your chosen name and avatar next to your comments, moods, forum posts and public analyses. Basis: contract and your consent when you choose to publish.
    • To run Connect — list you in the member directory (only after you switch the listing on in your profile), deliver connect requests and private messages, and reveal your email address to another member only after a connect request between you is accepted. Basis: contract; directory listing is opt-in and can be switched on or off in your profile at any time.
    • To capture and process audio — only after your browser grants microphone permission or you pick a file. Basis: your consent, withdrawable at any time in browser settings.
    • To improve detection quality — aggregated and de-identified statistics, and community-validated analyses. Basis: legitimate interest.
    • To keep the Service secure and prevent abuse — human verification, rate limits, device counting, logging. Basis: legitimate interest and legal obligation.
    • To answer support chats — verify a guest email with a one-time code, hold the conversation, manage the queue, and keep the transcript for follow-up and dispute handling. Basis: contract and legitimate interest.
    • To moderate and keep members safe — review flags, read Connect and support conversations where abuse is suspected, and block or close accounts. Basis: legitimate interest and legal obligation.
    • To handle unpaid orders — re-check them against the payment gateway, notify you, and close them where no payment exists. Basis: contract and legitimate interest.
    • To communicate — account, payment, notification and service emails, and campaign or announcement emails which may include AI-generated images. Basis: contract and legitimate interest; campaign emails carry an unsubscribe link.
    • To comply with law — tax, accounting and lawful requests. Basis: legal obligation.

    We do not sell personal data, and we do not use it for advertising, ad targeting or cross-site behavioural profiling.

    4. Audio, stems and AI processing

    Analysis is a mix of in-browser processing and cloud processing. Pitch tracking, the live pitch display while you sing, the headphone check and swara mapping run in your browser; the microphone stream used for the live display and the headphone check is not uploaded. Where vocal or lead-instrument isolation is used, your audio is transmitted to our AI stem-separation provider; where the AI second opinion is used, a description of the extracted musical evidence (and not, ordinarily, the raw audio) is sent to a large language model provider. These providers process data on servers that may be located outside India.

    Uploaded audio is additionally screened for copyright: an acoustic fingerprint of the recording is checked against a commercial music-identification database operated by an external provider, whose servers may also be outside India. Recordings that match a commercial release are blocked from analysis and sharing.

    Audio you submit and stems produced from it are stored in access-controlled storage tied to your account. Private analyses are readable only by you; administrators of the Service may access analyses, including private ones, for support, moderation and abuse investigation.

    5. Service providers we share data with

    We use third-party service providers to host and operate the Service. These providers may process your data on our behalf for purposes such as authentication, database and file storage, server functions, AI/ML audio processing, email delivery, human verification, network delivery, payment collection and embedded media playback.

    We do not publicly disclose our specific vendor list. Each provider is engaged to process data on our instructions for the purposes above. We may also disclose data where required by law, to enforce our Terms, or in connection with a merger or transfer of the business (with notice to you).

    6. What other users can see

    • Visible to everyone: your full name (or a masked email such as ni•••@gm•••.com if no name is set), your avatar, and any comments, mood suggestions, votes and analyses that are public — including the name you gave the recording and the audio itself.
    • Visible to signed-in members in Connect: your name, avatar, talents, languages, occupation, country, city, "looking for" line and any Talent-Demo video links you add — only if you have added a talent and switched on your directory listing. Listing is off by default; you can switch it on or off at any time in your profile.
    • Your email address is never displayed publicly. It is revealed to another member only when a connect request between the two of you is accepted.
    • Never shown to other users: your age group, nationality, credit balance, order history, private analyses and audio, connect requests and chats with other members, support chats, device identifiers and IP address.
    • Visible to our administrator: Connect requests and chat content, support-chat transcripts, flags, orders and analyses — including private ones — accessed for support, moderation, safety and abuse investigation. Connect chat is not an encrypted or confidential channel.
    • Internal record identifiers are replaced by short reference codes in anything shown to you or to others.

    7. How long we keep data

    • Audio, stems and saved analyses: retained for as long as your account is active, so you can revisit them and so we need not re-run paid processing. They are deleted when you delete an analysis or your account, or on request. If we introduce subscription plans with defined storage windows in future, those limits will be disclosed before they apply to you.
    • Account and profile data: until you delete your account.
    • Community contributions: until you delete them or your account is closed; anonymised aggregate counts may remain.
    • Connect requests and chat messages: kept while the accounts involved remain active, so the conversation stays available to both members; removed when an account is permanently deleted after its cooling-off period.
    • Orders, invoices and credit ledger: retained for the period required by Indian tax and accounting law (generally eight years) even after account deletion.
    • Support-chat transcripts and lead details: retained for up to 24 months for support quality and dispute handling, then deleted or anonymised. Guest verification codes are short-lived and expire within minutes.
    • Copyright screening results and moderation records: retained while the related content or account record exists, and for up to 24 months after a block or closure so repeat abuse can be identified.
    • Visitor and device analytics: retained in aggregate; individual device rows are kept for up to 24 months.
    • Security and error logs: typically up to 12 months.

    8. Your rights and choices

    • Access and portability — request a copy of the personal data we hold about you.
    • Correction — edit your profile directly at /profile, or ask us.
    • Deletion — delete individual analyses and comments yourself, or ask us to delete your account and its data. Unused credits are forfeited on deletion and are not refunded.
    • Withdraw consent — revoke microphone access in your browser, or switch public analyses back to private, at any time.
    • Directory and notifications — switch your Connect directory listing on or off in your profile (it is off by default), and choose which bell and email alerts you receive under Settings → Notifications.
    • Object or restrict — object to processing based on our legitimate interests.
    • Complain — escalate to our Grievance Officer (below), or to the data protection authority in your jurisdiction.

    Write to admin@workolo.com to exercise a right. We respond within 30 days and may ask you to verify your identity.

    9. Email communication

    Service emails (sign-up confirmation, password reset, payment receipts, order and support updates) are necessary to operate your account and cannot be opted out of while the account exists.

    Notification emails — comment replies, mentions, forum activity, Connect requests — follow the switches you set under Settings → Notifications.

    We may also send campaign and announcement emails about the Service. Some of these contain images generated by AI for illustration. Every campaign email carries a one-click unsubscribe link which we honour, and unsubscribing does not affect the service emails above. Emails are sent from noreply@raagfinder.com with replies going to admin@workolo.com.

    10. Security

    We use encrypted transport (HTTPS), row-level access controls so records are readable only by their owner, time-limited signed URLs for stored audio, hashed passwords managed by our authentication provider, human verification on authentication forms, and restricted administrator access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

    11. Children

    The Service is not directed to children. Account holders must be 18 or older. If we learn that we hold data of a child collected without an adult account holder's involvement, we will delete it. Contact admin@workolo.com to report such a case.

    12. International transfers

    Our providers operate globally, so your data — including audio submitted for AI processing — may be stored or processed outside India. We rely on the contractual protections offered by those providers and transfer only what is needed for the purposes described here.

    13. Breach notification

    If a personal data breach is likely to cause you significant risk, we will notify affected users and the relevant authority without undue delay, describing what happened, the likely consequences and the steps taken.

    14. Changes to this policy

    We may update this policy as the Service evolves. The "Last updated" date will change and material changes will be notified by email or an in-app notice.

    15. Contact and Grievance Officer

    General and privacy queries: admin@workolo.com

    Nidheesh Gopalan, Grievance Officer
    nidheesh@workolo.com
    Workolo Entertainments, 191/6, Lamech Street, Janaki Nagar, Valasaravakkam, Chennai 600087, Tamil Nadu, India
    +91-4443300011