This Privacy Notice explains how Stav Danino, a licensed business (Osek Murshe) in Israel operating Frequency (the "Service", "we", "us"), collects, uses, shares and protects your personal data. We act as the data controller for personal data processed through the Service.
1. Personal Data We Collect
- Account data: name, email, password (hashed), display name, username, avatar, language, country, role, account type, social links.
- Profile and public data: bio, artist/DJ/label name, photos, public posts, EPK / public profile pages, marketplace listings, label and teacher pages — these are visible to other users and may be visible to the public web.
- Content: audio files, track metadata, lyrics, images, cover art, videos, chat messages (text, audio, video, file attachments), teaching programs and student records, gig data, calendar events, ideas, tasks, strategy goals and other content you upload or create.
- Communications data: chat messages, reactions, voice and video messages, file attachments, 1:1 audio/video call signaling and call records (caller, callee, start/end time, duration, status — call audio/video itself is generally peer-to-peer and not stored by us).
- Usage and analytics data: features used, AI analyses and prompts, login timestamps, device, browser, operating system, IP address, approximate country/region (derived from CDN headers), referrer, UTM parameters, page views and clicks, performance and crash data.
- Presence and status: online/offline state, last-seen, "do not disturb" / "busy" / "available" call settings.
- Push notification data: push subscription endpoints, device tokens and preferences.
- Support communications: messages you send us, feedback and our responses.
- Billing data: handled by our payment processor Paddle. We receive only your subscription status, plan, customer reference, transaction events and (where applicable) coupon use.
- College, faculty and public inquiry data: institution name, logo, description, contact details, public page URL, instructor profiles (name, photo, title, teaching areas, biography), instructor-student assignments, and inquiries left by visitors on a public college page (name, email, phone, message). For this data the college account owner is the data controller and Frequency processes it on their behalf.
2. How We Use Your Data & Legal Basis
- Provide the Service (contract performance): account creation, processing uploads, running AI analyses, displaying your dashboard, delivering chat, audio/video calls, push notifications, calendar, marketplace, teaching and collaboration features.
- Billing & subscription management (contract performance): confirming your plan, renewals, plan changes and coupon use via Paddle.
- Security, fraud, abuse prevention and platform integrity (legitimate interests / legal obligation): detecting abuse, rate limiting, account protection, moderation and safety.
- Product improvement, troubleshooting and analytics (legitimate interests): understanding feature usage in aggregate, identifying bugs, planning improvements.
- AI processing (contract performance): sending the inputs you submit to AI subprocessors to return a result back to you. We do not sell your AI inputs or outputs and do not allow subprocessors to train their general models on your data.
- Customer support (contract / legitimate interests): responding to your requests.
- Legal compliance (legal obligation): tax records, responding to lawful requests, enforcing our Terms.
3. Data Sharing & Subprocessors
We share personal data only with the following categories of recipients:
- Paddle.com Market Limited — Merchant of Record for all sales; handles payments, tax, invoicing, refunds and subscription billing.
- Supabase — database, authentication, realtime and file storage hosting.
- Cloudflare — application hosting, CDN, edge delivery, DDoS protection (also provides approximate visitor country signal).
- AI providers (via Lovable AI Gateway and/or other model providers) — process your inputs (text, audio, images) solely to return an AI result. They do not use your inputs to train their general models.
- Push notification gateways — delivering push notifications to your devices.
- Other users — content you choose to publish or share (posts, public profile, marketplace listings, EPK pages, label pages, chat recipients, collaborators, students, teachers, group members) is visible to those audiences and, where the content is public, to the open web and search engines.
- Professional advisers (e.g. accountants, legal counsel) where required.
- Authorities where required by law, court order or to protect rights, property or safety.
- Successors in the event of a merger, acquisition or asset sale, subject to this Notice.
We do not sell personal data and do not engage in cross-context behavioral advertising.
4. International Transfers
Our subprocessors may process data outside your country, including in the EU, UK, United States and other regions. Where required by law, transfers are protected by appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
5. Data Retention
- Account and content data: retained while your account is active, and for up to 90 days after deletion to allow recovery and meet legal obligations.
- Chat messages, attachments and call records: retained while your account is active; you may delete individual messages where the feature allows.
- Billing records: retained for the period required by applicable tax and accounting law (typically 7 years).
- Security, fraud and abuse logs: retained for up to 24 months.
- Analytics page-view data (path, referrer, UTM, approximate country, device, session): retained for up to 24 months.
- Support messages: retained for up to 3 years.
- Aggregated or anonymized data: retained indefinitely.
6. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your personal data.
- Object to or restrict certain processing.
- Request a portable copy of data you provided.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at Stavdaninomusic@gmail.com. We respond within 30 days. Some content you shared with other users (e.g. messages they received, public posts that were re-shared) may remain visible after your account is deleted.
7. Security
We apply appropriate technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS), encrypted storage at rest, access controls, role-based permissions (Row Level Security), least-privilege keys, signed URLs for media and audit logging. No system is 100% secure; breaches that affect your data will be reported as required by law.
8. Cookies, Local Storage & Analytics
We use essential cookies and local/session storage to keep you signed in, remember your preferences, store drafts, and run first-party analytics about how the Service is used (e.g. page paths, referrer, UTM, approximate country derived from CDN headers, device class). We do not use advertising cookies or cross-site tracking. You can clear cookies and local storage from your browser settings.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us so we can remove it.
10. Changes to this Notice
We may update this Notice. Material changes will be notified via the Service, by email or by requiring re-acceptance on the billing page. The "Last updated" date reflects the most recent revision.
11. Contact
Data controller: Stav Danino
Email: Stavdaninomusic@gmail.com
Privacy Appendix — Latest Updates (effective July 20, 2026)
P.1 Cookie Categories
- Essential — session, security, language. Always on, no consent needed.
- Analytics — aggregated usage to improve the product. Consent required.
- Marketing — tailored updates and offers. Consent required.
- AI processing — running AI features on your content. Consent required. Manage anytime in the Privacy Center.
P.2 Teacher–Student Consent Record
When a teacher–student link is created, we store an explicit consent record listing which categories were shared (projects, audio, tasks, gigs in general details only — no financial data, no AI insights or analytics). The record is retained for compliance. On link termination, access is revoked in real time and the consent record becomes a historical entry, not an active grant.
P.3 Third-Party Integrations (OAuth)
- Google Calendar / Drive — encrypted OAuth token stored solely for calendar/folder sync you authorized. Disconnect any time.
- Paddle (billing) — Merchant of Record; payment details are stored with Paddle only.
- Cloudflare — CDN, WAF and Turnstile (anti-bot). Cloudflare may process IP and request headers for security.
- Sentry — technical error telemetry only (stack trace, version, device type). No user content.
P.4 Push Tokens & Devices
If you opted in to push notifications, we store an encrypted device token used only to deliver those notifications. Remove it via device settings or the Privacy Center.
P.5 Usage & Security Telemetry
- We measure in aggregate: storage volume, monthly bandwidth (Ingress/Egress), AI request counts, and basic actions (login/project creation) — for quota enforcement, security, and aggregate statistics.
- We run automated security scanners and anomaly detection (auth anomaly, new-country logins). Anomalies trigger notification and may result in temporary block.
P.6 Audit Log
Admin actions and sensitive operations (permission changes, account deletion, quota changes, support access on your request) are recorded in an Audit Log retained up to 24 months for security, investigation and compliance.
P.7 Privacy Center — Self-Service
The Privacy Center lets you: view/change all consents, export all your data, delete your account and associated data (Right to Erasure), disconnect integrations, and see which teachers/teams are linked to you. Deletions apply immediately; full purge from backups within 30 days.