Privacy Policy
Last updated: May 3, 2026
Gethsemane LLC ("Gethsemane," "we," "our," or "us") operates SavePoint.fm and the SavePoint Station Manager desktop software (together, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and the choices and rights you have over your data.
1. About This Policy
Gethsemane LLC is a United States company that operates SavePoint Broadcast Software, SavePoint.fm, and its supporting facilities. We follow practices aligned with widely-recognized data-protection principles, and we honor specific rights that data-protection laws like the GDPR give to users where those laws apply. References to GDPR articles elsewhere in this Policy describe the protections we extend to you and how we organize our processes.
2. Information We Collect
Account information
When you create an account, we collect:
- Email address
- Name (optional, for personalization)
- Password (stored only as a salted bcrypt hash, never in plaintext)
- Avatar selection (Gravatar opt-in or selected frog avatar from our gallery)
Authentication information (if you sign in with Google)
If you choose "Sign in with Google," we receive your Google account ID, email address, and display name from Google's OAuth service. We do not see your Google password.
License and activation data
To validate your software license, we record:
- An anonymized hardware fingerprint of each device you activate (no MAC addresses or unique identifiers we can use to track you outside our service)
- Activation environment (staging or production)
- Application version
- Activation timestamps
Payment information
Stripe processes all payments. We never see or store your full credit card number. Stripe provides us with limited information for billing records: your billing email, billing address, the last four digits of your card, and your Stripe customer ID.
Communications
If you contact our support team, we store your messages and our replies so we can help you and so we have a record of the conversation. If you submit comments on blog posts, those comments are stored on our servers.
Pulse FM submissions
If you submit a creator profile to Pulse FM, we store the information you provided (creator name, biography, social links, uploaded images, work descriptions) so we can review and publish it.
Behavioral and security logs
We store limited operational logs:
- Login attempts (email, timestamp, success or failure) for fraud and rate-limit enforcement
- IP address hashes (SHA256 truncated, never the raw IP) for security logging on certain public endpoints
- Search queries on the documentation (anonymous, no user link)
- Documentation feedback (anonymous, no user link)
- Page views and downloads attributed to your account when you are signed in (so we can answer support questions about what you've used and to help us improve the product)
- Acquisition data captured at registration: the referring URL (
document.referrer) and any UTM parameters in the registration URL, so we know how you found us
Cookie preferences and consent records
We store your cookie consent decision so we can respect it on subsequent visits. The consent record includes which categories you accepted or declined and when.
Data we do NOT collect
- Your audio files, playlists, schedules, and broadcast configurations are stored locally on your computer. We never upload them.
- We do not collect device identifiers beyond the anonymized license fingerprint.
- We do not buy data about you from data brokers or enrich your profile from third parties.
3. Why We Use Your Information
We use the personal data described in Section 2 for the following purposes:
| What we do | Why |
|---|---|
| Create and manage your account | To deliver the service you signed up for |
| Validate your software license | To enforce license terms you agreed to |
| Process payments and subscriptions | To fulfill paid orders |
| Send transactional emails (verify, reset, receipts, notifications) | To operate your account |
| Provide customer support | To respond to your requests |
| Detect and prevent fraud, abuse, and spam | To protect the service and other users |
| Security logging (IP-hashed) | To detect and respond to attacks |
| Send marketing and product-update emails | If you've opted in |
| Run analytics (Google Analytics 4) | If you've opted in via the cookie banner |
| Comply with legal obligations | Tax records, court orders, regulatory requests |
When we rely on your consent (marketing emails, analytics), you can withdraw it at any time without losing access to the Service. For other uses, you can object using our contact form.
4. Sub-processors
We use the following third-party processors to operate the Service. Each is bound by a Data Processing Agreement (DPA) requiring them to handle your data only on our instructions and with appropriate safeguards.
Required processors (necessary to operate the Service)
| Processor | Role | Country | Transfer safeguard | DPA |
|---|---|---|---|---|
| Cloudways (DigitalOcean) | Application and database hosting | United States | Standard Contractual Clauses | Cloudways DPA |
| Stripe | Payment processing | United States | SCCs + EU-US Data Privacy Framework | Stripe DPA |
| Resend | Transactional emails (account, license, support, receipts) | United States | Standard Contractual Clauses | Resend DPA |
| Google (OAuth) | "Sign in with Google" identity, only if you choose it | United States | SCCs + EU-US Data Privacy Framework | Google Cloud Customer Data Processing Terms (see Google's privacy policy) |
Optional processors (only if you consent)
| Processor | Role | Country | Transfer safeguard | DPA | How to control |
|---|---|---|---|---|---|
| Google Analytics 4 | Aggregate usage analytics | United States | SCCs + EU-US Data Privacy Framework | Google Ads Data Processing Terms | Cookie banner; Settings > Your data > Cookie preferences |
| Resend (marketing emails) | Newsletters, product updates, promotions | United States | SCCs | Resend DPA | Settings > Email preferences; one-click unsubscribe in every marketing email |
We update this list when we add or remove a processor; material changes are reflected on this page with a new "Last updated" date.
5. International Data Transfers
The Service is operated from the United States. Personal data of users in the European Economic Area, the United Kingdom, and Switzerland is transferred to the United States and other countries where our sub-processors operate.
We use the following safeguards for these transfers:
- Standard Contractual Clauses (SCCs) incorporated into each sub-processor's DPA.
- EU-US Data Privacy Framework (DPF) for sub-processors that are DPF-certified (Stripe, Google).
You can request a copy of the relevant safeguard using our contact form below.
6. Data Retention
We keep personal data only for as long as we need it for the purpose we collected it for, plus a reasonable period to satisfy legal, accounting, or audit requirements. Where we can keep data as anonymous statistics indefinitely without retaining anything that identifies you, we do; this gives us long-term insight into how the service is used without expanding our personal-data footprint.
| Data category | What we keep, and for how long |
|---|---|
| Account profile | Kept while the account is active. On erasure, the profile is anonymized (PII scrubbed; sentinel email substituted) but the row is preserved so the records that referenced it (licenses, support tickets, comments) remain intact and aggregable. |
| License and activation records | Until you delete your account. Activation rows for licenses that have been expired for 1+ year are pruned automatically (subscription-style licenses are unaffected). |
| Payment and subscription history | 7 years from last transaction (US tax record retention), then anonymized and deleted. |
| Support tickets and replies | Kept while your account is active. On account erasure, tickets are anonymized along with the rest of your account record so the history stays intact for our records without identifying you. Tickets you marked public remain in our public help knowledge base. Full removal of support history happens only when you separately request full deletion of all your data alongside account erasure. |
| Email preferences | Lifetime of account; deleted on erasure. |
| Consent audit log (every accept/reject/change you've made for cookies, analytics, or marketing emails) | Append-only log retained 3 years past your last consent event, then pruned. Used to demonstrate your consent decisions if asked. On account erasure the rows survive but are detached from your identifier (user_id set to null). |
| Login attempts (rate-limit table) | Lifetime of account when tied to a real user; orphan rows (failed logins against non-existent emails, typically bot probes) are hard-deleted after 90 days. |
| Email delivery events (Resend webhooks) | Lifetime of account when tied to a real user; orphan rows (sends to non-account addresses, e.g. waitlist) are hard-deleted after 90 days. |
| Page visits (when signed in) | Kept for the lifetime of your account. On erasure the rows are kept, tied to the anonymized stub, so we can still answer support questions about prior usage. Anonymous page visits (no signed-in user) are hard-deleted after 90 days. |
| Downloads | Kept for the lifetime of your account. On erasure the rows are kept, tied to the anonymized stub. Anonymous downloads have no link to identify a person. |
| Acquisition data (signup referrer + UTM) | Stored on your user row. On erasure the fields are nulled along with the rest of your row. |
| Documentation feedback | The thumbs-up/thumbs-down signal and the doc identifier are kept indefinitely as anonymous statistics. Personal identifiers (your account ID, IP hash, user agent) are removed from the row after 90 days. |
| Search query logs (documentation) | Already anonymized at the point of collection (only an irreversible IP hash is stored, never your raw IP or account ID). Retained indefinitely as anonymous statistics. |
| Stripe webhook event audit log | Contains no personal data (Stripe event IDs and statuses only). Retained indefinitely for accounting reconciliation. |
| Artist Feature Permission records (Pulse FM) | Kept indefinitely as a legal record of consent. Each row contains the artist's typed signature, the agreement text exactly as displayed at signing, the IP hash and user-agent that submitted the form, and the generated PDF receipt. Hard-deleted only when the artist separately writes to us asking for the permission record itself to be removed; account erasure alone does not remove a permission record because permission rows are not necessarily tied to a SavePoint account. |
When you exercise your right to erasure (see Section 7), three things happen at once. Your user row is anonymized: email is replaced with a non-routable sentinel, name and avatar are nulled, password and acquisition fields are wiped. Auth artifacts are hard-deleted: sessions, OAuth provider links, password-reset tokens, email preferences, and prior data-export records. Everything else with a foreign key to your account, including licenses, subscriptions, support tickets, blog comments, pulse-fm submissions, page visits, downloads, login-attempt rows, email-delivery events, and the consent audit log, is kept and tied to the anonymized stub so the operational and aggregate-analytics signal survives without identifying you.
Some records may be retained beyond the periods above if required by law or to defend against legal claims.
7. Granted Rights
We grant the following rights to every user of the Service:
- Access: Receive a copy of the personal data we hold about you.
- Data portability: Download your data in a structured, machine-readable format. Use the Export my data button at Settings > Your data.
- Rectification: Correct inaccurate personal data. Edit your profile in Settings, or contact us for fields you cannot edit yourself.
- Erasure: Delete your account and have your personal data removed. Use the Delete account button at Settings > Danger zone. We satisfy this right through irreversible anonymization rather than full row deletion: your email, name, password, and avatar are scrubbed, and any aggregate records that contained you (license activations, support tickets you opened, blog comments, pulse-fm submissions, page-visit logs) are kept but are no longer linked to anything that can identify you. After erasure, you cannot sign back in to the same account.
- Restriction: Ask us to limit how we process your data while a dispute is being resolved.
- Objection: Object to processing we have decided is in our legitimate operational interest, including any direct marketing.
- Withdraw consent: When we rely on your consent, you can withdraw it at any time. For analytics: Settings > Your data > Cookie preferences. For marketing emails: Settings > Email preferences, or click "unsubscribe" in any marketing email.
- Complaint: If you believe we are mishandling your data, contact us first so we have a chance to address it. You may also escalate to a data protection authority in your jurisdiction.
To exercise any of these rights, use the in-product controls at https://savepoint.fm/dashboard/settings, or use our contact form below. We will respond within 30 days.
8. Cookies and Tracking
We use a small number of cookies and similar storage technologies. Some are essential to operating the Service. Others are optional and only set with your consent.
Essential cookies (always on)
These are exempt from consent under the ePrivacy Directive Article 5(3) because they are strictly necessary to provide the Service you requested:
- Session cookies (NextAuth) to keep you signed in
- CSRF protection tokens to prevent cross-site request forgery
- Cookie consent record so we remember your choice
- Locale preference to remember your language
Optional cookies (consent required)
- Google Analytics (
_ga,_gid) for aggregate usage analytics. Loaded only after you accept the cookie banner.
You can change your cookie choices at any time at Settings > Your data > Cookie preferences. We use Google Consent Mode v2, which means analytics are denied by default until you accept.
9. Security
We use technical and organizational safeguards including:
- TLS encryption for all data in transit
- Encrypted storage at rest
- Bcrypt password hashing (12 rounds)
- IP address hashing for logs (raw IPs are never stored)
- Bot protection on public endpoints (rate limiting, behavioral signals)
- Restricted database access (admin credentials limited to engineering)
No security measure is perfect. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours where required.
10. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has created an account, please contact us and we will delete the account and any associated data.
11. Changes to This Policy
We may update this Privacy Policy as our practices evolve or as required by law. The "Last updated" date below reflects the most recent material change. For significant changes, we will notify users by email or through a prominent notice in the Service before the change takes effect.
12. Contact
For privacy questions, requests to exercise your rights, or any other concerns about this policy, use our privacy contact form.
For account-related support (not privacy-specific), use the support portal.
Data Controller. Gethsemane LLC ("Gethsemane," "we," "our," or "us") operates SavePoint.fm and the SavePoint Station Manager desktop software (together, the "Service") as the data controller for personal data processed through it. Gethsemane LLC operates as a remote-only business in the United States and does not maintain a public office address. All correspondence, including legal notice, should be submitted through our privacy contact form. We monitor it regularly and will respond within 30 days.