Privacy Sovereignty // Protocol

Privacy Policy

Last updated: 3 March 2026
Applies to: MousePlugins website, customer dashboard, newsletters, and MousePlugins software products (e.g., StudioHum)

Who We Are

This Privacy Policy explains how Stéphane Berger ("MousePlugins", "we", "us") processes personal data.

Data Controller
Stéphane Berger, Carrer Sant Bartomeu 35, 03560 El Campello, Spain
NIF/NIE
Y8132747F
EU VAT ID
ESY8132747F
Contact
privacy@mouseplugins.com
DPO
Not appointed (unless legally required). If appointed, we will publish DPO contact details here.

If you are in the EEA/UK, we process personal data in accordance with the GDPR and applicable local laws.

Zero Telemetry Policy (Software)

MousePlugins software products are designed to run as a closed system. We do not collect telemetry, usage analytics, audio content, or session data from your DAW.

Tracking Status
Disabled. No background reporting or analytic pings.
Session Privacy
We do not know what you are producing or how you use the software.
Offline Runtime
No internet connection is required to activate or run the software. The only online steps are purchasing the product and receiving your download link/license key.
Remote Disable
Not used. We do not implement "kill switches".

What We Collect

A) Purchases & Licensing

To sell and deliver products (including license keys), we may process:

  • Contact data: email address.
  • Transaction metadata: order/reference IDs, product, price, currency, timestamps, refund status.
  • License data: license key and its status (active/revoked), plus optional "seat" or entitlement metadata.
  • Tax data (if required): VAT ID and invoicing fields you provide for billing purposes.

We do not store your full card details. Payments are handled by our payment processor(s) (e.g., Stripe).

Activation is performed locally by entering a license key. We do not contact a server to validate it and we do not receive activation events.

B) Customer Dashboard (Magic Link)

If you use our customer dashboard, we process your email to send a sign-in link and keep security logs (e.g., sign-in timestamps, IP/UA) to prevent abuse.

C) Newsletter (Optional)

If you subscribe, we process:

  • Email address.
  • Your opt-ins (separate toggles): (1) event discounts (country-based), (2) product updates, (3) new releases.
  • Country (only if you opt into event discounts).
  • Subscription/unsubscribe timestamps (for compliance).

D) Support (Optional)

If you contact support, we process what you send us (messages, attachments). If you choose to provide diagnostics, it may include device/OS/DAW details and software version. Do not send audio projects or sensitive personal data unless you truly want to.

E) Website Technical Data

Like every website on Earth (sadly), our servers may receive technical data such as IP address, user-agent, referring URL, and request logs for security and troubleshooting. We also use Plausible Analytics to understand aggregate website traffic (e.g., page views and referral sources). Plausible is designed to be cookie-less and to avoid tracking you across sites; we use it for high-level metrics, not to profile individuals.

Third-party delivery: this page may load fonts from fonts.bunny.net, and we may serve static assets or product downloads via Bunny.net CDN. These providers can receive your IP address and user-agent as part of normal web requests. If you prefer, we can self-host fonts and reduce third-party delivery.

Why We Use Data (and Legal Bases)

Contract
To process orders, deliver downloads/license keys, provide customer access, and handle refunds/support.
Legal Obligation
To meet accounting and tax requirements (e.g., record-keeping).
Consent
To send newsletters and marketing emails only when you explicitly opt in. You can unsubscribe anytime.
Legitimate Interests
To secure the website, prevent fraud/abuse, maintain service reliability (minimal logs, rate limiting), and understand aggregate site usage (cookie-less analytics).

Who We Share Data With

We do not sell your personal data. We share it only with service providers who help us run MousePlugins:

  • Payment processing: e.g., Stripe (processes payments and related fraud checks; we receive confirmation and transaction metadata).
  • Hosting/infrastructure: to serve the website and downloads.
  • Email delivery: for transactional emails (magic links, receipts) and, if you opt in, newsletters.
  • Content delivery (CDN) & downloads: e.g., Bunny.net to serve files quickly and reliably (receives IP/user-agent as part of delivery).
  • Website analytics (aggregate): Plausible Analytics (cookie-less, used to measure overall traffic and site performance).

Service Providers (Processors)

We use the following providers to operate MousePlugins. They may process limited technical data (e.g., IP address and user-agent) as part of delivering these services.

Email
Proton Mail (transactional and support email)
Hosting
Infomaniak (website and app hosting)
Analytics
Plausible Analytics (cookie-less, aggregate website analytics)
CDN / Downloads
bunny.net (static assets and downloads delivery)

Some providers may process data outside the EEA/UK. Where required, we rely on appropriate safeguards (e.g., adequacy decisions and/or Standard Contractual Clauses).

How Long We Keep Data

  • Purchase/accounting records: typically kept for 6 years from the last entry for business documentation, unless a longer period is required by law or to handle disputes.
  • Licensing records: kept while the license remains active, plus reasonable time for audits, dispute resolution, and legal obligations.
  • Newsletter: until you unsubscribe.
  • Support tickets: kept as long as necessary to resolve your issue and for reasonable follow-up.
  • Server security logs: typically short retention (e.g., days to weeks), unless needed for incident response.

Your Rights

Depending on your location (especially within the EEA/UK), you may have rights to access, correct, delete, restrict, object to processing, and request portability of your personal data.

Request Channel
Email us at privacy@mouseplugins.com with enough information to identify your request.
Complaint
You can lodge a complaint with your supervisory authority. In Spain, this is the AEPD (Spanish Data Protection Agency).

Security

We use reasonable technical and organizational measures to protect personal data (TLS encryption in transit, access controls, and minimal data collection by design). No system is perfect, but we try harder than average.

Cookies

We use only what we need to make the website and dashboard work (e.g., session cookies, CSRF protection, and security/rate-limiting where applicable). We may also store your interface preferences (such as theme: light/dark and accent color) in a cookie or local storage so the site remembers your choice. We do not use tracking cookies for advertising. Our website analytics (Plausible) is designed to be cookie-less.

Changes to This Policy

If we change this policy, we'll update the "Last updated" date and, where appropriate, provide a notice on the website.

System Integrity: Verified Private