# Privacy Policy (Draft)

**Last updated:** September 7, 2026  
**Status:** Draft for counsel review — do not publish until [AV-T22](../mvp/TODO.md) sign-off.

> Adapted from the [Basecamp open-source policies](https://github.com/basecamp/policies) / [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Modified for Audio Vault and [DECISIONS.md](../mvp/DECISIONS.md).

**Controller:** Muse & Machine LLC (“we”, “us”)  
**Service:** Audio Vault at https://audiovau.lt  
**Contact:** privacy@audiovau.lt *(placeholder until mailbox confirmed)*

We do not sell your personal information.

## Private Library Model

Audio Vault stores **your** music for **your** use only. We do **not** expose your audio files to other subscribers, to anonymous visitors, or to the public internet through product features such as share links, embeds, or shared playlists. Playback and download authorization are scoped to **your account** (and devices you explicitly pair to it). We do not use your uploads to populate a catalog for other users or for any form of public distribution.

## What We Collect and Why

### Account and Identity

When you sign up, we collect your email address, password hash (or passkey credentials), and optional profile fields you provide. We use this to authenticate you, operate your library, send account and billing notices, and respond to support requests.

### Billing

Paid plans are processed by **Stripe**. Card numbers are submitted to Stripe and are not stored on our servers. We retain subscription status, plan identifiers, and limited billing metadata needed for invoices, tax, fraud prevention, and support.

### Your Music Library and Uploads

We store the audio files and sidecar files you upload, folder paths, upload manifests, checksums, and catalog metadata you edit. We use this solely to provide **private** storage, **owner-only** playback authorization, recovery, and library browsing **for your account**. **We do not transcode, downsample, or rewrite embedded tags in your audio files.** We do **not** make your music browsable or playable by other users.

### Metadata Identification (Optional)

When enabled, we may send **filenames, embedded tags, and audio fingerprints** to **AcoustID** and **MusicBrainz** to suggest catalog metadata. Default consent: a link to this policy at signup ([D-73](../mvp/DECISIONS.md#metadata-and-privacy)). You may disable auto-match; manual edits always win.

### Technical Logs

We log IP addresses, browser type, request timestamps, and error diagnostics for security, abuse prevention, rate limiting, and reliability. Login failure and API rate limits follow [CONFIG.md](../mvp/CONFIG.md) defaults.

## Subprocessors

We use service providers to run Audio Vault, including:

| Provider | Purpose | Location (typical) |
|---|---|---|
| **Cloudflare R2** | Private object storage for customer audio | United States (US jurisdiction) |
| **Servarica** (or successor VPS host) | Go API and PostgreSQL | As configured |
| **Stripe** | Payments and subscription billing | United States / global |
| **Resend** | Transactional auth email (magic links, password reset) | United States / global |
| **AcoustID / MusicBrainz** | Optional metadata identification | Third-party APIs |
| **Sentry / observability vendors** | Error and uptime monitoring | As configured |

We will maintain a published subprocessor list before go-live.

## When We Access or Share Information

- **To provide your private library** (upload, **your** playback, billing, recovery) — never to publish your music to others through the service.
- **With subprocessors** under contract, only as needed to operate the service (for example, storing encrypted objects in private storage). Subprocessors do **not** receive a license to distribute or publicly perform your music.
- **For abuse and security**, including investigating violations of our [Content Policy](content-policy.md) (such as account compromise or attempts to expose music outside your account).
- **When required by law**, such as valid legal process. We notify affected users when legally permitted.
- **Never for sale** of personal information to data brokers.
- **Never** to enable other subscribers or the public to access your music through Audio Vault.

## Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. When you delete your account, we **cancel your Stripe subscription first**, then begin a **30-day soft-delete period** before purge ([D-82](../mvp/DECISIONS.md#retention-and-account-lifecycle), [D-134](../mvp/DECISIONS.md#retention-and-account-lifecycle)). Trash items remain recoverable for **30 days** and count toward storage quota ([D-80](../mvp/DECISIONS.md#retention-and-account-lifecycle)–[D-81](../mvp/DECISIONS.md#retention-and-account-lifecycle)).

**Data export:** There is **no** self-service or email export until **public beta** ([D-120](../mvp/DECISIONS.md#legal-policies-and-accessibility)). We will add export options when beta launches; until then contact **privacy@audiovau.lt** only for privacy-rights requests not tied to a full library export workflow.

Contact **privacy@audiovau.lt** to exercise other privacy rights. We may verify your identity before responding.

## International Transfers

Audio Vault is operated from the **United States**. If you access the service from the EU, UK, Norway, or elsewhere, your information may be transferred to and processed in the US. We will use appropriate safeguards (such as Standard Contractual Clauses) where required — **to be confirmed by counsel**.

## Security

We encrypt data in transit (TLS). Customer audio is stored in private object storage, not on the public website apex. See operational security documentation before go-live.

## Backup and Recovery

We maintain database backups on a published schedule for disaster recovery. Customer-facing recovery expectations (RPO/RTO, what is and is not backed up) are documented in [BACKUP-RESTORE.md](../BACKUP-RESTORE.md). Backups protect catalog and account metadata; your music files remain in private object storage with separate durability controls.

## Children

Audio Vault is not directed to children under 13 (or higher age where local law requires). We do not knowingly collect data from children.

## Changes

We will update this policy when practices or law change. Material changes will be announced on the site and, where appropriate, by email.

## Questions

Email **privacy@audiovau.lt** or write to Muse & Machine LLC at the business address on file *(counsel to supply)*.
