Weaver Audio weaver audio
my account tangle modules contact
Home  ›  Privacy policy

Privacy Policy

Effective May 15, 2026 · Last updated September 23, 2026

Version 2026-09-23.1

Weaver Audio Pty Ltd (ACN 678 376 086) of Melbourne, Victoria, Australia — "Weaver Audio", "we", "us" or "our" throughout this policy — respects your privacy. We are the controller of the information described here. This Privacy Policy explains how we collect, use, and protect information in connection with our software products, including Cassette and the Tangle plugin family (together, the "Software").

1. Information We Collect

1.1 Information You Provide

  • License Information: When you activate the Software, we collect your license key, your email address, and basic activation metadata: a hashed machine identifier, the name your computer reports for itself (for example "DAVID-DESKTOP"), and the dates of first activation and most recent check-in. Your account page shows these back to you so you can see which machines a licence is on and free one up.
  • Account and Purchase Information: If you create an account, we store your email address and your account preferences. When you buy something, your card details go directly to our payment processor and never reach our servers — but the processor returns, and we keep, a record of the sale: your email address, the product, the amount, currency and any discount, and the billing country, state and postcode. If you reached our website through a campaign link or an advertisement, the sale record also carries the campaign tags and ad click identifier described in section 1.2b. We keep that record to deliver and support your licence and to meet our tax and accounting obligations.
  • Getting the Download onto Your Computer: Our software runs on Mac and Windows computers, so if you tap a download button on a phone or tablet, the website suggests creating your free account there — you need one to start a trial — and emails you the download link so it is waiting on your computer. If you are signed in, or create your account from that screen, the email goes to your account's address; you can instead just type an address, which we use only to send that one email. The email contains the download links, a link to our getting-started guide, a link to sign in or create your account and, if you were on a product page, a link back to it. If you arrived through one of our own campaign links, the links to our site in that email carry its source and campaign name (section 1.2b), so a visit from your computer is still credited to it. Our mail system is set to delete its copy of the email after 30 days. So that the form cannot be used to send mail to other people, we also keep, for a short time, a one-way hash of the address and one-way hashes of the network (IP) addresses the request came through — those salted with a random key that is replaced every day — and these records delete themselves automatically within a few days. Your address is not added to any mailing list unless you tick the box asking for next month's free pack.
  • Free-Pack Sign-ups: If you ask for next month's free pack — on the website, or on that phone screen — we keep your address, the page you asked from and when, and send you one confirmation email. We send the pack only once you confirm, and we never mail an address that has not confirmed. Every such email carries an unsubscribe link.
  • Consent and Acceptance Records: When you accept these documents (the Terms and Conditions, this Privacy Policy and the End User License Agreement) at signup, or change your marketing-email preference, we keep a dated record of that decision: what you chose, when, where on the site you did it, and which version of the documents was in force at the time. Where such a record has to identify an email address it holds a one-way hash of it, never the address itself. We keep these records because the law puts the burden on us — not on you — to show what you agreed to. If you say yes to product email when you create an account with an email address and password, we send you one email asking you to confirm that the address is yours. If you create your account with Google, which has no product-email box, we record a "no" and ask you the question once on your account page.
  • Support Communications: If you contact us for support, we collect the contents of your communication and any files or logs you choose to share.

1.2 Information Collected Automatically

  • Anonymous Usage Data: With your consent, we may collect anonymous, aggregated information about how the Software is used (feature usage frequency, crash reports, performance metrics) to improve the product. For the Tangle plugins this is described precisely in section 1.3 below.
  • Update Checks: The Software checks whether a newer version has been released. It does this by fetching one small public file from our website that lists the current version — the same file anyone can open in a browser — and comparing it on your own machine. The request tells us nothing about you or your installation: not which product is asking, not which version you are running, not your operating system, and no licence serial, no email address, no account identifier and no install identifier. Nothing about what you are working on. As with any request to a web server, the connection itself reveals the IP address it came from; we do not store that address against your account, your licence, or any other record of you. You can switch the check off inside the plugin.
  • Installer Downloads: When you download an installer from your account page, we record against your account which product, platform and version you took, and when. We use it to support you ("which build are you running?") and to see whether people who bought something ever managed to install it. Downloads from the public website, without signing in, are recorded by product, platform, version and time only, with nothing that identifies you.
  • Sign-in Records: When you create an account, sign in or sign out on our website, we record what happened, when, and whether it worked (with the error, if it did not), together with the email address used, the identification string your browser sends with every request (it names your browser and operating system), and your device's time-zone and language settings. The time zone tells us roughly where you are — for example "Australia/Melbourne" — and that is as precise as it gets: these records do not include your IP address, and we never ask your device for its location. We use them to diagnose sign-in problems and to understand roughly which countries our users come from.
  • Support Access to Your Account: When we are helping you with a problem, a member of our staff can sign in to your account and see your account page exactly as you see it. While signed in as you, they cannot accept these documents for you, change your product-email preference or delete your account — those choices are yours alone. Each such sign-in appears in your sign-in records.

1.2a Website Cookies and Advertising Measurement (opt-in)

This section applies only to our website, weaveraudio.com. It does not describe the Software.

We use advertising cookies from Meta (Facebook/Instagram) and Google to measure whether our advertising works — for example, whether someone who saw an ad later viewed a module page or bought a plugin. These cookies are set by those companies and allow them to recognise you on other sites they operate.

Nothing loads until you accept. No advertising cookie is set, and no advertising or measurement request is made to Meta or Google, unless you choose "Accept" on the banner shown on your first visit. If you decline, the site behaves identically and no such request is ever made. You can change your choice at any time by clearing your browser's storage for our site. (Separately, our pages load their fonts from Google Fonts, sign-in and checkout run on Google's Firebase, and some pages show videos through YouTube's privacy-enhanced mode. Like any web request, these reveal your IP address and browser to Google; they are not part of our advertising measurement.)

Where you have accepted, Meta's and Google's code records, as it does on any website, the address of each page you view (including any campaign tags or ad click identifier in it), the site that referred you, and basic facts about your browser and device; Google's also notes how you move through the site — for example how far you scroll, which outside links you follow and when you start filling in a form — but never what you type. On top of that we tell them which product a product page is and its price, which pricing option you tapped on the Tangle page, and — if you buy — that a purchase occurred, which product, its value and currency, and an order reference number. We have switched off Meta's automatic collection of button and page details, and we do not send your name, email address, licence serial, or anything you have made with our software.

1.2b Campaign Links and Page Counts (website)

This section also applies only to weaveraudio.com.

Page counts. We count visits to our website as anonymous daily totals: one tally per page and event (for example, which product's buy button was clicked, or that a page failed to load or loaded slowly), with the rough width of your browser window (phone, tablet or desktop), the website that referred you (its name only), and — where the link you followed carried them — its source, medium and campaign tags. These totals contain no cookie and no identifier for you, your browser or your device, and we do not keep your IP address or browser details with them.

Campaign links. Links we publish — in social media posts, on our profiles, in emails and in advertisements — can carry campaign tags (utm_source, utm_medium, utm_campaign, utm_content and utm_term) that name where the link was placed. When you click an advertisement, Meta or Google may also add their own ad click identifier to the link (fbclid or gclid). When you arrive through such a link, our website keeps these values (from the first such link, if you follow more than one) in your browser's session storage for that tab. This is not a cookie, it lasts only as long as that tab's browsing session, and it happens whether or not you accept advertising cookies (section 1.2a): it is our own record of where you came from, and on its own it sends nothing to Meta or Google.

If you buy something in that tab, the campaign tags and the ad click identifier are passed to our payment processor with your order and saved in our sales record (section 1.1), so we can tell which post or advertisement led to a sale. If you ask us to email you the download link from that tab (section 1.1), its source and campaign tags — never the ad click identifier — go with the request and are written into the links in that email. Other than to our payment processor, we do not send them to Meta, Google or anyone else from our servers. They are kept with the sales record for the period in section 4.

1.3 Tangle Usage Analytics (opt-in)

Tangle plugins can share anonymous usage statistics, and do so only if you opt in — via a one-time question shown inside the plugin. If you decline, or never answer, nothing is collected. You can change your answer at any time from the plugin's menu; switching it off is as easy as switching it on.

When enabled, each plugin sends one summary per session (the period a plugin window is open), containing:

  • which Tangle modules were in use and for how long the window was open;
  • basic technical context: host application (DAW), operating system, sample rate, plugin version;
  • a coarse hardware profile of the machine class: processor model, number of cores, memory size, and architecture — never serial numbers or any unique hardware identifier;
  • your licence state (trial or purchased) — never your serial number;
  • a random install identifier: a randomly generated ID that is not derived from your hardware, licence, or account, and cannot be traced back to you. Opting out deletes this identifier and any unsent data from your machine; data already on our servers remains pseudonymous and is not linked to your identity.

Usage analytics never include audio, file names, project contents, keystrokes, serial numbers, email addresses, or names. The data is stored on Google Cloud (BigQuery, United States) and analysed in aggregate to understand which modules and features matter most — informing what we build, fix, and promote.

Also covered by this same opt-in are two stability signals, which carry no more information than the session summary above: a flag recording whether the previous session ended cleanly, so we can measure how often the plugin fails; and a count of which modules produced invalid audio values. Neither contains audio, memory contents, or file paths. Crash *reports* — a different and more sensitive thing — are covered separately in section 1.3b.

1.3b Tangle Crash Reports (separate opt-in)

If a Tangle plugin crashes, it can send us a report about the failure. This is a separate question from the usage analytics above, and answering one does not answer the other, in either direction. Nothing is sent unless you specifically agree to send crash reports.

You see the report before it is sent. When a crash report is waiting, the plugin shows you its exact contents — not a summary, not an example, the literal file that would be uploaded — and you choose to send it, decide later, or never be asked again. Choosing never also deletes any reports already waiting on your machine.

A crash report contains technical information about the failure: which plugin and version stopped working, the operating system and host application, and the state of the program at the moment it failed — the sequence of internal functions that were executing, and the list of software components loaded into memory.

Please read this part carefully. On some platforms a crash report includes a snapshot of the memory the plugin was using. That snapshot is not curated, and it can incidentally contain fragments of whatever the plugin happened to be holding at that moment — which may include file paths, the name of a project or sample you had open, or fragments of audio data. We do not seek out such content, and we use crash reports only to diagnose the failure, but we cannot guarantee it is absent. This is exactly why crash reports have their own opt-in, and why we show you the report first.

Crash reports carry no install identifier and no licence information, and are stored separately from usage analytics, so the two cannot be connected to each other.

You may optionally add your email address and a description of what you were doing. Both are entirely optional — leaving them blank sends the report anonymously, and the only consequence is that we cannot reply to you. When you do provide them, they are stored apart from the crash data itself, so they can be deleted independently on request.

Crash reports are stored on Google Cloud (United States).

1.4 Information We Do NOT Collect

  • We do not collect, transmit, or store the audio content you process with the Software.
  • We do not collect the contents of your generated datasets, training data, or model files.
  • We do not access your local files outside of paths you explicitly select within the Software.
  • We do not link usage analytics to your identity, licence serial, or email address.
  • We do not link crash reports to usage analytics: they carry no install identifier and are stored in a separate system, so the two data sets cannot be joined.
  • We do not sell your personal information for money.
  • We do not set any advertising cookie on our website unless you have accepted it (see section 1.2a). Some privacy laws, including California's, treat sharing data with advertising platforms as a "sale" or "share" even where no money changes hands; if you have accepted advertising cookies and want that stopped, decline the banner or contact us using section 10.

2. How We Use Your Information

We use the information we collect to:

  • Validate and manage software licenses
  • Provide customer support
  • Send important updates about the Software (security fixes, major releases)
  • Send product news and offers by email where you have opted in — every such message carries an unsubscribe link, and you can also switch it off in your account at any time
  • Improve product stability and features through opt-in diagnostics and crash reports
  • Reply to you about a crash you reported, if you chose to give us an address
  • Understand, in aggregate, which modules and features are most used (opt-in usage analytics), to guide development and how we present our products
  • Understand which of our posts, links and advertisements bring visitors and sales, using the page counts and campaign information described in section 1.2b
  • Email you a download link you asked for from a phone or tablet, and stop that form being used to send mail to anyone else
  • Diagnose sign-in problems, and see roughly which countries our users come from, using the sign-in records described in section 1.2
  • Keep, and if asked produce, the record of what you consented to — your marketing choice and your acceptance of these documents
  • Comply with legal obligations

3. Third-Party Services

The Software, our website, and our account systems use the following third-party services. Each has its own privacy policy:

  • Payments (Stripe): Card details are entered directly with Stripe, our payment processor, and never reach our servers. Stripe returns the sale record described in section 1.1 — email address, product, amounts, and billing country, state and postcode — which we retain as our own sales and tax record. If you arrived through a campaign link, we also pass Stripe the campaign tags and ad click identifier described in section 1.2b, which it stores with the payment. Stripe keeps its own copy of the payment, including these tags, under its own retention rules, and also uses payment information for its own purposes, such as preventing fraud and meeting its legal obligations, as its privacy policy describes. Deleting your account with us does not delete Stripe's copy.
  • Email Delivery (SendGrid): Licence emails, account emails, emails you ask our website to send you (such as a download link), and opt-in marketing email are delivered through SendGrid, acting as our data processor, which receives your email address and the message. SendGrid reports delivery failures and spam complaints back to us so we stop mailing an address that is failing. We keep our own do-not-mail list and check every send against it. It holds a one-way hash of each address that has unsubscribed or switched product email off (which includes the "no" recorded after a Google sign-up until you say yes), complained, hard-bounced or asked us to delete their account — never the address itself. A bounce or a complaint is a delivery fact rather than a preference, so switching the marketing option back on in your account does not clear one; where that has happened your account page says so and tells you how to get it cleared.
  • Accounts and Storage (Google Firebase): Your account, licence, and purchase records are stored on Google Cloud (Firebase), which acts as our data processor.
  • Analytics Storage: Opt-in usage analytics are stored on Google Cloud Platform (BigQuery). Google acts as our data processor and does not use this data for its own purposes.
  • Advertising Measurement (website only, opt-in): If you accept advertising cookies on weaveraudio.com, Meta Platforms and Google receive the limited event data described in section 1.2a. Unlike our analytics processor, these companies act as independent controllers and may use that data for their own advertising purposes. See Meta's Privacy Policy and Google's Privacy Policy.
  • Plugin Catalog Sources: When you use catalog or research features, requests may be made to publicly available third-party websites.
  • Crash Reporting (separate opt-in): If you opt in specifically to crash reporting, reports are transmitted to and stored on Google Cloud Platform, which acts as our data processor. They are pseudonymous rather than strictly anonymous — see section 1.3b, which explains what a report can contain and the optional contact details you may choose to attach. We do not send crash reports to any third-party crash-reporting service.

4. Data Retention

  • License and account data: retained for the duration of your license plus a reasonable period for legal and accounting purposes.
  • Sales records (the order, the amount, and the billing country, state and postcode): retained for at least five years, because Australian tax law requires us to keep them — including after you delete your account.
  • Campaign tags and ad click identifiers attached to an order: tax law does not require these, but we keep them with the sales record for the same period so our sales figures stay complete. Ask us and we will remove them from your orders.
  • Download-link emails you requested from a phone or tablet: our mail system is set to delete its copy after 30 days, and the anti-abuse records described in section 1.1 are deleted within a few days.
  • Free-pack sign-ups: kept until you ask us to remove them. Once you unsubscribe, nothing more is sent to the address.
  • Public download records and website page counts: retained indefinitely; neither identifies anyone.
  • Support communications: retained for up to 3 years.
  • Installer download records: retained with your account. After you delete the account, what is left carries only an internal account identifier that no longer resolves to a person.
  • Sign-in records: retained with your account, and deleted when you delete it (section 5.2).
  • Do-not-mail list: the one-way hash of a suppressed address is kept indefinitely. It is the only thing that stops us mailing you again, and it holds no readable address.
  • Anonymous usage data: retained indefinitely in aggregated form.
  • Crash reports: the memory snapshot attached to a report is deleted after 90 days. The technical summary is retained in aggregate so we can tell whether a fault has been fixed. Optional contact details you attached are deleted on request — see section 10.

5. Your Rights

Depending on your jurisdiction (including GDPR for EU residents and CCPA for California residents), you may have the right to:

  • Access the personal information we hold about you
  • Request correction or deletion of your information
  • Opt out of anonymous data collection
  • Request a copy of your data in a portable format
  • Lodge a complaint with a supervisory authority

Two of these you can exercise yourself, immediately and without asking us: your account page has a download my data button (section 5.1) and a control that deletes the account (section 5.2). For anything else, contact us at [email protected].

5.1 Getting a copy of your data

Sign in and press download my data on your account page. You get a single JSON file — a portable, machine-readable format, as GDPR Article 20 requires — containing the personal information we hold against your account: your profile, your licences and the machines they are activated on, your orders and purchases, the checkouts you have started, the free trials you have taken, your installer downloads, your sign-in records, your consent history, the marketing email we have sent you, and any presets you have shared.

Two things are not in it, for the reason each was designed that way. Opt-in usage analytics and crash reports carry a random install identifier and no account, licence or email address, so there is no way for us to pick out yours (sections 1.3 and 1.3b). And contact details you attached to a crash report are released only to a verified email address, because they are matched by address alone and releasing them otherwise would hand someone else's report to whoever claimed the address first. Email us for either.

Some things depend on confirming your address. Anything you bought as a guest — without signing in, or before you made this account — is held against the email address you gave at checkout rather than against the account, and a failed attempt to sign in while signed out records only the address that was typed. We can only include those once we know that address is yours. Your account page will offer to email you a confirmation link; export again afterwards and those records are in the file.

The file names anything it held back and says why, so you never have to guess whether a short answer is a complete one. If it is still short of something you expected, or you would rather have it another way, ask us at [email protected].

5.2 Deleting your account

You can delete your account yourself from your account page. When you do, we delete your profile and your purchase list, delete your sign-in, remove your email address and your machine names from your licence records, delete the marketing email we have sent to your address along with our copy of the licence, receipt, password-reset, confirmation and download-link email we have sent you, delete the checkouts you started, your installer download history, your sign-in records and your unsubscribe links, and add your address to our do-not-mail list so nothing further is sent to it.

Some things deliberately survive. Your serials keep working — deleting your account does not switch off software you paid for. The sales records described in section 4 are kept for the period stated there; they still carry the email address and the billing country, state and postcode you gave at checkout, because that is the record we are required to keep. They also keep any campaign tags and ad click identifier attached to an order, which the law does not require; ask us and we will remove them. If you signed up for the free pack, that sign-up record stays too, but the do-not-mail entry means nothing more is sent to it; ask us and we will delete it. Patches you chose to share publicly stay published, because other people have them in their racks — they are not removed by deleting your account, so email us at [email protected] before you delete if you want yours taken down. A record that a computer has taken a free trial stays, stripped of any link to your account: it identifies the machine and the product, never you, and it is what stops the same machine taking the same trial over and over. And the do-not-mail entry stays, as a one-way hash of your address and nothing else, because it is what prevents us mailing you again.

Take your copy first (section 5.1). Deleting the account removes the account we would look your records up from: afterwards there is no route back to your serials or your receipts, not for you and not for us on your behalf.

6. Data Security

We use industry-standard security measures to protect your information, including encryption of data in transit. No method of transmission over the internet is 100% secure, however, and we cannot guarantee absolute security.

Like any website, our servers and our hosting provider, Google Cloud, keep short-lived technical logs of the requests they receive, which include the IP address and the identification string your browser sends. We use them only to keep the service running and to investigate abuse, and they are deleted after 30 days.

7. Children's Privacy

The Software is not directed to children under 13 (or 16 in the EU). We do not knowingly collect information from children.

8. International Users

By using the Software, you consent to the transfer of your information to the United States or other countries where our servers may be located.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Software or via email. Continued use of the Software after changes constitutes acceptance.

10. Contact

For questions about this Privacy Policy:

Weaver Audio Pty Ltd (ACN 678 376 086) Melbourne, Victoria, Australia Email: [email protected]

© 2026 weaver audio pty ltd · acn 678 376 086 · [email protected]