DoReMiWave Legal
Privacy & GDPR Effective: 4 October 2026

Privacy Policy

Contents

  1. Who is responsible
  2. What data we process
  3. Why we process it and on what legal basis
  4. How long we keep it
  5. Who else processes it
  6. Transfers outside the EU
  7. Cookies and local storage
  8. Your rights
  9. If you live outside the EU
  10. Deleting your account
  11. Security
  12. Children
  13. Automated decisions
  14. Changes to this policy

In short: we process only what we need to run the Service: your email, your password (stored only as a secure hash), the files you upload and the videos you create. We use one cookie, to keep you logged in. No advertising, no tracking, no analytics, no selling of data, and your files are never used to train AI. Payments are handled by Paddle. You can download your data or delete your account at any time from your account page.

1. Who is responsible for your data

The controller of your personal data under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and Romanian Law no. 190/2018 is Cucu Cosmin-Ionut, an individual (natural person) resident in Romania, Sat Valcica, nr. 1, Comuna Tatarusi, Oras Pascani, Judet Iasi, 707500, Romania (“we”, “us”), the operator of DoReMiWave.

For anything related to your data, write to legal@doremiwave.com. We are not required to appoint a Data Protection Officer; that address reaches the person responsible for data protection.

For payments, Paddle (our Merchant of Record) is a separate, independent controller of the data it collects at checkout; its own privacy notice applies to that data.

2. What data we process

  • Account data: your email address, your password (we store only an Argon2id hash, never the password itself), your date of birth, whether your email is confirmed, your plan, account dates and the date and version of the Terms you accepted. If you choose to, a display name shown at the top of the site instead of your email. If you sign in with Google, your Google account identifier and the email address Google confirms.
  • Your content: the audio files, cover images, logos, background images and videos you upload, the text you add, your projects, settings and saved templates, and the videos we render for you. Your content may itself contain personal data (for example a photo or a name).
  • Usage data: exports you start and their status, quotas used, preview sessions and the technical information needed to run them.
  • Subscription data we receive from Paddle: plan, billing period, subscription and transaction identifiers, amounts and status. We do not receive your card details.
  • Technical data: IP address and browser information sent with each request, and server logs. We use the IP address in memory to limit abuse (for example too many sign-up attempts); we do not store it in your account.
  • Communications: messages you send us by email and our replies; records of service emails we send you (for example whether a confirmation email was delivered).
  • Reports and notices: if you report content or are the subject of a report, the information in the report and the decision taken.

We do not ask for, and ask you not to upload, special categories of data (such as health data). We do not use your data for advertising or profiling.

3. Why we process it and on what legal basis

PurposeDataLegal basis (GDPR art. 6(1))
Creating and running your account, logging you in Account data, session cookie (b) performance of our contract with you
Checking that you meet the minimum age (16) and, if you are under 18, asking you to confirm a parent's or guardian's consent before a purchase Date of birth (b) contract; (c) legal obligation (Law no. 190/2018, art. 2; rules on contracts with minors)
Keeping proof that you accepted the Terms of Service and Privacy Policy Date and version of the accepted Terms (f) our legitimate interest in establishing or defending legal claims
Analysing your audio, showing previews, rendering and delivering your videos, storing your projects Your content, usage data (b) contract
Service emails: email confirmation, password reset, export notifications, important changes Email address, related account data (b) contract; (c) legal obligation for mandatory notices
Applying your plan, quotas and purchases Subscription and usage data (b) contract
Security, preventing fraud and abuse, keeping the Service stable, fixing errors Technical data, logs, usage data (f) our legitimate interest in a secure and working service
Answering your questions and support requests Communications, account data (b) contract or (f) legitimate interest in replying to you
Handling reports of illegal content and copyright notices, cooperating with authorities Reports, related content and account data (c) legal obligation (Digital Services Act, copyright law); (f) legitimate interest
Keeping records required by tax and accounting law; establishing or defending legal claims Subscription data, communications (c) legal obligation; (f) legitimate interest

Providing your email address, password and date of birth is necessary to create an account; without them we cannot provide the Service. Your date of birth is used only for the age checks above: it is not shown to anyone, not used for advertising or profiling, and we do not ask for your phone number or any other identity document. If we ever want to send you marketing emails, we will ask for your consent first, and you can withdraw it at any time.

4. How long we keep it

DataKept for
Account data, including your date of birthWhile your account exists; after you delete it, 30 days, then erased (see section 10)
Uploaded files, projects and templatesUntil you delete them or your account
Rendered videos3 days (Do), 15 days (Sol), 30 days (Clef) after rendering, then deleted automatically
Login sessionUp to 14 days, or until you log out
Email confirmation and password reset linksUntil used or expired (hours to days)
Server logs and abuse-prevention dataShort periods, normally no longer than 30 days
Support emailsUp to 2 years after our last exchange, unless needed for a legal claim
Subscription and transaction recordsAs long as required by tax and accounting law (in Romania up to 10 years); after account deletion they are kept without your email address
Content reports and decisionsUp to 3 years, to handle contests and repeat violations

Backups are overwritten on a rolling basis, so deleted data disappears from them within a short period.

5. Who else processes your data

We do not sell or rent your data. We share it only with the providers below, who help us run the Service, under contracts that require them to protect it (data processing agreements), or with Paddle as an independent controller for payments:

ProviderWhat forData
Paddle.com Market Ltd (United Kingdom) Merchant of Record: processes payments, invoices, taxes, refunds and payment-related customer service. Acts as an independent controller for payment data. Name, email, billing address, payment details (we never see card numbers), purchase history.
Resend, Inc. (USA; emails sent from the EU region, Ireland) Sends account and service emails (email confirmation, password reset, export notifications). Email address, email content, delivery status.
Cloudflare, Inc. (USA; video storage in the EU) Stores your exported videos (Cloudflare R2, EU jurisdiction) until they expire, and serves your downloads through private links that expire after a few minutes; domain name system (DNS), security and routing of emails sent to our @doremiwave.com addresses. Your exported videos; IP addresses and technical request data; for emails: sender, recipient and message content in transit.
Our hosting provider (servers located in the European Union) Hosts the website, the database and the files you upload, and renders your videos. All service data described in this policy.
Google LLC (USA) Hosts our support mailbox (Gmail); messages you send to our @doremiwave.com addresses are stored there. If you choose "Continue with Google", Google confirms who you are and tells us your email address and name; we never receive your Google password. Your email address and the content of your messages to us; if you sign in with Google: your email address, name and Google account identifier.

We may also disclose data when the law requires it (for example to a court or a competent authority), to protect our rights or the safety of others, or to a successor if the Service is transferred (for example to a company we set up to run it), in which case this policy continues to apply.

6. Transfers outside the European Union

Our servers are in the European Union. Some providers listed above are based in the United Kingdom or the United States. Transfers to the United Kingdom rely on the European Commission’s adequacy decision. Transfers to the United States rely on the EU–US Data Privacy Framework for certified providers and/or the European Commission’s Standard Contractual Clauses, with additional safeguards where needed. You can ask us for a copy of the relevant safeguards at legal@doremiwave.com.

7. Cookies and local storage

We use only what is strictly necessary for the Service to work:

NameTypePurposeDuration
ss_session First-party cookie (HttpOnly, Secure) Keeps you logged in and protects your account Up to 14 days
Preferences (names starting with ss_) Your browser’s local storage, not sent to us Remembers interface choices, such as which panels you have already seen and the audio/video timing of your device Until you clear your browser data
Paddle checkout Third-party, only when you open the checkout Processing your payment and preventing fraud, under Paddle’s own policy Set by Paddle
Cloudflare security cookies Third-party, only if needed Distinguishing people from malicious bots Short (minutes to hours)

Because these are strictly necessary, they do not require your consent under the ePrivacy rules (Romanian Law no. 506/2004, art. 4(5)), and we do not show a cookie banner. We use no analytics, advertising or tracking cookies. If that ever changes, we will ask for your consent first. You can block cookies in your browser, but then you will not be able to log in.

Because we do not track you across sites, there is nothing for “Do Not Track” or Global Privacy Control signals to switch off; if we ever introduce tracking, we will treat a Global Privacy Control signal as an opt-out.

8. Your rights

Under the GDPR you have the right to:

  • access your data and receive a copy of it (art. 15);
  • rectify inaccurate data (art. 16);
  • erase your data (art. 17);
  • restrict processing in certain cases (art. 18);
  • data portability: receive your data in a machine-readable format (art. 20) — use Privacy & data → Download on your account page for an immediate JSON copy;
  • object to processing based on our legitimate interest (art. 21);
  • withdraw consent at any time, where we rely on consent;
  • lodge a complaint with a supervisory authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, www.dataprotection.ro. You can also complain to the authority in the EU country where you live or work.

To exercise a right, use the tools in your account or email legal@doremiwave.com from the address registered on your account. We answer within 30 days (extendable by up to two months for complex requests, in which case we tell you why). Exercising your rights is free; we may ask for proof of identity if we are unsure the request comes from you. We may refuse or limit a request only where the law allows it (for example when it would reveal another person’s data, or when we must keep the data by law), and we will tell you why.

9. If you live outside the EU

We apply the same protections to every user, wherever they live. In addition:

  • United Kingdom: you have the same rights under the UK GDPR, and you can complain to the Information Commissioner’s Office (ico.org.uk).
  • United States (including California under the CCPA/CPRA and other states with privacy laws): in the last 12 months we collected the categories described in section 2 — identifiers (email address), account and commercial information (plan and purchase records), internet activity limited to security logs, and the content you upload — from you directly, for the purposes in section 3. We do not sell or share personal information for cross-context behavioural advertising, we do not use sensitive personal information to infer characteristics about you, and we have no actual knowledge of selling or sharing data of anyone under 16. You have the right to know, access, correct and delete your personal information, and to not be discriminated against for using these rights. You may use an authorised agent, with proof of their authority. If we refuse a request, you can appeal by replying to our answer; if the appeal is refused, you can contact your state Attorney General.

Requests: legal@doremiwave.com. We answer within the time required by the law that applies to you.

10. Deleting your account

You can delete your account at any time from your account page. When you do:

  • you are logged out everywhere and any active subscription is cancelled with Paddle, so you are not charged again;
  • the account can no longer be used; after 30 days we permanently delete your uploaded files, projects, templates and videos, delete your date of birth, display name and Google sign-in link, and replace your email address and password hash with anonymous values;
  • we keep, without your email address, only the subscription and transaction records that tax and accounting law require us to keep.

The 30-day period protects you from accidental or malicious deletion. If you want your data erased sooner, write to legal@doremiwave.com.

11. Security

We protect your data with technical and organisational measures appropriate to the risk, including: encrypted connections (HTTPS) for all traffic, passwords stored only as Argon2id hashes, session cookies inaccessible to scripts, access to files only through checks of who owns them, limits against automated abuse, safe processing of uploaded files, restricted access to servers and regular updates. No system is perfectly secure; if a personal data breach is likely to put your rights at risk, we will notify the authority and, where required, you, as the GDPR requires.

12. Children

The Service is not intended for children under 16. If we learn that a child under 16 has created an account, we will delete it. Parents or guardians can contact us at legal@doremiwave.com.

13. Automated decisions

We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Plan limits and quotas are applied automatically, but they are the same for everyone on a plan.

14. Changes to this policy

We will update this policy when our processing changes (for example a new provider). For important changes we will inform you by email or in the Service before they apply. The effective date is shown at the top of this page.

Related policies

Terms of ServiceRefund PolicyCopyright, DMCA & Content Reports

Help Center · Contact us · Questions: support@doremiwave.com · Legal and privacy: legal@doremiwave.com