Veery — Privacy Policy
Effective date: 2026-09-04 Version: 1.1
This policy explains what Northlane Studio (TODO: razon social exacta) ("Northlane Studio", "we") does with personal data when you use Veery, the Veery account and https://northlanestudio.dev.
We are the data controller for that data. Contact: [email protected].
The short version
- The app works without an account, and without us. Installed and never signed in, Veery sends us nothing at all except an update check.
- Your music is yours, and it only leaves your computer if you switch on Veery Sync. When you do, your audio files are stored in your account so your other computers can get them back. Nobody else can see them, search them or download them — not other users, and not us for any purpose other than storing and returning them to you.
- We never share your files with anyone. Two accounts that upload the same song get two separate copies; nothing is pooled.
- You can delete them at any time, from the app, in one click.
- We do not sell your data, we do not run ads, we do not track you across the web, and we do not train any model on what you listen to.
- We collect the minimum needed to run an account, deliver a licence, sync your own settings between your own computers, and answer you when you write.
1. What we collect, and why
1.1 If you never create an account
| Data | Why | Legal basis | Kept |
|---|---|---|---|
| Update check: app version, OS, architecture, IP address | To tell you a new version exists and serve the right installer | Legitimate interest (delivering a working, secure product) | IP in server logs, 30 days |
Everything else — your library, your history, your settings, your files — stays in a local database on your computer. We cannot see it.
1.2 If you create an account
| Data | Why | Legal basis | Kept |
|---|---|---|---|
| Email address | Identify you, deliver your licence, password reset, service notices | Contract | While the account exists |
| Display name (optional) | Show it in the app | Contract | While the account exists |
| Password, stored hashed (scrypt, per-user salt) — never in readable form | Let you sign in | Contract | While the account exists |
| Sessions: a hashed token, device name, OS, app version, IP address, first and last use | Keep you signed in; let you and us spot a session that should not be there | Contract + legitimate interest (security) | Until you sign out, or 180 days idle |
| Entitlement: plan, trial start, purchase date, order reference, issued licence key; Veery Sync subscription start, renewal date and reference | Know whether your account has Pro and an active Veery Sync subscription | Contract | While the account exists; purchase and subscription records for 10 years (tax law) |
| Support messages and our notes on them | Answer you, and remember what we already tried | Contract + legitimate interest | 3 years |
| Administrative actions taken on your account (who did what, when) | Accountability: nobody on our side touches an account without leaving a trace | Legal obligation + legitimate interest | 3 years |
1.3 If you turn sync on
Sync is off unless you turn it on, and you choose what it covers. It has two independent switches — the data one, and the music one — and turning one on does not turn on the other.
Your data. It can include:
- your library index: titles, artists, albums, genres, durations, file paths, ratings, tags, date added;
- favourites and playlists;
- listening history: what played and when;
- settings: appearance, theme, shortcuts, moods.
Legal basis: contract (you asked us to sync it). Kept while sync is on, deleted within 30 days of you turning it off or closing your account.
Your music (Veery Sync). A separate, paid monthly subscription — not part of Veery Pro. While it is active, and the switch is on, the audio files of the tracks in your library are uploaded and stored under your account, so that signing in on another computer brings your music with you.
| Data | Why | Legal basis | Kept |
|---|---|---|---|
| The audio files themselves | So your library follows you between your own computers | Contract (you asked us to store them) | Until you delete them, turn the switch off, or close your account. If the subscription lapses you can still download them; new uploads stop. |
| Their file name, title, artist, album and length | To show them and to name the file sensibly on the other computer | Contract | Same |
| A SHA-256 hash of each file | To recognise a file you already uploaded and avoid uploading it twice | Contract | Same |
How your files are stored and protected:
- Each account has its own folder. Files are named by their hash, never by your file names, and one account cannot read another's — the request is rejected even by someone who knows the hash.
- There is no public link, no sharing feature and no way to make a file public. Not a setting we recommend against: a feature that does not exist.
- Veery Sync is a monthly subscription. There is no per-account quota you are meant to hit; a high cap exists only so that one account cannot fill the shared server's disk. The app tells you how much you have used.
- We do not listen to, scan, fingerprint, analyse or train anything on your files.
Never uploaded: anything from a folder you did not add to Veery, and anything that is not one of the audio formats Veery plays.
1.4 If you buy Pro
Payment is processed by Stripe, which is its own controller for what it collects. We never receive your card number. From them we receive: an order reference, the amount, the currency, the country used for tax, and the email used to buy. We keep the invoice records that the Argentine Republic tax law requires.
1.5 The website
https://northlanestudio.dev is a static site. It sets no cookies, runs no analytics, and loads no third-party trackers. The server keeps standard access logs (IP, timestamp, page, user agent) for 30 days, to keep the site up and spot abuse.
2. Who else sees it
We use a small number of processors, each bound by a contract to use the data only to give us the service:
| Who | What for | Where |
|---|---|---|
| DigitalOcean, LLC | Runs the server, the database and the disk where your files are stored | TODO: region del droplet (ej. New York, United States) |
| TODO: Resend / Postmark / SES | Sends account emails (verification, password reset, licence delivery) | TODO: segun el proveedor |
| Stripe | Takes payments, handles tax | the United States and Ireland |
| Cloudflare, Inc. | Serves and protects the website | Global edge network |
Apart from those, we disclose personal data only when the law makes us, or to defend a legal claim. We never sell it and we never rent it.
3. Data leaving your country
Our servers are in TODO: region del droplet (ej. New York, United States). If you are in the European Economic Area, the United Kingdom or Switzerland, that is an international transfer, and we rely on the European Commission Standard Contractual Clauses with each provider, plus the technical measures in clause 5. A copy of the relevant clauses is available on request at [email protected].
4. How long we keep it
The tables above give the specific periods. The rules behind them:
- While you use it: account data lives as long as the account.
- After you leave: synced data and every audio file you stored are deleted within 30 days; encrypted backups can hold a copy for up to 30 days more, after which they rotate out. Deleting your music from the app removes the files from the server immediately.
- What we must keep: invoices and tax records, for 10 years.
- Logs: 30 days.
5. How we protect it
- HTTPS everywhere; the API refuses plain HTTP.
- Passwords hashed with scrypt and a per-user salt. A stolen database does not hand anyone your password, and it does not hand us your password either — we cannot read it, which is why support can only reset a password, never tell you what it was.
- Session tokens are stored hashed: what is in the database cannot be replayed.
- Administrative access is limited to 1 account(s), protected by its own login, and every action it takes is written to an audit log.
- Database backups are encrypted at rest.
No system is perfectly secure. If a breach affects your data and creates a real risk to you, we will notify you and the competent authority within the deadlines the law sets (72 hours to the authority under the GDPR).
6. Your rights
Wherever you live, you can ask us to:
- access the data we hold about you, and get a copy;
- correct it if it is wrong;
- delete it (right to be forgotten);
- export it in a machine-readable format (portability);
- restrict or object to a particular use;
- withdraw consent, where consent is what we relied on.
Write to [email protected]. We answer within 30 days, free of charge. We may ask you to prove you are the account holder — for exactly the reason you would want us to.
Specific to where you live:
- Argentina (Ley 25.326 and its successor): you can also complain to the Agencia de Acceso a la Información Pública (AAIP).
- European Union / EEA / UK: you can complain to your national data protection authority. Our lead supervisory authority, if we have one, is named at https://northlanestudio.dev/legal/privacy.
- California: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not discriminate against anyone for exercising their rights.
7. Children
Veery is not for children under 16. We do not knowingly collect their data. If you believe a child gave us data, write to [email protected] and we will delete it.
8. Automated decisions
We make none. Nothing about your account is decided by an algorithm without a person, and we do not profile you.
9. Changes
We will post any new version at https://northlanestudio.dev/legal/privacy with a new date. For a material change we will email you or tell you in the app at least 30 days before it applies. Old versions stay published so you can see what changed.
10. Contact
Northlane Studio (TODO: razon social exacta) TODO: direccion postal completa Privacy: [email protected] We are not required to appoint a Data Protection Officer; privacy questions go to the address above.