Privacy Policy

Last updated: 6 August 2026

Prodboard is a project-management, backup and file-sharing service for music producers. This policy explains exactly what we collect, why, where it lives and what you can do about it. It is written to be read, not to be survived.

The short version: we store what the product needs to work — your account, your projects and the files you upload. We do not sell your data, we do not use it to train AI models, and we never see your card details.

Who we are

Prodboard is the data controller for the information described here. Registration and contact details are available on request. For anything in this policy, including data requests, write to support@prodboard.io.

What we collect

Account

Your email address, display name and (if you sign in with Google) your profile picture. Passwords are handled by our authentication provider and are never visible to us; if you sign in with Google we never receive a password at all.

Your content

Everything you put into the product: project titles, notes, tasks, tempo and key, financial figures you record, contacts you add, and the files you upload — audio, stems, DAW project files, cover art and voice notes. This is your material. We store it so the product can show it back to you and so you can share it.

Backups from the desktop app

If you install the desktop app and point it at your project folders, it uploads copies of those DAW project files, with version history, so you can restore them later. It watches only the folders you choose. It reads project files to identify the DAW, tempo and key; it does not scan the rest of your computer.

Session tracking

When the desktop app is running it records when a DAW session starts and ends, which DAW it was, which project, how many saves you made, and the name of the machine. This is what produces your studio-time statistics.

Share analytics

When someone opens a link you shared, we record the event (viewed, played, completed, downloaded, commented), the country, the device type, the referring page and how long they listened — so you can see whether a client actually heard the track.

We do not store visitors' IP addresses. An IP is hashed one-way before it is written, purely so repeat visits can be counted without identifying anyone. The original address is never saved.

Diagnostics

Ordinary server logs — request paths, status codes, timing and error traces. They exist to fix faults and to stop abuse.

What we do not do

Why we are allowed to hold it

Under the GDPR our legal bases are: performance of a contract for everything the product needs in order to function (your account, your content, your backups); legitimate interests for security, abuse prevention and basic diagnostics; legal obligation for billing and tax records; and consent for anything optional, which you can withdraw at any time.

Who processes it for us

We keep the list deliberately short, and every provider below is bound by a data processing agreement.

ProviderWhat forWhere
SupabaseDatabase and sign-inIreland (EU)
Cloudflare R2File storageWestern Europe
VercelHostingEU / global edge
UpstashRate limitingIreland (EU)
ResendTransactional emailIreland (EU)
Lemon SqueezyPayments and invoicingUnited States
GoogleSign in with Google, if you use itGlobal

Your files and database records are stored in the European Union. Transfers outside the EU (payments, and Google sign-in if you use it) rely on the European Commission's Standard Contractual Clauses.

If you use the AI cover-art feature, the text prompt describing your track is sent to an AI provider to generate the image. Your audio is never sent. The feature is optional and only runs when you ask for it.

Payments

Lemon Squeezy is the merchant of record for every Prodboard subscription. They collect your payment details and billing address directly, handle sales tax and VAT, and issue your invoice. Prodboard receives only your email address, the plan you bought, the subscription status and the renewal date. We never see or store card numbers.

How long we keep it

Your rights

Wherever you live, you can ask us to show you what we hold, correct it, export it, delete it, or restrict what we do with it — and you can object to processing based on legitimate interests. In the EU and UK these are statutory rights; we apply them to everyone.

Email support@prodboard.io and we will reply within 30 days. We will not make you jump through hoops, and asking costs nothing. If you are in the EU and unhappy with the outcome, you may complain to your national data protection authority.

Security

Traffic is encrypted in transit. Files are served through short-lived signed URLs rather than public links, so a shared file cannot be found by guessing. Database access is restricted at row level. We are, however, a small operation and no service can promise perfection — if you find a security problem, please tell us at support@prodboard.io and we will treat it as urgent.

Share links

A Prodboard share link is unlisted, not secret. Anyone holding the URL can open it unless you set a password, restrict it to named recipients or give it an expiry date. Search engines are asked not to index share pages, but the honest way to think about a link you send is that it can be forwarded.

Cookies

Only what is necessary: a session cookie so you stay signed in, and a local preference for your theme and language. No advertising or analytics cookies, so there is no cookie banner to dismiss.

Children

Prodboard is not intended for anyone under 16. If you believe a child has created an account, write to us and we will remove it.

Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.