Privacy Policy

Last updated: September 7, 2026
Status: Draft for counsel review — do not publish until AV-T22 sign-off.

Adapted from the Basecamp open-source policies / CC BY 4.0. Modified for Audio Vault and DECISIONS.md.

Controller: Muse & Machine LLC (“we”, “us”)
Service: Audio Vault at https://audiovau.lt
Contact: support@audiovau.lt (D-156) (counsel review still required before publication — AV-T22)

We do not sell your personal information.

Private Library Model

Audio Vault stores your music for your use only. We do not expose your audio files to other subscribers, to anonymous visitors, or to the public internet through product features such as share links, embeds, or shared playlists. Playback and download authorization are scoped to your account (and devices you explicitly pair to it). We do not use your uploads to populate a catalog for other users or for any form of public distribution.

What We Collect and Why

Account and Identity

When you sign up, we collect your email address, password hash (or passkey credentials), and optional profile fields you provide. We use this to authenticate you, operate your library, send account and billing notices, and respond to support requests.

Billing

Paid plans are processed by Stripe. Card numbers are submitted to Stripe and are not stored on our servers. We retain subscription status, plan identifiers, and limited billing metadata needed for invoices, tax, fraud prevention, and support.

Your Music Library and Uploads

We store the audio files and sidecar files you upload, folder paths, upload manifests, checksums, and catalog metadata you edit. We use this solely to provide private storage, owner-only playback authorization, recovery, and library browsing for your account. We do not transcode, downsample, or rewrite embedded tags in your audio files. We do not make your music browsable or playable by other users.

Metadata Identification (Optional)

When enabled, we may send filenames, embedded tags, and audio fingerprints to AcoustID and MusicBrainz to suggest catalog metadata. Default consent: a link to this policy at signup (D-73). You may disable auto-match; manual edits always win.

Technical Logs

We log IP addresses, browser type, request timestamps, and error diagnostics for security, abuse prevention, rate limiting, and reliability. Login failure and API rate limits follow CONFIG.md defaults.

Subprocessors

We use service providers to run Audio Vault, including:

Provider Purpose Location (typical)
Cloudflare R2 Private object storage for customer audio United States (US jurisdiction)
Servarica (or successor VPS host) Go API and PostgreSQL As configured
Stripe Payments and subscription billing United States / global
Resend Transactional auth email (magic links, password reset) United States / global
AcoustID / MusicBrainz Optional metadata identification Third-party APIs
Sentry / observability vendors Error and uptime monitoring As configured

The table above is our current subprocessor list as of the last updated date. We will notify account holders of material changes before they take effect.

When We Access or Share Information

Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. When you delete your account, we cancel your Stripe subscription first, then begin a 30-day soft-delete period before purge (D-82, D-134). Trash items remain recoverable for 30 days and count toward storage quota (D-80D-81).

Data export: There is no self-service or email export until public beta (D-120). We will add export options when beta launches; until then contact support@audiovau.lt only for privacy-rights requests not tied to a full library export workflow.

Contact support@audiovau.lt to exercise other privacy rights. We may verify your identity before responding.

International Transfers

Audio Vault is operated from the United States. If you access the service from the EU, UK, Norway, or elsewhere, your information may be transferred to and processed in the US. We will use appropriate safeguards (such as Standard Contractual Clauses) where required — to be confirmed by counsel.

Security

We encrypt data in transit (TLS). Customer audio is stored in private object storage, not on the public website apex. See operational security documentation before go-live.

Backup and Recovery

We maintain database backups on a published schedule for disaster recovery. Customer-facing recovery expectations (RPO/RTO, what is and is not backed up) are documented in BACKUP-RESTORE.md. Backups protect catalog and account metadata; your music files remain in private object storage with separate durability controls.

Children

Audio Vault is not directed to children under 13 (or higher age where local law requires). We do not knowingly collect data from children.

Changes

We will update this policy when practices or law change. Material changes will be announced on the site and, where appropriate, by email.

Questions

Email support@audiovau.lt or write to Muse & Machine LLC at 5831 Forward Ave, Suite #360, Pittsburgh, PA 15217 (principal place of business per config/us_entity.json; counsel review before publication).