Privacy Policy
This Privacy Policy explains how Doseedo LLC, a Delaware limited liability company ("Doseedo," "we," "us," or "our"), collects, uses, shares, and protects information in connection with the Doseedo desktop application, web application, mobile applications, AI tools, cloud sync, collaboration features, and related services (collectively, the "Service").
We've tried to write this in plain language. Where we use defined terms, they have the same meaning as in our Terms of Service.
Who is responsible for your data. Doseedo LLC, a Delaware limited liability company located at 611 South Dupont Highway, Suite 102, Dover, DE 19901, USA, is the controller of the personal information described in this Policy. For privacy questions or to exercise your rights, contact us at [email protected]. We identify ourselves here as required by the EU and UK GDPR and the California privacy laws (including CalOPPA).
1. Information We Collect
1.1 Information You Provide
Account information. When you register, we collect your name, email address, password (stored hashed), and any optional profile information you provide.
Payment information. If you subscribe to a paid plan or make a one-time purchase (such as a Dø Desktop licence), we collect billing information through our payment processor, Stripe. Stripe shares with us the name and email address on the payment, the billing country and any postal address you enter, the amount, and a transaction reference, which we keep with your purchase record. We do not store full payment card numbers; Stripe handles that.
Communications. When you contact us (support, sales, feedback), we keep records of those communications.
Your Content. Sessions, audio uploads, MIDI, project files, and other content you upload, create, or store through the Service. See Sections 2 and 3 for how we handle this.
1.2 Information Collected Automatically
Usage data. How you use the Service: features accessed, actions taken, sessions created, generations performed, errors encountered, performance metrics. We use this to operate and improve the Service. We collect this with the help of PostHog, a product-analytics provider that processes it on our behalf; you can opt out in Settings → Privacy & data (see Section 8).
Device and connection information. IP address, device type, operating system, application version, browser type, language settings, time zone, and similar technical information.
Dø Desktop application data. When you use Dø Desktop, the application: signs in with your Doseedo account and labels that sign-in with your computer's name so you can recognise and revoke it (Settings → API keys); confirms your licence with our servers when you convert a project and periodically while online, sending your account key, the application version, and your IP address; checks releases.doseedo.com and packs.doseedo.com for application and DAW-pack updates when it starts, sending the application version and your IP address; and sends crash and error reports to Sentry, containing the error message and stack trace, the application version and operating system, and a short trail of recent in-app actions, which may include the file names of projects you were converting. Crash reports are not linked to your account. Dø Desktop does not upload your project files or your plug-in list: conversions and plug-in matching run on your computer. It also keeps a log file and a licence cache on your computer (in the Doseedo folder under your user library); these stay on your machine unless you send them to us for support.
Cookies and similar technologies. We use cookies, local storage, and similar technologies to authenticate users, remember preferences, and analyze usage. See Section 8 for details.
1.3 Information from Third Parties
Authentication providers. If you sign in via Apple, Google, or another identity provider, we receive basic profile information from them (typically email address and name).
Payment processors. Our payment processor confirms transactions and shares limited information needed for billing.
DAW integrations. When you use Doseedo with third-party DAWs (Logic, Pro Tools, Ableton, etc.), we receive session metadata you choose to sync. We do not receive information from your DAW that you have not authorized us to receive.
2. How We Handle Your Content
Your sessions, audio uploads, generated content, and other creative work require special treatment. Here's how we handle it:
Cloud storage and sync. When you sync sessions to Doseedo's cloud, we store them on our infrastructure (currently hosted on Fly.io, Modal, Cloudflare R2, and Neon) so you can access them from your devices. Your sessions are private by default — only you can access them, except where you have invited specific collaborators.
Audio-to-session uploads. When you upload audio for transformation into session data, we process it and return the result. We delete the original audio upload from active processing systems after processing completes. Brief retention may occur for technical reliability (queue redundancy, error recovery) but does not exceed 30 days. We do not retain, archive, or distribute your original audio uploads.
Generated content. AI outputs you generate through the Service are stored as part of your session data. They are treated the same as other Your Content.
Collaboration. When you invite a collaborator to a session, that collaborator gains access to the session as you authorize. We make the session available to them through the Service. Collaborators can view, edit, and contribute according to the permissions you grant.
Training data. We do not use Your Content to train Doseedo's AI models. Your audio uploads, generated outputs, sessions, and other content are not added to Doseedo's training corpus. This is enforced architecturally — Your Content is stored separately from training data and is not accessible to training pipelines.
Provenance. The Service tracks provenance of sessions and generations to support the Service's version control and rights-tracking features. This metadata travels with your content and is visible to you and (where applicable) your collaborators.
Embedded watermark. Audio generated through the Service carries an inaudible watermark (AudioSeal) embedded at the source's native sample rate. The watermark conveys a "doseedo signal" classifier value, not a unique identifier; uniqueness comes from the SHA-256 of the audio bytes the user receives. The watermark is designed to survive normal post-production (MP3/Opus encoding, EQ, time-stretch, analog re-recording) and is imperceptible at typical listening conditions. Free-tier exports are always watermarked. Pro, Studio, and Power exports default to watermarked but can be exported clean on a per-generation basis. The watermark itself contains no personally identifying information.
Opting out of the watermark. Pro, Studio, and Power users may export specific generations without the audio-side watermark using the per-export toggle in the Service, so the exported audio will not carry the inaudible signal. Free-tier exports are always watermarked.
3. How We Use Information
We use information to:
- Provide the Service. Authenticate you, sync your sessions, run AI generation, deliver collaboration features, process payments.
- Improve the Service. Analyze usage patterns to identify bugs, prioritize features, and improve performance. This analysis uses aggregated and de-identified data where possible. We do not analyze Your Content for product improvement except in aggregate forms that do not identify specific creative work.
- Communicate with you. Send service announcements, security alerts, billing notices, and (with your consent) marketing communications. You can opt out of marketing at any time.
- Provide support. Respond to your inquiries, troubleshoot issues, and assist you with the Service.
- Ensure safety and integrity. Detect and prevent fraud, abuse, security incidents, and violations of our Terms.
- Comply with law. Meet legal obligations, respond to lawful requests, and enforce our agreements.
We do not sell Your Content or your personal information.
4. How We Share Information
We share information only as described here:
With your collaborators. When you invite collaborators, they gain access to the relevant session as you authorize.
With service providers. We use third-party service providers to operate the Service, including cloud hosting, payment processing, email delivery, analytics, customer support, and AI infrastructure. These providers process information on our behalf under contracts that limit their use of information to providing services to us.
Current categories of service providers include:
- Cloud infrastructure and hosting (Fly.io, Modal, Cloudflare, Neon, Vercel)
- Payment processing (Stripe)
- Email and communications (Resend)
- Authentication (Clerk)
- Product analytics and error monitoring (PostHog; Sentry for backend errors and for crash reports from Dø Desktop) — opt out of analytics in Settings → Privacy & data; Dø Desktop crash reports are not linked to your account
- Advertising measurement (Google Ads, Meta) — used only to measure our own ad campaigns; see Section 8
- Machine translation (Google Cloud Translation) — processes only the text you ask the Service to translate
- AI model providers for the optional bring-your-own-key chat (Anthropic, OpenAI, Google, xAI) — used only if you connect your own API key for one of these providers, in which case the chat messages you send in that mode are transmitted to that provider under your key and their terms. Doseedo's own AI features run on our infrastructure (Modal) and do not share Your Content with these providers.
- Customer support (email-based, via [email protected])
With DAW integrations. When you use Doseedo with a third-party DAW, the DAW vendor may receive limited information necessary for the integration to function. We do not control how DAW vendors handle their information; consult their privacy policies.
For legal reasons. We may disclose information when we have a good-faith belief that disclosure is required or permitted by law, including in response to subpoenas, court orders, or other legal process; to investigate or address violations of our Terms; or to protect the rights, property, or safety of Doseedo, our users, or the public.
In a corporate transaction. If Doseedo is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of the transaction, subject to commitments consistent with this Privacy Policy.
With your consent. We share information for other purposes when you direct or consent.
5. Your Choices and Rights
Access and correction. You can access and update most account information through your account settings.
Export. You can export your sessions and generated content at any time.
Deletion. You can delete sessions, generated content, and your account through account settings or by contacting us. When you delete content, we remove it from active systems; backup retention may persist for up to 30 days before full deletion. Deleting your account also ends any Dø Desktop licence bound to it (see Section 9.6 of the Terms of Service).
Marketing opt-out. You can opt out of marketing emails through the unsubscribe link in any marketing email or in your account settings.
Analytics and cookies. You can opt out of analytics and advertising measurement in Settings → Privacy & data, and manage cookies through your browser settings. Disabling essential cookies may limit Service functionality.
Regional rights. Depending on where you live, you may have additional rights:
- California residents (CCPA/CPRA). You have rights to know what personal information we collect, request deletion, request correction, opt out of sale or sharing, and not be discriminated against for exercising your rights. We do not sell personal information; our use of advertising-measurement tags may constitute "sharing" under the CPRA, which you can opt out of via the "Do Not Sell or Share My Personal Information" link in our page footers, Settings → Privacy & data, or the GPC browser signal (see Section 8). For other requests, contact [email protected]. You may designate an authorized agent.
- EEA, UK, and Switzerland residents (GDPR/UK GDPR). You have rights of access, rectification, erasure, restriction of processing, data portability, and objection. You can withdraw consent where processing is based on consent. You may lodge complaints with your supervisory authority. Our legal bases for processing are: contract performance (providing the Service), legitimate interests (improving the Service, security, fraud prevention), consent (where required, e.g., marketing), and legal obligation. Where we are required to designate an EU/UK representative under Article 27, we will identify them here and at [email protected].
- Other regions. Where applicable law provides additional rights, we honor them.
To exercise any of these rights, contact [email protected].
6. Data Retention
We retain information as long as needed to provide the Service and as required or permitted by law. Specifically:
- Account information: While your account is active, plus a reasonable period after closure for legal and operational reasons.
- Your Content: While stored in your account; deleted when you delete it (with backup retention as noted above).
- Audio-to-session uploads: Deleted after processing as described in Section 2.
- Usage data: Typically retained in identifiable form for up to 24 months, then aggregated or deleted.
- Communications and support records: Retained for up to 3 years for service improvement and legal purposes.
- Billing records: Retained as required by tax and accounting laws (typically 7 years). Dø Desktop licence records (the purchase reference and its status) are kept for as long as the licence exists, so we can honour it.
- Crash reports: Retained by Sentry for up to 90 days.
7. Security
We use technical and organizational measures to protect information, including encryption in transit (TLS), encryption at rest for sensitive data, access controls, audit logging, and secure development practices. No system is perfectly secure; we cannot guarantee absolute security but commit to industry-standard practices and to notifying affected users of security incidents as required by law.
8. Cookies, Analytics, and Advertising Measurement
We use:
- Essential cookies. Required for authentication and core Service functionality. Cannot be disabled.
- Functional cookies. Remember preferences and settings. Can be disabled but may affect functionality.
- Analytics. We use PostHog to understand how the Service is used (pages viewed, features used, errors). If you sign in, analytics events are associated with your account (including your email address) so we can understand and support your use of the Service.
- Advertising measurement. We run ads for Doseedo on Google and Meta (Instagram/Facebook), and we use those platforms' measurement tags on our site — the Google Ads tag and the Meta pixel (which sets the _fbp/_fbc cookies) — to know whether our ads lead to sign-ups and purchases. When you arrive from an ad, we also store the ad click identifier (e.g. gclid, fbclid) and may send it, with the conversion event, back to the ad platform (including server-side) so the campaign that brought you can be credited. We use these tags only to measure and improve our own advertising; we do not sell your personal information or show third-party ads in the Service.
Consent. If you visit from the EEA, the UK, or Switzerland, analytics and advertising-measurement tags do not run until you allow them in the consent banner shown on your first visit ("Accept all" or "Essential only"). You can change your choice at any time in Settings → Privacy & data or via the "Do Not Sell or Share My Personal Information" link in our page footers.
Opting out. Everywhere else, you can turn off analytics and advertising measurement for your browser at any time in Settings → Privacy & data, via the footer link above, or right here: open my privacy choices. Essential cookies stay on either way, and you can also manage cookies through your browser settings.
Global Privacy Control. We honor the Global Privacy Control (GPC) browser signal as a binding opt-out of advertising measurement and of any "sale" or "sharing" of personal information as those terms are defined by the California privacy laws.
9. International Data Transfers
Doseedo is based in the United States. If you are outside the United States, the information we collect may be transferred to and processed in the United States or other countries where we or our service providers operate. These countries may have data protection laws different from those in your country.
For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other appropriate safeguards.
10. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn we have collected information from a child under 13, we will delete it. Parents or guardians who believe their child has provided information should contact [email protected].
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you (for example, by email or in-product notice) before the changes take effect.
12. Contact
Questions about this Privacy Policy or our practices? Contact us at:
Doseedo LLC 611 South Dupont Highway, Suite 102 Dover, DE 19901, USA [email protected]
For copyright/DMCA matters, see our Terms of Service or contact [email protected].
Doseedo LLC — 611 South Dupont Highway, Suite 102, Dover, DE 19901
[email protected]