Privacy Policy
This Privacy Policy describes the current information handling of the Shivay Music website at shivaymusic.com, the Śrutirā web application, and the supporting application programming interface at api.shivaymusic.com (together, “Shivay Music”).
Shivay Music is operated by Preet Poshiya, an individual based in India. Privacy questions and requests may be sent to shivaymusic11@gmail.com.
1. Information processed by Shivay Music
Google sign-in and account information. When a user chooses Google sign-in, the backend requests Google’s profile and email scopes. The current account code uses and stores the verified email address and stable Google account identifier returned by Google, together with an internal account identifier and account activity fields used for sign-in. The application code does not store Google OAuth access tokens or refresh tokens in its application database.
Authentication information. The backend creates signed cookies containing an internal account identifier, a session version, issue time and expiry time. The production authentication cookie is HTTP-only, secure and SameSite=Lax, and is valid for no more than 24 hours. A separate temporary cookie is used to validate the Google OAuth return and is valid for no more than 10 minutes.
Device and access information. The browser creates a random Shivay Music device identifier. The backend processes device identifiers, the associated account, pairing and last-seen times, and whether a device is active. These records are used to apply subscription access and the current limit of two active devices per account. Desktop pairing additionally processes a hashed pairing code, pairing state and expiry information.
Purchase, subscription and payment information. The backend processes the selected access plan, amount, INR currency, internal purchase identifiers, device identifier, payment status and timestamps. It also processes Razorpay payment-link, order, payment or QR identifiers and the provider responses and webhook events needed to verify, reconcile, refund or dispute a payment. Razorpay collects payment credentials through its checkout. Shivay Music does not ask users to provide a card number, bank password or UPI PIN to Shivay Music.
Support communications. If a user contacts Shivay Music by email or through a linked social platform, Shivay Music and that communication provider process the information the user chooses to send. Users should provide only the account email and relevant Razorpay payment identifier when asking about a payment, and must not send card details, bank passwords or UPI PINs.
Request and error information. The backend reads the request IP address for in-memory rate limiting. Application errors may be written to server logs using bounded, single-line error summaries. Production error summaries omit application stack traces.
2. Information stored in the user’s browser
- A random device identifier and a non-authoritative device cache are stored in browser storage and a same-site device cookie.
- An open purchase session can place its session identifier, plan and expiry in session storage for the current browser tab.
- Interface preferences and installation state may be stored locally.
- Workspace recovery snapshots are stored in IndexedDB. Signed-in account snapshots are encrypted with AES-GCM using account-specific key material supplied by the backend. Anonymous snapshots are stored locally with an integrity checksum but are not encrypted by the current code.
- The service worker uses Cache Storage for application files and, when requested by the user, the offline audio package.
Browser storage remains on the user’s device until it is replaced or cleared by the application, the browser or the user. Signing out does not by itself clear every local setting, device identifier, cache or workspace snapshot.
3. Projects, recordings and imported audio
The project save, load and automatic recovery features operate in the browser. They do not upload project contents, recordings or user-imported audio to the Shivay Music backend. A project file exported by the user is saved to a location selected or managed by the user’s browser or device.
4. How the information is used
The current system uses the information described above to:
- sign users in and protect account sessions;
- verify subscriptions and control access to subscription features;
- pair, list and deactivate authorised devices;
- create, verify, reconcile and adjust payments;
- send a verified payment receipt when transactional payment email is enabled;
- restore locally stored workspace state and provide offline application files;
- limit abusive request rates, diagnose errors and respond to support requests.
The current frontend contains no third-party advertising system or third-party analytics integration. The current backend email module sends transactional payment receipts only when that feature is enabled; it contains no marketing-email function. The current application code contains no feature for selling personal information.
5. Service providers
Shivay Music uses the following services for the functions shown:
- Google for Google account authentication;
- Supabase for server-side account, device, subscription and payment records;
- Razorpay for checkout and payment processing;
- Cloudflare to deliver the website;
- Render to host the backend API;
- Brevo only when transactional payment-receipt email is enabled.
Information is sent to these providers only as needed for the corresponding function. Their handling of information within their own services is also governed by their own terms and privacy documentation.
6. Retention and deletion
The current application code does not define a fixed automatic deletion period for server-side account, device, subscription, payment, webhook or receipt records, and it does not currently provide a self-service account-deletion control. A user may email shivaymusic11@gmail.com to request access to, correction of or deletion of account information. Each request will be reviewed against the records involved and applicable requirements.
Users can clear locally stored information through their browser’s controls for site data. Browser or device controls determine what local information is removed.
7. Security
The current system uses HTTPS, signed HTTP-only authentication cookies, signed device-bound entitlement tokens, signature validation for Razorpay webhooks, server-side payment verification and encrypted signed-in workspace snapshots. No internet service or storage method can guarantee absolute security.
8. User choices and requests
Users can sign out, deactivate eligible devices through the account interface, clear browser site data, decline the optional offline download, and choose not to start a purchase. Questions about account information or an unauthorised or incorrect payment should be sent to shivaymusic11@gmail.com.
9. External links
Shivay Music links to external services such as Google, YouTube, Instagram and Razorpay. This policy does not describe information handling on those external websites or services.
10. Changes to this policy
If Shivay Music changes the information it processes or how that information is used, this page must be updated and its “last updated” date changed. Users should review the current version available at this URL.
11. Contact
Operator: Preet Poshiya, India
Email: shivaymusic11@gmail.com