Privacy Policy

Last updated: 27 August 2026

Questions or requests: [email protected]

This policy explains what setshed stores, where it lives, and how to get it back or have it removed.

1. What we store

Your account. Your email address, a one way hash of your password (never the password itself), your display name, and the date you signed up. If you sign in with Google we store your email address and the fact that Google is your sign in method. We never receive your Google password.

Your band’s library. The material your band puts into setshed, however it gets there: audio stems uploaded individually or as a zipped folder, imported from a file, or synced from connected hardware. That includes backing videos, MIDI files, chart PDFs, lyrics, chords, markers, setlists, playlists, song and track settings, and the notes, riff recordings and lyric drafts your band creates in the app. Every saved version is kept so the band can go back to an earlier one.

Activity records. A per band history of who did what and when (saves, imports, invitations, role changes), and a system record of sign ins, registrations and errors. These include your email address and the IP address the request came from.

Connected hardware. If you connect a device, we store which device a band is synced with, its identifier and name, and the version of the setshed agent installed on your computer. We use this to sync correctly and to diagnose faults.

In your browser. A sign in cookie, a cookie recording which band you are viewing, and local preferences such as your sort order. These are not used for advertising or tracking across sites.

We do not use advertising networks, and we do not sell or share your data with anyone for marketing.

2. Where it is stored

The application and its database run on servers we operate. Audio and other large files are stored in Cloudflare R2. Traffic reaches us through Cloudflare, which sees connection data such as IP addresses in the course of delivering it. Transactional email (password resets, invitations) is sent through our email provider. If you choose to sign in with Google, Google handles that sign in.

These providers process data on our instructions in order to run the service. We do not give them your material for their own purposes.

3. Why we store it

To run the service you asked for: keeping your library safe, syncing it to your devices, letting your band work together, signing you in, sending the emails the service depends on, keeping the service secure, and investigating faults. Where the law requires a legal basis, ours is the performance of our agreement with you and our legitimate interest in operating and securing the service.

4. Sharing links

If you create a share link for a song or an export, anyone holding that link can download that file until it expires. Treat a share link as public. You can see and revoke your links in the app.

5. How long we keep it

Your account and library stay until they are deleted (see section 7). Version history is kept for as long as the library exists, because it is what lets a band undo a mistake. Activity and sign in records are kept for up to 12 months for security and troubleshooting. Backups are kept for up to 30 days and are overwritten on a rolling basis, so deleted material can persist in a backup for that period before it disappears.

6. Your rights

Depending on where you live, you may have the right to access your data, correct it, export it, restrict or object to how we use it, and ask for it to be deleted. You can also complain to your local data protection authority.

You can download your own material from the app at any time, without asking us.

7. Deleting your data

There are two different things here, and they are treated differently on purpose.

Your account. You can ask us to delete your account. We will remove your email address, display name, sign in credentials and your personal activity records, and remove you from any bands you belong to.

A band’s library. A band library is shared work. It usually contains material created and paid for by several people, so it is not deleted on the say so of one member. Deleting a band library can only be requested by the band’s owner, and it removes the material for every member of that band.

If you leave a band, or ask us to delete your account, the band’s library remains with the band. Your personal data is removed from it. Material you contributed to the shared library stays, in the same way that a part you recorded for a band’s song remains part of that song.

How to make a request. Email [email protected] from the address on your account and tell us what you want removed. We verify that the request genuinely comes from the account holder, and for a band library that you are its owner. We record every request and what we did about it, including the date and who asked.

Deletion is carried out by us rather than by a button in the app. That is deliberate: it gives us a chance to confirm the request is genuine and, where a whole band’s work is involved, to notify the other members before anything is destroyed. We aim to complete requests within 30 days, and will tell you if it will take longer and why. For a band library we allow a short confirmation period before we act, so an accidental or disputed request can be withdrawn.

Once deleted, material cannot be recovered, except that it may remain in encrypted backups for up to 30 days as described above. We may keep a minimal record of the request itself (that an account was deleted, when, and at whose request) so we have a record that we acted correctly.

8. Security

Traffic to setshed is encrypted in transit. Passwords are stored only as hashes. Access to your library requires being signed in and being a member of that band. Access to the servers is limited to the people who operate the service.

No service can promise perfect security. If a breach affects your data we will tell you and, where required, the relevant authority.

9. Children

setshed is not intended for children under 16, and we do not knowingly create accounts for them.

10. Changes

If we change this policy we will update the date at the top and, for anything significant, tell you in the app or by email.