Privacy policy
Last updated: August 2026
This policy describes how WavePhase, operated by Jaroslav Patočka (see our Legal notice), handles personal data when you use our website, sign in, purchase licenses, use WavePhase Cloud, PatchBay, or the desktop application with online activation.
Cookies and similar technologies
We use HTTP-only cookies to keep you signed in to your account and to protect security-sensitive flows. These are strictly necessary for the service you request. We store your cookie-notice preference in your browser's local storage when you respond to our banner. We do not use advertising or cross-site tracking cookies on this website.
If you choose Accept all on our cookie banner, we load Google Analytics (GA4) to collect aggregated usage statistics such as page views, approximate geography, device type, and referral source. Google may set first-party analytics cookies and receive your IP address (often truncated). You can decline optional analytics with Essential only; in that case Google Analytics is not loaded.
When error monitoring is enabled in our deployment, the browser or server may send diagnostic events to our monitoring provider (Sentry; see Processors below). We configure it not to send personal data by default. The desktop application may likewise send crash reports in release builds unless you opt out in Preferences. You can remove cookies through your browser settings; you will then need to sign in again.
What we collect
- Account data: email address when you sign in with a magic link or 6-digit code (web or device flow), an optional public username, session identifiers stored in secure HTTP-only cookies, and account creation timestamps.
- Licensing data: license identifiers, tier, status, device-binding information (hashed device fingerprints and optional device labels), update entitlement dates, activation secret hashes, Stripe checkout session references, and optional usage telemetry or heartbeat events linked to a license when the desktop app sends them.
- Billing: payments and subscriptions are processed by Stripe. We store references needed to fulfill licenses and cloud subscriptions (for example Stripe customer and subscription identifiers, checkout session IDs). We do not store full payment card numbers on our servers.
- Email delivery: transactional email (sign-in codes, purchase-related messages, workspace invitations where applicable) is sent via Resend using the address you supplied.
- WavePhase Cloud: workspace and project names, membership and roles, packaged show files you upload (including embedded media, images, fixtures/personalities, and related show content), version metadata, object-storage pointers and CDN delivery of those packages, control-link configuration hashes, audit events, and agent credit usage when you use cloud features. Do not upload show content you are not willing to store with the service.
- PatchBay: patches you publish or save, titles, descriptions, tags, optional preview image URLs, ratings, comments, and download counts tied to your account.
- Feedback: bug reports and feature requests you submit from the app or website, including optional contact email, app version, build number, platform, OS string, and diagnostics you choose to attach.
- Technical logs: server logs and optional error reports may include IP addresses, request paths, and timestamps for security and reliability.
- Website analytics (optional): if you consent via our cookie banner, Google Analytics receives page-view and usage events as described under Cookies above.
- Desktop crash reports (opt-out): release builds of the WavePhase desktop app may send crash diagnostics to Sentry when crash reporting is enabled in Preferences (on by default). Typical fields: panic message, backtrace, app version/build, and OS. Show files, audio, patch graphs, prompts, and license keys are not included. Reporting is disabled in debug/developer builds. Turning the preference off takes effect on the next launch.
- Desktop usage analytics (optional, opt-in): release builds of the WavePhase desktop app may send lightweight product-usage events to our first-party API when you grant consent during first-run setup or in Preferences → Updates. Events are buffered briefly and stored as aggregated summaries (for example last seen and session minutes per license). Typical fields: session start/heartbeat/end, install id, optional license attribution when signed in, app version/build, and OS. Show files, audio, patch graphs, prompts, emails, and license keys are not included. Declining consent finishes setup with nothing sent; existing installs that never opted in send nothing until Preferences is enabled.
Why we use data
We use this information to provide authentication, deliver and manage licenses and cloud entitlements, process purchases, operate PatchBay and cloud collaboration, secure the service, respond to support and feedback, improve reliability and the product, develop and operate features (including analysis and future assisted capabilities), and meet legal obligations. Cloud-uploaded shows and media are accessible to the service operator as needed to provide, maintain, and improve the Services under these purposes. We do not sell your personal data.
When you use Wavy or other cloud agent features, your prompts and relevant project context are processed on our servers and sent to our configured AI provider to generate a response. Do not submit sensitive personal data in prompts unless necessary for your use case.
Processors and infrastructure
We use reputable service providers under agreements that require them to protect personal data and process it only on our instructions where applicable. Depending on the features you use, data may be processed by:
- Stripe, Inc. — payment processing and billing portal.
- Resend, Inc. — transactional email delivery.
- Functional Software, Inc. (Sentry) — error and crash monitoring for the website, API (when configured), and desktop release builds (unless the user opts out of crash reporting in Preferences); configured without sending personal data by default.
- Google LLC (Google Analytics) — optional, consent-based website usage analytics when you choose Accept all on our cookie banner.
- Desktop product telemetry (first-party) — optional, consent-gated session metrics stored in our database when enabled in the desktop app; not a third-party analytics SaaS.
- DigitalOcean, LLC — object storage (Spaces) and CDN for PatchBay preview images and Cloud packaged show files when those features are enabled, and/or hosting infrastructure for our application and database.
- OpenAI or compatible API providers — server-side processing for Wavy when you invoke cloud agent features.
Installer files may be served from our CDN or object storage URLs recorded in our release database. Internet Web Control may route encrypted relay traffic through separately operated relay infrastructure; relay processes do not persist your show media by design.
Retention and security
We keep data only as long as needed for the purposes above and to comply with law (for example tax or accounting retention, where relevant). We use industry-standard measures appropriate to the nature of the service. Activation secrets, session tokens, and similar credentials are stored as one-way hashes, not plain text. Feedback may retain a copy of your contact email even if you later delete your account, so we can follow up on the report.
Your choices
From your account page you can export the personal data we associate with your account and request account deletion. You can change your sign-in email using the confirmation flow sent to your new address. On the website, decline optional analytics with Essential only on the cookie banner (or clear site data and choose again). In the desktop app, turn off crash reporting and/or usage analytics under Preferences → Updates (usage analytics applies immediately; crash reporting on next launch). For broader rights under the GDPR, see our GDPR summary.
Contact
For privacy questions: [email protected]. For the legally identified operator of this service, see the Legal notice.