Skip to content
NuePlugin

Privacy Policy

Draft. Operator details, contact address and effective date will be added before launch.

1. The short version

NuePlugin runs on your Mac. The plugins you own, the audio you measure and the matching work never leave your machine. This site only holds what it needs to run an account and a community: an email address, a public profile, and whatever you choose to publish.

2. What we collect

Account. When you sign in with Google we receive your email address, your name and a profile image URL from Google. When you sign in by email link we receive your email address. We create a profile with a handle (derived from your email, editable) and a display name.

Things you publish. If you publish a match to the community we store the format file, its report, preview audio rendered from our standard stems, the name and description you give it, and the review outcome. Published items are public and carry your handle.

Access tokens. If you create a personal access token for your agent we store a hash of it, its name and when it was last used. We never store the token itself.

Waitlist. If you ask to be notified about the Player we store your email address and where you signed up from.

Technical data. Our servers receive your IP address and browser details with each request. We use them for security, rate limiting and to keep the service running. We keep request logs for a short period.

We do not collect audio from your Mac, the plugins you own, or anything about which plugin a published match was made from.

3. Cookies

We set a session cookie when you sign in so you stay signed in. We do not use advertising or cross-site tracking cookies.

4. How we use it

  • To run your account and let you publish, edit and remove your own matches.
  • To review submissions against community rules and to act on takedown requests.
  • To send you emails you asked for: sign-in links, and the Player notification if you joined the waitlist.
  • To protect the service: rate limiting, abuse and fraud prevention, security investigations.
  • To understand how the site is used, in aggregate.

We do not sell personal data. We do not use it for advertising.

5. Who processes it for us

  • Vercel (hosting and delivery, United States).
  • Supabase (database, authentication and file storage, United States).
  • Google (sign-in, if you choose Google).
  • Resend (transactional email).

Each processes data only to provide its service to us. Data may be stored or processed in the United States.

6. How long we keep it

Your account and profile: until you delete your account. Published matches: until you unpublish them or we remove them under our rules. Waitlist emails: until we send the notification or you ask us to remove you. Request logs: 30 days. Backups: up to 30 days after deletion.

7. Your rights

You can view and edit your profile on your account page and revoke access tokens there at any time. You can ask us to export or delete your account and data by writing to the contact address on this page. We answer within 30 days. Depending on where you live you may have further rights under laws such as the GDPR or the CCPA; write to us and we will honour them.

8. Children

NuePlugin is not for anyone under 16. We do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.

9. Security

Sessions and tokens are protected in transit with TLS. Tokens are stored hashed. Database access is restricted by row-level policies. No system is perfectly secure; if we learn of a breach affecting you we will tell you.

10. Changes

We will post changes here and update the effective date. If a change matters we will say so on the site or by email.