Downpick

Privacy Policy

Last updated: August 15, 2026

Downpick ("we", "us") helps bands manage their songs, setlists and live gigs. This policy explains what we collect, how we use it, and the choices you have. It applies to the Downpick website, service, and Stage Player desktop application.

Information we collect

Account details you provide (username, email) and, if you sign in with Google or GitHub, the basic profile and verified email those providers share. We store the content you create — bands, members, songs, setlists, gigs, calendar events, date polls, notes and lyrics — to provide the service. Scheduling adds a few personal records: date ranges you mark yourself unavailable ("blockouts") with an optional private note, your Yes / No / Maybe attendance responses to events and gigs with an optional note, and your per-slot votes on proposed times. If you purchase a subscription, Stripe collects and processes your billing address, payment method, transaction details, tax location, and any information needed to calculate applicable tax. Downpick stores provider customer, subscription, price, and event identifiers, but not your full card number. We do not sell your data.

If you add a passkey, Downpick stores the credential identifier, public key, name you choose, creation time, signature counter, supported transports, and verification and backup state. The attestation object and client data used to validate registration are discarded after verification. Your fingerprint, face scan, device PIN, and passkey private key remain on your device or security key and are never sent to Downpick. While newly issued recovery codes wait for you to confirm that you saved them, Downpick keeps an encrypted copy in your account's authentication-token store; that copy is deleted when you confirm the handoff or turn off two-step verification.

How we use it

To authenticate you, operate and secure the app, send transactional emails (confirmation, password reset), and improve reliability. We use cookies strictly for authentication and session security.

Scheduling, availability and attendance

Who can see each scheduling record depends on what it is. The dates of a blockout are shown to every band you belong to as a warning when someone schedules over them; the note you attach to a blockout is visible only to you. Your attendance response and its note are visible to everyone in that band, alongside your display name. Your votes on a date poll, and your name beside them, are visible to everyone in that band. Your blockouts are personal rather than per band: entering a range once surfaces it in every band you belong to.

We email you about calendar activity in the bands you belong to — an event scheduled, moved or cancelled, a poll opened or confirmed, and a reminder when you have not yet responded to something in the next 48 hours. Those emails include the band name, the item's title, and its time. We check your membership again immediately before sending, so a queued email is not delivered after you leave the band. You can delete any blockout and update your responses or votes while their event or poll accepts changes. Deleting your account deletes all of them.

Calendar subscription link

You can create a private calendar feed URL and paste it into Google Calendar, Apple Calendar or Outlook. That URL contains a secret token and works without signing in: anyone who holds it can read the band names, event and gig titles, dates, times and locations from every band you are an active member of, covering everything upcoming plus the previous 30 days. It carries no availability, attendance, vote or note data. Only you can create the link, and you can reset it at any time, which immediately stops the previous link from working. Losing membership of a band removes that band from the next response. We keep these links out of our request logs and telemetry.

Stage Player updates and show synchronization

Stage Player sends Downpick a randomly generated installation identifier when it checks for signed software updates and when it synchronizes show audio. We use it to keep staged rollout assignment stable, resume interrupted downloads without charging the same installation twice, and account for a band's native-package download allowance. The update service itself does not store the identifier. Transfer sessions and recent asset acquisitions store it with the signed-in user and band; after 90 days Downpick removes those operational identifiers while retaining the reduced allowance ledger needed for accounting. When a signed-in rig has a synchronized band, update checks also include that band's identifier so an administrator can hold the band's rigs to a tested release. Stage Player checks at launch and approximately every six hours while it remains open, and stops sending the band identifier after sign-out. The installation identifier remains in local application data so rollout assignment and transfer recovery stay stable; removing that local data resets it.

Stage Player keeps a local index of verified cached audio, including immutable media identifiers, versions, file sizes, and cryptographic digests. During a sync it sends only the matching inventory for that show so Downpick can avoid transferring or charging files already verified on that installation. Cached audio remains on the rig for offline performance until you delete the show or application data; newly recovered files are protected from automatic pruning for seven days so an interrupted sync can resume.

Sharing

We share data only with processors that run the service and when required by law. These processors include cloud hosting and email delivery providers, plus Stripe for subscription checkout, payment processing, billing, fraud prevention, and tax calculation. We send Stripe your Downpick user identifier, selected plan and billing cadence, and Stripe receives the billing and payment information you enter in its hosted pages. Sign-in providers receive only what is needed to authenticate you. Content you deliberately publish — such as a share link to a gig's running order — is accessible to anyone who holds that link.

GitHub hosts Stage Player installers and automatic-update files. When your browser or Stage Player downloads one, GitHub receives your IP address, device or browser details, and request time under GitHub's privacy statement.

Embedded YouTube videos

If you link a YouTube video to a song as a practice timing source, that video plays in an embed served by YouTube from youtube-nocookie.com. We never download, copy, or store the video or its audio. When you press play, YouTube receives your IP address and the usual request data, and may set cookies or similar storage on your device — the no-cookie domain defers this until playback rather than preventing it. That playback is governed by Google's privacy policy, not this one. Songs without a linked video load no YouTube resources at all.

Security & retention

Data is encrypted in transit, secrets are stored in a managed vault, and passwords are hashed. We keep account data while your account is active. Blockout ranges — and any note attached to them — are deleted automatically 90 days after the last unavailable date, because a past range no longer warns anyone. Deleting your account ends its Stripe subscriptions and deletes the Stripe customer so saved payment details can no longer be used. Stripe and Downpick may retain limited transaction, tax, security, or audit records where required by law or needed to resolve disputes.

You can remove an individual passkey in Security settings. Turning off two-step verification removes the authenticator key, recovery-code hashes, pending encrypted recovery-code handoff, and all passkey records. Deleting your account also deletes those authentication records.

Crash and error reports

When Downpick or Stage Player hits an error, the app sends us a diagnostic report so we can fix it. These reports are always on: they are how we find faults nobody thought to tell us about, and a band mid-gig should not have to file a bug report. We use them only to keep the service working and secure — never for advertising, profiling, or building a picture of what you do in the app.

A report carries the error message and technical details of the failure, the app version, a coarse description of your device (operating system and browser, or for Stage Player the audio and MIDI hardware in use), and numeric identifiers for the band, gig, setlist, or song involved. It does not carry your song titles, setlist names, band names, notes, or any of your content. Reports are kept for 30 days and then deleted.

Stage Player also writes a log file on your own computer, which never leaves it unless you export it and send it to us yourself.

Your choices

You can update or delete your account and unlink social logins from settings. For privacy requests, contact us at privacy@downpick.app.