Privacy Policy
Kaldrik ("Kaldrik", "the Service", "I", "me", or "my") is a web application for planning multitrack recording sessions. Kaldrik is operated by an individual based in Texas, United States. For the purposes of the EU/UK GDPR, Kaldrik is the data controller responsible for your personal information. This Privacy Policy explains what personal information the Service collects, how it is used, and the choices you have. If you have questions, reach me through the contact page.
Kaldrik is currently a beta (pre-release) product under active development. New features are still being added and existing ones may change, which means the way data is handled can evolve over time. When that happens, I will update this Policy and revise the "Last updated" date above. I take your privacy and your feedback seriously. If anything here is unclear or you have a suggestion, please reach me through the contact page.
- I collect your email, the projects you create, and limited technical data (such as IP address) to run and secure the app.
- I don't sell your data, run ads, or use cross-site tracking.
- Product analytics is strictly opt-in: no analytics loads unless you accept the one-time banner, and declining changes nothing about the app. Separately, lightweight crash/error monitoring may run to keep the app working reliably; it sets no cookies and does no cross-site tracking (see Section 1).
- Kaldrik is free, and does not process payments. If you record quotes or mark payments for your own bookkeeping, those are just figures and notes you type in; I never collect or handle card or bank account details.
- If you upload audio for review (a mix, master, or stem), it is stored privately and is reachable only through short-lived links by the people you share that project with. It is never made public.
- You can export your data anytime (.json / .xlsx) and delete your account and its data from within the app.
- Read-only share links are optional and off by default. If you create one, anyone with the link can view that project (and, if you allow it, leave comments or confirm their availability and which parts they've learned) until you revoke it.
- If you upload a studio/band logo for your shared pages, that image is served publicly to anyone who has the link; a profile photo (avatar) you upload is shown in the app.
- You can invite other Kaldrik users to collaborate on a project. To do so I store the invitee's email and, once they accept, give them access to that project's contents (as an editor or viewer). You can remove them anytime. A project keeps an activity log of recent actions (including when a view-only collaborator opens it), visible to the project's members.
- The tuner can use your device microphone to detect pitch; that audio is processed on your device only and is never recorded, stored, or sent to me.
- At signup I log your acceptance of the Terms & Privacy (email, time, version, IP address) as proof of consent, and delete that record after one year.
- Questions or requests? Use the contact page.
1. Information I collect
I collect only what is needed to run the Service:
- Account information. When you create an account with email and password, I collect your email address. Your password is stored only in hashed form by my authentication provider (Supabase). I never see or store your plaintext password.
- Consent records. To create an account, you must affirmatively check a box agreeing to the Terms of Service and this Privacy Policy. When you do, I record a consent log entry containing: your email address; the fact that you accepted; the date and time of acceptance; the version of the documents you accepted; your browser's user-agent string; and the IP address the acceptance was submitted from (the IP is captured by my server, not read from your device). I keep this entry as proof of consent and for legal compliance, and automatically delete it one year after acceptance (see Section 6).
- Google sign-in (optional). If you choose "Continue with Google," I receive your Google account email address and a basic account identifier from Google so I can create and recognize your account. I do not receive your Google password.
- Content you create. The projects you create in Kaldrik, each containing song structures, arrangements, tempos, keys, lyrics, input lists, tracking orders, credits, notes, and session planning data (schedule, crew and their rates, budget, studio rate, meals / per-diem, taxes, currency/country, and invoice details), are stored so they can be saved to and synced with your account. You may keep multiple separate projects.
- Saved contacts & library. Separately from any project, you can keep a reusable address book of contacts (crew & collaborators, with optional pay rates) and a library of studios, venues, and bands (with addresses and default rates). These are stored on and synced with your account so you can reuse them across projects.
- Quotes & payment records. Within a project you can build quotes (line items, rates, and totals) and record payments you have received against them (such as an amount, date, and a note like "deposit, paid by bank transfer"). This is bookkeeping information you type in for your own records. Kaldrik does not process payments and never collects or stores card numbers, bank account details, or any other payment credentials. These records are stored with your project so you can track what has been quoted and paid.
- Bookings & rooms. If you use the booking calendar, I store the rooms or spaces you define and the sessions you schedule (such as a title, room, date and time, and any notes or linked project), so your calendar can be saved and synced to your account. An optional floor-plan layout you draw for a room is stored the same way.
- Contact messages. If you use the contact form on the public Contact page, I collect the email address, optional name, and message you submit, plus the IP address and browser user-agent of the submission (captured by my server for spam protection), so I can reply to you and keep a record of the conversation.
- Share links (optional). If you choose to create a read-only share link for a project, I store a randomly generated link token associated with your account so the link can resolve to that project. While a link is active, anyone who has it can view a read-only copy of that project without signing in, so only share it with people you trust. The link does not grant any ability to edit your data or access your account. You can revoke a link at any time from within the app, which immediately disables it. Sharing is off by default. If you add a location address to a project and share it, that address appears on the shared page and is used to display a map (see "Embedded maps" below).
- Comments on shared projects. A shared project page can let viewers leave comments. If someone posts a comment, I store the comment text, a display name they type in, and a timestamp, associated with that project, so it can be shown to you (the project owner) and to other viewers of that link. As the owner you are notified in-app and can delete any comment. Comments are visible to anyone who has the share link, so they should not contain sensitive information. You can turn the discussion off or revoke the link at any time.
- Band check-ins on shared projects. A shared project page can let band members confirm their availability and mark which songs' parts they have learned. If someone submits a check-in, I store the display name they type, their availability and per-song "parts learned" marks, and a timestamp, associated with that project, so you (the owner) and other viewers of that link can see who is ready. Like comments, check-ins are visible to anyone who has the link and should not contain sensitive information; you can revoke the link at any time.
- Uploaded images (logo & avatar). You can upload a studio or band logo for your shared pages and a profile photo (avatar) for your account. These image files are stored so they can be displayed. A logo appears on the public shared page and printed sheets of any project you share, so it is served publicly to anyone who has that link; your avatar is shown to you in the app and to collaborators on your projects. Only upload images you have the right to use, and don't put anything sensitive in a logo you intend to share.
- Uploaded audio (review files). In a project's audio review area you can upload audio files (such as a mix, master, or stem) so collaborators or clients can listen and leave time-stamped comments. These files are stored in a private location, are never given a public address, and are served only through short-lived links that expire shortly after they are created. They are reachable only by you, your project's members, and anyone you give a share link to. Only upload audio you own or have the rights to share. If a listener on a shared link leaves a comment or approves a version, I store the display name they type, their comment or decision, the point in the track it refers to, and a timestamp, the same way as other shared-project comments.
- Collaborators on a project. You can invite other Kaldrik users to a project by email. When you send an invite, I store the email address you entered, the role you chose (editor or viewer), and who sent it, so the invite can be delivered and accepted. When the invited person accepts, they become a member of that project and can view (and, as an editor, edit) that project's contents from their own account. As the owner you can change a collaborator's role or remove them at any time, and you are responsible for choosing who to invite and what you share with them. Inviting someone is the only way another signed-in user can access your project data; otherwise each user can only see their own. A project also keeps a short activity log of recent actions: who created, edited, invited, or joined it, structural changes (songs added or removed, share links created or revoked), and, when a view-only collaborator opens the project, a record that they viewed it, each with a timestamp and the member's name (or email). This log is visible to that project's members, including the owner, so the owner can see who has opened or changed a shared project.
- Microphone (tuner tool). Kaldrik's optional tuner can use your device's microphone to detect the pitch you play. This audio is analyzed locally in your browser in real time and is never recorded, stored, or transmitted to me or anyone else. Your browser will ask permission before the microphone is used, and the tuner only listens while you have it open and running.
- Feedback you send. If you use the in-app "Send feedback" form, I store the message you write along with your account email address (so I can follow up), and basic technical context (the page URL and your browser's user-agent) to help reproduce issues. You can optionally attach up to three screenshots, which are stored privately in Supabase; a short-lived link to them (valid about 30 days) is included in the notification email I receive. I use this only to support and improve the Service. You can instead email me directly if you prefer.
- Authentication & security data. If you enable two-factor authentication (2FA), the associated secret is stored by Supabase to verify your one-time codes. Session tokens are stored to keep you signed in. In your Account settings you can view the devices currently signed in to your account (each entry shows that session's IP address, browser or device type, and last activity) so you can recognize and sign out any session you don't recognize. This list is visible only to you, and is not used to track your location.
- Limited technical data. My hosting and infrastructure providers (Vercel, Supabase, and, where enabled, Cloudflare) automatically process limited technical data such as IP address, browser type, and request logs as part of delivering and securing the Service. To protect a few endpoints (such as the contact and feedback forms) from abuse, your IP address is also briefly stored in a rate-limiting store (Upstash Redis). I do not run any advertising or behavioral-tracking analytics. The only product analytics is the strictly opt-in Vercel Analytics described below, which never loads unless you accept.
- Opt-in product analytics (Vercel Analytics). The first time you visit, Kaldrik shows a one-time banner asking whether you'll allow analytics. Only if you click Accept does the app load Vercel Analytics, a privacy-friendly, cookieless analytics service provided by Vercel Inc. It gives me aggregated page and feature usage (which parts of Kaldrik get used) so I know what to improve. It sets no cookies, does no cross-site tracking, and builds no advertising profiles. Your choice (accept or decline) is stored in your browser's local storage so you're only asked once, and declining changes nothing about how the app works. You can change your mind by clearing that stored choice in your browser.
- Crash & error monitoring (Sentry). To find and fix bugs, Kaldrik uses Sentry to capture diagnostic data when something goes wrong, such as the error and stack trace, the page where it happened (with any share or recovery token stripped from the URL), and your browser type. Sentry may also receive your IP address as part of receiving that report. This is error monitoring, not analytics: it sets no cookies, does no cross-site tracking, and runs as a legitimate interest in keeping the Service working, so it is not tied to the analytics banner. It runs only when error monitoring is configured for the deployment.
2. How I use your information
- To create and authenticate your account and keep you signed in.
- To save, load, and sync the projects you create, including quotes, payment records, bookings, and uploaded review audio.
- To deliver uploaded review audio to the people you share a project with, through short-lived private links.
- To secure accounts and prevent abuse (including optional 2FA and bot protection).
- To send essential service emails, such as email confirmation and password-reset links.
- To record and retain proof that you agreed to the Terms of Service and this Privacy Policy when creating your account.
- To understand, in aggregate, which pages and features get used, but only if you opted in to analytics via the consent banner (see Section 1).
I do not sell your personal information, and I do not use it for advertising.
3. Legal bases (EU/UK users)
Where the GDPR or UK GDPR applies, I rely on these legal bases:
- Performance of a contract: creating your account, and saving, syncing, and providing the Service to you.
- Legitimate interests: securing and operating the Service, preventing abuse, and keeping the consent record described in Section 1 as evidence that you accepted the Terms and this Policy.
- Legal obligation: where I am required to retain certain records or respond to lawful requests.
- Consent: where consent is specifically required; you may withdraw it at any time, without affecting processing already carried out.
Accepting the Terms of Service is a contractual step, not "consent" to data processing, and checking the signup box confirms you have read this Policy. Providing an email address is necessary to create an account. Without it, the Service cannot be provided.
4. Service providers
I rely on a small number of trusted processors to run Kaldrik:
- Supabase: authentication, database hosting (your account and project data), and private file storage for the images and review audio you upload.
- Vercel (Vercel Inc.): hosting and delivery of the website, and, only if you opt in via the consent banner, the cookieless Vercel Analytics described in Section 1.
- Google: only if you choose Google sign-in, and to display an embedded map when a project has a location address (see "Embedded maps" below).
- Cloudflare: only if bot-protection (CAPTCHA) is enabled, to verify that a request comes from a human (this includes the contact form).
- Resend (Resend, Inc.): only to deliver the notification email when you submit the contact form.
- Upstash (Upstash, Inc.): a rate-limiting store that briefly holds request IP addresses to protect endpoints such as the contact and feedback forms from abuse.
- Sentry: crash and error monitoring, where enabled for the deployment, as described in Section 1.
These providers process data on my behalf and are not permitted to use it for their own purposes.
Embedded maps. If a project has a location address and you share it, the shared page embeds a Google Maps view of that address. When a visitor opens that page, their browser loads the map directly from Google, so Google may receive the visitor's IP address and standard request data as part of serving the map, subject to Google's own privacy policy. The map only appears when an address is present; remove the address (or don't share the project) to omit it. The printable version uses a locally generated QR code instead, which involves no third-party connection.
5. Cookies & local storage
Kaldrik uses your browser's storage to keep you signed in (session tokens), to cache a local copy of your project, and to remember preferences. These are necessary for the Service to function. Kaldrik does not use advertising or cross-site tracking cookies.
Local storage also remembers your analytics consent choice (accept or decline) from the one-time banner, so you aren't asked again. The opt-in analytics itself is cookieless and sets no cookies (see Section 1). Clearing your browser storage clears the choice, and the banner will simply ask once more.
For reliability, Kaldrik may also store a small diagnostic record of the most recent error in your browser's local storage to help it recover gracefully if something goes wrong. This information stays on your device and is not transmitted to me; you can clear it at any time by clearing your browser storage.
6. Data retention
I keep your account and project data for as long as your account is active. I do not maintain separate backups of your content, so you are responsible for exporting your own copies (Kaldrik provides .json and .xlsx export). When you delete your account (either using the in-app "Delete my account" option or by asking me), your account and all associated project data are permanently removed and cannot be recovered. This includes files you uploaded, such as logos, avatars, and review audio. You can also delete an individual audio file from a project's review area at any time, which removes it from storage.
Messages you send through the in-app feedback form or the contact page (including any feedback screenshots) are kept only as long as needed to handle and learn from them, and are deleted once they are no longer useful for support. The short-lived links to feedback screenshots expire about 30 days after you send them.
One exception: the consent record described in Section 1 (your acceptance of the Terms and this Policy, with the date, time, version, and IP address) is kept as a compliance record for one year from the date you accepted, after which it is automatically deleted. It is retained for that period even if you delete your account sooner. You may contact me to request earlier deletion, which I will honor unless I am required to keep it to meet a legal obligation.
7. Your rights and choices
You may request to access, correct, export, or delete your personal information. Depending on where you live (for example, under the EU/UK GDPR or the California CCPA/CPRA), you may have the right to know what data is held, to request deletion, to data portability, and to not be discriminated against for exercising these rights. I do not sell personal information.
To exercise any of these rights (including deleting your account and all associated data), reach me through the contact page and I will respond within a reasonable time.
If you are in the EU/UK, you also have the right to object to or request restriction of certain processing, and the right to lodge a complaint with your local data protection authority (your supervisory authority). I would welcome the chance to address your concern directly first, so please feel free to contact me before doing so.
8. Security
Data is transmitted over encrypted HTTPS connections. Each user's project data is protected by database row-level security, so you can only access your own data. Passwords are stored hashed, and you may enable two-factor authentication (2FA) for extra protection; when 2FA is enabled on an account, it is enforced at the database for access to that account's data, not only at the sign-in screen. No method of transmission or storage is 100% secure, but I take reasonable measures to protect your information.
9. International transfers
Kaldrik is operated from the United States, and your information may be processed and stored in the United States and other countries where my service providers operate. By using the Service, you understand that your information may be transferred to these locations.
10. Children
Kaldrik is not directed to children. You must be at least 16 years old to create an account or use the Service. I do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has provided information, contact me and I will delete it.
11. Changes to this policy
I may update this Privacy Policy from time to time. When I do, I will revise the "Last updated" date above. Significant changes will be reflected here, and your continued use of the Service after an update constitutes acceptance of the revised policy.
12. Contact
Questions or requests? Use the contact page.