Seen Live

Beta v1. Last updated: 2026-08-29

Privacy Policy — Seen Live Private Beta


§1. Data controller

The data controller for personal data processed by Seen Live is Charles Blethon, acting as a natural person during the private beta (a legal entity will be formed ahead of the public opening). Contact address: 1 rue Newton, 75116 Paris, France. For any privacy-related question or to exercise your RGPD rights: privacy@seenlivemusic.com.

§2. Personal data we collect

DataSourceLawful basis
Email addressWaitlist + magic link sign-inBeta consent (RGPD art. 6.1.a)
First name + last nameWaitlistConsent (art. 6.1.a)
Artist name + Instagram handleWaitlistConsent (art. 6.1.a)
Uploaded MP3 filesArtist uploadContract (art. 6.1.b — detection service)
Audio fingerprintDetection providerLegitimate interest (art. 6.1.f — service execution)
Analytics eventsSite navigationExplicit consent via banner
Error logsRuntime errorsLegitimate interest (debug + security, IP scrubbed)
Email metadataTransactional emailsContract (art. 6.1.b)

§3. Data retention

DataPhase 1 retention
Account profileAs long as the account is active, plus 30 days post-deletion (RGPD erasure)
Uploaded MP3 filesAs long as the track is being tracked, plus a security buffer post-account deletion
Audio fingerprintIndefinitely while the account is active
Detection recordsAs long as the account is active (cumulated identity proof)
Product analytics eventsPer our analytics provider's retention policy
Error logsPer our error monitoring provider's retention policy
Email metadataPer our email provider's retention policy
DMCA / LCEN takedown registerFor the duration required by applicable law (LCEN obligation)

A future automatic purge policy for uploaded MP3 files will be introduced ahead of the public opening (Phase 2).

§4. Hosting and data residency

All operational data is hosted in the European Union by default:

ServiceProviderRegionRole
Database + Storage + AuthSupabase Inc.Frankfurt (EU)Primary data store
Application hostingVercel Inc.Paris / Frankfurt (EU)Static + serverless
Async jobsInngest Inc.EU regionPipeline orchestration
Transactional emailsResendEU regionWaitlist + magic link + digests
Error monitoringSentryEU regionErrors + performance
Product analyticsPostHog CloudEU regionConsent-gated

§5. Sub-processors and international transfers

We rely on the following Phase 1 sub-processors: Supabase, Vercel, Inngest, Resend, Sentry, PostHog, Upstash (rate limiting), Loops (waitlist provider, US-based) and ACRCloud (detection provider).

Upstash (rate limiting). To prevent abuse of the magic-link sign-in, Upstash processes your email address and IP address as rate-limiting counters over a rolling one-hour window. Nothing else is sent, and these counters are not used for any other purpose.

Loops (US transfer). Loops processes waitlist emails and confirmation messages on US-based infrastructure under EU Standard Contractual Clauses (SCC, art. 46 RGPD).

ACRCloud (transfer outside the EU — detection provider). Audio fingerprinting and detection scanning are performed by ACRCloud PTE. LTD. (Singapore-based). Your uploaded audio file is transmitted for fingerprint generation only and is permanently deleted by the provider once the fingerprint is created — the original file remains hosted in the EU (see §4). Only the non-reversible fingerprint (which cannot be turned back into audio) is retained for scanning. This transfer is governed by EU Standard Contractual Clauses (SCC, art. 46 RGPD); a Data Processing Agreement with the provider is being finalized ahead of the beta opening.

A live list of sub-processors will be published at /legal/sub-processors starting Phase 2. The current Phase 1 list is enumerated above and updated in this section for any new processor added.

§6. Your rights (RGPD)

  1. Access (art. 15) — copy of all your data within 30 days.
  2. Rectification (art. 16) — via your account settings or by email.
  3. Erasure (art. 17)right to be forgotten within 30 days.
  4. Restriction (art. 18) — pause processing on request.
  5. Portability (art. 20) — a machine-readable copy of your data, on request by email, within 30 days.
  6. Object (art. 21) — opt out of analytics processing at any time (cookie banner or email).
  7. Withdraw consent (art. 7) — via cookie banner or email.
  8. Lodge a complaint with the CNIL (FR Data Protection Authority, cnil.fr).

§7. Cookies and tracking

We use a single first-party consent layer stored in your browser's local storage. When you accept, an EU-hosted product analytics SDK starts capturing page views, clicks, and feature usage events (no PII — IP scrubbed, email scrubbed at SDK level). When you reject (or by default — opt-out), no event leaves your browser. To revoke consent at any time: clear your browser storage or email privacy@seenlivemusic.com.

§8. Security measures

  • TLS 1.3 in transit, AES-256 at rest.
  • JWT httpOnly cookies for authentication (magic-link via Supabase Auth).
  • Strict security headers including Content-Security-Policy.
  • Rate limiting on sensitive endpoints.
  • Automated backups via point-in-time recovery.
  • Error monitoring with PII scrubbing at instrumentation level.

§9. Data breach notification

In the event of a data breach affecting your personal data, we will notify the CNIL within 72 hours (RGPD art. 33) and you directly within 7 days (best effort, RGPD art. 34) via email and a status page.

§10. Contact and DPO

For any privacy-related question or to exercise your RGPD rights, contact privacy@seenlivemusic.com. For Phase 1 beta, no formal DPO is appointed: Seen Live operates below the RGPD art. 37 thresholds (fewer than 250 employees, no large-scale processing of special-category data). DPO designation will be re-evaluated for the Phase 2 public opening.

§11. Updates to this policy

This policy is versioned. Any material change will be communicated by email to all active beta users with prior notice.