Privacy Policy
Last updated: September 29, 2026
What we collect, in plain English
We collect what we need to run the Service. Nothing more. We don't sell your data. We don't train AI models on your audio.
If you stop reading here, that's the gist.
1. Who runs this
Stempo is operated by Guilherme Bilton, an individual entrepreneur based in Brazil.
Data Protection Contact: guilhermebilton@gmail.com
2. What we collect
2.1 Account information
When you create an account: - Email address - Password (stored as a salted hash, not plaintext) - Display name (optional) - Country (optional)
2.2 Audio you upload
The audio files you upload to the Service, and the versions we generate from them (other keys and tunings, loudness-matched and guitar-removed renditions). They are kept in private object storage (Cloudflare R2), encrypted at rest, and transmitted over HTTPS.
2.3 Usage data
- Server logs of requests to the Service (including the data in section 2.5)
- Number and duration of audio jobs, so we can apply plan quotas
- Error reports (with personal data redacted)
- Product usage events linked to your account: when you visit, and which features you use (for example uploads, playback and practice time, tempo, key and loop changes, guitar removal, downloads)
- When you open the app: device type, screen size, language, and the website or campaign that sent you
Usage events are stored in our own database, not sent to an analytics company. We use them to understand how the Service is used and to improve it. We do not currently use a third-party product-analytics tool, and we do not track you across other websites.
2.4 Payment information
We use Paddle as our merchant of record. They collect and process payment details (card numbers, billing addresses, tax IDs). We never see your full card number. Paddle is a separate controller for that data; their privacy policy applies: https://www.paddle.com/legal/privacy
2.5 Technical data
- IP address (used for security and abuse prevention)
- Browser type and OS
- Local browser storage (see section 7)
2.6 Communications
If you email us or fill in a contact form, we keep that exchange to provide support.
3. What we don't collect
- We don't sell your data to anyone
- We don't train AI models on your uploaded audio
- We don't share your audio with third parties (except subprocessors strictly necessary to run the Service — listed in section 6)
- We don't use third-party advertising trackers
4. Why we collect it (legal bases)
Under GDPR/LGPD, we process your data on these grounds:
- Contract. To deliver the Service you signed up for.
- Legitimate interest. Security, abuse prevention, keeping the Service running reliably, and understanding how features are used so we can improve them.
- Consent. Marketing emails (separate from transactional). You can opt out anytime.
- Legal obligation. Tax records, DMCA compliance.
5. How long we keep it
| Data type | Retention |
|---|---|
| Account data | While your account is active; removal begins immediately after confirmed account deletion |
| Audio files (uploads and generated versions) | Until you delete them, or until account deletion begins; failed storage cleanup is queued for operator retry |
| Free-tool uploads (no account) | Download link expires 1 hour after upload; the uploaded and processed files are then deleted by an automatic cleanup that runs every few minutes and retries any failed deletion. A job record without audio (a one-way hash of your IP address, the effect applied, status and timestamps) is kept for 7 days after cleanup for operations and abuse prevention, then deleted |
| Temporary processing copies | Working copies made while a job runs are deleted when the job finishes; leftovers from interrupted jobs are removed by automatic cleanup |
| Payment records | 5 years (legal requirement) |
| Error logs | 90 days |
| Product usage events | 24 months, then deleted automatically; removed immediately on account deletion |
| Email communications | 3 years |
You can request earlier deletion via the controls in the app or by emailing guilhermebilton@gmail.com.
How deletion works. When you delete a song or your account, access is removed immediately. Account deletion first verifies immediate cancellation of any subscription, then removes application data, stored files, and the login identity. Minimal account and provider identifiers and cancellation confirmations are retained in a deletion record to retry unfinished work and reconcile late billing notifications. If a billing, storage, or identity provider is temporarily unavailable, the unfinished cleanup is recorded for an operator retry rather than reported as complete. Records held by our providers under their own retention schedules — for example database backups kept by Supabase, or payment records kept by Paddle as merchant of record — are removed on those providers' schedules, not ours.
6. Subprocessors
These third parties process some of your data on our behalf, under contract, only for the purpose of running the Service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Railway | Application hosting (website, app and API), job queue (Redis), and audio processing, including temporary working copies of audio while a job runs. Some files uploaded before we moved audio storage to Cloudflare R2 may remain on a Railway storage volume | US (us-east4 region) |
| Cloudflare | Cloudflare R2 object storage for uploaded audio, generated versions and free-tool files | US company; global infrastructure |
| Supabase | Authentication (including account emails) and database | US (us-east-1 region) |
| Paddle | Payment processing, merchant of record | US/EU |
| Sentry | Error monitoring, where enabled | US |
| Hostinger | Domain registration and DNS | EU |
We update this list when we add or change subprocessors. Material changes will be announced 30 days in advance to active accounts.
7. Cookies and local storage
We do not use cookies.
The Service stores a small amount of data in your browser's local storage, and only for things the Service cannot work without or that you asked for:
- Sign-in: your session so you stay logged in between visits.
- Preferences: settings you choose, such as the light/dark theme.
We do not use advertising cookies, analytics cookies, or any third-party tracking. Because we store nothing for advertising or tracking, there is no consent banner to manage.
You can clear this data at any time from your browser settings; doing so signs you out and resets browser-stored preferences.
8. Your rights
Under GDPR, LGPD, and similar laws, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Export your data in a portable format
- Object to certain processing
- Withdraw consent for any consent-based processing
- Lodge a complaint with your local data protection authority (in Brazil, ANPD; in the EU, your national DPA)
To exercise any of these rights, email guilhermebilton@gmail.com. We respond within 30 days (sometimes faster).
You can also delete your account directly from the settings page. You must confirm your email address; access is revoked immediately and application data cleanup begins at once. If identity-provider or storage cleanup cannot complete, the deletion request is retained for an operator retry rather than represented as complete.
9. International transfers
Some of our subprocessors are based outside Brazil/EU (e.g. Railway, Cloudflare, Supabase and Sentry in the US).
For EU users: we use Standard Contractual Clauses (SCCs) as the legal basis for these transfers, plus supplementary measures where the recipient country lacks an adequacy decision.
For Brazilian users: same — we comply with LGPD's international transfer requirements via contractual safeguards with US-based subprocessors.
10. Security
We use:
- HTTPS for all traffic
- Encryption at rest for audio files and the database, as provided by our hosting subprocessors
- Passwords handled by Supabase, our authentication provider, and stored only as salted hashes — we never see or store your password
- Every account's library scoped to that account, so users cannot access each other's files
- Access to production systems limited to the operator
- Notification to you and the relevant authority within 72 hours of a confirmed breach affecting your data
No system is 100% secure. If we discover a breach affecting your data, we'll notify you and the relevant authority within the legally required timeframes.
11. Children
The Service is not intended for users under 13 (or under the digital consent age in your country). We don't knowingly collect personal data from children. If you believe a child has provided us with data, contact guilhermebilton@gmail.com and we'll delete it.
12. Emails
- Account emails — sign-up confirmation, sign-in links and password resets, sent through Supabase, our authentication provider. Required to operate your account; can't be opted out of.
- Payment emails — receipts and subscription notices are sent by Paddle, our merchant of record.
We do not currently send lifecycle or marketing emails. If we start, lifecycle emails (such as onboarding tips) will include an opt-out link, and marketing emails will be opt-in only, with an opt-out link in every email.
We don't share your email with third parties for their marketing.
13. Data sales / sharing
We do not sell your personal data. Period.
We don't share your data with third parties except:
- Subprocessors listed in section 6, under contract, for the sole purpose of running the Service
- When legally required (court order, subpoena, etc.) — we challenge overbroad requests
- In a corporate event (merger, acquisition) — your data would be transferred to the new owner, and you'd be notified 30 days in advance with an option to delete first
14. Changes to this policy
We may update this policy. Material changes will be notified via email 14 days before they take effect, with a summary of what changed.
The "Last updated" date at the top reflects the most recent change.
15. Contact
- Privacy questions and data-subject requests: guilhermebilton@gmail.com
For Brazilian users specifically, you may also contact the ANPD (Autoridade Nacional de Proteção de Dados) at https://www.gov.br/anpd
For EU users, your national data protection authority — list at https://edpb.europa.eu/about-edpb/board/members_en