Privacy Policy
Chppr ("the Service") is an independent web application for audio sampling and beat creation. This policy explains what information is collected and how it is used.
Information we collect
When you create an account or sign in with Google, Discord, X / Twitter, or email, we receive the account information required for the selected authentication method:
- Your name
- Your email address, if provided by the OAuth provider
- Your profile picture URL, if provided by the OAuth provider
X email access is not enabled, so X may not provide an email address. Passwords are handled by Supabase Auth and are not visible to Chppr. Authentication emails, such as signup confirmations and password resets, are delivered through Supabase Auth using Resend.
We use account information to authenticate you, connect and manage your Beat Cards and profile, protect the Service, respond to support or deletion requests, and operate the Service. We do not sell personal information.
Account consent records
When authentication succeeds, we store your user ID, the version of the Terms and Privacy notice presented, the acceptance time, and the authentication source. This record is used to document the notice accepted for your account.
Internal operational notifications
When a permanent account is created, an internal notification may be sent to the private Chppr Slack workspace. The notification can include the account email address when available and is used only for operations, support, abuse prevention, and service security.
Project data
When you publish a project, the audio and project configuration are stored in cloud storage. Published projects are publicly accessible via their share URL. Only you can update or overwrite your published project.
Analytics
The Service uses Google Analytics 4 (GA4) to understand page views, traffic sources, approximate location, device and browser information, and feature interactions.
We may enable Google signals and Google Analytics Advertising Features, including demographics and interests reporting where available. These features may use Google Analytics cookies and other first-party identifiers together with Google advertising cookies or other third-party identifiers to provide aggregated analytics reports.
The Service also uses PostHog to understand product usage, feature adoption, funnels, retention, web analytics, heatmaps, session replay, and interactions with SEO entry pages. Upload, export, and project-save filenames may be sent to PostHog for product analytics and debugging. Filenames may contain personal information chosen by the user. We do not send audio file contents or project contents to analytics.
The Service also uses Microsoft Clarity to understand how visitors interact with pages through aggregated heatmaps, session recordings, clicks, scrolling, and similar usage signals. Clarity may collect device, browser, approximate location, page interaction, and diagnostic information.
Except for filenames that a user chooses for uploads, exports, or project saves, we do not intentionally send audio file contents, project contents, account names, email addresses, or other personally identifiable information in our analytics events. We configure analytics to focus on product usage patterns rather than personal content, and we do not combine analytics data with personally identifiable account data.
You can manage ads personalization in your Google Ads Settings, use the Google Analytics opt-out browser add-on, or control cookies and advertising identifiers through your browser or device settings.
Third-party services
- Supabase — authentication and database/file storage
- Resend — delivery of transactional authentication emails through Supabase Auth
- Google OAuth — sign-in
- Discord OAuth — sign-in
- X / Twitter OAuth — sign-in; Chppr does not request X email access
- Slack — private operational notifications for account creation, project sharing, and feedback
- Google Analytics — usage analytics, Google signals, and aggregated advertising feature reports
- PostHog — product analytics, funnels, retention, web analytics, heatmaps, session replay, and feature interaction events
- Microsoft Clarity — heatmaps, session recordings, and product usage diagnostics
- Railway — backend audio processing
- Vercel — frontend hosting
External resources
The post-signup welcome page can link to YouTube, the NOK Beats publication on Substack, and Discord. These links open the external service in a new tab. Chppr does not transfer your OAuth or account email to these services and does not subscribe you automatically. Any action you take there is governed by that service's terms and privacy policy.
Marketing email
Creating a Chppr account does not automatically enroll you in Chppr maker updates or a Substack publication.
If you explicitly select Chppr maker updates, we store your account user ID, the consent purpose and version, consent time, current subscription status, and any unsubscribe time. This permission covers tips for making, prompts to pick up where you left off, feature, plan, and release updates, and occasional short feedback requests. You can turn it off in Account at any time.
Creator Pass Early Access is a separate, explicit opt-in. When you register, Chppr stores your email address, stated feature preference, optional comment, consent version and time, and unsubscribe status solely to validate and communicate about Creator Pass, Pro Export, and its first release. Every update includes an unsubscribe method; you can also contact us to request deletion of this interest record.
Data retention
Your account data is retained as long as you use the Service. Published project files are stored until you publish a new project (which overwrites the previous one) or request deletion.
Your rights
You may request deletion of your account and associated data at any time by contacting us. We will process the request within a reasonable timeframe.
Children
The Service is not directed at children under 13. We do not knowingly collect information from children.
Changes
We may update this policy from time to time. We will show the effective date of the current version and may ask you to accept an updated notice during a future authentication flow.
Contact
Questions about this policy can be sent to @_nok__ on X.