Privacy Policy
Last updated: 6 September 2026
Prodboard is a project-management, backup and file-sharing service for music producers. This policy explains exactly what we collect, why, where it lives and what you can do about it. It is written to be read, not to be survived.
The short version: we store what the product needs to work — your account, your projects and the files you upload. We do not sell your data, we do not use it to train AI models, and we never see your card details.
Who we are
Prodboard is operated by MG Studio, a business registered in Israel, which is the data controller for the information described here. For anything in this policy, including data requests, write to support@prodboard.io.
What we collect
Account
Your email address, display name and (if you sign in with Google) your profile picture. Passwords are handled by our authentication provider and are never visible to us; if you sign in with Google we never receive a password at all.
Your content
Everything you put into the product: project titles, notes, tasks, tempo and key, financial figures you record, contacts you add, and the files you upload — audio, stems, DAW project files, cover art and voice notes. This is your material. We store it so the product can show it back to you and so you can share it.
Backups from the desktop app
If you install the desktop app and point it at your project folders, it uploads copies of those DAW project files, with version history, so you can restore them later. It watches only the folders you choose. It reads project files to identify the DAW, tempo and key; it does not scan the rest of your computer.
Session tracking
When the desktop app is running it records when a DAW session starts and ends, which DAW it was, which project, how many saves you made, and the name of the machine. This is what produces your studio-time statistics.
Share analytics
When someone opens a link you shared, we record the event (viewed, played, completed, downloaded, commented), the country, the device type, the referring page and how long they listened — so you can see whether a client actually heard the track.
We do not store visitors' IP addresses. An IP is hashed one-way before it is written, purely so repeat visits can be counted without identifying anyone. The original address is never saved.
Diagnostics
Ordinary server logs — request paths, status codes, timing and error traces. They exist to fix faults and to stop abuse.
What we do not do
- We do not sell or rent your data to anyone, for any purpose.
- We do not use your audio, projects or files to train AI models.
- We do not run advertising or third-party ad trackers.
- We never receive your card number. Payments are handled entirely by our payment provider (see below).
- No person here listens to your audio. Nobody at Prodboard plays your tracks, and no employee opens your projects. Our servers do read the audio automatically, because several features cannot work otherwise: drawing the waveform you see on a file, packing a backup into a ZIP, and streaming a share to whoever you sent the link to. That processing is machine-only, happens because you asked for the feature, and nothing is kept from it beyond what you can see in the app.
Why we are allowed to hold it
Under the GDPR our legal bases are: performance of a contract for everything the product needs in order to function (your account, your content, your backups); legitimate interests for security, abuse prevention and basic diagnostics; legal obligation for billing and tax records; and consent for anything optional, which you can withdraw at any time.
Who processes it for us
We keep the list deliberately short, and every provider below is bound by a data processing agreement.
| Provider | What for | Where |
|---|---|---|
| Supabase | Database and sign-in | Ireland (EU) |
| Cloudflare R2 | File storage | Western Europe |
| Backblaze B2 | Second copy of files, for disaster recovery | Central Europe (EU) |
| Vercel | Hosting | EU / global edge |
| Upstash | Rate limiting | Ireland (EU) |
| Resend | Transactional email | Ireland (EU) |
| Lemon Squeezy | Payments and invoicing | United States |
| Sign in with Google, and the written insights on paid plans | Global | |
| Anthropic | The daily studio plan and weekly review, on paid plans | United States |
| OpenAI | AI cover art, if you ask for it | United States |
Your files and database records are stored in the European Union. Transfers outside the EU (payments, and Google sign-in if you use it) rely on the European Commission's Standard Contractual Clauses.
Where AI is used, and what it is given
Three features in Prodboard call an AI provider. All three are on paid plans, and none of them touch your audio.
- AI cover art. A text prompt describing your track — its title, genre, tempo and key — is sent to generate the image. It runs only when you press the button.
- The written insights on your Insights page. What is sent is
statistics about how you work: hours, sessions, streaks, which hours of the week you
are productive, how long projects sit at each stage, how many versions you saved,
your top genres, median tempo and most-used keys, and — if you track money in
Prodboard — your income, expenses and per-project profit. Project
names are replaced with tokens (
p1,p2) before anything leaves us, and put back on your screen afterwards, so the provider never receives the name of a track. - The daily plan and weekly review. The same shape of information, for the day or week it covers, with project names replaced the same way.
Your audio, your project files, your backups and your file names are never sent to an AI provider, for any feature. Cover art has two modes that call nobody — pick a generated pattern or upload your own image — and the insights and the daily plan have a rules-based version underneath, which is what you see on a free plan and whenever the AI is unavailable.
Payments
Lemon Squeezy is the merchant of record for every Prodboard subscription. They collect your payment details and billing address directly, handle sales tax and VAT, and issue your invoice. Prodboard receives only your email address, the plan you bought, the subscription status and the renewal date. We never see or store card numbers.
How long we keep it
- While your account is open: as long as you keep it there.
- After you delete something: removed from the product immediately and purged from storage within 30 days.
- After you delete your account: content and files deleted within 30 days. Billing records are kept for seven years, because tax law requires it.
- After a trial ends and you never subscribe: 90 days, then deleted.
- After a subscription lapses: 12 months, then deleted. You can download everything throughout, and we email you four times before the date.
- Server logs: up to 90 days.
- Share analytics: for the life of the share link.
- Backups: up to 90 days. Everything above describes the live service — but we also take a nightly encrypted backup of the database, and keep a copy of your files with a second storage provider, so that a bad day at one company is not the end of your work. Something you delete leaves the product straight away and is purged from live storage on the schedule above; it can still exist inside a backup taken before you deleted it, for up to 90 days, until that backup expires on its own.
We do not read those backups, and we never restore one to bring back something somebody deleted. They exist for one purpose: putting the service back if it breaks. For the same reason a backup cannot be edited — being unable to rewrite history is the whole point of one — which is why deleted data leaves a backup by expiring rather than by being reached into.
Your rights
Wherever you live, you can ask us to show you what we hold, correct it, export it, delete it, or restrict what we do with it — and you can object to processing based on legitimate interests. In the EU and UK these are statutory rights; we apply them to everyone.
Email support@prodboard.io and we will reply within 30 days. We will not make you jump through hoops, and asking costs nothing. If you are in the EU and unhappy with the outcome, you may complain to your national data protection authority.
Security
Traffic is encrypted in transit. Files are served through short-lived signed URLs rather than public links, so a shared file cannot be found by guessing.
Your project files are encrypted before they leave your computer. The desktop app seals each file with a key belonging to your account, and what arrives on our storage is the sealed version. Sealing started in September 2026: backups saved from then on are sealed. Versions saved before that date are stored unsealed and stay that way. Backing a project up again seals its current files; it does not go back and change older versions.
This is not end-to-end encryption, and we will not call it that. We hold your account's key, deliberately. You have to be able to get your work back after a lost laptop, a reinstall or a forgotten password, and for a backup product “we cannot help you” is not a feature. It also means our servers open a file when the product needs one: drawing a waveform, building a download, or streaming a track on a share page. Nobody here listens to your music, but the honest statement is that the capability exists rather than that it does not.
Database access is controlled in the application: every action checks who you are and that what you asked for belongs to you. Row-level security is switched on in the database as a second line behind that, not as the first.
We are, however, a small operation and no service can promise perfection — if you find a security problem, please tell us at support@prodboard.io and we will treat it as urgent.
Share links
A Prodboard share link is unlisted, not secret. Anyone holding the URL can open it unless you set a password, restrict it to named recipients or give it an expiry date. Search engines are asked not to index share pages, but the honest way to think about a link you send is that it can be forwarded.
Cookies and browser storage
Only what is necessary, and here is the complete list. Cookies first, then the handful of preferences kept in your browser's own storage instead of a cookie — the law treats both the same way, so both are listed.
| Cookie | What it does |
|---|---|
sb-* | Keeps you signed in. Set by our authentication provider. |
locale | Remembers the language you picked. |
currency | Remembers the currency you chose for figures and invoices. |
daw-prefs | Remembers which DAW you work in, so the app stops asking. |
prodboard_onboarded | Remembers that you finished setup, so it does not start over. |
pb_trial_ack | Remembers that you dismissed the trial notice, so it stays dismissed. |
pb_storage_ack | The same, for the storage notice. |
pb_rail | Remembers that you kept the notifications panel open beside your work. |
| Stored in your browser | What it does |
|---|---|
theme, pb_theme | Remembers whether you chose light or dark. |
pb_lang | Remembers the language you picked on this website. |
sidebar-collapsed, projects-view, projects-rail, projects-rail-width | Remembers how you left the app laid out. |
prodboard_onboarding_step | Remembers how far you got through setup, so a reload does not send you back to the start. |
prodboard_anonymous_name | The name you typed when commenting on a share link without an account, so you do not type it again. |
That is all of them. No advertising cookies, no analytics cookies, no third-party trackers — we run none, on this site or in the app. Everything above is either strictly necessary or a preference you set yourself, which is the category that does not require consent under the ePrivacy Directive and the GDPR. So there is no cookie banner to dismiss, and that is a deliberate choice rather than an oversight.
Children
Prodboard is not intended for anyone under 16. If you believe a child has created an account, write to us and we will remove it.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.