Anocturne

Privacy Policy

Effective 19 August 2026.

Anocturne is a workspace for music artists, operated by [LEGAL ENTITY] ("we", "us"). This policy explains what we collect, why, who else sees it, and what you can ask us to do about it. It describes how the product actually behaves, not what a template says it might.

The short version

We collect what the product needs to work and nothing for advertising. We run no analytics, no advertising technology, and no third-party trackers of any kind. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never see your card number.

What we collect

Your account. Your email address, and your name if you give one. If you set a password we store only a bcrypt hash of it, never the password itself. If you sign in with Google we store Google's account identifier so we can recognise you on your next visit. We also store your preferences: theme, board layout, default reminder lead time, your craft role, and your country.

What you create in the app. Projects, tasks, notes, lyrics and drafts, contacts, quotes and invoices, expenses, gear, portfolio entries, bookings, community posts, and content-planner entries. This is your working material and we treat it as private to you and to the people you share it with.

Wellbeing entries. Mood check-ins and reflection entries, if you use those features. These are personal by nature. They are visible only to you, they are never shown to other members, and they are never used for anything other than displaying them back to you.

Files you upload. Audio, images, documents and other assets, along with their file names and sizes.

Payment records. If you subscribe, we store your Stripe customer and subscription identifiers, your plan, billing cycle, status and renewal date. We never receive or store your card number, expiry, or security code — payment details are entered on Stripe's own hosted checkout and stay with Stripe.

Sign-in security records. For each sign-in attempt we record the email address that was entered, whether it succeeded, the time, and the IP address. This exists to detect brute-force attacks on accounts. Note that this includes failed attempts, so an email address typed in error can appear in these records even if it has no account.

Push notification subscriptions. If you turn on desktop or mobile notifications, your browser gives us an endpoint URL and two keys that let us deliver a notification to that specific browser. Turning notifications off removes it.

Google Calendar and Google Drive, only if you connect them. These integrations request read-only access (calendar.readonly and drive.readonly). We can read; we cannot create, modify or delete anything in your Google account. We store the access and refresh tokens so the connection survives. You can disconnect at any time in Settings, or revoke access from your Google account's security page.

Cookies

We use two cookies, both strictly necessary, both httpOnly so they cannot be read by scripts in the page:

There are no analytics, advertising, or tracking cookies, which is why you are not asked to accept any.

AI features

When you use the project advisor or the assistant, the text you type is sent to Anthropic's API to generate a response. Only the text you type is sent, together with a fixed instruction telling the model what kind of help to give — not your project database, not your files, and not other people's material. Under Anthropic's commercial API terms, inputs sent through the API are not used to train their models. Treat AI output as a suggestion to check, never as professional advice.

Who else processes your data

We use a small number of service providers. Each one only receives what it needs to do its job:

| Provider | What it handles | |---|---| | Vercel | Hosting and delivery of the application | | Supabase | The primary database | | Cloudflare R2 | Storage of the files you upload | | Stripe | Subscription payments and billing | | Resend | Transactional email — password resets, invites, notifications | | Google | Calendar and Drive, only if you connect them | | Anthropic | AI features, only for the text you type into them |

We do not sell your personal information to anyone, and we do not share it with advertisers.

Where things are public

Some parts of the product are public by design, and only when you choose to use them: your public portfolio page, community posts in a community you have joined, and any share link you generate. A share link is a secret URL — anyone who has the link can open it, so treat it as you would a password.

Where your data lives

Anocturne is operated from the United States and the services we rely on store data in [PRIMARY DATA REGION]. Some of our processors operate globally and may process limited data outside that region in the course of running their service.

If you are in the UK, EU or EEA, that means your personal data may be transferred outside your country. Where it is, the transfer is covered by the European Commission's Standard Contractual Clauses, or by the processor's certification under the EU-US Data Privacy Framework where they hold one. Each processor in the table above operates under a data processing agreement that includes those safeguards. You can ask us for the details of any of them.

How long we keep things

We keep your account and its contents for as long as your account exists. Sign-in and security records are kept for 12 months. Backups may retain deleted material for up to 35 days after deletion before they age out. Records we are required to keep for tax or accounting purposes — invoices and payment records — are kept for seven years, because the law requires it and your deletion request cannot override that.

Your rights, and how to use them

You can ask us to give you a copy of your data, correct it, export it, or delete it. We will not treat you differently for exercising any of these.

If you are in the UK, EU or EEA, the GDPR gives you the right to: access your data; have it corrected; have it erased; restrict how we process it; object to processing carried out on the basis of our legitimate interests; receive it in a portable, machine-readable form; and withdraw any consent you have given, at any time, without that affecting anything done before you withdrew it. You also have the right to complain to your data protection authority — in the UK the Information Commissioner's Office, and in the EU the authority for the country you live in.

The legal bases we rely on are: performing our contract with you (running your account and the Service); our legitimate interests (keeping the Service secure, preventing abuse, and improving it); your consent (marketing email and push notifications, each of which you can withdraw); and compliance with legal obligations (tax and accounting records).

If you are in California, the CCPA gives you the right to know what personal information we collect, use and disclose; to have it deleted; to correct it; to receive it in a portable form; and not to be discriminated against for asking. The categories we collect are set out in "What we collect" above: identifiers (name, email), commercial information (your subscription and payments), internet activity (sign-in and usage records), and the content you upload. We disclose those categories only to the processors named above, and only so they can run the Service for us. We do not sell your personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to offer — but you may still ask us to delete or disclose, and an authorised agent may make a request on your behalf if you give them written permission.

There is currently no self-serve delete button in the app. To delete your account, email [PRIVACY EMAIL] from the address on the account and we will delete it, and the content in it, within 30 days.

Children

Anocturne is not intended for anyone under 16, and we do not knowingly collect information from anyone under 16. If you believe a child has given us personal information, email us and we will remove it.

Security

Passwords are hashed with bcrypt. Traffic is encrypted in transit over TLS. Files and database contents are encrypted at rest by our storage providers. Session and gate cookies are httpOnly and, in production, secure. Share links are unguessable tokens with an expiry you choose — but a share link is a secret URL, so anyone you send it to can pass it on. No system is perfectly secure, and we will not claim otherwise.

If there is a breach. If personal data is exposed in a way that is likely to put you at risk, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will tell affected people directly, without undue delay, by email and in the product. We will say what happened, what data was involved, what we have done about it, and what you should do. We will not wait until we have every answer before telling you.

Changes to this policy

If we change this policy in a way that materially affects you, we will say so in the product rather than quietly editing the page. The effective date at the top always reflects the current version.

Contact

Questions, requests, or complaints: [PRIVACY EMAIL], or by post at [POSTAL ADDRESS].

Privacy Policy · Terms of Service