Privacy Policy

Last updated: September 2026

This policy explains what data EnergyCurve collects, why, and the choices you have. EnergyCurve is a tool for DJs to analyze the energy of their sets, operated by StageLink LLC as part of the StageLink family.

What we collect

Account details you provide when you sign up (name and email), handled by our authentication provider WorkOS.

The content you create in the app: playlists, tracks, and their metadata (artist, title, BPM, key, energy).

Basic product analytics (pages visited, features used) so we can improve the app.

How we use it

To run the service — create your account, store your playlists, and compute your set analysis.

To send you essential transactional emails (for example, password resets).

To understand how the product is used and make it better. We don't sell your data.

Your music stays on your computer

When you import audio files, EnergyCurve reads their tags and analyzes them in your browser. Only the resulting text data (artist, title, BPM, key, energy) is sent to our servers. Your audio files are never uploaded, stored, or transmitted.

Who processes it

WorkOS (authentication), Supabase (database), PostHog (product analytics), Resend (transactional email), and Vercel (hosting). Each processes data only to provide their part of the service. Most are in the United States; the full list, with what each one receives, is on our Subprocessors page.

Anthropic, when you use AI-assisted set ordering. Only the track metadata described above is sent — never your audio. Anthropic does not train its models on this data.

GetSongBPM, only when you choose to look up a track by name. The artist and title are sent so they can return the BPM and key they hold for it. Never your audio — that feature exists precisely for tracks whose files you don't have.

Stripe, if you subscribe to a paid plan. Stripe handles the payment and stores the card details; we never see your full card number. The charge is processed by StageLink LLC.

Why we are allowed to process it

Running your account and storing your sets: because you asked us to — it is what the service is, and we cannot provide it otherwise (performance of a contract).

Billing, if you subscribe: the same reason, plus the tax and accounting records we are legally required to keep.

Keeping the service secure — rate limits, audit records of administrative actions, error reports: our legitimate interest in a product that is not trivially abused, balanced against the fact that none of it profiles you.

Product analytics, the AI reordering suggestion, and track lookup by title: your consent, given per feature. You can withdraw any of them at any time, and withdrawing is one click in the same place you gave it.

How long we keep it

Your account, sets and tracks: for as long as the account exists. Delete the account and they go with it.

Payment records: Stripe event payloads are stripped after 90 days, and immediately if you delete your account. The records Stripe itself must keep for tax purposes are outside our control.

Analyses: the score and date stay while the account does; the detailed breakdown is dropped after a year, because nothing in the product reads it after the day it was produced.

Records of administrative actions on an account: the action is kept, and the email attached to it is removed after a year.

Your rights

Access and portability: download everything we hold about you, as JSON, from your account page. No request needed.

Correction: change your name from the same page, immediately. To change your email, file a request from that page — it is also your login, and sets shared with you are matched by address, so it takes a couple of steps on our side rather than a save button.

Restriction and objection: file a request from your account page. It is recorded with its deadline, and you will see that deadline on the page until we answer.

Deletion: delete your account from your account page. It happens 30 days after you ask — not immediately — and you can undo it from the same page at any point in those 30 days. Your account keeps working in the meantime, so you can still download your data. Deleting removes it from our database and from our authentication provider, along with your sets, tracks, analyses and versions, and cancels any subscription. There is no refund for the unused part of a paid period.

What deletion does not reach, said plainly: rows in our billing log survive without their contents, because their id is what stops a repeated payment event being processed twice; Stripe keeps its own record of the transaction, which it is required to; and our analytics provider keeps what it already collected unless we ask it separately. Your audio files are not affected, because they were never on our servers.

Whichever way you ask, we answer within 30 days — that is the legal deadline and it does not depend on which route you used. Filing from your account page just means neither of us has to remember.

Withdrawing consent: the cookie banner and the Cookie Policy page both let you change your answer, and withdrawing takes effect immediately — including telling our analytics provider to forget the identifier it held.

Any of these can also be exercised by writing to hello@energycurve.app.

If you think we got it wrong

You can complain to a data protection authority. In the EU or the UK that is the regulator where you live; in Argentina it is the Agencia de Acceso a la Información Pública. We would rather you told us first, but you are not required to.

Cookies

We use a small number of cookies — see the Cookie Policy for details.

Children

EnergyCurve is for people aged 18 or over, and we do not knowingly collect data from anyone younger. We do not ask for a date of birth, because collecting one from everybody to screen a case we have no reason to expect would mean holding a new piece of personal data about every user. If you believe a minor has an account here, write to us and we will delete it and the data with it.

Contact

Questions about privacy? Reach us at hello@energycurve.app.