Kithara

Kithara — Privacy Policy

Version 2026-07-30-draft · draft pending operator and legal review

1. Who is responsible

The controller for personal data processed by Kithara is [OPERATOR: legal name · registered address · KvK number — pending KVK registration]. Reach us via the Support link in the app or at [OPERATOR: contact email].

2. What we process, and why

Your account — email address, password hash, the time and version of your Terms of Service acceptance, and your invite code's channel if you used one. Needed to run your account (contract).

Your workspace content — kits, presets, melody plans and rendered audio, stored on our servers with an encrypted backup copy. Needed to provide the service (contract).

Credits and purchases — your credit ledger and, for purchases, the Stripe checkout reference. Card numbers never reach us; Stripe processes the payment. Needed for the service (contract) and kept for bookkeeping (legal obligation).

Generation requests — the prompt material a generation needs is sent through our gateway to our AI model provider and the result is stored in your workspace (contract).

Support and product signals — messages you send via Support, and minimal product events (for example "a signup happened", keyed to your workspace id) in our own self-hosted analytics. No third-party advertising or tracking (legitimate interest in running and improving the service).

3. Who receives data

Processors we use to run Kithara: Stripe (payments), Postmark (delivery of account emails such as the confirmation link), and Anthropic (the AI model provider that processes generation requests; its terms state API requests are not used to train models). Hosting: [OPERATOR: hosting provider and location]. We do not sell personal data.

4. Cookies

Kithara sets functional cookies only: the sign-in session and the form-security token. When bot protection (Cloudflare Turnstile) is active on the signup page, it sets its own technical cookie. There are no advertising or cross-site tracking cookies.

5. Retention

Account and workspace data live as long as your account does, plus a limited backup cycle after deletion. Purchase records are kept for the legally required bookkeeping period (seven years in the Netherlands). Support threads are kept while they are useful for helping you.

6. Your rights

You can ask for access, correction, deletion, or a copy of your data, and object to processing based on legitimate interest — via Support or the contact address above. You can also complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.

Terms of Service Sign in

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.