This Privacy Policy describes how EasyDAW collects, uses, and protects the personal information of individuals who use the Service. This policy is written to be consistent with, among others, the California Consumer Privacy Act (CCPA/CPRA) and general U.S. privacy law. It does not extend rights beyond what applicable law grants you.
1. Information We Collect
1.1 Information you provide directly
- Account data. Email address, display name, password (stored only as a bcrypt hash — we cannot recover it), avatar color.
- Project data. Project names, tempos, time signatures, tracks, clips, MIDI notes, effect parameters, comments, and any audio you upload.
- Consent record. Timestamp and document version at which you accepted these Terms and this Privacy Policy.
- Support conversations. Feedback you submit via the in-app widget or by email.
- Payment data. Handled by Stripe. EasyDAW sees only the last four digits of your card and a Stripe customer identifier — never the full card number, CVV, or expiration date.
1.2 Information collected automatically
- Session cookies. An httpOnly access token (
cd_access) and refresh token (cd_refresh). These are set on the domain you connect from and are used purely for authentication. - Error telemetry. Application errors and warnings are forwarded to Sentry (a third-party error monitoring service) to help us diagnose bugs. Sentry records the browser type, URL path, and a stack trace. It does not receive your project audio.
- Usage counters. We record the count and category of your AI requests each day for quota enforcement (e.g. “user X made 12 mix-coach requests today”) — we do not record the content of the request.
2. How We Use Your Information
- To operate the Service — store your projects, sync your edits, deliver AI suggestions, process payments.
- To deliver transactional email (verification, password reset, billing receipts) via Resend.
- To enforce plan limits and prevent abuse.
- To respond to your support requests.
- To improve the Service through aggregated, non-identifying usage statistics.
We do not: sell your personal information, share it with data brokers, use your audio to train generative AI models (without your separate opt-in consent), or run behavioral advertising.
3. Third Parties That Receive Your Data
- Stripe, Inc. — payment processing. Stripe Privacy Policy.
- Anthropic, OpenAI, and Google (Claude / GPT / Gemini). — When you use the AI Coach or Chord Assistant, the extracted features of your session (RMS levels, spectral centroid, transients per second, key hint, etc.) are sent to the LLM provider on your behalf. Raw audio is not sent.
- Cloudflare R2 — storage of uploaded audio assets.
- Resend — outbound transactional email.
- Sentry (Functional Software, Inc.) — error monitoring.
- MongoDB Atlas / self-hosted MongoDB — primary database.
[Attorney review]This list must remain accurate; every time a new sub-processor is added it should be reflected here and existing users notified per applicable state law (e.g. California's CPRA disclosure requirements).
4. How Long We Keep Your Data
- Active account data is kept for as long as your account is active.
- After account closure we retain project data for up to 30 days to allow recovery, then permanently delete.
- Billing records (invoices, subscription history) are retained for at least 7 years to comply with U.S. tax and financial recordkeeping requirements.
- Anonymized aggregate usage counts may be retained indefinitely.
5. Security
- Passwords are stored as bcrypt hashes with per-user salts.
- Session tokens use httpOnly and Secure cookies over HTTPS.
- Passcode-protected share links store only bcrypt hashes of your passcode — we cannot see it.
- All traffic between your browser and the Service is served over HTTPS. Sub-processors similarly use encryption in transit.
- Access to production infrastructure is restricted to authorized personnel.
No system is perfectly secure. If we suffer a security incident that affects your data we will notify you promptly, consistent with U.S. state breach-notification laws.
6. Your Rights
Depending on your jurisdiction you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and associated data.
- Export a copy of your projects (available today via File → Export).
- Opt out of the sale or sharing of personal information — EasyDAW does not sell or share personal information for cross-context behavioral advertising, so this right is effectively met by default.
To exercise any right, email Josiah.Genesis@gmail.com from the address on your account. We will respond within 30 days.
7. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If we learn we have collected such information we will delete it.
8. International Users
EasyDAW operates from the United States. If you access the Service from outside the U.S., you consent to the transfer and processing of your information in the U.S.
[Attorney review]If you plan to actively market to EU/UK residents you must add a GDPR/UK-GDPR Article 13/14 disclosure block, a lawful-basis mapping, and an EU representative. Deferred for U.S.-first launch.
9. Changes to This Policy
Material changes are signaled by a version bump at the top of this page and, where practical, an in-app re-consent request. We keep prior versions available on request.
10. Contact
Privacy questions or requests: Josiah.Genesis@gmail.com.