The short version: your music never leaves your machine.
Draft. This policy has not yet been reviewed by a lawyer.
It will be finalised before Sessions is sold.
Sessions runs entirely on your computer. Your projects, samples, plugin lists, notes and
everything else it catalogs are stored in a local database on your device.
Sessions does not upload your files, your library, or any analytics about your music
anywhere.
The only network calls the app makes are: (1) license key activation and validation with
our payment provider — when you enter a key, and quietly in the background afterwards
(at startup and about once a day) to keep your license current; (2) checking for and
downloading app updates; and (3) sending a problem report — only when
you press Send, and containing only what was shown to you on screen first. Neither (1) nor
(2) carries data about your music: call (1) sends your license key, a seat identifier, and
your app version to the payment provider; call (2) sends your app version to our update
server and on to GitHub for the download, never your license key.
Problem reports are never sent on their own. Nothing is transmitted
unless you press Send, and the full contents are displayed before you do. A report contains
recent error messages, your app version, and simple counts — how many projects,
samples, library items and label contacts you have (the numbers only). Your account name is
replaced with ~. It contains none of your notes, ratings, tags, or the label
contacts themselves — but error messages quote file paths,
and a project folder name is usually a track title, so read it before you send it. There is
a checkbox to blank folder names if you would rather. You can also save the report to a file
and email it yourself instead. We keep reports only to fix the bug, and no report is linked
to you unless you choose to include your email address.
When you do press Send, the report travels over the internet like any web request, so it
reveals your IP address to Cloudflare, who host the
endpoint that receives it, and it is then delivered to our support mailbox through an email
provider. Both may log the request under their own privacy policies. If you would rather
not have that, use Save a copy and email the file yourself — the report is
identical either way.
Update checks go to our own update endpoint on saltadosessions.com, which
redirects the download itself to GitHub Releases (where the installers live).
Sessions checks for updates when it starts and every few hours, downloads a new version
automatically in the background, and installs it the next time you quit — there is
currently no setting to turn this off. Our endpoint keeps a count of how many
update checks it receives, from which country, and which app
version — a simple tally to gauge roughly how many copies are active. It stores
no identifier and not your IP address, and nothing about your music, files or
library. Like any web request, the check reveals your IP to us via Cloudflare and the download
reveals it to GitHub; both may log it under their own privacy policies.
Plugin Passports are files you create and share yourself; nothing is transmitted by the
app.
We don't run accounts, so there is no account data to breach.