coproducer — Privacy Policy
Short version: we collect the minimum needed to run a music studio in your browser, we never sell your data, and your music is not used to train AI. Analytics — and any advertising that may one day support the free plan — run only with your consent via the cookie banner. The detail follows.
What we collect
- Account: a username and a password (stored only as a salted scrypt hash — we cannot read it), or, if you sign in with Google, Discord, Facebook, X, Reddit, Spotify, Twitch or GitHub, the name, account id and (where the provider shares it) email address they give us. We never see your password for those services.
- Taste preferences: if you fill in the welcome wizard — genres, experience level, goals, reference artists — so the AI can make better musical choices for you. All optional.
- Usage counts: how many AI requests your account makes per day and month, to enforce plan limits. We do not keep a log of what you asked.
- Billing: payments are processed by Stripe. We never see or store card numbers — we keep only your plan, a Stripe customer reference, and subscription status.
- Launch list: if you leave your email on the homepage, we store that address, and use it only to tell you about coproducer.
- Cookies: one essential cookie keeps you signed in — it always runs and needs no consent. Any non-essential cookies (analytics, and advertising if it ever arrives — see the next section) run only if you chose "Accept all" on the cookie banner. You can change your mind by clearing the site's data in your browser, which brings the banner back.
Analytics and advertising
We use, or may introduce, Google Analytics to understand how the site and studio are used — page views, feature usage, rough geography. It runs only for visitors who accepted non-essential cookies, and we configure it without advertising features and with IP anonymisation where available. It never sees your music, your prompts, or your projects.
The free Bedroom plan may in future be supported by advertising. If that happens we'll update this policy first, ads will be clearly marked, any advertising cookies will sit behind the same consent banner, and paid plans will stay ad-free.
Your music and your audio
Your projects — songs, samples, the records you open — live in your browser and in project files saved to your device. When you ask coproducer to analyse or extract from an audio file, that audio is processed on our servers to do the job you asked for, and the results come back to your browser; we don't build a server-side library of your music and we don't use your audio or prompts to train AI models.
Who else touches data, and why
- AI model providers (Google Gemini and Groq, or a provider whose API key you supply): your instructions and the musical document they act on are sent to them to generate the response. These providers are located overseas (primarily the United States) and handle that data under their own terms.
- Railway hosts our servers and storage.
- Stripe processes payments.
- Resend delivers our emails (receipts, password resets).
- Google Analytics (consent-gated, as above) measures site usage.
We share data with these processors only as needed to run the service, and with nobody else — no data sales. We would disclose data if the law genuinely required it.
How it's protected
All traffic is encrypted in transit (HTTPS). Passwords are salted and hashed with scrypt. API keys you store with us are encrypted at rest with AES-256-GCM and are write-only — they can't be read back out through the interface, only replaced or removed. Access to server infrastructure is limited to the operator.
Your rights
You can see and change your preferences in the app, close your account (in the app or by emailing us) — which deletes your server-side account data — and ask us what we hold about you or ask for it to be corrected or deleted: hello@coproducer.pro. We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). If you're unhappy with how we've handled your data, contact us first and we'll do our best to fix it; you can also complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Data breach and changes
If a breach ever puts your data at risk we'll notify affected users and the OAIC as the Notifiable Data Breaches scheme requires. If this policy changes materially we'll note it here and flag it in the app.