Privacy Policy
Last updated 24 September 2026
smartist is a tool for musicians to keep their songs, setlists, gigs and venues in order. This page explains what it stores, why, who else sees it, and how to get it all back or have it erased.
It is written to be read rather than to be impressive. If something here is unclear, ask · the address is at the bottom.
Who is responsible
Kevin Sieg
5 Place Saint Etienne
76400 Fécamp
France
Email: hi [at] smartist.studio
This is a one-person project, not a company. There is no data protection officer, which is permitted at this scale.
What this covers
smartist.studio (this site), app.smartist.studio (the application), and demo.smartist.studio (the public demo). Bands who run smartist on their own domain or their own servers are responsible for their own copy · this policy covers the instances listed above.
What is collected
Your account. Your email address, a bcrypt hash of your password (never the password itself), your role in a workspace, and the date you joined. If you were invited, a temporary invitation token until you accept.
What you put in. Everything you enter: songs and their details, lyrics, setlists, gigs, venues and organisers including any contact details you record for them, rights and royalty data, and a log of changes made to songs. If you record a venue's phone number or a promoter's email, that is personal data about them, held because you chose to record it.
Files you upload. Audio recordings, sheet music and playback tracks.
Technical data. Server logs covering requests, errors and security events, and a short-lived record of request counts per address used to rate-limit abuse such as password guessing.
If you write to us. The contact form and the mailing-list signup store the address and message you send.
What is not collected
There are no analytics, no tracking pixels, no advertising, and no third-party scripts watching you use the app. Nothing about your behaviour is profiled or sold. This is not a policy promise that could change quietly · there is simply no such code, in either the site or the application, both of which are open source and can be checked.
Cookies and browser storage
smartist sets no cookies. Your login session is held in your browser's sessionStorage and disappears when you close the tab; your language choice and a few interface preferences are held in localStorage. None of it is sent anywhere except your session token, which authenticates your own requests.
Why, and on what legal basis
- To provide the service · your account and your content. Performance of a contract (GDPR Art. 6(1)(b)).
- To keep it secure and working · logs and rate limiting. Legitimate interest (Art. 6(1)(f)).
- To answer you · contact form messages. Legitimate interest, or consent where you signed up for updates (Art. 6(1)(a)).
Where processing rests on consent, you can withdraw it at any time.
Who else processes it
Running the service needs a small number of providers. Each acts on instructions and for no other purpose.
Some of these providers operate outside the European Economic Area. Where that happens, transfers rest on the European Commission's Standard Contractual Clauses or an adequacy decision.
The donation buttons link to Liberapay and Buy Me a Coffee. Their button images load from those providers, which means those providers can see your IP address on pages where a button appears. Following a link takes you to their site, under their own privacy policy, and any payment is handled entirely by them · no payment details ever reach smartist.
How long it is kept
Your content is kept while your workspace exists. Songs, venues and organisers you delete are marked deleted and kept for a while so they can be restored, then removed. Server logs are kept for a limited period for security and debugging. Rate-limiting records expire within hours.
When an account is deleted, its content is deleted with it. Backups roll off on their own schedule, so a deleted item may persist in a backup for a short period after it disappears from the app.
Your rights
Under the GDPR you may request access to your data, correction of it, erasure of it, a copy in portable form, restriction of processing, and you may object to processing based on legitimate interest.
Getting a copy is built in. Before deleting your account, your profile offers a download of everything in the workspaces that would be deleted with it · songs, gigs, setlists, venues, organisers, rights data and change history · as spreadsheet files (CSV, in one ZIP). For anything else, email the address below and you will get the same export.
Deletion is built in too. From your profile you can delete your account. We email a confirmation link to the address on the account; nothing is deleted until you open it and confirm. Workspaces only you belong to are deleted with everything in them. Workspaces you share with others carry on without you. If you are the only admin of a workspace that has other members, you first need to make someone else admin or remove them. If you cannot use the button, email hi [at] smartist.studio from the address on the account and it will be done within 30 days.
If you believe your data is being handled wrongly, you can complain to the French supervisory authority, the CNIL, or the authority where you live.
Children
smartist is not directed at children and accounts are not knowingly created for anyone under 16.
Changes
If this policy changes materially, the date at the top changes and account holders are told by email. The history of this page is public in the project's repository, so any edit can be seen.