Privacy Policy
Last updated: September 2, 2026
Neume is a music notation editor with version control and live collaboration, operated by Neume ("we", "us"). This policy explains what data we handle, why, and the choices you have. The short version: you can use the editor without an account and nothing is stored on our servers; if you sign in, we store your account details and the scores you save; we run no third-party analytics and we sell no data.
1. Data we collect and why
Using Neume without an account
You can open the editor and write music without signing in. In that case your work lives only in your browser and is not sent to our servers. It disappears when your browser session data is cleared. We keep no server-side profile of anonymous visitors.
Account data
When you sign in (with Google or with an email sign-in flow), authentication is handled by WorkOS AuthKit. We receive and store: your email address, whether it is verified, your first and last name, an optional display name, an optional profile picture URL, and an account identifier. We never see or store your password; credentials stay with WorkOS and, for Google sign-in, with Google.
Your scores and collaboration data
When you save scores to your account, we store the documents you create: titles, version history, and the musical content itself. Content is stored with our cloud provider (Google Cloud) in the United States or other regions our provider uses. If you share a score, we store the list of collaborators and their roles (editor or viewer), and each change made in a shared draft is recorded with the author's account id and display name. That attribution is a core feature: collaborators on a score can see who wrote what.
Payments
Neume Pro subscriptions are processed by Stripe. We store your Stripe customer id, subscription id, plan, subscription status, and billing period dates. Your card details go directly to Stripe and never reach our servers.
Error reports and usage telemetry
We run our own error and usage reporting; no third-party analytics service is involved. Error reports include an error message, a stack trace, recent app actions ("breadcrumbs"), your browser's user agent string, the app version, and a random install identifier. Usage events are short named signals (for example "first_playback") with small technical properties. Before anything is sent, and again on the server, payloads are scrubbed: email addresses and anything that looks like musical score content are removed. Your music does not leave your machine through telemetry. Telemetry is only accepted from signed-in sessions and only operates when the deployment has it enabled.
Feedback
If you send feedback from the app, we store your message, the title of the document you had open, your email address, your account id, and the app version, so we can follow up and reproduce problems.
Server logs
Our servers keep short-lived request logs (method, path, status, timing, and IP address) for security, rate limiting, and debugging. These logs are operational output, not a database we mine; they age out under our hosting provider's log retention.
2. Legal bases
Where the GDPR or similar laws apply, we rely on:
- Performance of a contract for account data, stored scores, collaboration, and payments; we cannot provide these features without this data.
- Legitimate interests for error reports, usage telemetry, security logging, and abuse prevention; we keep this data minimal and scrubbed.
- Consent where we ask for it explicitly (for example, a mailing list signup). You can withdraw consent at any time.
3. Processors and subprocessors
We share data only with the providers that run the service:
| Provider | Purpose | Data involved |
|---|---|---|
| WorkOS, Inc. | Authentication (AuthKit) | Email, name, sign-in identity |
| Google LLC | Sign in with Google (via WorkOS); Google Cloud hosting, file storage, and Firestore (feedback) | Sign-in identity; stored scores and app data; feedback records |
| Stripe, Inc. | Payments and subscription management | Email, payment details (held by Stripe), subscription state |
| GitHub, Inc. (GitHub Pages) | CDN for instrument sound samples (the open-source midi-js-soundfonts library) | Your browser fetches audio files directly from this CDN, which sees your IP address and user agent as with any web request; no account data is sent |
We do not sell personal data and we do not share it with advertisers.
4. Cookies and local storage
We use one first-party session cookie, neume_session, to keep you signed in. It is HttpOnly (not readable by scripts), marked Secure in production, limited to same-site requests (SameSite Lax), and expires after at most 30 days, or 7 days of inactivity. A per-session CSRF token protects state-changing requests. There are no advertising or cross-site tracking cookies. The app also uses your browser's local storage for app state and a random install identifier, and its cache storage for downloaded instrument samples; all of this stays on your device.
5. Retention
- Sessions expire after 7 days of inactivity, or 30 days at most, and expired records are pruned.
- Account data and stored scores are kept while your account is active.
- Deleting a document removes its records from our database. Deleting your account removes your identity from WorkOS and cascades through our database: sessions, documents, version data, collaborator entries, and subscription records. Residual copies of stored content may persist for a limited time in cloud storage and backups before being removed.
- Telemetry and feedback records are kept only as long as they are useful for debugging and support.
6. Security
Traffic is encrypted with TLS in production. Session tokens are stored only as SHA-256 hashes. Cookies are HttpOnly, and every state-changing request requires a CSRF token. Access to scores is enforced server-side: documents are owner-only unless you explicitly share them, and shared access follows the roles you assign. Data at rest is encrypted by our cloud providers' standard storage encryption. Administrative access to operational data is limited to authorized operators.
7. International transfers
Our providers process data in the United States and other countries. Where the GDPR applies to you, transfers rely on appropriate safeguards, such as the standard contractual clauses or equivalent mechanisms our providers offer.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct it; your display name is editable in the app.
- Delete it; account deletion is available in the app and removes your data as described above.
- Export your work at any time; the editor exports scores as PDF, MusicXML, MIDI, WAV, and its own file format, with no lock-in.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
- Complain to your local supervisory authority.
To exercise any of these rights, use the in-app controls or contact us at evan@neumescore.com.
9. Children
Neume is not directed to children under 13, and you may not create an account if you are under 13, or under the higher age your country requires for consenting to data processing (16 in parts of the EU). If you believe a child has created an account, contact us and we will delete it.
10. Changes
We will post any changes to this policy on this page and update the date at the top. If a change meaningfully reduces your rights, we will provide more prominent notice.
11. Contact
Neume
evan@neumescore.com
This policy is governed by the laws of the United States of America, without affecting any protections you are entitled to under the law of your residence.