Privacy Policy

Effective date: May 5, 2025

1. What We Collect

We collect the following information when you use Stave:

  • Account information: your name, email address, and profile picture from Google OAuth or email sign-up.
  • Uploaded files: the PDF files you submit for processing. These are used only to render the score and are not stored permanently on our servers.
  • Usage data: the number of uploads you perform per week, stored in your browser's local storage to enforce free-tier limits.
  • Payment information: handled entirely by our payment processor; we never see or store your full card details.
  • Log data: standard server logs including IP address, browser type, and pages visited, retained for up to 90 days.

2. How We Use Your Data

  • To provide and improve the Service.
  • To authenticate you and manage your subscription.
  • To send transactional emails (receipts, password resets, material policy updates).
  • To enforce fair-use limits and prevent abuse.

We do not sell your personal data to third parties.

3. Third-Party Services

We share data with the following third parties only as necessary to run the Service:

  • Google: for OAuth sign-in. Subject to Google's Privacy Policy.
  • AI provider: your uploaded sheet music images are sent to a third-party AI API for notation extraction. Images are processed in real time and not retained by the provider beyond the request.
  • Payment processor: payment and billing data are handled by our payment processor under their own privacy terms.
  • Hosting provider: server infrastructure and logs are managed by our cloud hosting provider.

4. Cookies and Local Storage

We use session cookies set by NextAuth to keep you signed in. We also use browser local storage to track your weekly upload count and your preferred display theme. No advertising or tracking cookies are used.

5. Data Retention

Account data is retained for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law (e.g. financial records).

6. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export the personal data we hold about you. To exercise any of these rights, email us at support@stave.app. We will respond within 30 days.

7. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us and we will delete it promptly.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice in the Service at least 14 days before they take effect.

9. Contact

Privacy questions or requests? Email support@stave.app.