Legal
Privacy Policy
Effective July 26, 2026
1. The short version
Tieline stores what a studio needs to run its client work — accounts, projects, client contacts, audio files, payment records — and nothing more. We don’t run ads, we don’t sell data, we don’t use third-party tracking, and the only cookies we set are the ones the app needs to work. That’s also why there is no cookie banner.
2. What we store
- Account data — your name, email, hashed password, avatar, and workspace settings.
- Studio content— projects, notes, client contact details, reference links, and the audio files uploaded by you or your clients. For your clients’ personal data, you are the data controller and Tieline processes it on your behalf, only to provide the service.
- Payment records — amounts, currencies, status, and Stripe identifiers. Card numbers and bank details never touch Tieline; they go directly to Stripe.
- Technical data — server logs and first-party performance metrics (page speed beacons), kept without advertising identifiers and used only to keep the service healthy.
3. Where it lives
Tieline runs on a small set of infrastructure providers acting as sub-processors:
- Supabase (AWS, US-West) — database and authentication.
- Cloudflare R2 — audio and file storage; downloads use short-lived signed links.
- Vercel — application hosting.
- Stripe— payments; money moves directly to the studio’s own Stripe account.
- Resend — transactional email (invites, receipts, password resets).
- Slack— only if a studio connects its own Slack webhook, notification texts are mirrored to that studio’s channel.
- Cloudflare Turnstile — abuse protection on public forms, where enabled.
Reference links pasted into a project (Spotify, Tidal, Apple Music, YouTube, SoundCloud) are resolved against those platforms’ public metadata endpoints so the link shows the artist and song name; only the link itself is sent.
3a. Cookies
Tieline sets only cookies the service needs to function:
- Session cookies — keep you signed in to the dashboard.
- Portal cookies — remember an unlocked, password-protected delivery and the name you sign notes with.
- Theme preference— stored in your browser’s local storage.
None of these are used for tracking or advertising, and no third-party analytics cookies exist here — so no consent banner is required. If that ever changes, this policy and the site will change with it.
4. What we don’t do
We don’t sell or rent personal data, we don’t use it for advertising, and we don’t use your audio or project content to train machine-learning models. Automated audio analysis (Soundcheck, waveforms) exists solely to produce the reports and players you see.
5. Retention and deletion
Content stays as long as your workspace needs it: studios can delete files, deliveries, clients, and projects at any time, and those deletions propagate to storage. Closing a workspace removes its content from live systems promptly and from encrypted backups on their rotation schedule (at most 35 days). Payment records may be retained longer where bookkeeping law requires it.
6. Your rights
You can access, correct, export, or delete your personal data — most of it directly in the app, the rest by emailing us. If you are in the EU/EEA or UK, you additionally have the GDPR rights to restriction, objection, portability, and to complain to your local supervisory authority. If you are a studio’s client, the studio is your first point of contact; we support them in answering your request.
7. Security
Traffic is encrypted in transit; files are served through expiring signed URLs; workspaces are isolated from each other at the database layer; passwords are hashed; delivery passwords are stored only as hashes. No internet service can promise perfect security, but access to production systems is limited and audited.
8. Children
Tieline is a business tool and not directed at children under 16.
9. Changes and contact
We’ll update this policy as Tieline evolves and announce material changes in the app or by email. Privacy questions and requests: hi@tieline.app.