Privacy Policy

Last updated: 6 September 2026

Prodboard is a project-management, backup and file-sharing service for music producers. This policy explains exactly what we collect, why, where it lives and what you can do about it. It is written to be read, not to be survived.

The short version: we store what the product needs to work — your account, your projects and the files you upload. We do not sell your data, we do not use it to train AI models, and we never see your card details.

Who we are

Prodboard is operated by MG Studio, a business registered in Israel, which is the data controller for the information described here. For anything in this policy, including data requests, write to support@prodboard.io.

What we collect

Account

Your email address, display name and (if you sign in with Google) your profile picture. Passwords are handled by our authentication provider and are never visible to us; if you sign in with Google we never receive a password at all.

Your content

Everything you put into the product: project titles, notes, tasks, tempo and key, financial figures you record, contacts you add, and the files you upload — audio, stems, DAW project files, cover art and voice notes. This is your material. We store it so the product can show it back to you and so you can share it.

Backups from the desktop app

If you install the desktop app and point it at your project folders, it uploads copies of those DAW project files, with version history, so you can restore them later. It watches only the folders you choose. It reads project files to identify the DAW, tempo and key; it does not scan the rest of your computer.

Session tracking

When the desktop app is running it records when a DAW session starts and ends, which DAW it was, which project, how many saves you made, and the name of the machine. This is what produces your studio-time statistics.

Share analytics

When someone opens a link you shared, we record the event (viewed, played, completed, downloaded, commented), the country, the device type, the referring page and how long they listened — so you can see whether a client actually heard the track.

We do not store visitors' IP addresses. An IP is hashed one-way before it is written, purely so repeat visits can be counted without identifying anyone. The original address is never saved.

Diagnostics

Ordinary server logs — request paths, status codes, timing and error traces. They exist to fix faults and to stop abuse.

What we do not do

Why we are allowed to hold it

Under the GDPR our legal bases are: performance of a contract for everything the product needs in order to function (your account, your content, your backups); legitimate interests for security, abuse prevention and basic diagnostics; legal obligation for billing and tax records; and consent for anything optional, which you can withdraw at any time.

Who processes it for us

We keep the list deliberately short, and every provider below is bound by a data processing agreement.

ProviderWhat forWhere
SupabaseDatabase and sign-inIreland (EU)
Cloudflare R2File storageWestern Europe
Backblaze B2Second copy of files, for disaster recoveryCentral Europe (EU)
VercelHostingEU / global edge
UpstashRate limitingIreland (EU)
ResendTransactional emailIreland (EU)
Lemon SqueezyPayments and invoicingUnited States
GoogleSign in with Google, and the written insights on paid plansGlobal
AnthropicThe daily studio plan and weekly review, on paid plansUnited States
OpenAIAI cover art, if you ask for itUnited States

Your files and database records are stored in the European Union. Transfers outside the EU (payments, and Google sign-in if you use it) rely on the European Commission's Standard Contractual Clauses.

Where AI is used, and what it is given

Three features in Prodboard call an AI provider. All three are on paid plans, and none of them touch your audio.

Your audio, your project files, your backups and your file names are never sent to an AI provider, for any feature. Cover art has two modes that call nobody — pick a generated pattern or upload your own image — and the insights and the daily plan have a rules-based version underneath, which is what you see on a free plan and whenever the AI is unavailable.

Payments

Lemon Squeezy is the merchant of record for every Prodboard subscription. They collect your payment details and billing address directly, handle sales tax and VAT, and issue your invoice. Prodboard receives only your email address, the plan you bought, the subscription status and the renewal date. We never see or store card numbers.

How long we keep it

We do not read those backups, and we never restore one to bring back something somebody deleted. They exist for one purpose: putting the service back if it breaks. For the same reason a backup cannot be edited — being unable to rewrite history is the whole point of one — which is why deleted data leaves a backup by expiring rather than by being reached into.

Your rights

Wherever you live, you can ask us to show you what we hold, correct it, export it, delete it, or restrict what we do with it — and you can object to processing based on legitimate interests. In the EU and UK these are statutory rights; we apply them to everyone.

Email support@prodboard.io and we will reply within 30 days. We will not make you jump through hoops, and asking costs nothing. If you are in the EU and unhappy with the outcome, you may complain to your national data protection authority.

Security

Traffic is encrypted in transit. Files are served through short-lived signed URLs rather than public links, so a shared file cannot be found by guessing.

Your project files are encrypted before they leave your computer. The desktop app seals each file with a key belonging to your account, and what arrives on our storage is the sealed version. Sealing started in September 2026: backups saved from then on are sealed. Versions saved before that date are stored unsealed and stay that way. Backing a project up again seals its current files; it does not go back and change older versions.

This is not end-to-end encryption, and we will not call it that. We hold your account's key, deliberately. You have to be able to get your work back after a lost laptop, a reinstall or a forgotten password, and for a backup product “we cannot help you” is not a feature. It also means our servers open a file when the product needs one: drawing a waveform, building a download, or streaming a track on a share page. Nobody here listens to your music, but the honest statement is that the capability exists rather than that it does not.

Database access is controlled in the application: every action checks who you are and that what you asked for belongs to you. Row-level security is switched on in the database as a second line behind that, not as the first.

We are, however, a small operation and no service can promise perfection — if you find a security problem, please tell us at support@prodboard.io and we will treat it as urgent.

Share links

A Prodboard share link is unlisted, not secret. Anyone holding the URL can open it unless you set a password, restrict it to named recipients or give it an expiry date. Search engines are asked not to index share pages, but the honest way to think about a link you send is that it can be forwarded.

Cookies and browser storage

Only what is necessary, and here is the complete list. Cookies first, then the handful of preferences kept in your browser's own storage instead of a cookie — the law treats both the same way, so both are listed.

CookieWhat it does
sb-*Keeps you signed in. Set by our authentication provider.
localeRemembers the language you picked.
currencyRemembers the currency you chose for figures and invoices.
daw-prefsRemembers which DAW you work in, so the app stops asking.
prodboard_onboardedRemembers that you finished setup, so it does not start over.
pb_trial_ackRemembers that you dismissed the trial notice, so it stays dismissed.
pb_storage_ackThe same, for the storage notice.
pb_railRemembers that you kept the notifications panel open beside your work.
Stored in your browserWhat it does
theme, pb_themeRemembers whether you chose light or dark.
pb_langRemembers the language you picked on this website.
sidebar-collapsed, projects-view, projects-rail, projects-rail-widthRemembers how you left the app laid out.
prodboard_onboarding_stepRemembers how far you got through setup, so a reload does not send you back to the start.
prodboard_anonymous_nameThe name you typed when commenting on a share link without an account, so you do not type it again.

That is all of them. No advertising cookies, no analytics cookies, no third-party trackers — we run none, on this site or in the app. Everything above is either strictly necessary or a preference you set yourself, which is the category that does not require consent under the ePrivacy Directive and the GDPR. So there is no cookie banner to dismiss, and that is a deliberate choice rather than an oversight.

Children

Prodboard is not intended for anyone under 16. If you believe a child has created an account, write to us and we will remove it.

Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.