Privacy Policy
Last updated: September 14, 2026- We collect as little as possible: a display name, a random account ID, your plan and usage hours, and short-lived technical logs.
- We do not store your projects. Files and edits are deleted automatically when the session ends (about 10 minutes) or 24 hours after the last activity.
- No analytics, no advertising, no tracking cookies. We never sell or share your data for advertising and never train AI on your music.
- Payments are handled by Paddle, which keeps your email and card details. We store only subscription IDs and status.
- You can ask us to access, correct or delete your data at any time: [email protected].
1. Who is responsible for your data
This Privacy Policy explains how the SameSet team (“SameSet”, “we”, “us”) collects, uses and protects personal data when you use the SameSet app, the SameSet Remote Script for Ableton Live, the website sameset.app and related services (the “Service”). We are the controller of the personal data described here, except for payment data, which Paddle controls as Merchant of Record (section 6).
Contact for all privacy matters, including requests under the GDPR, UK GDPR, CCPA/CPRA and the Law of the Republic of Kazakhstan “On Personal Data and Their Protection”: [email protected].
2. Data we process
Account data — provided by you or created by the app:
- display name you enter (it does not have to be your real name);
- a random account ID and a login token (we store only a SHA-256 hash of the token; the token itself stays on your Mac);
- your plan, the date the account was created, and for paid plans the Paddle customer ID, subscription ID, subscription status, billing period and next billing date.
Room and session data:
- room codes, which Account hosts a Room, when it was created, last used and closed;
- participants’ display names and roles, presence information (for example which track a person is on) and network latency;
- the log of edits made in the Room (for example changes to clips, notes, mixer and device parameters) needed to synchronise participants who connect later;
- hours of use per billing period and the total size of projects in your open Rooms, to apply plan limits.
Project content — Ableton Live sets, audio files, samples and plugin presets that participants share, and file metadata such as names, sizes and hashes. See section 4 for how briefly we keep them.
Technical data — IP address, connection times, app and protocol version, error messages and security events (for example failed room-code attempts), recorded in server logs and in short-lived memory counters used to prevent abuse.
Support data — if you email us, your email address, the content of your message and any information you choose to include.
We do not intentionally collect special categories of personal data, precise location, contacts, microphone or camera data. The app does not read your projects unless you share them in a Room.
3. Why we use it and our legal bases
- To create and run your Account, Rooms and synchronisation, to transfer project files between participants and to apply plan limits — performance of our contract with you (GDPR Art. 6(1)(b)).
- To process subscriptions and link payments to your Account — performance of a contract; Paddle processes the payment itself.
- To keep the Service secure, prevent fraud, abuse and brute-force attempts, and fix errors — our legitimate interests in a secure, working service (Art. 6(1)(f)).
- To answer your requests and send essential service messages (for example about changes to Terms or prices) — contract and legitimate interests.
- To comply with legal obligations, such as tax, accounting and lawful requests from authorities — legal obligation (Art. 6(1)(c)).
- Where the law requires consent (for example under the law of Kazakhstan), by installing the app, creating an Account and sharing Content you consent to the processing described in this policy. You can withdraw consent at any time by deleting your Account; this does not affect processing carried out before withdrawal.
We do not use your data for advertising, profiling or automated decision-making that produces legal or similarly significant effects, and we do not use your Content to train machine-learning or AI models.
4. Your projects are not stored
Project files, samples, presets and the edit log of a Room are processed only to deliver them to the participants of that Room:
- they are transferred over TLS-encrypted connections and held on our server in Helsinki, Finland (European Union) only while the Room is in use;
- when the Host ends the Session they are deleted automatically within about 10 minutes (enough for participants to finish downloading);
- an inactive Room is deleted with all its files and edit log 24 hours after the last activity;
- automatic deletion runs at least hourly; we keep no backups of project content, so deleted content cannot be restored.
The Service is not end-to-end encrypted: files are encrypted in transit but are processed by our server in readable form while the Session is open. We do not access them except automatically to operate the Service, or where strictly necessary to investigate abuse or comply with law.
Projects downloaded by participants are saved on their own computers (by default in ~/Music/SameSet) and remain there after the Session; we have no access to them and cannot delete them.
5. Data stored on your Mac
The app stores on your Mac: your display name, account ID and login token (in ~/.together/profile.json, readable only by your macOS user), app caches and downloaded updates (~/Library/Caches/SameSet), downloaded projects (~/Music/SameSet), received plugin presets (in your Ableton User Library) and the SameSet Remote Script. Ableton Live communicates with the app only on your computer (localhost). Uninstalling the app and deleting these folders removes this data.
If you allow notifications, macOS shows them through Apple’s notification system on your device.
6. Payments
Paid plans are sold by Paddle.com Market Limited (“Paddle”), which acts as Merchant of Record and as an independent controller of the data you give it during checkout: name, email address, billing address, country, payment method details and tax information. Paddle’s privacy policy applies to that data (paddle.com/legal/privacy).
Paddle sends us, through signed webhooks, the information needed to activate and manage your plan: customer and subscription IDs, plan, status, billing dates, currency and amounts. We do not receive or store your card details, and we do not store your email address on our servers. When you ask for help with billing we may look up your purchase in Paddle’s dashboard.
When you open the checkout page, Paddle.js is loaded from Paddle and may use cookies and similar technologies for fraud prevention and to complete the purchase.
7. Website, cookies and similar technologies
sameset.app does not use analytics, advertising pixels or tracking cookies, and we honour Global Privacy Control and Do Not Track signals by default because we do not track.
- The site is delivered through Cloudflare, which processes your IP address and may set strictly necessary security cookies (for example to detect bots).
- Fonts are loaded from Google Fonts and a scrolling library from jsDelivr; these providers receive your IP address and browser information to deliver the files.
- If you close the “Site available in Russian” banner, your browser remembers it in local storage on your device; this value is never sent to us.
- The checkout page loads Paddle.js as described in section 6.
8. Who we share data with
We share personal data only as needed to run the Service:
- other participants in your Rooms — your display name, role, presence, edits and the Content you share;
- Hetzner Online GmbH (Germany) — server hosting in Finland;
- Cloudflare, Inc. (USA) — website delivery, DNS, protection against attacks, and routing of emails sent to [email protected];
- our email provider — to receive and answer your emails;
- Paddle — payments, as an independent controller;
- Google (Google Fonts) and jsDelivr — delivery of website fonts and scripts;
- professional advisers, auditors and authorities where required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice to you).
We do not sell personal data and do not “share” it for cross-context behavioural advertising as those terms are defined in California law.
9. International transfers
Our servers are in the European Union. The Service is operated from the Republic of Kazakhstan, and some of our providers are located in other countries, including the United States and the United Kingdom. Where personal data is transferred outside the European Economic Area or the United Kingdom, we rely on adequacy decisions (such as the EU–US Data Privacy Framework for certified providers) or Standard Contractual Clauses, together with additional safeguards where appropriate.
10. How long we keep data
- Project files, samples, presets and Room edit logs — while the Room is in use; deleted about 10 minutes after the Host ends the Session or 24 hours after the last activity.
- Room records and codes — deleted together with the Room.
- Account data — while your Account exists. You can ask us to delete it at any time; Accounts inactive for more than 24 months may be deleted.
- Usage hours — the last six billing periods.
- Subscription and payment records — as long as needed for accounting, tax and legal claims (typically up to 5 years after the transaction), unless the law requires longer.
- Server logs with IP addresses — up to 14 days; abuse-prevention counters (for example failed room-code attempts) — kept only in memory for a few hours at most.
- Support emails — up to 24 months after the conversation ends.
11. Security
We protect data with measures appropriate to the risk, including: TLS encryption for all connections with certificate pinning in the app; storing only hashes of login tokens; strict file permissions and a sandboxed, unprivileged server process; a firewall and key-only administrative access; rate limits against guessing room codes; automatic deletion of project content; digitally signed app updates; and access to production systems limited to the people who operate the Service.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will notify you and the competent authorities as required by law.
12. Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data (you can change your display name in the app at any time);
- delete your data and Account;
- restrict or object to processing based on legitimate interests;
- data portability — receive data you provided in a machine-readable format;
- withdraw consent where processing is based on consent;
- not be discriminated against for exercising your privacy rights;
- lodge a complaint with a data protection authority, for example in the EU/EEA country where you live or work, the UK Information Commissioner’s Office, or the authorised body for personal data protection in Kazakhstan.
To exercise your rights, email [email protected] and include your account ID (SameSet → Account) so we can find your data. We may ask for information to verify that the request comes from you. We respond within one month (or the period required by your local law) and do not charge a fee. Residents of California and other US states may also use an authorised agent.
13. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided personal data to us, contact us and we will delete it.
14. Changes to this policy
We may update this Privacy Policy. We will post the new version on this page with a new “Last updated” date and, for significant changes, notify you in the app or by email before they take effect.
15. Contact
Privacy questions and requests: [email protected].