Last updated 1 October 2026
This policy explains what Cove Sound Studio's online service stores about you, why, and for how long. We collect only what sign-in, licensing, cloud projects and keeping the service secure need. We don't sell your data, and we don't use it for advertising.
1. What we store
- Account: your username and password. Your password is stored only as an Argon2id hash, which can't be turned back into the password. We don't ask for your email address.
- Discord: your Discord user ID, username, display name and avatar, from Discord's authorization with the "identify" permission only. We can't see your email address, servers or messages on Discord, and we don't keep your Discord access token. Your connected Discord account is also how you can prove an account is yours to reset its password.
- Devices: for each computer you sign in on, its name, its Windows version, the app version, a public key the app creates, and a device identifier. The device identifier is a one-way hash of hardware identifiers, made on your computer. The service stores only a keyed hash of it, never the hardware identifiers themselves.
- Licenses: the plan, dates and status, the computers a license is active on, and a hash of the license key.
- Cloud projects: the settings of packs you save to your account, such as names, weapon assignments and processing settings, and the names and properties (such as length and sample rate) of your sound files. Never the audio itself. File locations on your computer are removed before a project is uploaded.
- What the app reports: when a build starts, finishes or fails, and when a pack is exported, with the pack's name and a few numbers, such as the number of weapons. Never file locations.
- Security records: sign-ins, license checks, account changes and suspicious activity, with a shortened IP address (the network part only, not your full address) and the app version.
2. On your computer
The app keeps your sign-in and license information on your computer, encrypted with Windows' own data protection for your Windows user account. Unsaved changes to your projects are kept in the app's folder on your computer, so they can be recovered after a crash. They are never uploaded.
When you connect Discord or reset your password with Discord, Discord's own page opens in a window of the app. That window has a separate browsing session of its own: whatever you enter there goes to Discord, not to us, and the session is erased when the window closes.
3. Why we use it
- To let you sign in and to keep your account secure, including locking it for a while after repeated wrong passwords.
- To let you reset a forgotten password: by confirming your connected Discord account in the app or with the /reset-password command in the Cove Sound Studio Discord server, or with a one-time code an administrator gives you after checking it's you.
- To check that your license is valid and used on the computers it allows. The device identifier is what limits a license to its computers.
- To tell you about a license given to your Discord account: the Cove Sound Studio bot sends you a direct message on Discord with the license's details, and its key when the license is new.
- To keep copies of your projects that you can open on another computer.
- To prevent and investigate abuse. The service's administrators see accounts, licenses and account, license and security events in the admin panel of the Cove Sound Studio app, and some events in private channels of the Cove Sound Studio Discord server.
4. How long we keep it
- Account, Discord, device, license and project data: until you delete your account, or remove the device or project.
- Unfinished sign-ups: 30 minutes.
- A Discord connection in progress (what Discord answered, before it's added to your account): about a day.
- Password reset codes (stored as hashes): they work for 15 minutes through Discord, or 24 hours when an administrator gives you one, and are deleted a day after they stop working.
- A direct message about your license, while the bot sends it: its content is stored encrypted, and erased as soon as it's sent (or can't be). The record that a message was sent is deleted after a month.
- Ended sign-in sessions: deleted after 90 days.
- Earlier versions of a cloud project: the last 20.
- Security records: 12 months.
5. Deleting your data
In the app, Account, then Delete account, deletes your account, devices, sessions and cloud projects at once. A license you were given stays attached to your Discord account, so it isn't lost if you create a new account; ask us if you want it removed too. Security records are kept for the time above, without a link to your account, and records already posted to the administrators' Discord channels stay in Discord.
6. Who else processes your data
- Discord: when you connect your Discord account, for the direct messages the bot sends you, and for the administrators' private channels.
- Our hosting provider, which runs the service.
7. Your rights
You can ask for a copy of your data, for a correction, or for deletion. Contact us through the Cove Sound Studio Discord server.
8. Changes to this policy
We may update this policy. If a change matters, we'll tell you in the app or in the Cove Sound Studio Discord server before it takes effect.