Privacy

Privacy Policy

Last updated 24 September 2026

smartist is a tool for musicians to keep their songs, setlists, gigs and venues in order. This page explains what it stores, why, who else sees it, and how to get it all back or have it erased.

It is written to be read rather than to be impressive. If something here is unclear, ask · the address is at the bottom.

Who is responsible

Kevin Sieg
5 Place Saint Etienne
76400 Fécamp
France

Email: hi [at] smartist.studio

This is a one-person project, not a company. There is no data protection officer, which is permitted at this scale.

What this covers

smartist.studio (this site), app.smartist.studio (the application), and demo.smartist.studio (the public demo). Bands who run smartist on their own domain or their own servers are responsible for their own copy · this policy covers the instances listed above.

What is collected

Your account. Your email address, a bcrypt hash of your password (never the password itself), your role in a workspace, and the date you joined. If you were invited, a temporary invitation token until you accept.

What you put in. Everything you enter: songs and their details, lyrics, setlists, gigs, venues and organisers including any contact details you record for them, rights and royalty data, and a log of changes made to songs. If you record a venue's phone number or a promoter's email, that is personal data about them, held because you chose to record it.

Files you upload. Audio recordings, sheet music and playback tracks.

Technical data. Server logs covering requests, errors and security events, and a short-lived record of request counts per address used to rate-limit abuse such as password guessing.

If you write to us. The contact form and the mailing-list signup store the address and message you send.

What is not collected

There are no analytics, no tracking pixels, no advertising, and no third-party scripts watching you use the app. Nothing about your behaviour is profiled or sold. This is not a policy promise that could change quietly · there is simply no such code, in either the site or the application, both of which are open source and can be checked.

Cookies and browser storage

smartist sets no cookies. Your login session is held in your browser's sessionStorage and disappears when you close the tab; your language choice and a few interface preferences are held in localStorage. None of it is sent anywhere except your session token, which authenticates your own requests.

Why, and on what legal basis

Where processing rests on consent, you can withdraw it at any time.

Who else processes it

Running the service needs a small number of providers. Each acts on instructions and for no other purpose.

Vercel
Hosting and delivery of the site and application.
Neon
The PostgreSQL database holding accounts and content.
Cloudflare R2
Storage for audio, sheet music and playback files.
Resend
Sending transactional email · invitations, password resets, sign-in links, shared setlists.
BetterStack
Application logs in production.
Google (Gemini)
Only when you ask for a lyric suggestion. The song title and artist name are sent so the model can search for them. Your own lyrics and files are never sent.
Google / Meta
Only if you choose to sign in with Google or Facebook. We receive your email address from them and nothing else. Signing in with an email address and password avoids this entirely.

Some of these providers operate outside the European Economic Area. Where that happens, transfers rest on the European Commission's Standard Contractual Clauses or an adequacy decision.

The donation buttons link to Liberapay and Buy Me a Coffee. Their button images load from those providers, which means those providers can see your IP address on pages where a button appears. Following a link takes you to their site, under their own privacy policy, and any payment is handled entirely by them · no payment details ever reach smartist.

How long it is kept

Your content is kept while your workspace exists. Songs, venues and organisers you delete are marked deleted and kept for a while so they can be restored, then removed. Server logs are kept for a limited period for security and debugging. Rate-limiting records expire within hours.

When an account is deleted, its content is deleted with it. Backups roll off on their own schedule, so a deleted item may persist in a backup for a short period after it disappears from the app.

Your rights

Under the GDPR you may request access to your data, correction of it, erasure of it, a copy in portable form, restriction of processing, and you may object to processing based on legitimate interest.

Getting a copy is built in. Before deleting your account, your profile offers a download of everything in the workspaces that would be deleted with it · songs, gigs, setlists, venues, organisers, rights data and change history · as spreadsheet files (CSV, in one ZIP). For anything else, email the address below and you will get the same export.

Deletion is built in too. From your profile you can delete your account. We email a confirmation link to the address on the account; nothing is deleted until you open it and confirm. Workspaces only you belong to are deleted with everything in them. Workspaces you share with others carry on without you. If you are the only admin of a workspace that has other members, you first need to make someone else admin or remove them. If you cannot use the button, email hi [at] smartist.studio from the address on the account and it will be done within 30 days.

If you believe your data is being handled wrongly, you can complain to the French supervisory authority, the CNIL, or the authority where you live.

Children

smartist is not directed at children and accounts are not knowingly created for anyone under 16.

Changes

If this policy changes materially, the date at the top changes and account holders are told by email. The history of this page is public in the project's repository, so any edit can be seen.