This Privacy Policy describes how easy-daw collects, uses, and protects the personal information of individuals who use the Service. This policy is written to be consistent with, among others, the California Consumer Privacy Act (CCPA/CPRA) and general U.S. privacy law. It does not extend rights beyond what applicable law grants you.
1. Information We Collect
1.1 Information you provide directly
- Account data. Email address, display name, password (stored only as a bcrypt hash — we cannot recover it), avatar color.
- Project data. Project names, tempos, time signatures, tracks, clips, MIDI notes, effect parameters, comments, and any audio you upload.
- Consent record. Timestamp and document version at which you accepted these Terms and this Privacy Policy.
- Support conversations. Feedback you submit via the in-app widget or by email.
- Payment data. Handled by Stripe. easy-daw sees only the last four digits of your card and a Stripe customer identifier — never the full card number, CVV, or expiration date.
1.2 Information collected automatically
- Session cookies. An httpOnly access token (
cd_access) and refresh token (cd_refresh). These are set on the domain you connect from and are used purely for authentication. - Error telemetry. Application errors and warnings are forwarded to Sentry (a third-party error monitoring service) to help us diagnose bugs. Sentry records the browser type, URL path, and a stack trace. It does not receive your project audio.
- Usage counters. We record the count and category of your AI requests each day for quota enforcement (e.g. “user X made 12 mix-coach requests today”) — we do not record the content of the request.
2. How We Use Your Information
- To operate the Service — store your projects, sync your edits, deliver AI suggestions, process payments.
- To deliver transactional email (verification, password reset, billing receipts) via Resend.
- To enforce plan limits and prevent abuse.
- To respond to your support requests.
- To improve the Service through aggregated, non-identifying usage statistics.
We do not: sell your personal information, share it with data brokers, use your audio to train generative AI models (without your separate opt-in consent), or run behavioral advertising.
3. Third Parties That Receive Your Data
- Stripe, Inc. — payment processing. Stripe Privacy Policy.
- Anthropic, OpenAI, and Google (Claude / GPT / Gemini). — When you use the AI Coach or Chord Assistant, the extracted features of your session (RMS levels, spectral centroid, transients per second, key hint, etc.) are sent to the LLM provider on your behalf. Raw audio is not sent.
- Cloudflare R2 — storage of uploaded audio assets.
- Resend — outbound transactional email.
- Sentry (Functional Software, Inc.) — error monitoring.
- MongoDB Atlas / self-hosted MongoDB — primary database.
This list reflects every sub-processor we use today. It is updated the moment we adopt a new one — check back here, or ask us, if you need the current list for your own compliance records.
4. How Long We Keep Your Data
- Active account data is kept for as long as your account is active.
- After account closure we retain project data for up to 30 days to allow recovery, then permanently delete.
- Billing records (invoices, subscription history) are retained for at least 7 years to comply with U.S. tax and financial recordkeeping requirements.
- Anonymized aggregate usage counts may be retained indefinitely.
5. Security
- Passwords are stored as bcrypt hashes with per-user salts.
- Session tokens use httpOnly and Secure cookies over HTTPS.
- Passcode-protected share links store only bcrypt hashes of your passcode — we cannot see it.
- All traffic between your browser and the Service is served over HTTPS. Sub-processors similarly use encryption in transit.
- Access to production infrastructure is restricted to authorized personnel.
No system is perfectly secure. If we suffer a security incident that affects your data we will notify you promptly, consistent with U.S. state breach-notification laws.
6. Your Rights
Depending on your jurisdiction you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and associated data.
- Export a copy of your projects (available today via File → Export), your full account data, and your AI activity log (available today, self-service, from Account → Privacy & Data).
- Opt out of the sale or sharing of personal information — easy-daw does not sell or share personal information for cross-context behavioral advertising, so this right is effectively met by default.
Correction and deletion requests are submitted from the same Account → Privacy & Data page and reviewed by a human — we don't auto-delete a collaborative project shared with other users without checking it first. You can also email Josiahgenesis@easy-daw.com from the address on your account. We respond within 30 days.
7. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If we learn we have collected such information we will delete it.
8. International Users
easy-daw operates from the United States and the Service is directed at users in the United States today. If you access the Service from outside the U.S., you consent to the transfer and processing of your information in the U.S.
easy-daw does not currently market to or target residents of the EU/UK. If that changes, this section will be updated with the GDPR/UK-GDPR-specific disclosures (lawful basis, EU representative, Article 13/14 notices) those residents are entitled to.
9. Changes to This Policy
Material changes are signaled by a version bump at the top of this page and, where practical, an in-app re-consent request. We keep prior versions available on request.
10. Contact
Privacy questions or requests: Josiahgenesis@easy-daw.com.