Privacy Policy
Last updated: August 1, 2026
Downpick ("we", "us") helps bands manage their songs, setlists and live gigs. This policy explains what we collect, how we use it, and the choices you have. It applies to the Downpick website, service, and Stage Player desktop application.
Information we collect
Account details you provide (username, email) and, if you sign in with Google or GitHub, the basic profile and verified email those providers share. We store the content you create — bands, members, songs, setlists, gigs, notes and lyrics — to provide the service. If you purchase a subscription, Stripe collects and processes your billing address, payment method, transaction details, tax location, and any information needed to calculate applicable tax. Downpick stores provider customer, subscription, price, and event identifiers, but not your full card number. We do not sell your data.
How we use it
To authenticate you, operate and secure the app, send transactional emails (confirmation, password reset), and improve reliability. We use cookies strictly for authentication and session security.
Stage Player updates
Stage Player sends Downpick a randomly generated installation identifier when it checks for signed software updates. We use it only to keep staged rollout assignment stable; the update service does not store it. When a signed-in rig has a synchronized band, the check also includes that band's identifier so an administrator can hold the band's rigs to a tested release. Stage Player checks at launch and approximately every six hours while it remains open, and stops sending the band identifier after sign-out. The installation identifier remains in local application data so rollout assignment stays stable; removing that local data resets it.
Sharing
We share data only with processors that run the service and when required by law. These processors include cloud hosting and email delivery providers, plus Stripe for subscription checkout, payment processing, billing, fraud prevention, and tax calculation. We send Stripe your Downpick user identifier, selected plan and billing cadence, and Stripe receives the billing and payment information you enter in its hosted pages. Sign-in providers receive only what is needed to authenticate you. Content you deliberately publish — such as a share link to a gig's running order — is accessible to anyone who holds that link.
GitHub hosts Stage Player installers and automatic-update files. When your browser or Stage Player downloads one, GitHub receives your IP address, device or browser details, and request time under GitHub's privacy statement.
Embedded YouTube videos
If you link a YouTube video to a song as a practice timing source, that video plays in an embed served by YouTube from youtube-nocookie.com. We never download, copy, or store the video or its audio. When you press play, YouTube receives your IP address and the usual request data, and may set cookies or similar storage on your device — the no-cookie domain defers this until playback rather than preventing it. That playback is governed by Google's privacy policy, not this one. Songs without a linked video load no YouTube resources at all.
Security & retention
Data is encrypted in transit, secrets are stored in a managed vault, and passwords are hashed. We keep account data while your account is active. Deleting your account ends its Stripe subscriptions and deletes the Stripe customer so saved payment details can no longer be used. Stripe and Downpick may retain limited transaction, tax, security, or audit records where required by law or needed to resolve disputes.
Your choices
You can update or delete your account and unlink social logins from settings. For privacy requests, contact us at privacy@downpick.app.