Feedback Loop

Privacy Policy

Effective Date: March 18, 2026

Last Updated: April 21, 2026

Summary: Feedback Loop is a music collaboration platform. We collect your account data, audio uploads, feedback activity, and usage data to power the platform. We do not sell your personal data. You have full rights to access, correct, and delete your data. This policy is GDPR and CCPA compliant.

Welcome to Feedback Loop ("Feedback Loop," "we," "us," or "our"). This Privacy Policy explains in detail how we collect, use, store, protect, and share your personal information when you access or use our web application at feedbackloop.studio (the "Service"). It also describes your rights and choices regarding your data.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please discontinue use of the Service.

1. Who We Are and How to Contact Us

Feedback Loop is a music feedback and collaboration platform that allows independent musicians, producers, and audio creators to share their work, receive structured peer feedback, participate in feedback pools, and grow as artists.

Data Controller: Feedback Loop
Contact Email: privacy@feedbackloop.studio
Support Email: support@feedbackloop.studio

For all privacy-related enquiries, data subject requests, or concerns about this policy, please contact us at the email addresses listed above. We will respond within 30 days.

2. Information We Collect

We collect information in three primary ways: information you provide directly, information collected automatically, and information from third parties.

2.1 Information You Provide Directly

  • Account Registration Data: Name, email address, and password (hashed) when you create an account.
  • Profile Information: Display name, biography, profile picture/avatar, primary and secondary music genres, social media links (Instagram, X/Twitter, TikTok, YouTube, Spotify, SoundCloud, Facebook, personal website), and any other information you add to your public profile.
  • Audio Content: Audio track files you upload to the Service, including associated metadata (title, description, genre tags, version labels, upload notes). Audio files are encrypted at rest using AES-256-GCM encryption.
  • User-Generated Content: Comments, feedback, ratings, reactions, and messages you create or send on the platform.
  • Pool Activity: Feedback pools you create or join, pool submissions, moderator roles, and participation history.
  • Payment Information: When purchasing credits or a Pro subscription, your payment is processed by Stripe. We do not store your full credit card number or banking details — only transaction IDs, subscription status, and billing history. See Section 7 for more on payment processing.
  • Communications: Messages you send to us via email or our support chat, including feedback or support tickets.
  • Consent Records: Records of your consent choices (e.g., cookie consent, marketing preferences, terms acceptance) including timestamps and policy version at time of consent.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent on specific sections, clicks, search queries within the app, and general interaction patterns.
  • Device and Technical Data: IP address, browser type and version, operating system, device type, screen resolution, language settings, and referring URLs.
  • Session Data: Session identifiers, login timestamps, session duration, and authentication events.
  • Performance Metrics: Page load times, error logs, and crash reports used to improve Service stability.
  • Analytics Events: Custom events we track to understand feature usage (e.g., track uploads, pool joins, feedback given). These are tied to your user ID internally but reported in aggregate for analytics purposes.
  • Cookies and Similar Technologies: See Section 9 (Cookies) for full details.

2.3 Information from Third Parties

  • Authentication Providers: If you sign in via a third-party provider (e.g., Google), we receive your name, email address, and profile picture from that provider, as permitted by your account settings with them.
  • Payment Processors: Stripe provides us with confirmation of successful transactions, subscription status, and payment method type (e.g., card last 4 digits).
  • Referral Data: If you were referred to Feedback Loop by another user, we store the referral token and link it to your account upon registration.

3. How We Use Your Information

We use your information for the following purposes, each supported by a legitimate legal basis:

3.1 To Provide and Operate the Service (Contract Performance)

  • Create and manage your account.
  • Store and serve your uploaded audio tracks and versions.
  • Enable pool creation, membership, and submission workflows.
  • Facilitate peer feedback, comments, ratings, and reactions.
  • Manage your credit balance and process credit transactions (earning and spending credits).
  • Enable direct messaging and social connections between users.
  • Display your public profile to other users on the Loopers page.
  • Send transactional notifications (e.g., new feedback received, pool invite accepted, connection requests).

3.2 To Improve and Personalise the Service (Legitimate Interest)

  • Analyse usage patterns to understand which features are most valuable.
  • Personalize content recommendations and in-app suggestions.
  • Track and award achievements and badges based on your platform activity.
  • Run A/B tests to improve platform design and usability.
  • Monitor platform performance and fix bugs.

3.3 AI-Powered Features (Contract Performance / Legitimate Interest)

  • Generate AI feedback on your tracks using third-party large language model APIs. Your audio content and associated context are transmitted to these APIs solely to generate requested feedback. We do not use your content to train external AI models without explicit consent.
  • Power the in-app support chat assistant.

3.4 For Safety and Legal Compliance (Legal Obligation / Legitimate Interest)

  • Detect, investigate, and prevent fraudulent transactions, abuse, and security incidents.
  • Enforce our Terms of Service and Community Guidelines.
  • Comply with applicable laws, regulations, and lawful governmental requests.
  • Maintain data breach incident records and fulfill regulatory reporting obligations where required.

3.5 For Marketing (Consent)

  • Send you product updates, new feature announcements, or promotional offers — only if you have opted in.
  • You may withdraw consent at any time via Settings or by contacting us.

4. Sharing Your Information

We do not sell your personal data. We share your information only in the following limited circumstances:

4.1 With Other Users (By Design)

The following information is visible to other registered users of the Service as part of the platform's core collaboration features:

  • Your public profile: display name, bio, avatar, genre tags, social links, and badges/achievements.
  • Tracks you have set as "public" or submitted to a pool.
  • Comments and feedback you leave on others' tracks.
  • Your activity in shared pools.

Tracks you mark as "private" are only visible to you and users you explicitly share them with.

4.2 With Service Providers (Data Processors)

We engage the following categories of trusted third-party service providers who process data on our behalf under strict data processing agreements:

  • Cloud Infrastructure & Hosting: For storing data, audio files, and running the application.
  • Payment Processing: Stripe, Inc. — for handling credit card payments and subscription billing. Stripe's privacy policy is available at stripe.com/privacy.
  • AI/LLM Providers: For processing AI feedback requests on your tracks. Audio content is transmitted only when you explicitly request AI feedback.
  • Analytics: For aggregated usage analytics to improve the Service.
  • Email Delivery: For sending transactional and notification emails.

4.3 For Legal Reasons

  • In response to valid legal process (court order, subpoena, or other lawful request).
  • To protect the rights, property, or safety of Feedback Loop, our users, or the public.
  • In connection with an investigation of fraud, intellectual property infringement, or other illegal activity.

4.4 Business Transfers

If Feedback Loop is involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service before your data is transferred and becomes subject to a different privacy policy.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you the Service. Specific retention periods by data category are as follows:

  • Account & Profile Data: Retained for the lifetime of your account, and deleted within 30 days of a verified account deletion request.
  • Audio Tracks & Versions: Retained as long as your account is active. Deleted upon account deletion or when you manually delete a track.
  • Feedback Comments: Retained for 3 years after creation, unless you delete them or request deletion.
  • Payment Records: Retained for 7 years as required by financial and tax regulations.
  • Authentication & Session Logs: Retained for 90 days.
  • Usage & Analytics Data: Retained in aggregated, anonymized form indefinitely. Individual-level usage logs are retained for 12 months.
  • Support Communications: Retained for 3 years from the date of last correspondence.
  • Consent Records: Retained for 5 years as evidence of compliance.

When data reaches the end of its retention period, it is either permanently deleted or anonymized. You can request early deletion at any time (see Section 8 — Your Rights).

6. Data Security

We take the security of your data seriously and implement the following measures to protect it:

  • Encryption at Rest: All audio files are encrypted using AES-256-GCM. Database records containing sensitive data are encrypted at rest.
  • Encryption in Transit: All data transmitted between your browser and our servers uses TLS 1.2 or higher (HTTPS).
  • Access Controls: Access to production systems and user data is restricted to authorized personnel on a need-to-know basis.
  • Authentication Security: Passwords are stored as one-way cryptographic hashes. We support secure session management with automatic timeout.
  • Incident Response: We maintain a documented data breach response process. In the event of a breach affecting your data, we will notify you within 72 hours of discovery, where legally required.
  • Third-Party Auditing: We review our service providers' security practices before onboarding them and periodically thereafter.

Despite these measures, no system is 100% impenetrable. We encourage you to use a strong, unique password and to report any suspected security vulnerabilities to security@feedbackloop.studio.

7. Payments and Financial Data

Feedback Loop uses Stripe, Inc. as our payment processor for credit purchases and Pro subscription billing.

  • All payment card data is collected and stored directly by Stripe. We never receive or store your full card number, CVV, or bank account details.
  • We store only: transaction IDs, payment status, subscription plan type, billing cycle, and the last 4 digits of your card (as provided by Stripe for display purposes).
  • Stripe is a PCI DSS Level 1 certified payment processor. Their privacy policy governs how they process your financial data: stripe.com/privacy.
  • Credit balances and transaction history (credits earned and spent) are stored on our platform and are visible to you in your Credits dashboard.
  • Payment records are retained for 7 years to comply with financial regulations, even if you delete your account.

8. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal data. We honor these rights for all users, regardless of jurisdiction.

8.1 Right of Access (GDPR Art. 15 / CCPA)

You have the right to request a copy of all personal data we hold about you. You can submit a Subject Access Request (SAR) from your Privacy Center in the app, or by emailing privacy@feedbackloop.studio.

8.2 Right to Rectification (GDPR Art. 16)

You can update most of your profile data directly in your account settings at any time. For other corrections, contact us.

8.3 Right to Erasure / Right to Be Forgotten (GDPR Art. 17 / CCPA)

You may request deletion of your account and personal data. We will delete your data within 30 days, except where retention is required by law (e.g., financial records). You can initiate this from your Privacy Center or by contacting privacy@feedbackloop.studio.

8.4 Right to Data Portability (GDPR Art. 20)

You can export your data in a structured, machine-readable format (JSON) via the Privacy Center. This includes your profile, track metadata, comments, and activity history.

8.5 Right to Restrict Processing (GDPR Art. 18)

You may request that we restrict processing of your data in certain circumstances (e.g., while disputing accuracy or pending an erasure request).

8.6 Right to Object (GDPR Art. 21)

You may object to processing of your data for marketing purposes or where we rely on legitimate interests as the legal basis. To opt out of marketing emails, use the unsubscribe link in any email or update your notification preferences in Settings.

8.7 Right to Opt-Out of Sale / Sharing (CCPA)

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. California residents have the right to confirm this and to request disclosure of any sharing practices.

8.8 Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights. You will continue to receive the same quality of service regardless of any requests you make.

To exercise any of these rights, visit your Privacy Center in the app, or email us at privacy@feedbackloop.studio. We will verify your identity before processing your request and respond within 30 days (or 45 days for complex requests, with notification of extension).

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on the Service. When you first visit, you will be presented with a cookie consent banner allowing you to choose your preferences.

9.1 Types of Cookies We Use

  • Essential / Strictly Necessary: Required for the Service to function. These include session cookies for authentication, CSRF protection tokens, and load balancing. Cannot be disabled.
  • Preference / Functional: Remember your settings and preferences (e.g., notification preferences, view modes). Optional.
  • Analytics: Help us understand how users interact with the platform, which features are most used, and where performance can be improved. Optional.
  • Marketing / Targeting: Used to show you relevant content or track the effectiveness of campaigns. Optional. We will only set these with your explicit consent.

9.2 Managing Cookies

You can manage your cookie preferences at any time via the cookie banner (accessible from the footer) or your browser settings. Note that disabling essential cookies will impair the Service's functionality.

10. Children's Privacy

The Service is not directed to children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information without parental consent, please contact us at privacy@feedbackloop.studio and we will delete that information promptly.

11. International Data Transfers

Feedback Loop may store and process your data in countries outside of your own, including the United States. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we ensure that any international transfer of your personal data is protected by appropriate safeguards, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Adequacy decisions where applicable.
  • Binding Corporate Rules where implemented by our service providers.

12. Third-Party Links

The Service may contain links to third-party websites (e.g., social media profiles linked from user pages, Spotify artist pages). We are not responsible for the privacy practices or content of those third-party sites. We encourage you to read the privacy policies of any third-party sites you visit.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Post the updated policy on this page with a new "Last Updated" date.
  • Send you an in-app notification and/or email notification.
  • For significant changes, we may require your re-acknowledgment via the Terms Acceptance modal on your next login.

Your continued use of the Service after any changes constitutes your acceptance of the new Privacy Policy.

14. How to Lodge a Complaint

If you have a complaint about how we handle your personal data, we encourage you to contact us first at privacy@feedbackloop.studio so we can try to resolve the issue directly.

If you are not satisfied with our response, and you are located in the EU/EEA, you have the right to lodge a complaint with your local Data Protection Authority (DPA). A full list of EU DPAs can be found at: edpb.europa.eu/about-edpb/board/members_en.

If you are located in the UK, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Feedback Loop – Privacy Team

Email: privacy@feedbackloop.studio

Support: support@feedbackloop.studio

Response Time: Within 30 days