Version 1.15 — Effective September 23, 2026
This version adds to Section 9 how long an account is kept while you belong to a team or have a request to join one waiting, and how long an account that never held a licence or trial is kept. Version 1.14, of September 22, 2026, had corrected one number and changed nothing else about what we collect or how we use it: it dated the list in the short version by this policy's own version, the number at the top of this policy, instead of by an app version number it never tracked. Version 1.13, of September 17, 2026, had said (Section 3.8) that you can be on more than one team and an owner can run more than one, and that an owner's team bundles are one pool serving all of their teams: a seat covers you on any of them and is returned when you leave the last one. Version 1.12, also of September 17, 2026, had added optional names inside a team (Section 3.8): you can set a display name for yourself, the team's owner or an administrator can give you a label, and both are seen by your team. It also corrected Section 3.8 to say that you can be on a team without a seat, and that a team can run on more than one team bundle. Version 1.11, also of September 17, 2026, had changed how you join a team and what a team runs on (Section 3.8): a team needs a team bundle, you join by entering the team's join code in the app and waiting for the owner to approve you, and Setliner no longer emails invitations or assignment notices; what is kept about a request is in Section 9. Version 1.10, of September 16, 2026, had added optional device names: you can type a name for each of your devices so you can tell them apart, and the app tells our licensing service what kind of device it is (Section 3.6), and what happens to both is in Sections 3.1 and 9. Version 1.9, earlier that day, had corrected four statements that did not match what our services do. Version 1.8, of September 15, 2026, had added one disclosure to Section 3.6: to keep you signed in, the app stores your verified email address and a sign-in token on your device, and logging out deletes both. Version 1.7, of September 14, 2026, had answered a fifth independent review with one correction: Section 3.8 no longer says a team's audit trail stops identifying a former member once their account is gone; it says what the audit trail keeps and that those records stay protected. Version 1.6, also of this date, had answered a fourth review with a consistency pass: the transfer commitment in Section 8 is scoped to transfers the law actually restricts, what deleting an account or leaving a team leaves behind is described the same way everywhere, and Section 12 is scoped to use without an account. Version 1.5, also of this date, had answered a third review: it names the small record that survives deleting your account, says what happens to a used invitation, makes the owner of every team responsible for what the team says about its members, and removes the last absolute statements that had exceptions elsewhere. Version 1.4, also of this date, had answered a second review: it says what happens to your licences if you delete your account, how leaving a team is recorded, that Teams never stores or transmits setlist contents, which team roles see what, and makes the transfer wording conditional. It replaces versions 1.3 and 1.2 of the same day and 1.1 of September 13, 2026, which had replaced the policy dated August 13, 2026; previous versions are at https://setliner.com/privacy/archive. It describes the connections the app makes when you ask it to (linked devices, folders synced by a provider you choose, an iOS OneDrive diagnostic), and the services we now operate ourselves: accounts, trials and licensing for paid features, purchases through our merchant of record, teams, and the desktop update check. Section 3 says exactly what each one sends and to whom.
The short version
Your library is stored on your own devices by default, and Setliner, LLC does not receive it unless you choose to attach part of it to a support request (Section 3.4): your songs, setlists, annotations and play history stay on your devices and in folders you control. We receive only the account, licensing, purchase and Teams information described below, including the specific things you choose to share through Teams, and only when you use those services. As of version 1.15 of this policy, that is:
- a verified email address, a random device identifier and the kind of device it is (such as Windows or Android), when you start a trial or activate a paid feature, and a name for that device if you choose to type one (Section 3.6);
- a purchase record from Polar, our merchant of record, when you buy something through our website (Section 3.7);
- what you and your teammates put into a team, which is membership and scheduling information, never your charts (Section 3.8);
- the request the desktop app makes when it checks for an update, which is on by default and which you can turn off (Section 3.9);
- a support email or a debug log, if you choose to send us one (Sections 3.4 and 3.5).
There is no Setliner-operated sync or storage service for your library, no ads, no analytics and no automatic crash reports, and we do not sell or share personal information.
The app also talks to other things when you ask it to, and only then:
- Linked devices (the Follow feature) connect directly to each other over your local network so one device can lead a set and the others follow along. If you turn on temporary chart sharing, selected charts are sent to those devices too.
- A cloud storage provider you point the app at (such as Google Drive or OneDrive) syncs the files in that folder under its own policy.
- On iPhone and iPad, an optional OneDrive sign-in diagnostic contacts Microsoft while it runs.
- Video links you add to a song open in your browser or music app.
- The Customer Support button opens your own email app addressed to us.
Here is how that can be checked rather than taken on trust. The Android app requests the INTERNET permission and the CAMERA permission; the camera is used only to scan a linked-device invitation. A network monitor will show local discovery and linked-session traffic on your local network; connections to Microsoft only while the OneDrive diagnostic runs; a connection to our licensing service only when you start a trial, activate, name or deactivate a device, or the app renews an entitlement; on desktop, a periodic request to our update server unless you turn automatic checks off; and connections to our team service while you use Teams. Nothing else leaves the app, apart from what you yourself put in an email to us.
Anything we might collect in future remains subject to the notice commitment in Section 4. Section 6 lists the services we do not offer; nothing in it is active.
1. Who we are
Setliner, LLC ("we," "us," "our") makes Setliner, an application for organizing and displaying chord charts and song files. Who is responsible for which information is set out under Roles below.
Contact: support@setliner.com · 12042 SE Sunnyside Rd, Unit #2160, Clackamas, OR 97015
Roles: we are the controller for the information in Sections 3.4 to 3.7 and 3.9 (support correspondence, debug logs, accounts, licensing, purchase records and update requests). A team belongs to its owner, whether that is a church, a band or one person: the owner and the administrators they appoint decide what goes into it, the owner is the controller of that information, and we process it only on the owner's behalf under Section 11 of the End User License Agreement and our Data Processing Addendum at https://setliner.com/dpa/, which applies to every team owner. What stays on your devices (Sections 3.1 to 3.3 and 3.10) never reaches us and has no controller on our side. Polar is an independent controller for the checkout it runs (Section 3.7).
2. What this policy covers
This policy covers the Setliner desktop and mobile applications and any online services we operate for them. It does not cover third-party services you may use alongside Setliner — such as a cloud storage app you keep your song files in, or the app store you downloaded us from. Those have their own policies.
3. What the app connects to today
The connections below are the only ones the current version makes. Sections 3.1 to 3.3 are connections you start from your device to a party you choose; they never pass through a Setliner server. Sections 3.4 and 3.5 are things you may send us yourself. Sections 3.6 to 3.9 are the services Setliner, LLC operates, and say exactly what each one receives.
Permissions: the Android app declares the INTERNET permission and the CAMERA permission for the features in Section 3.1. It requests no location, microphone, Bluetooth, contacts or notification permission. Foot pedals and page-turners work as ordinary keyboards and need no permission of their own.
3.1 Linked devices (Follow)
Follow lets one device lead a set while other devices on the same local network follow its position. Everything it exchanges travels device to device over your local network, on an encrypted connection pinned to a certificate the leading device generates for that one session. There is no Setliner relay, and nothing about the session reaches us.
- To let followers find and join it, the leading device advertises a service name and its network address on the local network, together with the name you gave the device if you gave it one, and shows an invitation as a QR code, a short code, or text you can copy. The invitation contains the session's connection secret. Anyone holding the invitation can ask to join while it is valid, so share it only with the people you intend to join. Joining also requires the leader's approval or a matching short code. Anyone on the same local network can see an advertised device name while that device is leading.
- The leading device sends followers the identity of the current song and position, a fingerprint of each chart so a follower can tell whether its own copy matches, and the playback settings for the set (key, capo and section order). It does not send your library location, your tags, your play history, your preferences, or any file other than the charts described next.
- If a follower turns on temporary chart sharing, the leader also sends that follower the title, chart text, key, capo and tuning of charts the follower does not already have, so it can display them. Those copies are temporary and are not added to the follower's library. Chart sharing is off until the follower turns it on, and songs that exist only as a PDF are not shared this way.
- A follower sends the leader a device name it chose, which starts as the name you gave the device and can be changed before joining, and acknowledgements of what it received. Other participants can see the name you choose and the charts you share with them.
- Scanning an invitation uses your device's camera, only while the scanner is open. The camera image is used to read the code and is neither stored nor transmitted.
- A follower can remember the leader it last joined so it can rejoin without a new invitation. That memory, and the leader's list of approved followers, stays on the device that made it, and each has a Forget option.
3.2 Folders synced by a provider you choose
Setliner reads and writes your songs and setlists in a folder you pick. If that folder is one a cloud storage app keeps in sync (Google Drive, OneDrive, Dropbox or similar), that provider transfers its contents under its own privacy policy. On desktop and Android, Setliner does not sign in to the provider; it only reads and writes files in the folder, like any other program on your device.
3.3 The OneDrive sign-in diagnostic (iPhone and iPad)
Settings on iOS includes a diagnostic that proves a OneDrive sign-in works. Running it opens a Microsoft sign-in page and then asks Microsoft for the names of the top-level folders in that OneDrive. The application identifier you type, the sign-in code and the resulting access token go to Microsoft; the folder names come back to your screen. Setliner does not store the token or the folder names, and it is not a Setliner account. Nothing happens until you tap the button.
3.4 Links you open, and email to us
A video or web link you add to a song opens in your browser or the relevant app when you tap it, and that site sees your visit as it would any other. The Customer Support button opens your own email app addressed to support@setliner.com; whatever you send is then an ordinary email between you and us. We keep the correspondence for 12 months after the matter is closed so we can handle a follow-up, then delete it. A chart, setlist or debug log you attach is used only to look into your problem and is deleted when it is resolved, as Section 3.5 says for logs.
3.5 Diagnostics
The app keeps a short debug log in memory while it runs. It is never sent anywhere automatically. You can save it to a file from Settings and send it to us if you choose; if you do, we use it only to look into the problem you reported and delete it when that is done.
3.6 Your Setliner account, trials and licensing
Paid features are licensed through our website and activated in the app. Nothing in this section happens until you start a trial, buy something, or sign in on a device.
- Your Setliner account is your email address, verified by a code or link we send to it. We do not ask for a password: signing in on a new device means proving you can read that mailbox. We keep the address and the entitlements attached to it. When you ask for a sign-in code the app also asks which country you are in, and we keep the answer you give, so that we can apply the restriction in Section 8. That answer is only ever what you tell us: we do not look it up, and nothing works it out from your IP address or your device's language or region.
- Starting a free trial of a paid feature sends us that email address and a random device identifier the app generates. Apart from the verification message, we email the address only for things the service needs: a receipt or renewal notice, a security alert, or a change to these terms. We do not email you about teams, and we do not send marketing email without your separate opt-in.
- Activating a purchase or trial on a device sends our licensing service the device identifier, your email address, which feature you are activating, and the kind of device it is. We use that to record which devices hold an entitlement, to enforce the seat or device limits of what you bought, and to let you deactivate a device you no longer use. The identifier is generated by the app, is not derived from your hardware, and stays in the app's private storage on that device.
- You can give a device a name, such as "Stage iPad", so you can tell your devices apart. The name is only ever what you type: the app never reads your device's own name, its computer name or your account name. It is kept in the app's private storage on that device and, when you are signed in and the device is activated, sent to our licensing service, which shows it on your other devices in Manage devices, uses it in the emails we send when a device is added to or released from your account, and shows it to us when we help you recover a lost device. You can change or remove it at any time, and logging out removes it from the device. So that a device you have not named can still be told apart, the app also tells the licensing service what kind of device it is: Windows, Mac, Linux, Android, or iPhone or iPad. That is the operating system only, never its version, the model, or anything else about your hardware.
- To keep you signed in, the app stores your verified email address and a sign-in token in its private storage on that device for up to 30 days. Logging out deletes both from the device and ends the sign-in on our service.
- Once activated, the app keeps working without a connection. It contacts the licensing service again only to renew its cached entitlement, or when you deactivate, and if it cannot reach us it keeps working on what it last knew for at least 30 days, as Section 5.8 of the End User License Agreement promises.
- Licensing tells us that a device holds an entitlement. It does not tell us what songs you have, what you play, or what you do with a licensed feature, and we keep no such record.
3.7 Purchases
Purchases made through our website are sold by Polar Software, Inc. (Polar), our merchant of record, and processed by Polar's payment provider. Polar collects your name, email address, billing address and payment details under its own privacy policy at https://polar.sh/legal/privacy; we never receive or store your card number. Polar sends us a record that a purchase occurred, namely the transaction identifier, the item, the date, the amount and the email address it was bought under, so that we can attach the entitlement to your account. Where an app store handles a purchase instead, that store's privacy policy governs the payment and we receive an equivalent receipt from the store.
3.8 Teams
If you create or join a team, our team service stores the team's name; each member's account email address and permission level, and up to two optional names: a display name that only you can set for yourself, and a label that the team's owner or an administrator can give you. Both are plain text of up to 40 characters, are shown to everyone in the team, including you, where your email address would otherwise appear, and your own display name is shown instead of the label. You can change or clear your display name at any time; the owner or an administrator can change or clear the label. Both are deleted when you leave the team or are removed from it; the roles the team defines; its events (title, date and time zone) and who is assigned to them; and, for each setlist a member has been granted, only the setlist's identifier and who may receive it. It does not store or transmit your songs, charts or the contents of a setlist: a grant records that you may receive a setlist, and the setlist itself reaches you through the channels you already use, such as a shared folder, an export or a linked session. If we ever carry setlist files through our own service, we will describe that here first.
A team runs on one or more team bundles: purchases, described in Section 3.7, that each come with a fixed number of seats, and an owner's bundles are one pool that serves every team the owner runs, so a seat given to you covers you on any of that owner's teams. Creating a team requires holding one. The owner keeps one seat and gives the others to members; while a seat is yours, the bundle's features are unlocked on your devices as if you had bought them, and the owner can see, in Manage seats, the email address each seat is assigned to. Giving a seat back ends that; so does leaving or being removed from the last of that owner's teams you are on. Neither affects anything you bought yourself. If a bundle is refunded or charged back, its seats stop working; when the owner has no team bundle left, every team they run is frozen: nobody can change them or use their seats, and nothing in them is deleted unless the owner deletes the team.
You can be on more than one team, and an owner can run more than one. You join a team by entering its join code in the app. The owner or an administrator sees the code in the app and passes it on however they choose; Setliner does not send it, and we email nobody about a request, an approval or an assignment: everything a team tells you appears in the app. Entering a code creates a request that holds your account email address and when you asked, which the team's owner and administrators can see until one of them approves or declines it, or you withdraw it. Approving it puts you on the roster, with or without a seat. A member without a seat can be scheduled and can answer, and the bundle's features are not unlocked for them; the owner can give them a seat later, and can take a seat back without removing them from the team. A declined, withdrawn or unanswered request is deleted 30 days after it was made. Owners, administrators and planners see the whole team; ordinary members see the roster and roles, and only their own assignments, grants and the events those belong to. A member can leave at any time, and the owner or an administrator can remove a member. Either ends that person's access to that team, takes them off its roster and cancels their grants at once, and returns their seat unless they are still on another of the owner's teams with a seat assigned. Assignments they had are marked cancelled and stay in the team's schedule history for as long as the team exists; only owners, administrators and planners can see that history. On request we replace the departed member's name and email address in that history and in any request record with a placeholder. The team's audit trail is not changed by that: it keeps, for each change made to the team, the acting account's internal identifier, what was changed, and a reference to the item changed, which for a request is a one-way hash of the requester's email address. Those records can still be linked to a person by someone who already knows the identifier or the address, so they remain personal information, stay visible to nobody but our staff under the access rule in Sections 7 and 9, and are deleted with the team under Section 9.
A team's name and roles, and a label given to you, may say something about you, for example that you are on a church's worship team. The team's owner or administrator, not Setliner, chooses to enter that and, as the team's controller, is responsible for having whatever agreement from you the law requires; the join code you enter names the team before you ask to join, so you know what you are joining. We use it for nothing but running the team, and leaving the team takes you off its roster.
3.9 Update checks (desktop)
The Windows desktop app checks our update server for a newer version automatically, by default. You can turn that off, or check manually, under Settings, About. A check is one request to our update server, which necessarily reveals your IP address and, by what it downloads, the version you are running. Nothing else is sent; the request carries no account or device identifier, and we do not link it to you. An update is downloaded and installed only after you approve it. Android and iOS receive updates through their app stores, under the store's policy.
3.10 Data the app stores on your own device
The Software writes files to your device so it can remember your library and preferences. Local files are not sent to Setliner, LLC. Files you place in a synced folder or choose to share can leave the device through those features. Uninstalling the app may leave user-selected folders, exports and provider copies intact. Local storage includes:
- your song and setlist files, wherever you chose to keep them;
- annotations, tags and per-song settings you have made;
- play history: the app records locally when you view a song or play through a set, so it can show you usage reports and export them as a spreadsheet. That history stays in the app's own storage on the device (~/.setliner on desktop, or the platform equivalent) and is not synced or sent to us;
- application preferences, window layout, language and theme choices, stored in the same place;
- feature-specific preference files, such as the Fretboard Builder's saved orientation, foot-pedal key mappings on Android, remembered linked-device leaders and approvals (Section 3.1), and the record of which version of the license agreement you accepted and when;
- the random device identifier and the cached entitlement described in Section 3.6, in the app's private storage.
You are in control of these files. You can copy, back up, move, or delete them like any other files on your computer, and we recommend you do keep backups — the Software is not a backup service.
3.11 Files you open
The Software reads files you point it at, and on Android and iOS may receive files other apps share with it. It reads them locally to display them. It does not upload them to Setliner, LLC or index them on a Setliner server. Selected charts can be sent to linked devices when a follower chooses temporary chart sharing (Section 3.1), and your selected cloud provider can sync files in its folder (Section 3.2).
4. What we do not do, and will not start doing quietly
Independent of any feature we add later, we commit to the following:
- We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under California and other US state privacy laws.
- We do not serve ads in the Software and do not embed advertising or tracking SDKs.
- We do not use your Content to train AI models. See Section 6.2.
- We will not read the substance of your songs, setlists, or annotations, other than material you deliberately send us for support (Section 3.4). Teams stores membership and scheduling information, never charts (Section 3.8); apart from that support exception, the only way we could read your songs would be through a Setliner-operated cloud sync service, which does not exist (Section 6.1), and even then only in the narrow circumstances listed there.
- We will give notice before any collection begins. If a future version introduces any data collection, we will update this policy, raise the version number, and give at least 30 days' notice in the app or by email before that version's collection takes effect.
5. Legal basis for processing (EEA/UK users)
We rely on: contract, to provide the account, trial, entitlement, team or update you have asked for; legitimate interests, to keep those services secure, to prevent fraud and to enforce the limits of what you bought, balanced against your rights; consent, for anything optional, such as a debug log you choose to send us or marketing email you opt in to, which you can withdraw at any time; and legal obligation, to keep tax and transaction records. Where a team's name or your role in it reveals something about your religious or other beliefs, the team's owner, whether an organization or a person, is the controller of that fact and is responsible for meeting whatever condition the law requires before entering it; we process it only as the team's processor and only to run the team (Section 3.8).
The connections described in Sections 3.1 to 3.3 are made by you, from your device, to parties you choose, and involve no processing by us. What you send us under Sections 3.4 and 3.5, we process to answer you.
6. Services we do not offer [NOT YET ACTIVE]
The following are not offered in the current version and are not planned for the near future. They are described here so that the commitments in Section 4 are on record before any of them exists. Nothing in this section is active.
6.1 Setliner-operated cloud sync [NOT YET ACTIVE]
A future sync service operated by Setliner, LLC would store copies of the song files, setlists, and annotations you choose to sync. This is separate from existing local linked sessions and folders synced by a third-party provider you choose.
We would treat that content as yours and private. We would access its substance only where reasonably necessary to: provide support you have specifically asked for; investigate a suspected violation of our terms or a copyright complaint; maintain the security of the service; or comply with a legally binding order. Where the law permits and it is practical, we would tell you before disclosing your content in response to a legal request.
Synced content would be encrypted at rest and in transit using keys we control, not end-to-end encryption — which means we would be technically able to access it under the circumstances described in the paragraph above (support you have specifically asked for, investigating a suspected violation, maintaining security, or complying with a legally binding order), and nowhere else.
6.2 AI features [NOT YET ACTIVE]
If we add AI features, the text you submit to them would be sent to a third-party AI provider to generate a response.
We would not use your content, your prompts, or the results to train, fine-tune, or develop any machine learning model, ours or anyone else's — and we would not engage an AI provider unless it contractually commits to the same. This matches Section 9.5 of the End User License Agreement, and it is a commitment we are making because our users routinely handle licensed material they may not be permitted to feed into a training corpus.
AI features would be opt-in. Nothing is sent anywhere unless you invoke one.
6.3 Crash reports [NOT YET ACTIVE]
If we add crash reporting, it would be opt-in, and we would say plainly what a report contains — typically a stack trace, the app version, and the operating system version. We would configure it not to transmit file contents or file paths that might include song titles. Until then, the only diagnostic that reaches us is a debug log you save and send yourself (Section 3.5).
7. Who we share data with
We share personal information only with the providers that run the services in Section 3. This paragraph is the list, and we update this policy before adding to it:
- Polar Software, Inc., Dover, Delaware, United States: merchant of record and payment for website purchases (Section 3.7). Polar runs the checkout as an independent controller under its own policy, and uses Stripe, Inc. to process cards.
- Hostinger: hosting for our website and for the licensing, team and update services, and the mail service that delivers our verification and account messages. Hostinger acts on our instructions as a processor.
What you send to linked devices, a cloud storage provider or Microsoft under Sections 3.1 to 3.3 goes from your device to them directly, and we are not a party to it. Within a team, the information in Section 3.8 is visible to that team's other members because you or the team's owner chose to share it with them, and an invitation you send shows the invitee your name and the team's name.
We may also disclose information: to comply with a law, subpoena, or court order; to enforce our terms or protect the rights, safety, or property of any person; or to a successor entity in a merger, acquisition, or sale of assets, in which case we would give notice and this policy would continue to apply to information transferred until the successor provides its own.
8. International transfers
Our services are hosted in the United States, so if you are outside it your personal information is transferred there. We have not put transfer clauses in place, because we do not offer the services that would need them in the EEA or UK. Where a disclosure to us, or by us, would be a restricted transfer under the data-protection law that applies to it, we will establish the safeguards that law requires before it occurs (for the EEA the European Commission's Standard Contractual Clauses, for the UK those clauses with the UK International Data Transfer Addendum, each with any supplementary measures required) or we will not make that disclosure. Not every contact with us is such a transfer: a support email you send, a visit to our website or a desktop update check is handled under Sections 3 and 13, and whether the EU or UK GDPR applies to it depends on the processing, not only on where you live. Ask us at support@setliner.com and we will tell you what applies to your case.
Accounts, trials, purchases and Teams are currently offered only outside the European Economic Area and the United Kingdom: our checkout does not accept EEA or UK billing addresses, and we do not market those services there. For that reason we have not appointed an EU or UK representative under Article 27 of the GDPR. The free app can be used anywhere: on its own it involves none of those services, and the desktop update check (Section 3.9) can be turned off. If, despite that restriction, we find an account, trial or team being used from the EEA or UK, for example because a US organization invites a member who lives there, we will tell the people affected and either establish the safeguards described in the previous paragraph before continuing or end that service for them and delete what the service holds about them. If we open those services to the EEA or UK, we will appoint a representative and name them in this section first.
9. Retention
Your library never reaches us, apart from material you deliberately send us for support (Section 3.4), so there is nothing else of it for us to retain. The periods below are for our active systems; copies in routine backups age out within 60 days after that. We keep something beyond these periods only where the law requires it, or where a specific claim, investigation or abuse case is already open when the deletion falls due, in which case we keep only what that case needs and delete it when the case ends.
- Account information (your email address, the country you declared and the entitlements attached to it) is kept while any entitlement or trial attached to it is active and for 12 months after the last one ends, so a lapsed purchase can be restored. It is also kept while you belong to a team or have a request to join one waiting. Once you are in no team, the 12 months are counted from when your last entitlement or trial ended, not from when you left. An account that never held a licence or trial is kept for 12 months after you last signed in to it, then deleted; signing in again starts the 12 months over. Either way, your team account is deleted with it. You can ask us to delete your account sooner and we will. Deleting the account erases its verification state and its device activations and ends its current team memberships, and it cannot be undone; records a team keeps about a former member stay with that team as the team bullet below describes, and restoring a licence later does not restore team access. Deleting the account does not revoke a licence you bought: we keep one licence-restoration record, made of the email address you verified, the entitlements attached to it and the purchase transaction identifier, for as long as any of those entitlements exists, and we use it for nothing except restoring the licence when that address is verified again. If you ask us to erase that record too, we will tell you that the licence can then never be restored, and erase it once you confirm. Deleting an account does not cancel a subscription: cancel it through Polar's customer portal or your app store, or it will keep billing.
- A device activation record is the random identifier the app generates for that device, when it was activated, and which licence it holds. Releasing a device marks the record released rather than erasing it, because that record is what stops a free trial already used on that device being started again from a different email address. Deleting your account erases those records, and keeps in their place only the fact that a trial of a feature has been used on a device: a device identifier and a feature name, with no email address and no account identifier attached to either. That last record has no end date, because outlasting the account is the whole of what it is for. A device's name and kind are kept only while that device holds an active licence or trial on your account: they are deleted when its last one is released, including by support, and when you delete your account.
- Team data, including its join requests, its audit trail of who changed what and when, and the history described in Section 3.8, is kept while the team exists and deleted within 30 days of the team being deleted. A declined, withdrawn or unanswered join request is deleted 30 days after it was made. A member who leaves or is removed is taken off the roster, their seat is returned and their grants are cancelled at once; their cancelled assignments stay in the team's history for the life of the team, visible only to its owners, administrators and planners, with the name replaced by a placeholder on request.
- Verification codes expire within 24 hours and are stored only as hashes until then. A team's join code is stored only as a hash and lasts until the owner or an administrator replaces it.
- Update-server and website request logs are kept for no more than 30 days.
- Transaction records (what was bought, when, for how much, under which email address) are kept for as long as tax and accounting law requires, typically seven years, and are not affected by deleting an account.
- Support correspondence is kept for 12 months after the matter is closed; a debug log you send us is deleted when the problem it concerns is resolved.
- The app keeps a local record of which version of these terms you accepted and when; the text of every version is at https://setliner.com/privacy/archive, so the two together show what you accepted.
10. Security
The security of your library depends on your devices, any cloud provider you choose, and the people with whom you share files or linked sessions. Linked sessions use encrypted connections and invitation-based approval. Share invitations only with intended participants. We encourage full-disk encryption and regular backups, as for other important files.
For the services we operate, we use industry-standard measures including encryption in transit (TLS), encryption at rest, and access controls limiting staff access to what is necessary. We do not store passwords, because we do not ask for one. Entitlements are signed so the app can verify them without contacting us. No system is perfectly secure, and we cannot guarantee absolute security. We will notify you and any relevant regulator of a personal data breach as required by applicable law, without undue delay.
11. Your rights
11.1 Everyone
Most of what Setliner handles never reaches us. Your library, setlists, annotations and play history stay on your devices and in folders you control, so the way to access, export or delete them is to open, copy or delete the files; the app exports songs in the formats it supports at any time.
For the personal information we do hold (Sections 3.4 to 3.9), you can see and change your email address and activated devices from the app's Licensing screen or our website, leave a team from within the team, and exercise every right below by contacting support@setliner.com. We verify a request by asking you to confirm it from the email address on your account, or by other reasonable means if you have none. We will respond within the period required by law (generally 45 days under US state laws, one month under GDPR), and we will not discriminate against you for exercising them. If we refuse a request, we will say why, and you may appeal by replying to that answer; we will decide the appeal within the period the applicable law allows and tell you how to complain to your regulator if you are still unsatisfied.
11.2 EEA and UK (GDPR)
You have the right to access your personal data; to rectify inaccurate data; to erasure; to restrict or object to processing, including profiling; to data portability; and to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority.
11.3 California (CCPA/CPRA)
California residents have the right to know what personal information is collected, used, disclosed, or sold; to delete it; to correct it; to opt out of sale or sharing; to limit the use of sensitive personal information; and to non-discrimination.
We do not sell or share personal information, and we have not done so in the preceding twelve months. We do not ask for sensitive personal information; if a team's name or your role in it reveals something about you, such as membership of a church's worship team, that is information you or your team's owner chose to enter, and we use it only to run that team (Section 3.8). We have no actual knowledge of selling or sharing the personal information of consumers under 16 years of age. The categories of personal information we collect, as defined by Cal. Civ. Code § 1798.140(v), are: identifiers (email address, the app's random device identifier, and the IP address on licensing, update and website requests); commercial information (records of purchases and entitlements); the contents of support correspondence you send us; and, for team members, the display name, role and assignments entered by you or your team's owner. We collect them for the purposes in Section 3, keep them for the periods in Section 9, and disclose them only to the providers in Section 7, to the other members of a team you join, and where Section 7 says the law may require.
You may designate an authorized agent to make a request on your behalf.
11.4 Other US states
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have broadly similar rights of access, correction, deletion, portability, and opt-out, and a right to appeal a refused request. Use the same contact address; tell us which state you are in.
12. Children's privacy
Setliner is a tool for musicians of any age, faith, or none. Youth worship teams, school bands, and young players learning an instrument are exactly the kind of users we expect.
Using the app without an account or an activated paid feature tells us nothing about who is using it, so a child can use Setliner that way on a device that a parent, guardian or organization manages. In that use the only thing the app sends on its own is the desktop update check (Section 3.9): a request that reveals the IP address it comes from and the version it downloads, carries no account or device identifier, is not linked by us to anyone, is logged for no more than 30 days, and can be turned off. What a linked-device session shares (Section 3.1) goes only to the people in that session.
Accounts, trials, purchases and teams are different, because they send us an email address, so they have age rules, and they are the same rules the End User License Agreement sets:
- Under 13. We do not knowingly collect personal information from a child under 13, and we do not allow anyone under 13 to create an account, start a trial or be invited to a team. A younger player uses the app without an account, on a device an adult manages; that adult's own account stays their own, because accounts may not be shared (End User License Agreement, Section 7.3), and the child needs none.
- 13 to 17. You must be at least 13 to have an account, start a trial or join a team, and at least 18, or the age of majority where you live, to make a purchase. Between 13 and the age of digital consent where you live (16 in several EU member states) you may hold an account, join a team or start a trial only with the consent of a parent or legal guardian, and we require that consent. A group leader is not a substitute for a parent or guardian.
- If we learn we have collected information from a child in a way that did not comply with these rules, we will delete it promptly. Parents and guardians can contact support@setliner.com to review, delete, or refuse further collection of their child's information.
13. Our website and cookies
Our website at https://setliner.com is a static site hosted by Hostinger. Like any web server, it records the IP address, requested page, time and browser type of each visit in a server log, which is kept for no more than 30 days for security and which we do not use to identify visitors. We set no cookie of our own: the site is static and there is no website sign-in to keep you signed in to. Checkout is provided by Polar, which sets the cookies its checkout and customer portal need under its own policy. We don't use any of these to track visitors, and we don't run analytics or marketing cookies on the site. If we add analytics, we will assess what consent the law that applies to you requires before switching it on, and update this section first. The Software itself does not use cookies.
14. Changes to this policy
We may update this policy. When we do, we will change the version number and effective date at the top. For any change that expands what we collect or how we use it, we will give at least 30 days' advance notice in the app, by email where we have your address, or at https://setliner.com — and where the change requires your consent under applicable law, we will ask for it rather than assume it.
Previous versions will remain available at https://setliner.com/privacy/archive so you can see what changed.
15. Contact
Questions, requests, or complaints:
support@setliner.com Setliner, LLC 12042 SE Sunnyside Rd, Unit #2160, Clackamas, OR 97015
If you are in the EEA or UK and are not satisfied with our response, you may complain to your local data protection authority. If you are in California, you may contact the California Privacy Protection Agency.
Setliner is a product of Setliner, LLC.