These legal documents are provided in English. Localized versions will follow counsel review.
Home
Remy Cooper logo

Privacy Policy

Last updated: September 15, 2026

1. Introduction

Remy Cooper Music ("we," "us," or "our") operates VAULT, a music organization platform. We are committed to protecting your privacy and handling your personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Dutch General Data Protection Regulation (AVG).

This Privacy Policy explains how we collect, use, process, and protect your personal data when you use the VAULT platform. By using our Service, you consent to the data practices described in this policy.

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date and notify you of material changes. Continued use of the Service after changes constitutes acceptance of the updated policy.

2. Data Controller

The data controller responsible for processing your personal data is:

Remy Cooper Music, sole proprietorship registered in the Netherlands
KvK: 61473413
VAT: NL002378599B97
Location: The Netherlands
Email: vault@toolkit.music

Our registered geographic address is on file with the Dutch Chamber of Commerce (KvK) under the registration number above and is available on request. We are not required to appoint a Data Protection Officer under GDPR Art. 37, and we have not voluntarily designated one. As we are established in the EU, we have not appointed an Art. 27 representative.

For any questions about this Privacy Policy or our data practices, please contact us using the information above.

3. Information We Collect

We collect and process the following categories of personal data:

3.1. Account Information

  • Email address (required)
  • Password (hashed and encrypted, required)
  • Name (required)
  • Username (required)
  • Profile picture/avatar (optional)
  • IPI code (optional, for music industry identification)

3.2. Content You Upload

  • Songs, tracks, and audio files
  • Artwork and images
  • Lyrics and text content
  • File attachments
  • Song metadata (title, artist, genre, tags, etc.)
  • Comments and messages

3.3. Usage Information

  • Storage usage data
  • Last login timestamp
  • Onboarding completion status
  • Feature usage patterns

3.4. Payment Information

  • Polar customer ID and billing references
  • Subscription status and plan name
  • Billing information (processed securely by Polar as Merchant of Record, not stored by us)

3.5. Communication Data

  • Email communication history
  • Marketing preferences (opt-in/opt-out)
  • Notification preferences

3.6. Consent Records

  • Terms of Service acceptance timestamp and version
  • Privacy Policy acceptance timestamp and version
  • Cookie consent choices and timestamp (browser-level analytics opt-in/opt-out)

3.7. User Search and Contact Features

  • User searchability preference (whether you allow other users to find you by name, email, or username)
  • Contact information stored by other users when they add you as a contact
  • Collaboration relationships and contact lists

3.8. AI Assistant Inputs (Conductor)

When you use Conductor, our built-in AI assistant, we collect the prompts and catalog context needed to provide the requested workflow. Conductor is available to active Creator and Pro users, with plan-specific capacity limits:

  • The prompts you submit and the conversation history within a session
  • Catalog items, attachments (including images and PDFs), and metadata you reference or that the assistant retrieves on your behalf
  • Token usage and billing telemetry per conversation

We retain conversation history to provide chat continuity. You can delete a conversation at any time, which permanently removes the associated prompts and responses from our active systems. New Conductor turns stop when the plan-specific capacity is exhausted or the plan is no longer eligible.

3.9. MCP Connections

Direct MCP and Agent Plugin access is available to eligible Personal Pro users and eligible Team seats. Creator Personal users use Conductor and do not receive direct MCP credentials. When you use MCP, VAULT processes the catalog and workflow data you request through the selected workspace, credential metadata, workspace binding, tool and audit metadata, and last-use and revocation timestamps. MCP credentials are bound to one workspace and cannot switch workspace through request input. OAuth or PAT revocation stops server access immediately, although the client-side plugin tile may remain installed. The connected AI provider receives only the catalog or workflow data you request through that workspace and applies its own privacy terms.

3.10. Technical and Log Data

  • IP address and approximate location derived from it
  • Browser, device, and operating-system information (user agent)
  • Native app platform, app version, operating-system version, and app activity timestamps
  • Server access logs (request URLs, timestamps, response codes)
  • Session identifiers and security tokens

We use this data to operate the Service, prevent abuse, and protect security. Logs are retained for up to 90 days unless required for an active security investigation.

3.11. Browser extension imports

If you use the optional VAULT Chrome extension, it captures an authenticated provider request only after you select a provider, review the disclosure, grant the requested host permission, and click the connection action. Depending on the provider, the captured request may contain authentication cookies, headers, tokens, and the request fields needed to read your library. The extension sends the structured connection to your signed-in VAULT session so that VAULT can validate, scan, review, and import the selected content.

Raw provider credentials are not stored in Chrome extension storage, URLs, clipboard history, analytics, or support diagnostics. VAULT keeps credentials only for the existing import job lifecycle where a queued import needs them, using the existing encrypted credential storage and deletion behavior. Browser handoff tokens are short-lived, one-use, workspace-bound, and stored only as hashes. We do not ask support users to send cookies, tokens, or copied cURL requests.

Browser imports replay requests to the provider endpoints needed for the selected import. Provider private API behavior, permissions, and terms may change independently of VAULT. You can stop a capture from the extension, revoke its provider host permission in Chrome, or use the manual importer instead. See the browser extension installation page for the current supported providers and setup instructions.

3.12. Testimonials and Reviews

If you use a private review link, we collect your name, email address, review text, and any optional role, company, profile URL, or photo you choose to provide. We also record the version and time of your publication and photo choices, moderation status, and withdrawal request. Your email address and profile URL are not published. Review text is published unchanged after moderation.

3.13. Watermark and Rights Records

When a watermarked copy is issued, VAULT creates a rights record that can connect that copy to its distribution context. Depending on how the copy was requested, this record may contain:

  • A snapshot of the song, artist, track, and artwork details at the time of issue
  • The VAULT account or recipient label for whom the copy was issued
  • The internal or public-link context through which it was requested
  • Request, generation, and download-initiation timestamps
  • Approximate city and country and a broad device category

An IP address may be used briefly to derive an approximate city and country, but the IP address, a subnet, or a hash of either is not stored in the watermark rights record. The record identifies the VAULT copy and its intended distribution context. It does not prove who later shared or redistributed the file.

Audio submitted solely for watermark verification is stored privately and temporarily while the check runs, then removed. Limited verification metadata may be retained for up to 24 hours to finish processing and support retries.

3.14. Education Program

If you apply for VAULT Education, we process school email addresses, enrollment evidence you upload, and verification outcomes to confirm eligibility and prevent abuse. Evidence files are restricted to authorized reviewers and are scheduled for deletion 30 days after a decision. Incomplete uploads and unattended applications have separate cleanup periods. We retain the verification outcome and a record of the Education terms you accepted separately from the evidence file. A school partnership does not itself give the school access to your private catalog or verification documents.

4. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR Article 6:

  • Contract Performance: To provide and maintain the Service, process payments, and fulfill our contractual obligations to you
  • Consent: For marketing communications, publication of testimonials, and each optional testimonial photo source. You can withdraw consent at any time. We also record Terms of Service and Privacy Policy acceptance.
  • Legitimate Interests: To improve our Service, prevent fraud, ensure security, and send transactional emails necessary for service delivery. User Search and Contact Management: We process user search data based on legitimate interests to enable collaboration and contact management features. Users can opt out at any time in their account settings.
  • Legal Obligation: To comply with applicable laws and regulations, including tax and accounting requirements

5. How We Use Your Information

We use your personal data for the following purposes:

  • To provide, maintain, and improve the VAULT platform
  • To process your account registration and authenticate your identity
  • To store, organize, and make your content accessible to you and authorized collaborators
  • To process payments and manage subscriptions
  • To send transactional emails (welcome emails, collaboration invitations, password resets, etc.)
  • To send marketing communications (only if you have opted in)
  • To enable user search and contact management features for collaboration
  • To respond to your inquiries and provide customer support
  • To ensure security, prevent fraud, and enforce our Terms of Service
  • To comply with legal obligations and resolve disputes
  • To analyze usage patterns and improve our Service
  • To moderate and publish testimonials when the reviewer has given specific permission

6. Data Sharing and Third-Party Services

We share your personal data with the following third-party service providers to operate the Service:

6.1. Payment Processing

Polar: We use Polar as our Merchant of Record to process payments and manage subscriptions. Polar processes your payment information securely and handles tax collection, invoicing, and compliance. We only receive and store limited billing identifiers and subscription state, not your full payment details.View Polar's Privacy Policy.

6.2. File Storage

Wasabi S3 Storage: Your uploaded files (audio, images, attachments) are stored using Wasabi S3 Storage, a secure cloud storage service. Data is encrypted in transit and at rest. Wasabi provides S3-compatible object storage for your content.

6.3. Authentication

Supabase: We use Supabase for user authentication and session management.View Supabase's Privacy Policy.

6.4. Email Services

Amazon SES: We use Amazon SES to send transactional emails and, when you have opted in, marketing emails. Your email address and message content are shared with Amazon SES only for delivering those emails.

6.5. Database and Server Hosting

Hostinger (VPS): Your account information, metadata, and self-hosted Supabase PostgreSQL database are stored on a Virtual Private Server provided by Hostinger International Ltd. The server is located in the European Union. Hostinger acts as a hosting infrastructure processor.

6.6. Content Delivery Network

Bunny CDN: We use Bunny CDN to deliver your audio, images, and other static assets to listeners with low latency. Files transit through Bunny's global edge network. Bunny acts as a processor and does not use your content for any purpose other than delivery.

6.7. AI Processing (Conductor and MCP)

OpenAI (Conductor): When you use Conductor, our built-in AI assistant, the prompts, conversation history, and any catalog content you reference are sent to OpenAI, L.L.C. (United States) to generate responses. Content is sent only when you actively use the feature, is processed under OpenAI's business-tier data processing agreement, and is not used to train OpenAI's models.

MCP and Agent Plugin (bring your own AI): If you connect VAULT to ChatGPT, Claude, Codex, or another compatible AI client, that client receives only the catalog and workflow data you request through the selected Personal Pro or Team workspace. Once data leaves VAULT through your MCP connection, it is governed by the privacy terms of the AI provider you selected. We are not responsible for the actions of that AI client. VAULT technical and audit logs follow a maximum 90-day period unless needed for an active security investigation. Active credential metadata remains while connected. Revoked credentials cannot authorize new requests. Residual backup copies and service-provider logs follow the retention schedules in section 8.

6.8. Realtime Collaboration

Liveblocks: Collaborative editing features (such as multi-user lyrics or notes) use Liveblocks Inc. (United States) as a realtime synchronization service. Liveblocks receives the document content you and your collaborators are editing in real time. Document content is processed under a data processing agreement and is not used to train models.

6.9. Music Service Integrations

Spotify: If you choose to connect your Spotify account (Pro feature) to sync playlists, we share your VAULT-stored playlist data with Spotify AB (Sweden) and receive playlist data from Spotify on your behalf. We do not share data with Spotify unless you explicitly connect your account, and you can disconnect at any time from your account settings.

6.10. Advertising Measurement

Meta (Facebook): Only after you grant analytics consent through our cookie banner, we share page-view, sign-up, and purchase events with Meta Platforms Ireland Ltd. via Meta Pixel (browser-side) and Meta Conversions API (server-side) to measure advertising performance. This sharing is gated entirely by your consent; if you decline, no data is sent. See our Cookie Policy.

TikTok: After you grant analytics and advertising measurement consent, we share page-view, sign-up, checkout, purchase, and subscription events with TikTok through TikTok Pixel and Events API. Matching may use TikTok click and cookie identifiers, IP address, user agent, and hashed email and account identifiers. If you decline, no TikTok tracking data is sent.

6.11. Mobile Push Notifications

Expo Push (Expo, Inc.): If you install our mobile app and enable push notifications, your device push token is shared with Expo, Inc. (United States) and forwarded to Apple Push Notification service or Firebase Cloud Messaging (Google) to deliver notifications to your device.

6.12. Error Monitoring

Sentry: We use Sentry for application error monitoring and performance diagnostics. Sentry may receive error messages, stack traces, request URLs and headers, IP addresses, device/browser metadata, and user identifiers. In the authenticated web app, error-triggered session replays can also capture interaction context to help reproduce failures. We use Sentry to operate and debug the Service, not for advertising.

6.13. Product Analytics

SiteBehaviour: We use SiteBehaviour for product analytics, including page flows, interaction patterns, and heatmaps, to understand usage and improve VAULT. See our Cookie Policy for information about analytics cookies and preferences.

6.14. Mobile Subscriptions

RevenueCat: If you subscribe through the iOS or Android app, subscription status events may be processed by RevenueCat so we can unlock the correct plan features on mobile. Billing itself remains handled by the app store and/or Polar according to the purchase path you used.

6.15. Bot Protection

Cloudflare Turnstile: On selected public forms (such as signup or inbox submission), we may use Cloudflare Turnstile to distinguish humans from bots. Challenge tokens are verified with Cloudflare for that security purpose.

6.16. Testimonial Moderation

Telegram: When a review is submitted, we may send its name, optional role and company, and review text to a restricted Telegram chat for moderation. We do not send the reviewer's email address or profile URL to Telegram. Authorized moderators can approve publication from that chat.

6.17. Subprocessor Changes

When we engage a new sub-processor that processes personal data, we will update this list at least 14 days before the new sub-processor begins processing. If you object, you may terminate your subscription and request a pro-rata refund of any unused prepaid period in accordance with our Refund Policy.

6.18. AI Training Commitment

We do not use your content, prompts, or any data you submit to VAULT to train artificial intelligence or machine-learning models, and we contractually require our AI sub-processors to do the same.

6.19. Other Sharing

We may share your data in the following circumstances:

  • With users you explicitly share content with through collaboration features
  • If required by law or legal process
  • To protect our rights, property, or safety, or that of our users
  • In connection with a business transfer (merger, acquisition, etc.)

7. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where our third-party service providers are located.

We ensure that such transfers comply with GDPR requirements by:

  • Using service providers that are certified under appropriate frameworks (e.g., EU-U.S. Data Privacy Framework)
  • Implementing Standard Contractual Clauses (SCCs) where applicable
  • Ensuring adequate data protection measures are in place

8. Data Retention

We retain your personal data for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law:

  • Account Data and Content: Retained while your account is active. When you delete your account, we begin permanent deletion of your content from our active systems immediately. Encrypted database backups can retain deleted account data for several years: our backup schedule includes daily copies and longer-lived monthly and yearly archives, including five annual snapshots. Account deletion does not immediately erase those backups. Cached content and service-provider logs follow separate retention schedules, so we do not promise a single purge deadline for all copies. Account recovery after deletion is not available.
  • Payment Records: Retained by Polar as Merchant of Record for tax and accounting for the periods required by applicable law. App stores retain records of purchases made through their billing systems under their own legal obligations. Local billing mirrors stored in VAULT may be removed when your account is deleted.
  • Consent Records: Terms and Privacy acceptance timestamps are stored on your account while it is active and are removed with the account. Copies may remain in the database backups described above.
  • MCP credentials and logs: Credential metadata remains while a connection is active. Technical and audit logs are retained for up to 90 days unless needed for an active security investigation. Revoked credentials cannot authorize new requests. Residual backup copies and service-provider logs follow the retention schedules described above.
  • Marketing Preferences: Retained until you withdraw consent or delete your account
  • Testimonials: Published and pending testimonial content is retained until you withdraw permission or we delete it. A withdrawal immediately hides the testimonial, removes stored testimonial photos, and anonymizes its submitted content. We retain a minimal consent and withdrawal audit record where needed to demonstrate compliance.
  • Watermark Rights Records: Copy, distribution-context, and access snapshots are retained while the issuing customer keeps the associated rights record and for only as long afterward as reasonably necessary to establish, exercise, or defend legal claims. We periodically review whether identifiable attribution remains necessary and delete or anonymize it when that purpose ends.

Important: Account deletion is permanent and cannot be reversed. Payment records retained by Polar for tax and accounting, and limited abuse or fraud records we must keep, are handled separately from your active catalog. Please ensure you have backed up any content you wish to keep before deleting your account.

For data that we are legally required to retain (such as payment records), we will securely delete or anonymize it after the retention period expires.

9. Your Rights Under GDPR/AVG

You have the following rights regarding your personal data:

  • Right of Access: You can request a copy of the personal data we hold about you
  • Right to Rectification: You can request correction of inaccurate or incomplete data
  • Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data (subject to legal obligations)
  • Right to Restrict Processing: You can request that we limit how we process your data
  • Right to Data Portability: You can request a copy of your data in a structured, machine-readable format
  • Right to Object: You can object to processing based on legitimate interests, including opting out of user searchability in your account settings
  • Right to Withdraw Consent: You can withdraw consent for marketing communications or a testimonial at any time. The confirmation email for a testimonial contains a private withdrawal link.

To exercise these rights, please contact us at vault@toolkit.music. We will respond to your request within one month.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe we have violated your data protection rights.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of data at rest
  • Secure password hashing (bcrypt)
  • Regular security assessments and updates
  • Access controls and authentication
  • Regular backups of your data

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

11. Cookies and Tracking Technologies

We use cookies and similar technologies to operate the Service, authenticate users, and remember your preferences. For detailed information about our use of cookies, please see our Cookie Policy.

When you consent to affiliate-link attribution, we process a pseudonymous visitor identifier, referring partner, touch time and expiry for up to 60 days. If you then create a new account, we store the referral source, rate snapshot and conversion history to calculate and audit commission. Affiliates receive an anonymous referral ID and do not receive your name or email. Collaborator-invite attribution uses the invite token server-side without a general affiliate cookie.

12. Children's Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.

13. Marketing Communications

We only send marketing communications if you have explicitly opted in. You can:

  • Click the unsubscribe link in any marketing email
  • Use the one-click unsubscribe header where supported by your email client
  • Contact us directly to unsubscribe

Note that even if you opt out of marketing communications, we may still send you transactional emails necessary for the Service (e.g., account notifications, collaboration invitations).

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes:

  • We will update the "Last updated" date
  • We will notify you via email or through the Service
  • For significant changes, we may require you to review and accept the updated policy

Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Remy Cooper Music
Email: vault@toolkit.music
Location: The Netherlands

For complaints regarding data protection, you can also contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.