Privacy Policy
This policy explains how the OpenStudio desktop app and openstudio.org.in handle local files, optional online services, website analytics and support information.
Who is responsible and what this policy covers
OpenStudio is maintained by Sourav Das. This policy covers the OpenStudio desktop application, including its Microsoft Store distribution, and openstudio.org.in. Contact support@openstudio.org.in about privacy or information handled by the project.
The desktop application processes your music on your device. Accessing information to record or edit it is different from collecting it on the maintainer's servers. Optional online integrations and the public website have the separate data flows described below. Third-party providers are responsible for their own services under their privacy policies.
Audio, MIDI, projects and device information
To record, play, edit and export, the app accesses audio inputs, MIDI devices, files you open, and available audio devices and plugins. Recordings can include identifiable voices; project names, file paths, metadata and device names can also contain personal information. Microphone access is subject to your operating system's permission settings.
The built-in recording, editing, mixing and export workflows store audio, projects, presets, exports and recovery data locally. They do not upload your recordings or project contents to OpenStudio servers. Files placed in a cloud-synced folder may be transferred by your chosen sync service independently of OpenStudio. Third-party plugins or scripts you run may have their own network behavior.
Optional TONE3000 login and NAM Rack
Core recording and editing do not require an OpenStudio account. If you connect NAM Rack to TONE3000, authentication takes place through TONE3000's browser sign-in flow. OpenStudio receives authorization results and access/refresh tokens so it can make requests associated with your TONE3000 account. OpenStudio does not receive the password you enter on TONE3000's login page.
The app keeps authentication tokens locally to maintain the connection across restarts and sends them to TONE3000 for authorized requests and token refresh. Browsing and downloading captures sends search terms, filters and requested tone/model identifiers to the service. TONE3000 and its delivery providers also receive ordinary network information, such as your IP address. These library requests do not upload your recorded audio to TONE3000.
Use NAM Rack's sign-out control to remove the app's saved connection credentials. Signing out of OpenStudio's connection does not delete your TONE3000 account or necessarily sign you out in your browser. Manage that account and its data with TONE3000 directly. Downloaded captures and locally saved projects are separate from your login credentials.
Optional AI tools and downloads
Optional stem separation and music-generation workflows install or import runtime components and model files. The built-in local workflows process audio, text prompts, lyrics and generated results on your computer; they do not send that content to a hosted inference service as part of the normal workflow.
Setup and model downloads can connect to OpenStudio's release site, GitHub, Hugging Face, Python package indexes, PyTorch distribution servers and model publishers. Those services receive the requested resource and normal network information. A model provider may require its own account or license acceptance. Independently installed plugins, scripts, modified builds or services can behave differently and are subject to their own policies.
App updates, website hosting and network requests
Update checks and downloads contact the relevant distribution provider, such as openstudio.org.in, GitHub or Microsoft Store. These services receive IP addresses, requested URLs and other normal HTTP connection information. The purpose is to deliver version information and software, not to upload your audio or project contents. Update controls depend on the installed distribution and your operating system settings.
The website is hosted using Netlify and links to GitHub release assets. Hosting and download providers may keep request logs, including IP addresses, browser/user-agent information, referrers, requested pages and timestamps, to deliver content, diagnose failures and protect infrastructure. Those essential requests occur even when website analytics are rejected.
Website analytics and privacy choices
The website uses Google Analytics 4 for traffic and engagement measurement and Microsoft Clarity for interaction analysis, heatmaps and session replays. These integrations run on the website, not inside the OpenStudio desktop app. They can process page visits, referrers, approximate location, browser/device information, identifiers, download/outbound-link interactions, clicks and scrolling. A replay represents website interactions, not a recording of your desktop or DAW session.
Optional website analytics load only after you choose Accept analytics. Choose Reject analytics to use the site and downloads without loading either provider. You can reopen Privacy choices in the footer to change your decision. Your choice is stored in this browser for up to 180 days; if browser storage is unavailable, it applies to the current page session. Changing your choice takes effect without reloading the page. When a saved choice expires or is cleared, optional analytics stop and the site asks you to choose again.
The site does not enable advertising consent or Google advertising personalization. Analytics providers may use cookies and similar identifiers when analytics are accepted. Rejecting later stops future website tracking through these integrations and clears accessible first-party analytics cookies; it does not automatically erase information already processed by Google or Microsoft or cookies belonging to other domains. Their privacy policies and privacy controls also apply.
Local diagnostics and information you send us
The app can write local startup logs, error reports, recovery records and crash diagnostics. These may contain application and operating-system versions, device/plugin names, file paths, error details and, in crash dumps, portions of process memory. The built-in crash-reporting workflow saves these reports on your device and does not automatically upload them to the maintainer. Review diagnostic files before choosing to share them.
If you email support@openstudio.org.in, contact the maintainer or post a GitHub issue, we receive the details you choose to provide, such as your email address, message and attachments, and use them to respond and investigate. GitHub issues are public: do not include private recordings, passwords, tokens or other confidential data.
Storage, protection and retention
Local projects, recordings, exports, downloaded models and captures remain in your selected folders or the app's data/cache folders until removed by you or the relevant cleanup process. Recovery copies, logs, browser data and credentials may be stored separately from the main project. Deleting one project or uninstalling an app does not necessarily remove every copy, backup or external file.
Connections to online authentication and download services use HTTPS. The TONE3000 browser sign-in flow can return an authorization result to a temporary HTTP callback on 127.0.0.1, the loopback address of your own computer. That callback is local to your device.
On Windows, saved TONE3000 authentication tokens are encrypted using Windows Data Protection (DPAPI) under your Windows user account. Other platforms use the app's platform-specific credential handling. Access to local files also depends on your operating-system account, device security and backup configuration. Project and audio files are not automatically encrypted by OpenStudio. No system can guarantee absolute security.
Hosting logs and analytics are retained under the providers' applicable service policies and account retention settings; periods differ by provider and data type. Support correspondence is kept as needed to answer requests, resolve issues and meet applicable obligations. Contact us for information about records held by the maintainer or the current provider settings. We cannot remotely delete files that remain solely on your device.
Your controls and privacy requests
You can access your recordings and projects by opening them in OpenStudio or their saved folders, and export audio using the app's export controls. Locally stored files are under your control; you do not need to send them to the maintainer to access or copy them. Contact us if you need help locating app data or diagnostic files for your installation.
You can revoke microphone access through your operating system, decline optional online features, sign out of TONE3000 in NAM Rack, and change website analytics consent using Privacy choices. You can delete your own projects, exports and app data using your device's file-management tools. Back up anything you want to keep before clearing app data, and check any separate cloud backups or synced copies.
Depending on applicable law, you may have rights to access, correct, delete or obtain a copy of personal information, restrict or object to processing, or withdraw consent. Send requests concerning the maintainer's records to support@openstudio.org.in. We may need proportionate information to verify your request; do not send passwords or authentication tokens. Withdrawing consent does not undo processing that already occurred. You may also raise concerns with your local data-protection authority.
For accounts or information held independently by TONE3000, Microsoft, Google, GitHub, Netlify or another provider, use that provider's privacy-request process. Providers may process data in countries other than your own under their applicable policies and safeguards. We will explain any limitation that prevents us from fulfilling a request directed to us.
Children and changes to this policy
The public website and its analytics are not designed to collect personal information from children. If you believe a child has provided personal information to the maintainer, contact support@openstudio.org.in so we can review and address it. Third-party account services have their own age requirements.
We update this policy when the application's data flows, website services or privacy controls change. The Last updated date identifies the current revision. Material changes will be described on this page and, where appropriate, in release communications or a renewed consent request.
