Privacy Policy
Last updated: July 23, 2026
This Privacy Policy explains what data Epitrite ("we," "us," or "the Service") collects, how we use it, and your rights.
1. What We Collect
Account Information
- Email address (used for login and communication)
- Password (hashed, never stored in plain text)
- Display name (if you set one)
Content You Upload
- Audio files (MP3, WAV, etc.)
- Video clips and images
- Lyrics and project data
- Rendered/exported video files
Payment Information
Payments are processed by Stripe. We do not store your credit card number, CVV, or full card details. Stripe provides us with a customer ID, basic transaction records (amount, date, plan), and a non-secret card fingerprint that we use to prevent referral abuse.
Automatically Collected Data
- IP address and approximate location (country/region)
- Browser type and operating system
- Pages visited and features used within Epitrite
- Timestamps of account activity
- Browser push subscription endpoint and encryption keys, only if you enable render alerts
- Referral code attribution, qualification, and reward status when you use the referral program
2. How We Use Your Data
- To provide the Service — storing your projects and rendering videos
- To process payments — managing subscriptions and billing through Stripe
- To communicate with you — account notifications, billing receipts, service updates, and opt-in render alerts
- To improve the Service — understanding usage patterns to fix bugs and build features
- To operate referrals — attributing eligible referrals, issuing rewards, and preventing self-referral or payment-method abuse
- To enforce our Terms — preventing abuse and unauthorized access
We never claim rights to your music. Your songs, lyrics, audio files, and rendered videos belong to you. We do not sell your personal data. We do not use your content to train AI models. We do not license, sublicense, or distribute your music or creative content to any third party. The only ad-related data sharing is described in Section 4, happens only if you accept our cookie banner, and never includes your music, lyrics, or videos.
3. How We Store and Protect Your Data
- Database: Hosted on Supabase with row-level security (RLS) — users can only access their own data
- File storage: Media files stored in secure cloud storage with access controls
- Passwords: Hashed using industry-standard algorithms (handled by Supabase Auth)
- Transport: All data transmitted over HTTPS/TLS
4. Third-Party Services
We use the following third-party services that may process your data:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Authentication, database, file storage | Account data, uploaded files |
| Stripe | Payment processing | Email, payment details |
| Vercel | Hosting | IP address, request logs |
| Meta (Facebook/Instagram) | Advertising measurement — only if you accept the cookie banner | A hashed (irreversible) version of your email, page activity, and ad-click identifier |
We share data with Meta only to measure whether our ads work, and only after you click "Accept" on our cookie banner. Your email is hashed (scrambled one-way) before it is sent, so Meta never receives your actual address. If you decline, nothing is shared with Meta.
If you explicitly enable browser render alerts, your browser's push provider (such as Apple, Google, or Mozilla) processes an opaque subscription endpoint and an encrypted notification payload to deliver the alert. You can disable render alerts from Epitrite's notification panel at any time.
iPhone and Android app:Epitrite disables Meta Pixel, Google advertising tags, PostHog, Vercel Analytics, advertising attribution, and marketing-cookie prompts inside the native mobile app. The native app does not ask for App Tracking Transparency permission and does not use data from the app to track you across other companies' apps or websites. Hosting, authentication, storage, security, and product API requests still operate so the editor can provide its core functionality.
5. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required under GDPR Article 33. Notifications will describe the nature of the breach, the categories of data affected, the likely consequences, and the measures we are taking to address it.
6. Your Rights
You can:
- Access your data — your projects, media, and account info are visible in the app
- Export your data — download your rendered videos and project files at any time
- Delete your data — delete individual projects/media, or delete your entire account
- Cancel your subscription — from your billing settings, effective at end of billing period
Delete your account directly from Settings > Profile > Delete account. If you cannot sign in, follow the account-deletion instructionsor email support@epitrite.com for an ownership-verified request.
7. Cookies
Epitrite uses essential cookies for authentication (keeping you logged in). We also use an essential, short-lived referral cookie when you follow a referral link so an eligible discount can be applied at checkout. We also use marketing cookies to measure our advertising — but only if you click "Accept" on our cookie banner. If you click "Decline" (or ignore it), no marketing or advertising cookies are set and no data is sent to Meta. To withdraw consent after accepting, open cookie preferences and choose "Decline", or email support@epitrite.comand we'll turn off ad measurement on your account. See Section 4 for exactly what is shared and with whom.
The native iPhone and Android app uses only essential authentication and app-functionality storage; the optional marketing-cookie flow is disabled there.
8. Data Retention
- Active accounts: Data is retained as long as your account is active
- Deleted accounts: Data is deleted within 30 days of account deletion
- Rendered videos: Stored until you delete them or your account is closed
- Billing records: Retained as required by tax and financial regulations
9. Children's Privacy
Epitrite is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, contact us and we'll delete it.
10. International Users
Epitrite is hosted in the United States. If you're accessing from outside the US, your data will be transferred to and processed in the US. For users in the EU/EEA, UK, and Switzerland, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission as the lawful basis for international data transfers. You have additional rights under GDPR including the right to access, rectify, erase, restrict processing, object to processing, and data portability. Contact support@epitrite.com to exercise these rights. You also have the right to lodge a complaint with your local data protection authority.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we'll notify you via email or a notice in the app. The "Last updated" date at the top will always reflect the most recent version.
12. Contact
Questions or concerns about your privacy? Email us at support@epitrite.com.