This Privacy Policy explains how MySetlist.app ("we", "us") collects, uses and protects your personal data when you use mysetlist.app (the "Service"), including the website, the web application, the MySetlist.app Desktop Audio Bridge, and the MySetlist.app Song Sections Exporter device for Ableton Live. A note on the Song Sections Exporter. This is a Max for Live device that runs entirely inside Ableton Live on your own computer. It reads your arrangement and writes a JSON file to your local disk. It does not connect to our servers, does not send us any data, and does not require an account. We receive nothing from it unless you choose to upload the exported file to your MySetlist.app account yourself. We are the data controller for this processing under the General Data Protection Regulation (GDPR).
MySetlist.app ("MySetlist.app", "we", "us", "our") is operated by:
Privacy questions : privacy@mysetlist.app
Security reports : security@mysetlist.app
We are not required to appoint a Data Protection Officer. For any privacy question, use the email address above.
When you create an account we process your email address, your password (stored only as a salted hash — we never see it), your display name, and an optional profile picture. MySetlist.app accounts use email and password only. We do not offer sign-in through Facebook, Google, Apple or any other social or identity provider, so no data about you is exchanged with those companies when you register or log in.
If you take a paid plan we process your plan type, subscription status, billing period and invoice history. Payments themselves are handled by Stripe. We never receive or store your full card number. For invoicing and EU VAT purposes we (or Stripe on our behalf) process your name, billing address, country and, where applicable, VAT number.
The Service is built to store the material you put into it: artist and band profiles, setlists, songs, audio stems, sheet music, lyrics, notes, song section data and any images you upload. You can also record rights and copyright information alongside your songs — for example composer and lyricist credits, publisher, rights holder, PRO or collecting society affiliation, ISRC or ISWC codes, and licensing notes. This information often names real people, so it counts as personal data where those people are identifiable. You are responsible for having a proper basis to record details about third parties such as co-writers, and for keeping that information accurate. Content you upload may contain personal data in other ways too — band member names, or a photograph. You decide what you upload. Your content is private to your account and the accounts you explicitly grant access to. We do not use your audio, sheet music or setlists to train machine learning models, and we do not sell or license it.
When you use the Service we automatically process your IP address, browser type and version, operating system, device type, timestamps of requests, pages and features used, and error and diagnostic logs. Our hosting provider and Cloudflare also log this data for security and abuse prevention.
If you email us or submit a support request, we process the content of that message and any attachments you send.
Purpose Legal basis (GDPR Art. 6)
Creating and managing your account; Performance of a contract (Art. 6(1)(b)) providing the Service
Storing, streaming and syncing your Performance of a contract (Art. 6(1)(b)) content
Processing payments, subscriptions and Performance of a contract (Art. 6(1)(b)) and legal invoices obligation (Art. 6(1)(c))
Retaining invoices and tax records Legal obligation — Dutch tax law (Art. 6(1)(c))
Service, security and outage emails Performance of a contract (Art. 6(1)(b))
Securing the Service, preventing abuse Legitimate interests (Art. 6(1)(f)) — keeping the and fraud, debugging Service available and secure
Handling support requests Performance of a contract / legitimate interests (Art.
Aggregated, cookieless website statistics Legitimate interests (Art. 6(1)(f)) — understanding
Marketing emails to people who are not Your consent (Art. 6(1)(a)) customers
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing that took place before you withdrew.
We do not use advertising, tracking or profiling cookies. We do not use the Facebook (Meta) Pixel, Google Analytics, or any other cross-site advertising technology. We do not build advertising profiles and we do not track you across other websites. The only cookies and browser storage we use are strictly necessary for the Service to function. Under Article 11.7a(3) of the Dutch Telecommunications Act these are exempt from the consent requirement, which is why you will not see a cookie banner.
Name / purpose Set by What it does Retention
Authentication MySetlist.app Keeps you logged in Session / until session (Supabase) logout or
Security token MySetlist.app Protects against cross-site request Session
Player and interface MySetlist.app Remembers volume, mute/solo, active Local storage, state artist, and which browser tab is until cleared
__cf_bm Cloudflare Distinguishes real visitors from bots; 30 minutes
cf_clearance Cloudflare Records that a security challenge was Up to 1 year
__stripe_mid , Stripe Fraud detection during payment. Only 1 year / 30 __stripe_sid set on our billing and checkout pages, minutes
None of these are used for advertising or to profile you. You can clear this data at any time through your browser settings. If you do, you will be logged out and your player preferences will reset.
We do not use any third-party analytics service. No tracking scripts run on this site, nothing is stored on your device for measurement, and no visitor data is shared with anyone for that purpose. We calculate aggregate figures — such as how many artists and tracks exist across all accounts, and how much storage is in use — from the data we already hold in order to run the service. These figures are totals and averages only and cannot be traced back to you. We rely on our legitimate interest in understanding capacity and how the service is used (Article 6(1)(f) GDPR).
When something goes wrong in the Service, a report of the fault is sent to Sentry so that we can find and fix it. That report contains the technical detail of the error — the message, the location in our code, the page or route involved, and the version of the software that was running.
It is configured not to carry personal data. We disable Sentry's collection of IP addresses, cookies and user identifiers, and every report is filtered before it leaves our server to remove email addresses, authentication tokens and file access links. Query strings are stripped from addresses, and identifiers inside them are replaced with placeholders, so a page address arrives as a description of the page rather than a record of what you were looking at. Reports are held in Sentry's European region and deleted after 30 days. We rely on our legitimate interest in keeping the Service working correctly and securely (Article 6(1)(f) GDPR).
We do not sell your personal data. We do not share it with advertisers, data brokers, or any third party for their own marketing purposes. We do use a small number of service providers ("processors") to run the Service. They act only on our instructions and are bound by data processing agreements. They may not use your data for their own purposes.
| Provider | Role | Location |
|---|---|---|
| Supabase | Authentication and user account database | eu-west-3 (Paris), European Union |
| Cloudflare | R2 storage for audio stems and files | European Union (EU jurisdiction) |
| TransIP | Server hosting (VPS), domain and DNS, transactional email (confirmations, password resets) | The Netherlands |
| Stripe | Payment processing, subscription billing, invoicing | Ireland / United States |
| MBS Benelux | Accountancy and bookkeeping — processes invoicing and payment records | The Netherlands |
| Exact | Accounting software used by MBS Benelux to process those records | The Netherlands / European Union |
| Sentry | Error tracking — records technical details of software faults so they can be fixed. Configured to strip identifying data before anything is sent (see below) | European Union (EU region) |
| ntfy.sh | Relays a content-free wake-up signal to the operator's phone so that Apple's push service can deliver an alert. Used only for our own operational alerts — never for anything about you or your account | Germany |
We may also disclose personal data where we are legally required to do so — for example in response to a valid order from a competent authority — or where necessary to establish, exercise or defend legal claims. If MySetlist.app is sold or merged, your data may transfer to the acquiring party. We will notify you before that happens and you will be able to delete your account first.
Our servers and primary storage are in the European Union. Sentry is used in its European region and ntfy.sh operates from Germany, so neither involves a transfer outside the EEA. Some providers listed above (Stripe, Cloudflare) may process data outside the EEA, including in the United States. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, and — for providers certified under it — the EU-US Data Privacy Framework, together with additional technical measures such as encryption in transit and at rest. You can request a copy of the relevant safeguards from us at the address in §12.
Data Retention
Account data For as long as your account is active
Uploaded content (stems, setlists, sheet Until you delete it, or 30 days after account deletion music)
Backups Rolling backups retained for 30 days, then
Invoices and tax records 7 years (Dutch Tax Administration requirement)
Server and security logs 90 days
Support correspondence 2 years after the request is closed
When you delete your account, we delete your account data and content from our active systems within 30 days. Data in encrypted backups is removed as those backups rotate out.
We protect your data with encryption in transit (TLS) and at rest, hashed passwords, access controls limiting who can reach production systems, signed and time-limited URLs for audio file access, and regular patching of our servers and dependencies. No system is perfectly secure. If a data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the Dutch Data Protection Authority as required by Articles 33 and 34 GDPR.
Under the GDPR you have the right to:
You can exercise most of these directly in your account settings, including exporting your setlists and content and deleting your account. For anything else, email us at privacy@mysetlist.app. We respond within one month, and will tell you if we need to extend that in a complex case. If you are not satisfied with our response, you can complain to the Dutch Data Protection Authority: Autoriteit Persoonsgegevens Postbus 93374, 2509 AJ Den Haag https://www.autoriteitpersoonsgegevens.nl If you live in another EU country, you may also complain to your local supervisory authority.
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this Privacy Policy as the Service changes. The date at the top shows when it was last revised. If we make material changes, we will notify you by email or through a notice in the app before those changes take effect.
Questions about this policy or about your data: Ricardo Braun, trading as MySetlist.app (a trade name of Trefoil Audio), established in the Netherlands. Email: privacy@mysetlist.app. KvK: 82625972.