ClearroomDownload

Privacy.

DRAFT — version 2026-09. This policy is published while our legal and accounting review finishes, and the wording may change. What it describes is what the software actually does today. Questions to support@clearroom.studio.

What we store

Your email address, because it is how a licence is looked up, how a key is delivered, and the only way to sign in. Your order — its id, dates and amounts. We never see or store your card details.

Paying in dollars, our merchant of record reports the order to us and keeps the billing details itself. Paying in rupees you are buying from us directly, so the invoice particulars you type at checkout are stored with the order: your name, the state the invoice is billed to, and — if you are buying as a business — your GSTIN and registered address. A GST invoice cannot be raised without them.

For each machine you activate: the machine name macOS reports, the macOS version, and the dates it checked in. The machine name is usually a real person's name — “Rupendar's MacBook Pro” — which is why it is treated as personal data and shown to nobody but you.

A machine is known to us by a number rather than by its hardware: the app hashes the id macOS gives your Mac together with a Clearroom salt, and sends only the hash. The hardware id itself never leaves the machine, and the hash cannot be turned back into it.

We do not store your measurements, your audio or your room. Captures and corrections stay on your Mac and are never uploaded.

Our servers run on Cloudflare, which logs the IP address of requests it serves as part of running the network. We keep a few addresses ourselves, each with one job. The one a machine last checked in from is held on that machine's activation record: it is what our rate limits count against, and it is how we can tell that two seats sit on one studio's network rather than two continents apart. The one a trial started from is held on the trial's record — it is what the trial limits count. And if a check-in looks like a copied installation, that single event is kept with its address for 90 days, as the evidence a human reads before anyone's licence is touched.

What the app sends

Clearroom makes two kinds of connection, and no others.

Licence check-ins, to our licence server: when you activate a machine, start a trial or release a seat, and about once a day while the app is running. They carry the licence credentials, the machine number above, and — when you activate — the machine name and macOS version. The app's version number travels with the request and is written to our logs, never to the database.

Profile downloads, from this site: the headphone and microphone catalogue the app corrects against. Those are ordinary file downloads, with nothing about you attached.

There is no analytics in Clearroom, no usage tracking, no crash reporter and no telemetry of any kind — not in the app, not in the audio driver, not in the plugin, and not in the beta builds, which are the same code. The measurement engine runs on your own Mac and answers only to the app in front of you.

This website

The site sets no cookies and runs no analytics — no tracking pixels, nothing counting your visit. Signing in to your account puts one short-lived token in your browser's session storage; it expires after 30 minutes and is gone when you close the tab.

Two things are loaded from elsewhere. The typeface comes from Google Fonts, so your browser asks Google's servers for it — an ordinary web request, carrying what every request carries and nothing about you or your account. And paying in rupees brings Razorpay's checkout into the page when you press the button, so your card details go straight to them and never through us. What their checkout does while it is open is theirs to describe, and their own privacy policy covers it.

Why we are allowed to

To perform our contract with you: a licence you bought has to be deliverable, recoverable and enforceable, and each of those needs the data above. Beyond that, a legitimate interest in preventing licence abuse — the rate limits and the seat rules — and a legal interest in keeping the records tax and accounting law requires.

How long we keep it

The schedule, by what it is:

  • magic_tokens sign-in links, stored hashed, never in the clear. A link expires 15 minutes after it is sent and is single-use; the row itself is deleted 7 days after it expires.
  • licenses for the life of the licence and then as long as tax and accounting law requires the order record.
  • activations while the seat is in use; an ended activation keeps its dates as the transfer record.
  • emails_sent the delivery ledger, 90 days.
  • webhook events 90 days, as the record that a payment was processed once.
  • rate-limit counters 2 days.
  • rate-limit lockouts the state behind a temporary block, cleared the next day.
  • trials a started trial keeps its machine number, email address, and the address and network it came from — that is what stops one machine taking the trial twice. The limits look back 365 days by email address and 30 days by network.
  • clone_events a check-in that looks like a copied installation, with its IP address, 90 days.
  • checkout_orders the invoice particulars from a rupee purchase, 90 days after the last document is raised from them — 30 days if the checkout is never paid.
  • invoices a tax invoice we have issued, with the name, email address and any address and GSTIN printed on it, for as long as tax law requires us to keep it. This is the one record erasure does not reach: a document already issued to a tax authority cannot be unissued.
  • alerts an operational alert raised when something on the payment path needs a human. A resolved one is deleted after 90 days; one still open is kept until it is dealt with. Where an alert carries an email address, erasure replaces it.

Two things sit outside that table. Cloudflare keeps short-lived operational logs for the network it runs on our behalf — the ordinary record of requests a network keeps in order to work, and to let us see that it is working — held on its own schedule rather than a period we set. And anything tax and accounting law requires us to hold — an order, an invoice — is kept for as long as that law says, which outlasts everything above.

Who else processes it

Cloudflare — hosting, the database and network logs. Polar — our merchant of record: it takes the payment, holds the billing details and handles tax. Resend — the service that delivers our email. Each receives only what its job needs.

Razorpay — the payment provider for purchases in rupees, where you buy from us directly rather than through a merchant of record. It takes the card details, and we pass it your name and email address so the payment and the invoice can be raised. No phone number is collected, so none is sent.

Where your data goes

Cloudflare, Polar and Resend are United States companies, so running the licence server, taking a payment in dollars and delivering our email all involve processing outside India. Razorpay is Indian, and a rupee purchase stays on that rail.

Each of them is bound by its agreement with us and gets only what its job needs. The two payment companies also hold their own record of the payment and answer for it under their own legal duties — which is why a refund is executed by the one that took the money.

How we protect it

Your licence key is stored encrypted, and found by an irreversible hash of the key rather than by the key itself. Sign-in links are stored hashed too: they expire in 15 minutes, work once, and every other live link for your address dies the moment one is used. The secret each machine authenticates with is stored the same two ways the key is — checked against a hash, held encrypted so a repeat activation can return it — and the keys that unseal any of it are not kept in the database, so a copy of the database alone cannot be replayed as a credential.

Everything travels over HTTPS. The operator console that can read a licence row is reachable only with a separate token, and it is the only way a person here looks anything up.

Erasure, and what it costs

You can ask us to erase your personal data. We cannot delete the licence row itself — that row is what keeps a licence you paid for working — so instead we pseudonymize: your email address is replaced with a permanently unreachable placeholder, every machine name and macOS version on the licence is cleared, and what remains is the irreversible hash of the key, the order id and the dates we keep under contract.

This cannot be undone, and it takes things with it. After erasure we can never send you a sign-in link again, never email your key again, and never resume a cancelled rent-to-own plan for you — resuming matches on your email address, and there will no longer be one. Your installed copies keep working; the account behind them becomes unreachable, to us as much as to you. Ask only when you mean it, and consider getting your key emailed to yourself first.

One carve-out: a backup taken before your request still contains the old values until it ages out on its own schedule. We do not restore backups to bring erased data back.

What erasure does not reach: the address a machine last checked in from stays on its activation record, a trial's record keeps its machine number and address (its email is erased with the rest), and a tax invoice we have already issued keeps the name, email address and any address printed on it for as long as tax law requires — the checkout form behind it is cleared, but the document itself stands. None of it is a way back into the account.

Children

Clearroom is sold to adults — you must be 18 to buy a licence — and nothing here is directed at children. We do not knowingly collect a child's data. If you believe we hold any, write to us and it will be removed.

Your rights

You can ask for a copy of what we hold, ask us to correct it, ask us to erase it, or object to how we use it. Write to support@clearroom.studio from the address on the licence, or tell us the order it belongs to.

A copy can come as a machine-readable file if you want one — there is not much of it, and we will email it to you. Our mail is transactional: your key, sign-in links, receipts and notices about the service. There is no marketing list, and we do not sell your data or share it for advertising.

If something goes wrong

If we have handled your data badly, tell us first. Write to support@clearroom.studio from the address on the licence and say what happened.

Our grievance officer is Rupendar Venkatesh, reachable at support@clearroom.studio — the same address as everything else — care of the registered office on our contact page. He answers data-protection questions too.

If our answer does not settle it, a complaint in India can go to the Data Protection Board of India. Anywhere else, your own country's data-protection authority can hear it.

Versions

This is version 2026-09, published alongside the terms. When it is replaced, this version stays published at /privacy/2026-09. The previous version, 2026-08, stays published at /privacy/2026-08; the text of this page did not change between the two versions.