Cadorin · draft
Privacy Policy
DRAFT — not published, not legal advice, and subject to Founder approval and legal review.
Operator: individual sole proprietor. Legal name, notice address, and effective date: pending Founder supply. Privacy, support, and deletion requests: hello@cadorin.app.
1. Scope and contact
This policy describes how Cadorin, operated by an individual sole proprietor, handles information through its website, account system, admitted beta, and composition Runtime. The operator's legal name, notice address, and effective date are pending and must be supplied before publication. Privacy, support, and deletion requests may be sent to hello@cadorin.app.
2. Information Cadorin handles
Depending on how you use Cadorin, we may handle:
- Clerk account identifiers, email, verification, and session-security information;
- early-access requests, admissions, entitlement, and notification records;
- manuscripts, songbooks, snapshots, musical structures, notes, and continuity state;
- requests, selected musical context, generated suggestions, and feedback;
- operational records such as opaque references, event identifiers, provider/model identifiers, cost metadata, error categories, timestamps, and webhook receipts; and
- functional local browser state used to preserve work through reloads or interrupted operations.
Local browser state is not ordinarily an operator-readable account record unless it is sent through the persistence path.
3. Uses of information
Cadorin uses information to provide the beta, authenticate accounts, enforce ownership boundaries, recognize admitted musicians, preserve and return musical work, provide support, send service email, protect the Service, diagnose failures, control provider cost, prevent webhook replay, comply with law, and evaluate beta reliability.
When you request AI-assisted generation, the relevant request and musical context are sent through the server-side Runtime to the provider selected by active routing. Deterministic navigation and persistence do not require AI processing.
4. Providers and infrastructure
- Clerk: authentication, identity, sessions, and signed webhooks.
- Supabase: database storage, RLS, functions, persistence, admissions, feedback, operational records, and recovery packages.
- Cloudflare: public delivery, edge controls, and Turnstile when configured.
- Render: Runtime hosting, logs, and metrics.
- Resend: admission, service, and redacted operator-alert email where configured.
- OpenAI: the configured default AI-generation provider.
- Anthropic: an available provider used only when active Runtime routing selects it.
- Stripe: optional integration present in the codebase; payment flows are inactive for the current free beta.
Provider handling remains subject to applicable provider terms, settings, contracts, regions, and retention practices. Cadorin does not make unsupported claims about provider training or retention.
5. Musical ownership and AI processing
You retain ownership of your original compositions and other material you submit, subject to rights you already owe to others. You grant Cadorin a limited, non-exclusive license to host, store, copy, transmit, display, back up, secure, debug, support, and process that material as reasonably necessary to operate the beta and provide requested functionality.
AI-generated suggestions may be inaccurate, similar to other outputs, unavailable, or unsuitable. Cadorin does not promise that generated material is unique, exclusive, protectable, non-infringing, or human-authored.
6. Cookies and functional storage
Clerk uses authentication cookies and related browser storage. Cadorin uses functional local storage for working state, recovery state, preferences, and related application behavior. Turnstile may process security signals when enabled. No analytics SDK or analytics endpoint was found in the inspected application source; any dashboard-level tracking remains subject to final confirmation.
7. Security and proposed retention schedule
Cadorin uses authentication, ownership checks, Supabase RLS and constraints, privileged operator paths, signed handoffs, webhook receipts, redacted diagnostics, and application-data recovery packages. These safeguards do not guarantee that the Service is invulnerable.
The following schedule is a practical proposal for Founder and legal approval, not a current binding commitment. Current implementation behavior is described first; the proposed periods require approval before publication:
- Live musical data: current behavior is retention while the account is active and through verified deletion processing, subject to approved holds. Proposed policy: delete or de-identify the live records when that process completes.
- Account, admission, and feedback records: current behavior retains records needed to operate the beta, support requests, prevent abuse, and satisfy approved legal or audit needs. Proposed policy: retain for up to 12 months after account closure unless a shorter legal or operational period applies.
- Operational logs and diagnostics: current behavior uses redacted operational evidence; certain beta evidence has a documented 90-day pruning rule. Proposed policy: retain ordinary redacted diagnostics for 30 days and security/deletion receipts for 24 months, subject to counsel review.
- Provider logs: governed by the applicable provider settings and terms; Cadorin will not promise a provider deletion timeline it cannot control.
- Recovery packages: current behavior stores packages separately under restricted operator access and does not automatically erase them when live rows are deleted. Proposed policy: retain the minimum rolling set needed for recovery, with a maximum 90-day retention unless an approved hold requires longer.
8. Deletion and other requests
After identity verification, requests may be sent to the privacy contact at hello@cadorin.app. Deletion is currently handled through an operator-controlled, service-role-only workflow. It previews affected categories and may address Clerk identity, admissions, manuscripts, snapshots, feedback, sessions, provider reservations, and payment linkage where applicable.
Cadorin does not promise immediate erasure from provider logs, email records, legal records, or independently retained recovery packages. Requests may be delayed or limited for security, fraud prevention, payment disputes, legal holds, legal obligations, or audit integrity.
9. Beta eligibility
Cadorin is a limited, admitted beta for people who are at least 18 years old and located in the United States. Access remains subject to admission and applicable export, sanctions, and other legal restrictions. Cadorin does not promise technical blocking beyond the controls it actually operates.
10. Changes
Cadorin may update this policy as the Service or legal requirements change. The published version will identify the operator, notice address, contact, effective date, and change-notice method. Until approval, this page remains a draft and is not a binding notice.