Privacy policy
Last updated September 2026
Your media stays with you
The songs, artwork, footage, logos and lyrics you add to the studio are processed in your browser. They are stored in your browser's own storage so your projects reopen on the same device, and they are not sent to our servers.
One optional exception, where the studio offers it and only when you press the button: Transcribe from the song sends a small copy of that song to our server, which passes it to OpenAI's transcription service and returns the words with their timings. The copy is not kept by us; OpenAI's API terms apply to the processing. Nothing is sent unless you choose it, and the button says so.
A second optional exception, where the studio's Social tab is offered: posting a finished video to YouTube or Facebook sends the file straight from your browser to that platform with your own account — we never see the file or your login. Instagram and TikTok only accept a link, so if you tick the box at that button, the finished video is copied to our storage under a signed link that expires within the hour and is deleted as soon as the post is through. Your platform logins stay with the platforms: Google's and Meta's tokens live in your browser for the session, and TikTok's is sealed inside a cookie only our server can read. We keep no copies and no tokens. Where the studio offers Post everywhere, your accounts are connected on the page of a posting service (Upload-Post) under a profile named after your LimeLight account; that service holds those connections and posts on your behalf when you press the button, fetching the same temporary copy. You can disconnect any account on the same page at any time, and their privacy policy applies to what they hold.
The waiting list
While LimeLight is not yet open, the front page collects email addresses for a waiting list. If you join it we store your email address, the sentence you agreed to when you gave it, the date, and — only when the link you arrived through carried them — where the link was shared and the referral code of whoever sent you. We also store a one-way hash of your network address, which lets us stop a script signing up a thousand times; the address itself is never written down, and the hash cannot be turned back into one. Nothing is stored on your device by this page: no cookies, no local storage, no analytics or tracking scripts of any kind.
We use it for one thing: to tell you when LimeLight opens, and to give you the free release pass promised on that page. We do not sell or share the list, and we do not add you to anything else. Every email we send will have an unsubscribe link, and you can ask us to delete your address at any time by writing to the address at the bottom of this page — we will remove it and confirm.
What we store when you have an account
Your email address, your name, a hashed password, and which plan you are on. These live with Supabase, our authentication and database provider. If you use the label tools, the artists, releases and lyrics you enter there are stored too.
Payments
Card details go straight to Stripe. We never see or store your card number. Stripe tells us which plan you bought and whether it is active, and we keep your Stripe customer id so you can manage billing.
Cookies
We use a session cookie to keep you signed in. We do not run advertising trackers.
Your rights
You can see and change your details on your account page, and you can ask us to delete your account and everything tied to it by emailing support. We answer within thirty days.
Changes
If this policy changes in a way that matters, we will say so on this page.