Privacy Policy
This Policy describes how we handle your “Personal Data”, which is information that is directly linked or can be linked to you. It applies to the Personal Data that Procedural Audio LLC processes as the “Data Controller” when you interact with websites, applications, and services that display this Policy (collectively, “Services”). Route stores projects, assets and application settings on your device, and you can compose and play audio without an account.
Personal Data we collect and how we use it
We collect Personal Data directly from you, automatically from your device and from third parties. What we collect depends on how you interact with our Services and which features you use.
Accounts and content
- Account data: For email sign-up, our authentication service receives your email address, password and display name and sends them to Google Identity Platform to create your account. Sign-in sends the email and password to the same provider. We use your account identifier and sign-in credentials to sign you in, maintain your session and authorize access to the Services.
- Sign-in providers: If you sign in with Google, GitHub or Apple, that provider receives your sign-in interactions and returns sign-in information to us. We use Google Identity Platform to establish your Route identity from this information, including your account identifier, email address and display name. We do not receive the password for your provider account.
- Profile information: We store your username, display name, biography and the link to your profile image. Your initial username is based on your display name or, when it is blank, the part of your email address before the @. You can change your profile in your account settings. Other signed-in users can look up your account identifier and profile by username; that lookup does not return your email address.
- Project content: Enabling cloud sync uploads the project's content, editing history and referenced assets, including module source code, audio and sequences. We also store the project identifier, name, owner, invitations, membership roles and sync setting. The cloud keeps a copy of the project and exchanges changes with connected members. Disabling sync stops subsequent project synchronization; it does not delete the existing cloud copy.
- Account library: While signed in, Route automatically synchronizes the library for that account, including asset names, descriptions, properties, identifiers, installed community assets and records of removed entries. Private asset files upload separately. Library synchronization runs independently of each project's sync setting and requires an active subscription. Signing out stops account-library synchronization on that device.
- Published assets: Publishing sends the asset's source code or audio/sequence file and its name, description, author account identifier and classification information to our services. We use published content to generate previews and measurements, support catalog browsing and search, and let users install assets in their libraries.
- Other users: Project owners identify invited collaborators by username. Shared projects contain the content contributed by their members. Published assets contain their authors' supplied names, descriptions and content.
- Generation requests: To create or revise a module, sample or sequence, we send generation inputs to Google's Vertex AI. For modules, these include your instructions, current and earlier source code, error messages and artwork. Any prompts you include from earlier versions are sent with the request. Sequence generation sends instructions, existing notes and the requested playback range. Sample generation sends instructions and the name of the sample being replaced, but not that sample's audio. Generated content is returned to Route and follows the library, project-sync and publication rules when you save or publish it.
- Catalog searches: We receive your search text and filters. We send multiword searches to Google's Vertex AI to find related assets; single-word searches use text matching without that model processing. We temporarily store the matching asset identifiers and filters so you can view successive pages of the same results.
- Payment information: Stripe collects payment details on its hosted checkout and subscription-management pages. We send Stripe your Route account identifier, selected plan and price, and your email address when creating checkout without an existing Stripe customer. We store Stripe customer and subscription identifiers, plan, subscription status and billing-period dates, and receive updates from Stripe to keep these records current. We use subscription and storage records to provide paid features, enforce plan allowances and reconcile billing with Stripe. Route's subscription records do not contain payment-card numbers.
- Support data: When you email support@procedural.audio, we receive your email address, message and any attachments you send. We use this information to respond to your request.
Automatic collection
- Service logs: Google Cloud records requests to our cloud services, including request times, requested addresses and actions, response status, response time, IP addresses and the browser or application information supplied with the request. Application logs record errors and operational events, including account and request identifiers and generation usage, to diagnose failures and rejected requests. Cloudflare receives network requests when serving our website, downloads and public asset files.
- Synchronization connections: When you join a synced project, Route shares your device's connection identifiers and network addresses with our cloud service and the project's connected members. Direct connections expose your IP address to the peers you connect to. Number 0 provides services that help devices find and connect to each other, including relays that forward traffic. Its public lookup service publishes device connection identifiers and relay addresses; relays receive IP addresses, connection times and traffic volumes. Peer traffic is encrypted between endpoints, so a relay cannot read the project content it forwards.
- Updates: Desktop versions with automatic updates contact downloads.route.audio, hosted by Cloudflare, to check for and download updates. These requests occur without signing in and expose your IP address to Cloudflare. Snap and Flatpak packages do not use Route's automatic updater.
Generation and automated catalog processing
Publishing sends sample audio, or module and sequence names, descriptions and classification information, to Google's Vertex AI to make those assets searchable. Changes to module or sequence metadata update the search information. We also use the analysis of sample audio to arrange samples in maps. Module generation includes source code and artwork from public catalog modules as examples. These uses of published content occur even if its author does not use generation.
We keep usage records to bill for generation, enforce generation allowances and prevent duplicate charges. They contain account and request identifiers, the generation type and model, attempt counts, dates and times, charges and processing usage, including the length of generated audio. These records do not contain prompts or generated files. Saved assets and source versions in synced projects are stored separately, under the library and project-sync rules. Route does not save generation prompts in project history.
Under Google's Service Specific Terms, Google needs prior permission or instructions from Procedural Audio LLC, as its cloud customer, to use data submitted through our account to train or fine-tune models. This contractual permission is distinct from an individual user's decision to use generation. Google's data-governance documentation explains its rules for temporarily caching model inputs and outputs and monitoring requests for abuse. Google's handling of these requests is separate from Route's storage of usage records and saved content.
Sharing of Personal Data
We share data with these service providers for the functions listed:
| Provider | Data and function |
|---|---|
| Google Cloud | Account sign-in; hosting and storage of account profiles, subscription records, projects, libraries and catalog records; operational logs; and generation and catalog analysis through Vertex AI. |
| Backblaze B2 | Storage and delivery of private asset files used by synced projects and account libraries. |
| Cloudflare | The website, application downloads, storage of community catalog files and previews, and private files used to display sample maps. Route's authenticated services deliver community files to subscribers. Cloudflare receives network requests when it serves content to you or our services. |
| Stripe | Account ID and email address, checkout, payment details, subscriptions and subscription-management interactions. |
| Number 0 (n0.computer) | Services that connect devices for project synchronization, including public device connection identifiers and relay addresses, and the network information described above. |
When you use third-party extensions, integrations, or follow references and links within our Services, the privacy policies of these third parties apply to any Personal Data you provide or consent to share with them. If you connect an external assistant or other client to Route's Model Context Protocol (MCP) interface, that client can read and edit the open project through scripts and receive images of its nodes. Edits made through that interface follow the project's existing sync settings.
Invited project members receive shared project content according to their viewer or editor role, and a project owner can transfer ownership to an accepted collaborator. Community publications carry the author account identifier and supplied metadata. Catalog browsing and downloads of published files and audio previews require an account with an active subscription. Other subscribers can retain copies they have already downloaded.
We disclose Personal Data when a binding legal obligation requires disclosure. We do not sell Personal Data or share it for cross-context behavioral advertising.
Access to private content and security
Our services check identity and project membership to control access to private cloud data, and subscription status to enforce access to paid storage and synchronization. Private files are delivered through download links that expire. Cloud sync sends project content to our servers, where it is read and processed; encryption of connections between devices does not prevent us from accessing this cloud copy.
Connections to our cloud services and file storage are encrypted, as are direct connections between devices. Access to the administrative dashboard is restricted to authenticated operators on an approved list. The dashboard displays account, subscription, library and catalog records and project details, but does not display private asset files or project editing history. We record administrative changes to accounts, catalog entries and system prompts, including the account or asset identifier, who made the change, the reason, and the information before and after the change.
Retention and deletion
We do not automatically delete accounts or cloud projects because you stop using them. Turning project sync off or signing out does not erase cloud records. Removing an asset from your library marks its entry as removed so other devices can apply the change; the entry's metadata remains until the library is cleared through account Reset or deletion.
When a subscription expires, local copies remain usable, but cloud uploads and downloads stop, including retrieval of your own existing cloud data. Sync the content you need to each device before your subscription expires. Expiry does not itself delete retained cloud data.
Account deletion and recovery
You can request account deletion from your account settings. This marks the account and its owned projects for deletion, releases the username, and removes invitations and memberships in other people's projects. Your sign-in account remains available during the 15-day recovery period. Recovering the account restores the account and projects marked by that deletion, but it does not restore the released username or the removed memberships.
After the recovery period, automatic account cleanup cancels the recorded Stripe subscription and attempts to remove the account records. It does not delete the separate sign-in account held by Google; email support@procedural.audio to request that deletion. Account removal cannot complete while retained projects or catalog records still identify you as their owner or author. Projects are cleaned up separately, and account cleanup does not remove public catalog records. Deletion therefore takes longer than the recovery period and does not erase every copy of your data.
Reset and Delete now
The account interface also offers the following actions:
- Reset: Keeps the account, clears its library and generation usage records, and leaves its owned projects scheduled for deletion. Reset does not cancel the subscription.
- Delete now: Does not cancel your Stripe subscription. Use Manage Subscription to cancel billing before selecting Delete now. This action requests immediate removal of account records, followed by deletion of the sign-in account held by Google. Owned projects and published catalog records can prevent account removal from completing; the Google sign-in account is deleted only after that removal succeeds.
Project and private-file deletion
Deleting an individual cloud project starts a 15-day retention period. The project retains its associated private files until project cleanup runs. Removing a library asset makes its private files eligible for cleanup once no cloud project or other library entry uses them. Account Reset and Delete now also schedule that account's private files for cleanup. Files retained for another account after an ownership transfer remain available to that account.
A separate cleanup process removes private files that are no longer referenced, along with abandoned uploads. Files queued for storage deletion wait at least another 24 hours before removal. Cleanup runs on a schedule, removes all stored versions and retries failures, so deletion is not immediate. Cloud deletion does not erase files on your own devices or copies already obtained by collaborators or other users.
Published assets
Unpublishing removes a listing from community discovery and prevents new installations through the catalog. The published files, listing record and existing installations remain, so previously installed assets continue to work. Account cleanup does not remove public catalog records or files. Unpublishing also does not revoke copies already downloaded by other people.
Other retained records
Expiry makes a record eligible for scheduled deletion; it does not guarantee physical removal at that exact time.
| Record | Retention |
|---|---|
| Generation usage records | Eligible for automatic deletion 395 days after creation. Account removal and Reset also delete these records. |
| Database version history | Earlier versions of database records are kept for seven days, including versions preceding a deletion. |
| Catalog search results | Matching asset identifiers and filters expire after ten minutes and become eligible for deletion. These records do not contain the search text or an account identifier. |
| Temporary copies used for search | The catalog service keeps text and its numerical search representation in memory with a one-hour expiry. |
| Temporary Apple desktop sign-in information | Sign-in credentials expire after five minutes and become eligible for deletion. Retrieving them through the app removes the stored copy. |
| Administrative audit records | Retained indefinitely, including after account deletion. |
Cookies and local storage
The website stores sign-in credentials in your browser to restore your session. Signing out or clearing the site's browser storage removes the saved credentials; a failed session refresh also removes them. A short-lived credential used for service requests stays only in memory. Google and GitHub sign-in also store temporary information in your browser tab to verify that the returning sign-in response belongs to the request you started. That information is removed when the response is processed or when you close the tab.
On supported operating systems, Route saves sign-in credentials in the system's protected credential storage. It does not save them on systems without supported credential storage. Signing out ends the session on that device and requests removal of the saved credentials; if removal fails, Route reports the failure and retries it. Signing out does not sign out other devices.
Route and route.audio do not include software for advertising or behavioral analytics, and the website code does not set advertising or analytics cookies. Sign-in providers and Stripe apply their own storage and privacy rules to the pages they host.
Lawful bases for processing Personal Data (EEA and UK)
We process account, subscription and content data to provide the Services you request, including authentication, cloud storage, synchronization, sharing, catalog access and generation. These activities are necessary to perform our contract with you. We also rely on our legitimate interests in operating and securing the Services to diagnose errors, control service access and keep administrative audit records. These interests must not override your data-protection rights or your fundamental rights and freedoms.
We process data when it is necessary to comply with applicable legal obligations, including responding to binding legal requests for information. Where processing is based on your consent, you have the right to withdraw that consent by contacting support@procedural.audio. Withdrawal does not affect the lawfulness of processing before withdrawal.
Your privacy rights
Depending on where you live, you may have the following rights over your Personal Data:
- The right to access the data collected about you
- The right to request detailed information about the specific types of Personal Data we've collected over the past 12 months, including data disclosed for business purposes
- The right to rectify or update inaccurate or incomplete Personal Data under certain circumstances
- The right to erase or limit the processing of your Personal Data under specific conditions
- The right to object to the processing of your Personal Data, as allowed by applicable law
- The right to withdraw consent, where processing is based on your consent
- The right to receive your collected Personal Data in a structured, commonly used, and machine-readable format to facilitate its transfer to another company, where technically feasible
To exercise these rights, make an opt-out request or raise a privacy concern, email support@procedural.audio. For requests to remove personal information from a published asset or profile, include the content's identifier or URL. We request additional information when needed to verify your identity before addressing your request. We respond within the period required by the law applicable to your request. A legal obligation to retain a record, or its necessity for establishing, exercising or defending a legal claim, can limit a deletion request.
Depending on your region, you have the right to complain to your local Data Protection Authority. European users can find authority contacts on the European Data Protection Board website, and UK users on the Information Commissioner's Office website.
International data processing
Our application services and database are hosted by Google Cloud in the United States, and private asset files are stored by Backblaze B2 in the United States. We have not selected a single country for Google's generation and catalog analysis. Cloudflare delivers our website, downloads and public files through its international network, and Number 0 provides an international network of relays for device connections. Using these cloud features sends the data described in this Policy to these providers, including when you use Route from outside the United States.
US state-specific information
This section uses the term “personal information” as an equivalent to “Personal Data.” The categories processed by the Services are identifiers and contact information; account and subscription information; internet and network activity; and audio, electronic and visual content you submit. The collection, purposes, recipients and retention sections above describe these categories. Stripe collects payment information on its own pages. Route's search and generation features process your content and search text; they do not profile people to make decisions with legal or similarly significant effects.
If you choose to use an authorized agent to submit a request on your behalf, please ensure they have your signed permission or power of attorney as required. We do not discriminate against you for exercising your privacy rights. Where your state's law provides a right to appeal a denial, reply to our response at support@procedural.audio to appeal. You can also contact your state's attorney general or privacy regulator.
Contact us
Procedural Audio LLC
Email: support@procedural.audio.
Information for minors
Our Services are not intended for individuals under the age of 13. If you become aware that a minor has provided us with Personal Data, please notify us.
Changes to our Privacy Policy
We update the effective date at the top of this Policy when we revise it. We publish revisions at route.audio/privacy-policy/.
Attribution
Adapted from GitHub's General Privacy Statement, licensed under Creative Commons Attribution 4.0 International. Modified by Procedural Audio LLC to describe Route and its cloud services.