Privacy Policy
The short version: nothing about your music leaves your machine unless you turn on Vault backup.
Early access. This is the current privacy policy for Sessions,
written in plain language. A lawyer's review is planned; any changes will be posted on this page.
Sessions is made by Saltado LLC (Texas, USA). This policy explains what the app does and doesn't do with your data. Questions go to [email protected].
- Sessions runs entirely on your computer. Your projects, samples, plugin lists, notes and everything else it catalogs are stored in a local database on your device.
- Sessions does not upload your files, your library, or any analytics about your music anywhere. The one exception is Vault backup, described below: it is a separate subscription, it is off until you switch it on, and it only ever carries the folders you tick.
- The only network calls the app makes are: (1) license key activation and validation with our payment provider, when you enter a key, and quietly in the background afterwards (at startup and about once a day) to keep your license current; (2) checking for and downloading app updates; (3) sending a problem report, only when you press Send, and containing only what was shown to you on screen first; (4) researching a label, only if you subscribe to Sessions A&R and only at the moment you click research on a label; (5) backing your work up to the Vault, only if you subscribe, only once you switch it on, and only the folders you tick; and (6) asking the help assistant a question, only when you press send, and carrying only what you typed. Neither (1) nor (2) carries data about your music: call (1) sends your license key, a seat identifier, and your app version to the payment provider; call (2) sends your app version to our update server and on to GitHub for the download, never your license key.
- Label research sends a label's name or a genre, and nothing else. If you subscribe to Sessions A&R and click research on a label, or ask it to find labels for a genre, that name or genre and your subscription key go to our research service so it can look it up. The service does the research with Claude, an AI model made by Anthropic, which searches the web for it: the label name or genre is passed to Anthropic for that purpose, on its own, with nothing that identifies you (not your key, not your account, not your address). Your projects, your notes, your ratings, your submission history and the rest of your label book never leave your machine. Results are written into your own copy of the book and stay there, including if your subscription lapses. Don't subscribe, and this call never happens.
- Help assistant. If you ask the help assistant a question (the Help button on this site or in the app), your question and the conversation it belongs to are sent to our help service, which produces the answer with Claude, a model from Anthropic. The conversation is used only to answer you: we do not store it, and nothing identifying you is sent with it. The assistant cannot see your account, your library, or your files. Please do not type personal information into it. If you use the Send a message tab on this site instead, we do keep that message, and the reply address if you give one, so we can read it and answer: it goes to our own message box, not to the AI.
- Vault backup is off until you turn it on. The Vault is an optional paid service that keeps a copy of your studio off your machine. Nothing goes anywhere until you subscribe, switch it on and tick the folders you want kept. After that, the app talks to the backup service only when a backup runs, when you browse your backup, or when you make a share link. The service runs on Cloudflare, so like any web request it reveals your IP address to them and to us, and they may log it under their own privacy policy.
- Standard backup: we can read what you back up. This is the default. Your files travel over an encrypted connection and are stored encrypted on disk, but we hold the keys, so the service can open them and read what is inside. That is not an oversight, it is what the rest of the feature is built on: browsing your backup in a web page, downloading a file, playing a bounce, zipping a folder and sending someone a share link all need the server to read the actual bytes. For the same reason your file names, folder names, file sizes and the name of your computer are stored as plain readable text. If you would rather we could not, mark the folder private.
- We can, and we don't. Being able to read a standard backup is a capability, not a habit. We do not open, view or analyse your files, and no screen we operate shows us their names or their contents: our own dashboards see only totals, like how much space an account uses. Reading a customer's files would take a deliberate act against this policy, and this policy is the promise that we will not take it. The one way to make your work unreadable to us as a matter of mathematics rather than policy is the paragraph below.
- Private folders: we cannot read them, and we cannot help you if you lose the passphrase. You can mark any folder private. It is encrypted on your computer with a passphrase you choose, before a single byte leaves it. We cannot read the contents of a private folder, and we cannot read its file names either: all the service can see is the total size and how many files there are. The trade is real. If you lose the passphrase and the recovery code we print for you, those files cannot be opened again by anyone, including us. There is no reset link and no support request that can undo it. Private folders also cannot be browsed on the web, downloaded in a browser or shared by link, because none of that is possible without reading them.
- A share link is a key to whatever it points at. If you create one, anyone holding that link can open, play and download what you shared, with no account and no sign-in, until the link expires or you switch it off. Treat it like handing someone the file. We store only a one-way fingerprint of each link, never the link itself, so a copy of our database hands nobody a working link, and so we cannot show you a link again after you make it or recover one you have lost. Make a new one instead.
- What the Vault keeps, and for how long. A copy of a file stays as long as one of your backups still points at it. When none does (you deleted the file, or saved over it) the old copy is kept for 30 days and then deleted for good, which is what lets you get yesterday's version back. If your subscription lapses nothing is wiped: your backup stays readable for 30 days on the monthly plan or a full year on the yearly plan, and the copies on your own computer are never touched. You can delete everything in your Vault at any time, whatever state your subscription is in, and that erases the files themselves, not just your access to them.
- Problem reports are never sent on their own. Nothing is transmitted
unless you press Send, and the full contents are displayed before you do. A report contains
recent error messages, your app version, and simple counts, how many projects,
samples, library items and label contacts you have (the numbers only). Your account name is
replaced with
~. It contains none of your notes, ratings, tags, or the label contacts themselves, but error messages quote file paths, and a project folder name is usually a track title, so read it before you send it. There is a checkbox to blank folder names if you would rather. You can also save the report to a file and email it yourself instead. We keep reports only to fix the bug, and no report is linked to you unless you choose to include your email address. - When you do press Send, the report travels over the internet like any web request, so it reveals your IP address to Cloudflare, who host the endpoint that receives it, and it is then delivered to our support mailbox through an email provider. Both may log the request under their own privacy policies. If you would rather not have that, use Save a copy and email the file yourself: the report is identical either way.
- Update checks go to our own update endpoint on saltadosessions.com, which redirects the download itself to GitHub Releases (where the installers live). Sessions checks for updates when it starts and every few hours, downloads a new version automatically in the background, and installs it the next time you quit, there is currently no setting to turn this off. Our endpoint keeps a count of how many update checks it receives, from which country, and which app version, a simple tally to gauge roughly how many copies are active. It stores no identifier and not your IP address, and nothing about your music, files or library. Like any web request, the check reveals your IP to us via Cloudflare and the download reveals it to GitHub; both may log it under their own privacy policies.
- Plugin Passports are files you create and share yourself; nothing is transmitted by the app.
- The app itself still asks for no account. Install Sessions, point it at your folders and use it: no email address, no password, nothing to remember. An account is needed only to buy a license or a subscription, and to manage them afterwards. Where the Vault has to know whose backup is whose, on the web too, it goes by your subscription key, and it stores only a one-way fingerprint of that key, never the key itself.
- If you do make an account, here is everything it holds. Your email address, a one-way hash of your password (never the password), your license keys stored encrypted, which computers you have activated, and the dates any of that happened. If you use Continue with Google instead, Google tells us your email address and a Google account identifier, and nothing else: not your name, not your photo, not your contacts, and never your Google password. We use your address to send you your license, to verify the address, to let you reset your password, and to tell you about something that affects your account or your backup. We do not send marketing email to it unless you separately ask for product updates. You can delete your account at any time, which deletes the account record with it.
- If you add your phone number for sign-in codes, it does exactly that and nothing else. Text-message codes are optional: they exist only if you add your mobile number as a two-factor sign-in method in your account's Security settings, and the number is confirmed with a code before it is turned on. We store the number encrypted, screens that list your sign-in methods show only its last four digits, and it is used only to text you one-time verification codes when you sign in or change your security settings, so how often you get one depends entirely on how often you do those things. We never use it for marketing, and we never share, sell or rent your mobile number, and your consent to receive these texts is never shared with anyone. The texts are delivered by Twilio, our messaging provider, which processes the number to deliver them under its own privacy policy. Message and data rates may apply. You can stop at any time by removing the SMS method in your account settings, which deletes the stored number, or by replying STOP to any code; reply HELP to a code or email [email protected] if you need a hand.
- The phone app is a separate app, and it comes with the membership. It plays bounces that are already in your Vault. It never changes anything in your library or your backed-up files. The one thing it can send is a note: a sentence you type at a moment in a track, kept by the backup service until you mark it handled in the desktop app, which deletes it for good. Signing in sends your email address and password (and a one-time code, if you have two-factor turned on) to our account service, together with the app's name, your phone's platform and system version, and the app version, so the signed-in sessions panel in your account can show you which device is signed in. That is a description of a phone, not an identifier for one: there is no advertising id and no device fingerprint. The app then keeps a sign-in token in your phone's own secure storage (Keychain on iPhone, Keystore on Android). Signing out forgets it, and you can end that session from your account on the web at any time. After sign-in it makes five kinds of request and no others: one for a Vault token, then which of your computers have backed up, what is playable on the one you pick, the audio itself, and, only when you press Save on a note, the note. Nothing is downloaded or kept on the phone: every play streams from your Vault. The app contains no analytics, no tracking and no advertising identifiers, and it asks for no location, contacts, photos or files. The camera is used for one thing, reading a sign-in code your computer is showing on screen: the picture is read on the phone and thrown away, nothing is recorded and nothing is uploaded. Folders you marked private never reach the phone at all, because they are sealed and the service cannot open them. Like any web request, streaming reveals your IP address to Cloudflare, who host the Vault.
- This website sets one cookie, only with your permission, and the app sets none. If you reach saltadosessions.com through an affiliate's link, a small bar asks whether a script from Lemon Squeezy may note which affiliate sent you so they can be credited if you buy. Say yes and it sets one cookie that lasts 30 days; when you press Buy, that referral is passed along to the checkout so the credit reaches them. Say no and nothing is set, the choice is remembered on this browser, and the bar does not come back. Everyone else never sees the bar, because without an affiliate link there is nothing to set. The cookie is only ever read by this website and the account page you buy from: Sessions itself contacts no analytics or advertising service and sets no cookies, and this one knows nothing about your music, your files or your library. Page visits are also counted by Cloudflare Web Analytics, which is cookieless and identifies nobody. We also use Umami, a cookieless, privacy-first analytics service, to see which pages get read and roughly how long so we can improve the site; it uses no cookies, keeps no cross-site identifier, and does not store your IP address. And when you click Download or Buy, the page sends a single cookieless ping to our own counter (the same endpoint that tallies update checks), recording only that a download or buy was clicked, on which page, and the country it came from – never an identifier, and never your IP. If you sign in to browse your Vault in a browser, that page sets one more, on vault.saltadosessions.com: a session cookie that keeps you signed in for an hour so downloads and playback work. It tracks nothing, follows you nowhere else, and signing out clears it.
- If you type your email into the "Product updates" box, we store that one address so we can let you know when a new release or feature is available. It is kept on our own server, used for nothing else, and never sold or shared; the same coarse Cloudflare country is recorded, never your IP. We email rarely, every message we send will include an unsubscribe link, and you can ask us to remove you at any time.
Questions: [email protected]