Privacy Policy
Thank you for using the WaveLoop apps — including WaveLoop, Choppa, layerz, tide, wake, roadie and infininote ("the Apps"). This Privacy Policy explains how we handle your data when you use our software, plugins, and website.
1. Audio in the Native Apps
WaveLoop and Choppa are purely local audio production tools. We do not collect, transmit, store, or have access to any audio you record, chop, or process using the Apps. All microphone input and audio processing happens entirely on your local device. roadie can stream audio and video between your own devices over your own local network — that traffic goes device-to-device on the network you are already on, never through us, and we have no access to it.
2. Email Collection & Downloads
When you download waveOS or other free software from our website, we ask for your email address. Here's what we do with it:
- What we store: Your email address, the products you signed up for, download timestamps, and any feedback you submit through our website.
- Why: To send you product updates (only for the products you downloaded), to understand how our software is being used, and to provide support.
- Where: Your data is stored in a secure, managed database hosted on DigitalOcean infrastructure.
- We will never: Sell your email, share it with third parties for marketing, or email you about anything other than the products you signed up for.
- Deletion: You can request deletion of all your data at any time by emailing us or submitting a feedback request through the website. We will remove your record within 30 days.
3. App Store & In-App Data (iOS/macOS)
If you purchase or download Choppa or WaveLoop via the Apple App Store, Apple collects standard analytics, crash reports, and purchase history according to their own privacy policies. We do not receive personally identifiable information from Apple regarding your app usage beyond anonymous crash logs (if you opt-in via your device settings).
- Microphone Access: Microphone input is used to record sample material for immediate, local processing. We never receive, transmit or store your audio.
- Dictation (infininote, macOS): Holding to dictate uses Apple's speech recognition to turn speech into text on your page. Recognition runs on your device whenever your language supports it. If it does not, Apple processes the audio under Apple's privacy policy. We never receive the audio, and we never store it.
4. The Members Room (waveloop.app/members)
Owning a WaveLoop app gives you access to a members-only room on our website. Your purchase is the key: the app sends Apple's signed proof-of-purchase receipt to our server, which returns a sign-in link. We never receive your Apple ID, name, email or payment details — only an anonymous member identifier derived from that receipt, plus whichever app you signed in from.
- The board: what you write there is stored against your member identifier, with the time and the app you posted from. Other members can read it — the room is not public and is not indexed by search engines, but anyone who owns a WaveLoop app can open it. Please don't post anything private.
- The wall: the room shows public Bluesky posts tagged #waveloop by members who linked their Bluesky account. Linking stores that account's identifier (its DID) and handle with your member identifier, so your posts can appear there; Unlink in the room removes it. You post from your own Bluesky account with your own sign-in: the post lives there, and we read posts to show them and store none of them.
- The old upload wall is retired. Until 5 September 2026 some Apps had a → WALL button that uploaded a file to the room. Since then it uploads nothing: the server throws away anything sent to it without storing it. Files shared before then are no longer listed in the room; a link you published yourself still opens. Email us and we'll delete yours within 30 days.
- Where: DigitalOcean (database and private object storage).
- Your alias: optional. If you don't set one, your posts show a shortened form of the anonymous identifier.
- Deletion: contact us and we will delete your member record, your posts and anything you shared within 30 days.
- We do not analyse, train on, sell, or share what you post.
Guestbook & Dev Log
The website shows public AT Protocol posts tagged #waveloop, plus Elijah Lucian's #waveloopdev posts. Messages you send are public Bluesky posts in your own account. Sign-in happens with your account provider; WaveLoop never receives your password. Session tokens, drafts and read positions stay in your browser. Our server briefly caches public feed results to display them. Delete a guestbook post through your Bluesky account.
Shared Choppa sampler
The website sampler is separate from the native Choppa app. Recording requires Bluesky sign-in and microphone permission. Up to 12 seconds of audio stays in a private browser draft while you trim, chop and preview it. Only pressing “Share” uploads the edited audio to your AT Protocol account, saves an app.waveloop.choppa.sample record and creates a public Bluesky post with #choppasample. Your public name, sample and pad boundaries then appear in the shared library. Other visitors can load and play those samples. Unshared drafts remain in this page’s memory until discarded or the page is left or reloaded; you can save a WAV locally.
Our Relay service coordinates the current bank and live pad hits, and temporarily caches public sample audio for playback. The lasting copy is stored by your account’s PDS provider. The trash button on your shared sample removes its sample record and linked Bluesky post from your AT Protocol repository. Relay removes cached entries as it rechecks the source. Removing only the Bluesky post elsewhere does not remove the separate sample record or its audio. Public material may have been copied by others. Cancelling before publication discards the microphone capture. Audio is never monitored back through your speakers while recording.
5. Testers, Promo Codes and Discord
A few records we keep by hand, to run the Apps:
- Testers: if you test an App for us, we keep your email, the name you gave us, which Apps you test, any promo code we sent you, and a short note on how we know you. We add these ourselves, to send you builds and codes; ask and we'll remove you.
- Promo codes: when we give you an App Store promo code, we note which code went to which email, and when, so no code is handed out twice.
- Discord: if you link your Discord account to the members room, we store your Discord user ID and username so we can give you the members role. Ask and we'll unlink it.
6. Your Drawings, Recordings and Documents
Your work stays yours and stays local. Where an app syncs (for example infininote canvases), it uses your own iCloud account — the data goes to Apple's servers under your Apple ID, and we have no access to it. We can also access material you deliberately publish through the website guestbook or shared Choppa sampler.
7. Website & Paddle Storefront (macOS/Windows)
If you purchase WaveLoop licenses directly through our website (waveloop.app), we use Paddle.com as our Merchant of Record and payment processor. When you buy a license:
- Paddle collects your name, email, billing address, and payment information to process the transaction securely and calculate taxes.
- We (the developer) only receive your name, email, and license key status to provide customer support.
- We never see or store your credit card numbers.
For more details on how Paddle handles your payment data, please review the Paddle Privacy Policy.
8. Website Analytics
Our website (waveloop.app) uses standard Google Analytics to understand basic traffic patterns (e.g., how many people visit the site).
We also count, on our own server, which pages are viewed, which links and buttons are clicked, and which downloads are served. Each record holds the page, what was clicked, the site you came from, and a rough device type (phone, tablet or desktop, and the operating system). No cookies are set. We never store your IP address or browser string; they are combined with a random value that changes every day and is then thrown away, which lets us count one visit as one visit for that day and never link it to you or to another day. These records are kept for 12 months.
Our web server also keeps standard access logs (IP address, time, the file requested, browser string) for 14 days, for security and for counting downloads, and then deletes them.
None of this tracks your usage inside the standalone apps or plugins.
Live visitors: public pages share an anonymous gem colour, the page you are browsing, and cursor positions with other visitors on that page. The visitor list includes people on the same page, even when their cursors are idle. Link badges show anonymous page totals. This presence is temporary and is not saved. Your approximate country flag is also shared when available, using a country database on our server to look up your connection's IP address. Other visitors receive only the country code, never your IP address. If you sign in with Bluesky, your name stays hidden unless you enable “Share my Bluesky name.” When enabled, other visitors on that page can see your verified public display name, handle, and Bluesky profile link. We verify your identity using a short-lived proof; your login tokens are never shared with the visitor relay. Your choice is saved for that Bluesky account in this browser. Turning the toggle off, hiding your presence, or signing out removes your name. You can hide your presence or turn off your flag in the Live visitors control. No form contents are shared.
9. Changes to this Policy
We may update this privacy policy from time to time. If we make significant changes, we will post the updated policy on this page.
10. Contact Us
Questions about this policy or your data: hello@waveloop.app, or the feedback form on the home page.
WAVELOOP