Privacy Policy
Last updated: September 5, 2026
This Privacy Policy explains how Epitrite LLC, based in Sarasota, Florida, United States ("Epitrite," "we," or "us"), collects and uses personal information when you use our content planning and video editing services. Epitrite LLC is responsible for the account and service data described here. Contact us at support@epitrite.com.
We serve customers worldwide. The rights available to you depend on where you live; applicable local privacy protections continue to apply when you use our Service.
1. What We Collect
Account Information
- Email address (used for login and communication)
- Password (hashed, never stored in plain text)
- Display name (if you set one)
- For signup abuse prevention, we process your network address, a first-party device cookie, a local browser identifier, and limited browser characteristics. Epitrite stores keyed one-way identifiers, not the raw network address or raw device values, in its account identity ledger.
Content You Upload
- Audio files (MP3, WAV, etc.)
- Video clips and images
- Lyrics and project data
- Rendered/exported video files
- Content OS campaign facts, drafts, recording plans, approvals, and publishing schedules
- Support messages and feedback you send us
- Email addresses and signup preferences submitted through newsletter or artist fan-signup forms
- Connected social account identifiers, access tokens, posts, and performance data when you enable a supported integration
Payment Information
Web payments are processed by Stripe. Purchases made in the iPhone app are processed by Apple through In-App Purchase. We do not store your credit card number, CVV, or full card details. Stripe provides us with a customer ID, basic transaction records (amount, date, plan), and a non-secret card fingerprint that we use to prevent referral abuse. Apple provides signed product, transaction, subscription-status, and expiration information so we can activate and maintain your in-app entitlement.
Automatically Collected Data
- IP address and approximate location (country/region)
- An opaque first-party browser identifier used to prevent repeated Free-account abuse
- Browser type and operating system
- Pages visited and features used within Epitrite
- Timestamps of account activity
- Browser push subscription endpoint and encryption keys, only if you enable render alerts
- Referral code attribution, qualification, and reward status when you use the referral program
2. How We Use Your Data
- To provide the Service — storing your projects and rendering videos
- To process payments — managing subscriptions and billing through Stripe on the web or Apple In-App Purchase on iPhone
- To communicate with you — account notifications, billing receipts, service updates, and opt-in render alerts
- To improve the Service — understanding usage patterns to fix bugs and build features
- To operate referrals — attributing eligible referrals, issuing rewards, and preventing self-referral or payment-method abuse
- To enforce our Terms — preventing abuse and unauthorized access, including repeated Free-account benefit claims
- To prevent repeat-account abuse — limiting account creation by network and device and screening VPN, proxy, hosting, and privacy-relay traffic
We never claim rights to your music. Your songs, lyrics, audio files, and rendered videos remain yours, subject to the rights of other owners. We do not sell your personal data for money. Optional advertising disclosures may be considered a sale or sharing under some privacy laws; see Sections 4, 6, and 7. We do not use your content to train models. We send necessary content to service providers to perform the features you request, and to connected platforms when you authorize publishing. This is not a transfer of ownership. Advertising events are not intended to include your music, lyrics, or videos.
3. How We Store and Protect Your Data
For repeat-account abuse prevention, Epitrite converts the first-party browser identifier and IP address into keyed, one-way HMAC values before database storage. We do not store the raw browser identifier or raw IP in the duplicate-account ledger. A reused browser identifier may block another Free account from claiming export benefits. IP matches alone never block an account or open a duplicate-account case; they are retained as bounded operational context and may add context to a case already supported by a reused browser identifier. Paid Pro access is not blocked by these Free-tier controls.
- Database: Hosted on Supabase with access controls, including row-level security for user data; authorized administrators can access information needed for support and operations
- File storage: Media files stored in secure cloud storage with access controls
- Passwords: Hashed using industry-standard algorithms (handled by Supabase Auth)
- Transport: All data transmitted over HTTPS/TLS
4. Third-Party Services
We use the following third-party services that may process your data:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Authentication, database, file storage | Account data, uploaded files |
| Stripe | Web payment processing | Email, payment details |
| Apple App Store | iPhone In-App Purchase processing | App account identifier, product and signed transaction entitlement information |
| Vercel | Hosting, Web Analytics, and Speed Insights | Request logs, device/browser and page information, aggregate usage, and page-performance measurements; the hosting and cookieless measurement services are separate from optional marketing cookies |
| DeepSeek | Drafting Content OS ideas when you request a plan, replacement, refresh, or remix | Campaign facts and recent idea text needed for that draft; no Epitrite account, project, or campaign identifiers |
| Groq | Audio transcription and lyric translation when you request those features | The audio, lyrics, or source text needed to complete your request |
| Cloudflare Turnstile | Automated signup-abuse screening | Challenge response and request/device signals |
| proxycheck.io | VPN, proxy, hosting, and network-risk screening at signup | Network address |
| Meta (Facebook/Instagram) | Advertising measurement — only if you accept the cookie banner | Hashed email, advertising/cookie identifiers, page and conversion activity, and request signals such as IP address and browser information |
| Google Ads and AdSense | Optional advertising, conversion measurement, and ad delivery after consent | Device/request information, cookie and ad-click identifiers, page activity, and conversion details |
| PostHog | Optional product analytics and click heatmaps; masked session replay when enabled | Page and feature events, account identifiers, device information, and click positions. Replay is configured to mask inputs and text and block media |
| Brevo | Account, service, and lifecycle email delivery | Email address, message content, and delivery or engagement information |
| Connected publishing platforms | Publishing and performance reporting you enable, including supported YouTube, TikTok, and Instagram connections | Authorized account tokens, selected media and post text, publication details, and available engagement metrics |
Optional advertising and PostHog processing require your cookie choice. Hashed identifiers are pseudonymous, not anonymous: a provider can match a hashed email to an account it already knows. You can decline or withdraw optional processing using cookie preferences. Provider processing is also subject to the provider's terms and privacy information. We may disclose information when legally required, to protect rights and security, or as part of a business transfer subject to applicable privacy protections.
If you explicitly enable render alerts, your browser's push provider (such as Apple, Google, or Mozilla) processes an opaque subscription endpoint and an encrypted notification payload to deliver the alert. You can disable render alerts from Epitrite's notification panel at any time.
iPhone and Android app:Epitrite disables Meta Pixel, Google advertising tags, PostHog, Vercel Analytics, advertising attribution, and marketing-cookie prompts inside the native mobile app. The native app does not ask for App Tracking Transparency permission and does not use data from the app to track you across other companies' apps or websites. Hosting, authentication, storage, security, and product API requests still operate so the editor can provide its core functionality. For signed-in accounts, Epitrite also stores one coarse first-party app-open record per mobile platform per day. We use the earliest record to measure activation and later records to measure aggregate app usage. This record contains no music, lyrics, media, advertising identifier, or cross-app tracking data.
5. Data Breach Notification
We investigate personal data breaches and provide notices required by applicable law. Where GDPR applies, reportable breaches must be notified to the competent authority without undue delay and, where feasible, within 72 hours of awareness. Affected individuals must be informed without undue delay when the breach is likely to present a high risk, unless a legal exception applies. Other jurisdictions may have different thresholds and deadlines.
6. Your Rights
You can:
- Access your data — your projects, media, and account info are visible in the app
- Export your data — use available downloads or request a copy of your personal information
- Delete your data — delete individual projects/media, or delete your entire account
- Cancel your subscription — from your billing settings or Apple subscription settings, depending on where you subscribed; cancellation is effective at the end of the billing period
Delete your account directly from Settings > Profile > Delete account. If you cannot sign in, follow the account-deletion instructionsor email support@epitrite.com for an ownership-verified request.
Our supported YouTube connection uses YouTube API Services, which are subject to the YouTube Terms of Service and Google Privacy Policy. Manage connections in Settings > Connections. You can also revoke Google access through your Google account permissions. To request deletion of data held by Epitrite, use the data-deletion instructions or contact support. Disconnecting Epitrite does not delete posts already published to a third-party account.
Privacy requests and US state rights
Depending on your location and the laws that apply to Epitrite, you may request access, correction, deletion, or a portable copy of personal information, and opt out of sale, sharing, or targeted advertising. You may also have rights concerning sensitive information or consequential automated decisions. Email support with your request; an authorized agent may contact us on your behalf. We may verify identity or authority proportionately, but do not require an account to submit a request. We respond within applicable legal deadlines, explain any permitted denial or extension, and do not discriminate for exercising a right. To appeal a decision where an appeal right applies, reply with "Privacy appeal". You may also contact your state regulator or data protection authority.
Use Cookie preferencesto opt out of optional sale, sharing, and targeted advertising on this browser. We honor Global Privacy Control (GPC) by declining optional tracking, even if an earlier browser choice was Accept. This browser choice does not change another device's storage; signed-in choices are also sent to your account. We do not treat the older Do Not Track signal as consent or as a separate preference mechanism.
7. Cookies
Marketing email preferences are separate from cookie choices. Use the unsubscribe link in a promotional email or contact support to stop promotional messages. Necessary account, security, billing, and requested service messages may continue. Artist fan signups may also involve the artist's own privacy practices; check the signup notice before submitting.
Epitrite uses essential cookies for authentication (keeping you logged in) and one long-lived, HttpOnly first-party browser identifier for Free-account abuse prevention. We also use an essential, short-lived referral cookie when you follow a referral link so an eligible discount can be applied at checkout. We also use optional cookies and storage for advertising and PostHog analytics — but only if you click "Accept" on our cookie banner. Before you opt in, optional advertising scripts do not load. To withdraw consent after accepting, open cookie preferences and choose "Decline", or email support@epitrite.comand we'll turn off ad measurement on your account. If advertising scripts have already loaded, the preferences panel lets you reload after saving your work to unload them completely. Your browser choice lasts up to 180 days; clearing cookies or expiry may cause us to ask again. Essential storage also supports saved settings, consent choices, and site experiments. See Section 4 for the providers and processing purposes.
The native iPhone and Android app uses only essential authentication and app-functionality storage; the optional marketing-cookie flow is disabled there.
8. Data Retention
- Active accounts: Data is retained as long as your account is active
- Deleted accounts: Account content is deleted within 30 days of account deletion
- Repeat-account prevention: Keyed, one-way network and device identifiers may remain after account deletion for the bounded periods described below so deletion does not restore account-limited free benefits. These identifiers are pseudonymous; hashing alone does not make them anonymous.
- Rejected signup attempts: Keyed identifiers and risk outcomes for blocked or failed signup attempts are retained for up to 90 days for abuse investigation. Raw network and device identifiers are not stored in this rejection ledger.
- Rendered videos: Stored until you delete them or your account is closed
- Billing records: Retained as required by tax and financial regulations
- Abuse-prevention signals: User-linked hashed IP and browser observations are deleted 30 and 400 days, respectively, after they were last observed. Pseudonymous claim records can survive account deletion, contain no user ID, and each expires 30 days after an IP claim or 400 days after a browser claim. Enforcement events are retained for up to 400 days.
- Other operational records: Retention depends on the feature, support need, security investigation, provider configuration, and applicable recordkeeping duties. Deletion may exclude records we must retain by law, to prevent abuse, or to establish or defend claims. Restricted backup copies may remain until their normal rotation.
9. Children's Privacy
Epitrite is not intended for children under 13 or below a higher minimum age required in their location. We do not knowingly collect their personal information. A parent or guardian may contact support to request review and deletion of a child's information.
10. International Users
Epitrite is hosted in the United States. Providers may process information in other countries, including the countries described in their linked privacy information, whose laws may differ from those in your location. Where transfer restrictions apply, the transfer must be covered by a valid mechanism, such as an applicable adequacy decision or appropriate contractual safeguards with any required UK or Swiss provisions. Contact us for information about the safeguards applicable to your data. You have additional rights where GDPR applies, including the right to access, rectify, erase, restrict processing, object to processing, and data portability. Contact support@epitrite.com to exercise these rights. You also have the right to lodge a complaint with your local data protection authority.
Where EU or UK data protection law applies, the processing purposes above generally rely on performing our contract for account, project, and paid features; legitimate interests in security, abuse prevention, support, and service reliability; legal obligations for required records and disclosures; and consent for optional tracking or other consent-based features. You can withdraw consent prospectively without affecting earlier lawful processing. Required account and payment information is necessary to provide the corresponding features. Automated abuse checks can restrict signup or Free benefits; contact support for human review if you believe a decision is wrong.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we'll notify you via email or a notice in the app. The "Last updated" date at the top will always reflect the most recent version.
12. Contact
Questions or concerns about your privacy? Email us at support@epitrite.com.