Privacy Policy.
1. Who is responsible for your information
Perfect Pitch Audio LLC, a California limited liability company, is responsible for the personal information described in this policy when it determines how that information is used. This policy covers our website, accounts, Phaeton, Telion, support, release waitlists and related services. A feature-specific description applies when that feature is available and you use it.
Paddle separately handles purchases as merchant of record. Other organisations may also have responsibilities for information they process for their own purposes, as explained below.
2. Information we handle and why
Account and licence information
We handle your email address, account identifier, password verification data, licence keys, product entitlements, activation records and account-security events. Activation records include a device identifier or derived identifier, machine name and activation or last-contact times. We use this information to operate your account, issue and validate licences, manage device activations, recover access and prevent misuse.
Passwords are stored as salted hashes rather than readable passwords. Account verification and reset processes use time-limited credentials. Do not send us your password in a support message.
A hashed or derived device identifier can still distinguish a device or be connected with an account. We therefore treat it as personal information where that connection is possible, rather than describing it as necessarily anonymous.
Purchases and subscriptions
Paddle collects payment, billing and tax information under its Privacy Policy. We receive or can access the customer and transaction information needed to fulfil and administer an order, such as contact information, order references, purchased products, amounts, currency, tax information, transaction status and subscription events. Where Paddle makes billing details available to us for order administration, those details are also covered by this policy.
We do not receive your full payment-card number or card security code through our checkout integration. Paddle's own retention and handling of purchase information are governed by its policy and legal duties. Requests concerning information held by Paddle may need to be made to Paddle directly.
Trials, activation and update checks
Trial and activation requests use licence or trial information, device identifiers and request metadata to establish eligibility and manage the permitted devices. Update checks use product and version information to check availability. The receiving server also processes connection information such as an IP address and request time.
These licensing and update functions do not require uploading your DAW projects or the audio being processed. Options to control update checks are provided in the plugin where available.
Support and optional problem reports
If you contact us, we receive your contact information, message and any files you choose to provide. An optional diagnostic report may include host, operating system and plugin versions, error details and timestamps. The report is sent only when you choose to submit it. Do not include client material or other people's information unless you have the right to share it.
We use support information to respond, diagnose problems and improve reliability. Support files are not required merely to browse the site or hold a licence.
Telion audio and connection information
For online streaming, Telion sends live audio through relay infrastructure to the listeners who connect. Operating the stream requires connection information, such as participant IP addresses, stream identifiers, connection times, listener counts and the entitlement or authentication information needed to authorise access. A password-protected stream also requires processing the access credential used to check admission.
The relay uses audio for transmission and temporary buffering, not to create a recording library or backup of your sessions. We do not use streamed audio for advertising or model training. Operational connection records are separate from the audio itself.
In local-network mode, the audio path remains on your local network. The plugin may still make separate licensing, account or update requests. Local audio routing therefore does not mean that the application makes no internet requests at all.
Listeners receive the audio you choose to share. They may record or redistribute it outside our control. Do not share a stream link or password more widely than intended.
Waitlist and other email
When you join a release waitlist, we use your email address, the product or list selected, and records of the request, confirmation, delivery and unsubscribe status to send the release notifications you asked for. Joining that list does not automatically subscribe you to unrelated marketing.
Other promotional email requires the separate choice offered when subscribing. You can unsubscribe through the link in a promotional message or contact us. Essential account, security, purchase and service messages are separate and may still be sent when needed to provide the service or meet a legal duty.
Instagram messages and comments
If you comment on one of our Instagram posts or send us a message on Instagram, Meta delivers it to us and our messaging provider ManyChat receives it so that we can reply, including with automated replies. This involves your Instagram username and display name, profile picture, the comments and messages you send, the keywords or buttons you use and the time of each interaction. Automated replies are sent only in response to your own comment or message.
If you give us your email address in a conversation, we use it only for the purpose stated at that point, for example a release waitlist, and the waitlist terms above then apply. Instagram itself, including your account and the messages it stores, is operated by Meta under its own terms and privacy policy.
Public game scores
If you submit a game score for publication, we handle the nickname, score and a device-derived identifier used to associate and protect the entry. The nickname and score become public. The device identifier is not displayed publicly. Choose a nickname that does not disclose information you want kept private. Contact us to request correction or removal.
Website and security information
Our infrastructure handles IP addresses, request times, requested resources, browser or device information, response status and security events needed to deliver pages and protect the service. These records help detect failed logins, abusive activation attempts, spam and attacks. Short-lived rate-limit counters are distinct from other security or provider logs.
Optional website measurement is described in Section 4. We do not use account credentials, licence keys or the contents of private support messages as advertising inputs.
3. Legal grounds where data-protection law requires them
We use information necessary to supply an account, licence, purchase-related service or requested stream to perform our agreement with you or take steps you request before it.
We rely on our legitimate interests in securing accounts, preventing trial and licence abuse, resolving support issues, answering messages you send us on Instagram and maintaining reliable services where those interests are not overridden by your rights. We use no more information than is reasonably needed for those purposes.
We rely on consent for optional website analytics, advertising technologies, requested promotional email and optional diagnostic submissions where consent is the applicable basis. You can withdraw it without losing unrelated paid entitlements.
We also process information where needed to meet an applicable legal obligation, including required accounting records or lawful requests. A purpose that is merely convenient for us is not automatically necessary to perform your contract.
4. Cookies, analytics, advertising and your choices
Essential functions
Essential browser storage supports sign-in, security and privacy choices. The ppa_session cookie supports your authenticated session. ppa_consent stores your privacy choices in local storage. If used, ppa_geo stores a country code for up to one day; it is not used to enable optional tracking without permission.
Blocking essential storage may prevent account functions. Optional analytics and advertising are not required to create an account, buy a licence or use a purchased product.
Optional measurement on public pages
With your affirmative permission, we use:
- Microsoft Clarity to understand interactions on public pages through information such as page views, clicks, scrolling, heatmaps and session replays. Replays can reconstruct visible page content and interactions. We configure masking and exclusions for personal fields and private content.
- Meta Pixel to measure advertising and activity on public marketing pages. It can disclose page and event information, browser or device information, IP addresses and online identifiers to Meta. Meta may connect information with other activity or an account it holds, according to its own policies and the settings that apply.
Neither service loads until you allow its category, regardless of your country. Analytics and advertising choices are separate, and you can reject both. We do not run either service on account, sign-in, registration, password-reset, email-verification or Telion listener pages.
Changing a choice
Use Cookie settings in the website footer to review, reject or withdraw optional permissions. Withdrawal stops future optional collection from this website for the affected categories. It does not automatically erase information already received by a provider; contact us about deletion requests. You do not need to clear all browser data to change your choice.
We treat Global Privacy Control (GPC) as a refusal of optional analytics and advertising, including when an older saved choice allowed them. This control is provided across our website regardless of location. Where applicable law treats advertising disclosures as a sale or sharing of personal information, it also serves as an opt-out of those disclosures. We do not require identity verification merely to reject these technologies.
The older Do Not Track (DNT) signal is distinct from GPC. We do not assign an additional automatic response to DNT; the consent requirement, Cookie settings and GPC controls above still apply.
When permitted technologies are active, third parties may collect information about activity over time and across websites. This is why permission for advertising is a separate choice. This policy does not characterise all advertising disclosures as exempt from privacy laws merely because no money is paid for the information.
5. Who receives information
The following providers receive information for the relevant functions:
- Cloudflare: Website, API, data infrastructure and security; relevant account, service and request information.
- Paddle: Merchant-of-record purchase processing; customer, payment, billing, tax and transaction information under its separate responsibilities.
- Resend: Delivery of requested and operational email; recipient details, message content and delivery-related records.
- Hetzner: Infrastructure used for Telion relay hosting; transmitted audio and the connection or operational information needed for that service.
- Microsoft Clarity: Optional public-page analytics and session replay information, only with the relevant permission.
- Meta: Optional advertising measurement and event information, only with the relevant permission. Separately, as operator of Instagram, the comments and messages you exchange with our Instagram account.
- ManyChat: Instagram message automation; your Instagram username, display name, profile picture, the comments and messages you send us and the replies we send.
- Stream listeners and leaderboard visitors: Audio deliberately shared with listeners, and nicknames and scores deliberately made public, respectively.
Providers acting on our instructions receive information for the services they provide under applicable agreements. Some recipients, particularly Paddle and advertising providers, may also determine their own processing purposes. Describing a recipient as a provider does not mean all its processing is solely on our behalf.
We may disclose relevant information to professional advisers or authorities where necessary for legal obligations, disputes, fraud prevention or protection of legal rights. If a business restructuring or transfer affects personal information, disclosure will be limited to what is necessary, protected appropriately and notified where required. These situations do not authorise unrelated use of audio or private project material.
When you submit a copyright notice or counter-notification through the procedure on our Copyright Policy page, we process the contact details, statements and evidence you provide to assess and respond to it. Where the applicable procedure requires or permits it, we may share relevant notice or counter-notification information, including contact details, with the other party or its representative. We retain complaint records for handling the matter, implementing our repeat-infringer policy and relevant legal claims, only for as long as those purposes lawfully require. Avoid including unrelated personal information in a submission.
6. Automated checks
Our systems automatically check matters such as trial eligibility, activation counts, subscription status and suspicious request rates. These checks can refuse a request or temporarily restrict access. If you believe a decision is wrong, contact support for human review and provide enough information to identify the account or affected licence. Do not send a password.
7. Retention and deletion
We retain information for the period needed for its stated purpose, subject to applicable legal duties. The relevant criteria are:
- Account, licence and activation records: While needed to administer the account and continuing licence entitlements. After closure, only information needed for an ongoing entitlement, a required record or a specific lawful dispute or abuse-prevention purpose is retained.
- Trial eligibility records: While the relevant trial programme operates and the minimal device-derived record remains necessary and proportionate to enforce its one-trial rule. Continued need is reviewed; it is not a reason to retain unrelated account details indefinitely.
- Verification, reset and session credentials: Until use, expiry, revocation or logout as appropriate. Separate security-event records may remain under the criteria below.
- Security and operational records: For the relevant rate-limit window or the period reasonably needed to investigate and address an incident, maintain service reliability or establish a legal claim. Provider logs may have different retention from application counters.
- Live audio and stream information: Audio buffers only for the time needed to relay the stream. Connection and security records follow the operational-record criteria and are not a retained recording of the session.
- Orders and financial records: For applicable accounting, tax, dispute and recordkeeping duties. Paddle separately determines retention for records it controls.
- Support and diagnostic information: While handling the issue and for a proportionate follow-up period needed for recurring faults, warranty questions or relevant claims. Unneeded attachments are deleted sooner where possible.
- Waitlist, marketing and consent records: Until the requested notifications are complete, you unsubscribe or the relevant list is discontinued. Limited consent evidence and suppression information may remain to demonstrate a choice and avoid contacting you again improperly.
- Instagram conversations: Records held by ManyChat are kept while the conversation and any follow-up you asked for continue, and are deleted on request or when no longer needed. Instagram keeps its own copy of messages under Meta's terms.
- Public scores: While the leaderboard operates and the entry remains requested, subject to correction or removal requests and any necessary limited integrity records.
- Optional analytics and advertising information: According to the configured provider retention and the purposes for which permission was given; we review continued need and stop future collection when permission is withdrawn.
Deleted information may persist temporarily in restricted backups until those backups are overwritten or expire under the applicable recovery schedule. If information must be retained for a specific legal reason, we restrict its use to that reason and delete it when it no longer applies. A generic possibility of future litigation does not justify keeping everything forever.
8. Where information is processed
We are based in the United States. The providers identified above may process information in the United States and other countries in which the relevant services operate. Privacy laws in those locations may differ from those in your country.
For transfers subject to European, UK or Swiss restrictions, the applicable destination and safeguard information is:
Where we or our providers process information in the United States or another country outside your own:
- Cloudflare (website, API, database, security) processes information in the United States and in its global network.
- Resend (email delivery) processes information in the United States.
- Hetzner (Telion relay hosting) processes information on a server located in the United States.
- Paddle (merchant of record) processes information in the United Kingdom and the United States under its own responsibility and policy.
- ManyChat (Instagram message automation) processes information in the United States and other countries in which its service operates.
- Microsoft Clarity and Meta, where you have permitted them, process information in the United States and other countries under their own terms.
For transfers restricted by European, United Kingdom or Swiss law, we rely on the data protection terms of each provider, which incorporate the European Commission's standard contractual clauses together with the United Kingdom addendum and the provisions required for Switzerland, or on an adequacy decision where one applies to the destination. Some of these providers also self-certify under the EU-US Data Privacy Framework; we do not rely on that certification here without confirming that it is active for the specific service.
You can contact us for information about relevant safeguards and how to obtain a copy, subject to lawful protection of confidential information.
9. Your rights and requests
You can contact us to request access to, correction of or deletion of your information. Depending on the law that applies, you may also have rights to a portable copy, restriction of processing, objection to processing based on legitimate interests, withdrawal of consent, and an opt-out of sale, sharing or targeted advertising. Where applicable, you may request limits on uses of sensitive information that the law covers.
Use Cookie settings or GPC for the browser choices described in Section 4, and an email's unsubscribe link for promotional email. These choices do not require you to close an account or surrender a purchased licence.
For requests involving private account information, we may request proportionate evidence of identity or an authorised agent's authority. We use that evidence for verification and do not request more than reasonably necessary. A browser opt-out does not require account verification.
We respond within the time required by the law applicable to your request. If a permitted extension is necessary or part of a request cannot be fulfilled, we will explain why and describe available review or appeal options. You may ask us to reconsider a decision and use any appeal process required by applicable law. We do not penalise you for exercising a privacy right.
Before removing information needed for account access or activation, we will explain the practical consequences and available options. We may retain a limited record where a valid ongoing licence, legal obligation or other lawful exception requires it; deletion is not automatically a cancellation of a paid entitlement.
You may complain to the data-protection or privacy authority with jurisdiction over you. In the EEA, this includes your local supervisory authority; in the UK, the Information Commissioner's Office; and in Switzerland, the Federal Data Protection and Information Commissioner. Contacting us first is not a condition of that right.
10. Security
We use technical and organisational measures intended to protect personal information, including access restrictions and safeguards for authentication and transport. No website, network or storage system can be guaranteed completely secure. This statement does not waive our legal duties concerning security, breach notification or remedies.
If you suspect an account or security problem, contact us at the address at the bottom of this page. Avoid including passwords, full payment details or unnecessary private project material in the report.
11. Children
Our website, accounts and products are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided information, contact us so we can investigate and take appropriate action. The age threshold states our intended audience; it does not replace protections required by applicable children's privacy law.
12. Changes to this policy
We identify the effective date at the top of this policy. We will notify you of material changes through an appropriate website notice and, where relevant, account email. If a new purpose or technology requires consent, we will ask before starting that processing. A policy update or continued use of a paid product does not itself provide optional marketing or tracking consent.
Perfect Pitch Audio LLC · [email protected]
2291 Moss Court, Thousand Oaks, CA 91362, USA · +1 820-386-4159