The licence audit behind our key and BPM detection
When we chose which stems to ship, the deciding question was not which model scored best but which ones we were allowed to sell. Key and BPM detection turned out to be the same story, with two new twists: a licence that reaches through a network connection, and a package name that belonged to someone else.
The rule
Every model we ran sat on an allowlist, and anything not on it was refused. We used an allowlist rather than a blocklist on purpose: a blocklist would let the next better-scoring model in by default, before anyone had read its licence. The analysis models got their own list, separate from the separation models, because "cleared to separate audio" and "cleared to detect a key" are different questions.
madmom: open code, non-commercial weights
madmom is a long-standing, well-regarded library for beat and tempo tracking, and its source code is BSD-licensed. But the licence on the code is not the licence on the trained models. Every pre-trained model file madmom ships is CC-BY-NC-SA 4.0 — the "NC" is NonCommercial. A paid service cannot use them under that grant.
This is the same shape as the models we left out of stem separation at the time: code you can read freely, weights you cannot sell. Checking the code licence and stopping there is the most common way to get this wrong.
Essentia: a licence that follows the network
Essentia is AGPL-3.0. Ordinary GPL obligations are triggered by distributing software, and running it on your own server to return a result is generally not distribution. The AGPL was written to close exactly that gap: it extends to software offered to users over a network. For a hosted API, it would apply. A commercial licence exists; its price is not published.
What we use: two MIT models, checked at source
Tempo is Beat This! (Foscarin, Schlüter & Widmer, CPJKU). Its project metadata declares MIT, and its README states that the code and the published model weights are released under the MIT licence — the weights clause is the one that matters, and it is explicit. The README also notes that some training material was copyrighted and leaves that assessment to the user; we record that as a provenance note, not a licence defect.
Key is S-KEY (Kong et al., Deezer), MIT, with the licence file carried alongside our copy of the code.
MIT asks for one thing in return: credit. Both models are credited in the footer of every page on this site, next to each tempo and key we show you, and in our API documentation — the same way the separation model's authors are credited, and as a licence condition, not a courtesy.
The package that was not the package
The obvious way to use S-KEY would be to install it by name. On PyPI, the package called skey is not Deezer's: it is an unrelated project with no files in it. Installing by name would have pulled a stranger's package into our production image.
So we vendored the model instead — about 190 lines of model definition plus a 748 KB checkpoint, pinned to a specific upstream commit with the checkpoint's hash recorded, and the MIT licence file copied verbatim. MIT permits exactly that. It also let us write our own inference call, because the packaged one discards the model's scores and keeps only its top answer, which left nothing to measure confidence with.
What this costs us
Probably some accuracy we cannot legally have. We have not benchmarked the excluded models against the ones we run, and we do not claim ours are the best available — only that they are the best we measured among the ones we can sell, and that we measured them.
Try the vocal remover
Upload a song and hear a free 60-second preview of all six stems. No account needed.
Remove vocals free