PARTITA STUDIO PARTITA STUDIO
Privacy

Privacy Policy

This Policy describes the data PARTITA STUDIO actually collects — on partita.pro, in the account dashboard and in the Windows and macOS applications. The headline first: your music, your projects, your AI prompts and your model keys never reach our servers. We run your account and your licence, nothing more.

Last updated August 23, 2026
Operator The owner and operator of the PARTITA STUDIO service available at partita.pro and through the PARTITA STUDIO app.
Language note This English version is provided for convenience. If a conflict arises, the Russian version governs.

1. Scope

This Policy applies to the PARTITA STUDIO website, the account dashboard, checkout flows, the documentation, the update server, and the Windows and macOS desktop applications.

By creating an account you accept this Policy and the Terms of Use. We record that acceptance separately — which version of the documents was in force, the date and time, the IP address and the user-agent — so that either side can confirm what was agreed.

Where processing is based on consent, you may withdraw it for the future. That does not make earlier processing unlawful and does not affect data we must keep by law or to defend our rights.

2. What data we process

This is the complete list — not "including but not limited to", but everything that lands on our servers.

  • Account: email address, the name we address you by, interface language, registration and last-login dates, email verification state. The password is stored only as an argon2id hash — it cannot be reversed, and we do not know it.
  • Sign-in and security: login sessions (the database holds a hash of the token, not the token), the IP address and user-agent at sign-in, a failed-attempt counter and a temporary lock after a series of failures.
  • Free-trial protection: an installation id (a random number created on first launch) and a device fingerprint. The application computes the fingerprint on your machine as an irreversible SHA-256 hash of an available operating-system identifier, the computer name, the user name and the platform, and sends only the finished hash. Those underlying values are never sent to us and never stored. The single purpose is one free trial per device.
  • Licence: licence type, start and end dates, the perpetual flag, the number of instalment months paid, pause state and the balance of saved days.
  • Payments: the request reference, amount, status, the provider's payment id, the payment method type and the masked label of a saved card such as "MasterCard •••• 4416", charge dates, and the error text if a charge fails.
  • Licence log: what changed in your access, when, and who did it — you, an automatic charge, or an administrator. It exists so a billing dispute can be resolved.
  • Acceptance of documents: document type and version, date and time, IP address, user-agent.
  • Support requests: whatever you choose to write to us by email.
  • Website analytics: anonymous page-visit data — see section 6.
What we do not have. Your projects and MIDI files. Your AI prompts or your conversations with the agent. Generated notes. Your API keys. Your password in readable form. Your card number, expiry date or CVC — you enter those on YooKassa's page and they never reach us. The name of your computer or your Windows account in readable form.

3. Where the data comes from

  • from you — when you register, sign in, pay, or contact support;
  • automatically — the IP address and user-agent arrive with every network request, as they do for any website; the application additionally sends the installation id and the device fingerprint;
  • from YooKassa — payment statuses and the label of a saved payment method;
  • from our mail server — confirmation that the message carrying a verification or sign-in code was delivered.

The application checks for updates every few hours by requesting a file that describes the latest version. As with any request to a website, the server logs record the IP address, the time and the file requested. There is no other telemetry in the application: it sends neither usage statistics nor crash reports.

4. Why we collect it

Every item in section 2 has exactly one practical reason:

  • So you can sign in: the email and password hash to authenticate you; sessions so you do not retype the password on every launch; email verification so the address is really yours and a typo cannot lock you out.
  • To protect the account: IP, user-agent, the failed-attempt counter and the lock make brute-forcing a password impractical.
  • To keep the free trial honest: the device fingerprint stops the free month from being reopened on the same computer.
  • To run the licence: to know whether access is open, how many instalment months are paid, how many days are banked during a pause.
  • To take payment: to process a charge, continue an instalment plan, show you the history, and work out what happened when a charge fails.
  • To answer support requests and restore access.
  • To understand the website: how many people open the pages and where they get stuck.
  • To confirm what was agreed: the record of document acceptance at registration.

Legal grounds: performance of our contract with you, our legitimate interest in protecting the service from abuse, statutory accounting and tax duties, and your consent where consent is required.

5. AI bypasses us

The application runs on your computer and connects to the model you chose, using your own key. Prompts, project fragments and notes go directly to that provider — OpenAI (including via OpenAI Codex), Anthropic, Google, OpenRouter, Polza.ai. Our servers take no part in that exchange, never see its contents and never store them. What happens to the data afterwards is governed by that provider's policy.

If you use local models through Ollama or LM Studio, model requests never leave your computer.

Agent web search is a separate feature that you can switch off. When enabled, the application sends Parallel.ai only the search query or the public-page URL the agent requested. Parallel.ai also receives the IP address and ordinary connection metadata. The full prompt, chat history, project, MIDI data and model keys are not sent there. Our servers take no part in that exchange.

Model keys stay with you, in the application's settings file on your disk. We do not receive them and cannot.

The application used to include a built-in AI that ran through our servers. It is switched off, and we no longer receive any model requests. Do not send third-party personal data or someone else's trade secrets to any AI service you connect — that applies to every provider, not just ours.

6. Who receives data

Five possible recipients, and exactly what goes to each:

  • YooKassa — the amount, our request reference and our internal identifiers, so a payment can be taken and an instalment charged. We do not send them your email or your name. You enter card details on their page, and those details never pass through us.
  • The hosting provider of our mail server — verification and sign-in codes are sent from auth@partita.pro through our own mail server (mailcow) on a rented machine in Russia. We hand the recipient address to no third-party mail service; from there the message is accepted by your own mail provider.
  • Yandex Metrica — anonymous data about visits to the public pages of the site, see below.
  • Parallel.ai — the search query or public-page URL, IP address and technical HTTPS request data, only when agent web search is enabled.
  • Our hosting provider — the site and the server physically run on its hardware.

We must also disclose data on a lawful order from a court or competent authority. We do not sell personal data and do not pass it to advertising networks.

Website analytics

The public pages and the documentation carry a Yandex Metrica counter. Besides counting visits it records on-page activity (Webvisor), which shows where the website itself is awkward to use. Session recording is switched off in the account dashboard and the admin panel — those pages hold personal and payment data and there is no reason to record them. The Policy and Terms pages carry no counter at all.

Your dashboard sign-in token is kept in your browser's local storage rather than in a cookie, and is not shared with anyone.

7. How long we keep it

  • Account data — for as long as the account exists.
  • When you delete your account a 30-day recovery window begins: signing in during that time brings everything back. After it expires the record is deleted from the database, and with it go the sessions, the licence, the payment history, the device records, the acceptances and the event log — they are tied to the account and do not outlive it.
  • Payment records may be kept longer, separately from the account, to the extent accounting and tax law requires.
  • Web-server logs, which contain the IP addresses of requests, are kept for a limited time and used only for diagnostics and incident investigation.

8. How we protect it

No vague assurances — specifically what is in place:

  • passwords are stored as argon2id hashes;
  • session tokens and email-confirmation links are stored as hashes — they cannot be taken from the database and reused;
  • rate limits on registration, sign-in and re-sending the verification email;
  • a temporary lock after a run of failed sign-in attempts;
  • the whole site and API run over HTTPS;
  • your account tokens on your computer are encrypted with the operating system's protected storage.

What we do not claim: there is no two-factor authentication. PCI DSS certification is not required of us because card data never passes through our servers. The internet offers no absolute guarantees, so a strong password and the security of your computer remain on your side.

9. Your rights

Depending on applicable law, you may have the right to:

  • request information about your personal data;
  • ask us to correct inaccurate or incomplete data;
  • request deletion where we no longer have lawful grounds to keep the data;
  • withdraw consent where processing is based on consent;
  • object to certain processing activities if permitted by law;
  • complain to a competent regulator or court.

To exercise these rights, contact support@partita.pro. We may need additional information to verify your identity and protect your account.

10. Transfers abroad

Verification and sign-in codes are delivered by our own mail server, hosted in Russia — nothing leaves the country for that. The analytics counter belongs to a foreign company, so the anonymous data about visits to public pages connected with it is processed outside the Russian Federation.

When you connect a foreign AI provider with your own key, you enter into that relationship yourself, and the data is processed in that provider's jurisdiction under its rules. We take no part in that transfer.

When web search is enabled, search queries and requested public-page URLs are processed by Parallel.ai under its rules. The transfer goes directly from the application; our servers do not see it.

11. Children

The service is not intended for children who are not old enough to enter into binding agreements under applicable law. If you believe that a minor's data was submitted without proper authorization, contact support@partita.pro.

12. Changes to this Policy

We update this Policy when the product, the billing setup or the law changes. The rule is simple: first the software changes, then this text — and it always describes how things actually work, not how they are planned to work. The current version is published here with a new date. We announce material changes through the site, the dashboard or email.

13. Contacts

For anything about this Policy or the processing of personal data, write to support@partita.pro. We answer from the same address.

  • auth@partita.pro — a service address: email-verification and sign-in codes are sent from it. We do not read mail sent to it; a reply goes to support instead.
  • support@partita.pro — support, account access, licences, and requests under this Policy.
  • sales@partita.pro — commercial enquiries, team and educational licences, partnerships.