Sessio

Privacy Policy

Effective date: 28 July 2026 · Last updated: 3 August 2026

Sessio ApS ("Sessio," "we," "us," "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the Sessio mobile application, our website (sessio.io), and related services (collectively, the "Platform"). It also explains how we handle information about people who do not use Sessio, where their names appear in the external records we process for a royalty or profile hunt (see section 3.5).

This policy describes our practices. Where we rely on your consent, we ask for it separately and you can withdraw it at any time.

For the processing described in this policy we are the data controller. Where an organisation you have authorised starts a hunt for you, section 3.5 explains what that organisation can see and who is responsible for that use of your information. Contact: [email protected].

1. Who we are

2. What this policy covers

This Privacy Policy covers:

  • The Sessio mobile app (iOS and Android)
  • sessio.io, our marketing website
  • Email and form-based contact with us
  • Royalty and profile hunts, including hunts an organisation you have authorised runs for you (section 3.5)
  • The public find-my-money scan on sessio.io, including scans run without an account
  • The map of professional music-industry places in the Sessio app (section 3.6)
  • Any future services we add and link to this Privacy Policy

3. Information we collect

3.1 Information you give us

Account and profile.

  • Email address, password (stored only as a salted hash — never in plaintext).
  • Display name, country, optional city.
  • Profession(s), instruments, genres, experience level (from a fixed option list).
  • Short biographical text ("BIO"), optional.
  • Optional career fields: "Member of," "Represented by," and "Credits / Worked with" (free-text).
  • Optional audio embed link to Spotify or SoundCloud (a single URL pointing to a public track — Sessio does not connect to your Spotify or SoundCloud account; we only display the link).
  • Profile photo (required at onboarding).

Sessions.

  • Title, optional description, optional genre tag.
  • Date and time, location type (in-person or remote) and free-text location detail.
  • Visibility settings: discoverability toggle on your profile, Public-session toggle, "Looking For" professions, and "Who Can View" scope (Everyone / Connections / Favourites).
  • Optional reference playlist URL (free-text URL).
  • Optional cover image (host-uploaded).
  • The list of participants you invite or who accept invitations.
  • Group chat thread tied to the session.

External email invites.

When you invite a non-Sessio user to a session via email, we store the recipient email, your user ID as the inviter, and the session ID. We send a transactional email containing a magic link scoped to that session. The recipient email is used only to deliver invitations and to attribute conversions if the recipient later signs up. The lawful basis for this processing is legitimate interest (GDPR Art. 6(1)(f)), with anti-harassment safeguards (a per-recipient rate limit of 15 invitations per rolling 7-day window) and a delete-on-request route via [email protected].

Messages and communications.

  • Direct 1:1 messages between connections.
  • Session group-chat messages.
  • Support emails or in-app reports.

We store messages so that you and your collaborators can refer back to them.

3.2 Information collected automatically

  • IP address, browser type, device type, operating system, app version.
  • Pages visited, screens viewed, features used, time spent, session start/end.
  • Crash reports and performance diagnostics.
  • Marketing attribution: UTM parameters from links you click; install attribution for the app.
  • Cookies and similar technologies on sessio.io (see Section 10).

We use this data to operate the Platform, debug issues, and understand product usage in aggregate.

3.3 Information from third parties

  • App Store and Google Play may share install attribution and crash reports with us according to their own privacy practices.
  • If you embed a Spotify or SoundCloud track on your profile, the embed loads content directly from those services when other users view your profile. In this embed context Sessio does not connect to your Spotify or SoundCloud account and receives no account data; we only display the public URL you chose to share. Separately, a profile hunt may read your public artist or channel pages on services like these — see section 3.5.
  • Public and licensed music-industry sources, when a royalty or profile hunt runs for you — see section 3.5.

3.4 Connected calendars (Google Calendar)

Connecting a Google Calendar is optional. If you — or an organisation you administer on Sessio, such as a publisher or label workspace — choose to connect a Google account, Google asks you to grant access on Google's own consent screen. You can decline, and you can revoke access at any time (see below). We only request this access when you actively start the connection.

Why we offer it. Connected calendars let a workspace see when a roster artist is busy or available, map each Google sub-calendar to the right person, and keep Sessio sessions in sync with the calendar you use every day.

When connected, we access the following through the Google Calendar API:

  • Authorisation tokens — a short-lived access token and a long-lived refresh token that let Sessio call the Google Calendar API on your behalf. The refresh token is encrypted at rest (AES-256-GCM) and is never shown to other users.
  • Calendar list — the names and identifiers of the calendars in the connected account, so you can choose which calendar belongs to which person.
  • Event data, read (calendar.readonly scope) — for the calendars you map, the events' times and busy/free status, used to display availability inside the Sessio calendar.
  • Event write-back (calendar.events scope) — when you create or change a Sessio session for a person whose calendar is connected, we add or update the matching event in that Google Calendar. We only create and update the session events that Sessio itself manages; we do not read, change, or delete your unrelated personal events.

Lawful basis. We rely on your consent — given on Google's consent screen and within Sessio — and, for organisation features, on performance of our contract with that organisation (GDPR Art. 6(1)(a) and (b)). You can withdraw consent at any time by disconnecting.

Google API Limited Use. Sessio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google Calendar data only to provide and improve the calendar features described above; we do not use it for advertising; we do not sell it; we do not transfer it to others except as necessary to provide these features, for security purposes, or to comply with applicable law; and we do not allow humans to read it, except with your consent for support you have asked us for, for security, to comply with law, or where the data has been aggregated and anonymised.

Revoking access and deletion. You can disconnect at any time from your Google Account's "Third-party apps with account access" page (myaccount.google.com/permissions) and, where available, from the connection settings in the Sessio workspace. On disconnection or account deletion we revoke and delete the stored Google tokens and the calendar-mapping data, and we stop accessing the account. Session events already written to your Google Calendar stay in your own calendar until you remove them there.

3.5 Information we collect from public and licensed industry sources (royalty and profile hunts)

When you use Sessio's Find My Money or profile hunt, or when an organisation that represents you runs these tools on your behalf under a grant you have approved, we collect and process information about your professional activity from external sources. Those sources are: public music-industry registers and databases (for example works, recordings and repertoire registers operated by collecting societies); licensed commercial data feeds we have a written agreement with; public pages on artist and label websites; public artist or channel pages on streaming, video and social-media services; and public music-credit, release and catalogue databases. Examples can include Spotify, YouTube, Instagram and Discogs. The relevant result shows the source name and link where the source permits us to do so.

What a hunt can return. Find My Money can return work and recording titles, identifiers (such as ISRC, ISWC, IPI, IPN or ISNI), credits and roles, releases, and the royalty pools they relate to. For a profile hunt, this is limited to your professional or stage name, public professional biography, credited roles, public profile image and links to public professional pages. We do not use private posts, contact lists or messages, collect precise location from those pages, use facial recognition, or infer sensitive traits from text or images.

How we access a source. We use a source only after documenting the access and reuse route that applies to it, for example its published terms, a written licence or written permission. A source being public does not by itself mean we may reuse it, and we do not bypass access controls or contractual restrictions.

Where the royalty estimate's numbers come from. When you use Find My Money, we obtain play counts for your own recordings (identified by their ISRC codes) from Soundcharts S.A.S., a licensed music-data provider in France. We use those counts for one thing only: computing the indicative royalty estimate we show you. We never display or pass on the raw counts, and the estimate is a modelled range, not a statement of money owed. The collecting societies always decide final amounts. The counts follow the finding they support: they live with your scan results, and deleting your findings or your account deletes them.

Automated matching. We use automated matching and ranking to generate possible results. These results are leads, not decisions about identity, ownership or payment. We do not make a decision with legal or similarly significant effects based only on automation: a person reviews the evidence, and you decide whether anything is submitted outside Sessio.

Lawful basis. When you start a hunt yourself, we process this information to perform our contract with you (GDPR Art. 6(1)(b)). When an organisation holding your approved representation grant starts a hunt for you, we rely on legitimate interests (Art. 6(1)(f)). Section 4 sets out both entries in full.

What an organisation and its operators can do. A trained operator may verify a suggestion and, if the approved grant allows it, add it to your hunt findings. An organisation you have given the highest level of representation can also apply professional details a profile hunt finds to your Sessio profile, within the limits described above. That write only touches profile details such as your biography, professions, instruments and links; it never changes your works, your splits or your rights identifiers. You can change or remove anything added this way, and you can lower or withdraw an organisation's access at any time. Every hunt or profile action an organisation runs for you is listed in your app under Privacy & Data, in "Organisation activity". A claim is submitted outside Sessio either by you, or by Sessio's own team under the authorisation you gave us and can revoke at any time (see section 5): an organisation can never file a claim as you.

Hunts an organisation runs for you. Before an organisation receives its first result about you, we tell you that it has asked us to run a hunt and we name the organisation. It then receives only the hunt results and supporting information its grant permits, and it is separately responsible for how it uses them. Sessio is responsible for the information collected and matched when a hunt runs, whether you started it or an authorised organisation started it for you. You can object to organisation-run hunts at any time in the Sessio app under Settings → Privacy & Data: that stops future organisation-run hunts about you and stops organisations receiving further results from them, and it leaves hunts you start yourself untouched. To see, correct, delete or object to any of this, contact us at [email protected]; you do not need to go through the organisation.

The public scan on sessio.io. You can run a royalty scan on sessio.io by entering a name, without an account. That scan searches information we already hold, and its results are not stored: we do not save the name you type or the results it returns. To see full results you create a Sessio account, and everything described above then applies.

People named in external records. External records may name co-writers or performers who do not use Sessio. We process their details only to understand and verify the specific work or recording; we do not create account-like records for them, rank them, contact them, or use their details for unrelated recommendations. If a name remains in a saved finding, we do not copy it out into anything else — who can see that finding is set out in full in the public notice below. Because individual notice would involve disproportionate effort, we rely on Article 14(5)(b) and provide this public notice as a safeguard.

Revoking access and deletion. You can delete any hunt finding or claim draft at any time in the Sessio app, and you can lower or withdraw an organisation's representation grant whenever you want, which stops that organisation's future hunts. Section 8 sets out how long we keep hunt data.

3.6 Places on the Sessio map

The Sessio app includes a map of professional music-industry places — studios, venues, music schools and industry organisations. For each place we show business information the place publishes itself — its name, the kind of place it is, city, website and an access label — with its location cited from OpenStreetMap (© OpenStreetMap contributors). Our sources are the places' own websites, official member directories and business registers.

The map never shows personal addresses or your location: this directory requests no location permission, and where a place appears to be run from a private home we do not show a street address at all. We show this directory to signed-in Sessio members on our legitimate interest (GDPR Art. 6(1)(f)) in helping working musicians find professional places. Because the information comes from what each place has published itself, this section serves as the public notice for the people behind those places (Art. 14(5)(b)).

If you run a listed place and want its entry corrected or removed, contact [email protected].

3.7 People on the Sessio map

If your profile is discoverable, you show up on the Sessio map as one face in your city's group, and in a city you have a public trip to while that trip is running. The map only ever shows the city: no street, no neighbourhood, no distance, and never where your phone is. Turn Discoverable off in Settings and you are off the map, the same way you leave Connect.

One thing on the map does use your location: tap the paper plane and Sessio asks your phone where you are, so the map can centre there and show the standard blue dot. That happens on your device and nowhere else. We never receive it, we never store it, and it never changes what you or anybody else is shown.

3.8 The Discogs artist index

Sessio keeps a searchable copy of the artist lists that Discogs publishes as open data once a month. Those lists describe about ten million people credited on records worldwide, almost none of whom use Sessio. For each person we copy only what Discogs already publishes: the Discogs artist number that appears in the address of their own Discogs page, the name shown there, any aliases and spelling variants recorded on it, their real name where Discogs publishes one, and the first 500 characters of their profile text. The lists carry no email addresses, no postal addresses and no phone numbers, and we do not go looking for any. This is separate from the public Discogs pages a hunt may read (section 3.5): these are the bulk lists Discogs publishes for anyone to download.

Why we keep it. Someone looking for money they are owed, or trying to credit the right person on a session, often has nothing to go on but a half-remembered or misspelled name. Searching our own copy answers that in an instant, which asking Discogs one name at a time cannot. We use it for that search and nothing else: we do not score or rank you, we do not build a profile of you, we add nothing Discogs has not already published, and we do not connect a Discogs entry to anybody's Sessio account. Results go only to the signed-in person who typed the name, never to an organisation.

Because Discogs refreshes these lists monthly, our copy can be up to a month behind, and every result we show says which monthly edition it came from. If something about you is wrong on Discogs, correcting it there carries through to us at the next refresh. We keep this copy on our legitimate interest (GDPR Art. 6(1)(f)) in helping musicians identify the right people and find money owed to them. Because the information comes from what Discogs publishes openly rather than from the people it describes, and because those lists carry no way of writing to the people in them, this section is the public notice for them (Art. 14(5)(b)).

How to be removed. Email [email protected] and ask to be taken out of the Discogs index. Send the name or a link to your Discogs page; you do not need a Sessio account and you do not need to give a reason. We delete the entry and record the removal, so the next monthly refresh does not bring it back. One limit, stated plainly: this removes you from Sessio's copy only. Your page on Discogs belongs to Discogs, and only they can change or remove it.

4. Legal basis for processing (GDPR Art. 6)

We rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — to create and operate your account, enable discovery, connections, sessions, messaging, and send transactional emails.
  • Performance of a contract (Art. 6(1)(b)), royalty and profile hunts — when you start a royalty or profile hunt, we process the external information objectively necessary to run that hunt and prepare the findings or drafts you requested.
  • Consent (Art. 6(1)(a)) — to notify you about product updates if you opted in, send marketing newsletters, set non-essential cookies via the cookie banner, and enable the optional signals described under Collaboration-signal ranking in section 5 (opt-in). You can withdraw consent at any time.
  • Legitimate interest (Art. 6(1)(f)) — for analytics and product improvement, fraud prevention and security, external email invites to non-members (subject to the safeguards described in Section 3.1), and collaboration-signal ranking in Find My Money (see Section 5).
  • Legitimate interest (Art. 6(1)(f)), organisation-run hunts — when an organisation holding your approved representation grant starts a hunt for you, we process the external information necessary for Sessio's, your and the authorised organisation's legitimate interest in identifying royalties and professional credits that may belong to you. We notify you, limit the organisation's access to its grant, and allow you to object at any time.
  • Legitimate interest (Art. 6(1)(f)), discoverability and session suggestions — when your profile is discoverable, we show it to other creators and to organisations using Sessio, and we may suggest it to an organisation planning a session (see Discoverability in section 5). We rely on Sessio's, your and the organisation's legitimate interest in collaborators finding each other for real work. You can turn discoverability off at any time, and you can object at the address in section 16.
  • Legal obligation (Art. 6(1)(c)) — to retain financial and tax records under Danish law and to respond to legal process.

You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Your confirmation controls whether we add a suggested field or send a claim; it is not the legal basis for the earlier search and matching.

5. How we use your data

  • Create and operate your account.
  • Match you with collaborators via Explore (no automated decision-making with legal effects on you — Explore is a discovery surface, not an automated ranking with consequences).
  • Schedule sessions; deliver invitations and reminders; auto-create group chats.
  • Show availability and add your Sessio sessions to a connected Google Calendar, where you or your organisation have connected one (see Section 3.4).
  • Send transactional notifications by push, email, or in-app.
  • Detect, prevent, and respond to abuse, fraud, and unauthorised access.
  • Improve the Platform through aggregated analytics.
  • Comply with legal obligations.

We do not sell your personal data. We do not engage in cross-site behavioural advertising. We do not make automated decisions that produce legal or similarly significant effects on you.

Discoverability. Being discoverable means other creators and organisations using Sessio can find your profile, and organisations planning a session can see you suggested as a collaborator. Organisations on Sessio are publishers and labels, and they can browse and search discoverable profiles from their own Sessio workspace when they are looking for someone to work with. If your profile is discoverable, you also appear on the Sessio map at the level of your city, as described in section 3.7. When an organisation is planning a session and looking for a collaborator outside its own roster, we may also suggest discoverable profiles that fit, ordered so the most experienced people appear first. Either way, what they see is your profile as it already appears on Sessio: your name, photo, professions and the other details you have put there. They never see your contact details or your rights identifiers, and they cannot reach you outside Sessio — an invitation comes to you on Sessio and you decide whether to accept it. We do this on our legitimate interest in helping people find collaborators for real work; you can object at any time at the address in section 16. You can turn discoverability off at any time in the Sessio app or on the web under Settings, and you stop appearing for all of it.

Royalty and profile hunts. We use the information described in section 3.5 to find works, recordings, credits and royalty pools that may relate to you, to propose profile enrichments you approve field by field, and to prepare your royalty claims. With your explicit authorisation — the claim mandate, which you can revoke at any time — Sessio's own team then files those claims with the collecting societies on your behalf, manually and one society at a time. Nothing is submitted automatically, and nothing is submitted without that authorisation. Every claim and its status is visible to you in the Sessio app. Estimates shown in a hunt are indicative; collecting societies decide final amounts.

Collaboration-signal ranking (Find My Money)

We use two kinds of signals to help identify works where you may be missing a credit or royalty payment. First, we use your documented collaboration history—such as works, recordings, sessions, roles and credits, including the external-source information described in section 3.5—to rank possible matches and show relevant hunts. We rely on our legitimate interest in helping you identify and recover royalties, after balancing that interest against your rights and freedoms. You may object to this use at any time in the Sessio app under Settings → Privacy & Data, or by contacting us at the address in section 16; if you object, we will stop using your data for ranking entirely - both as a suggested candidate and as a signal for ranking others. (Signed agreements are still retained for their own contractual and legal-claim purposes.)

Second, if you actively opt in, we also use optional signals—including your follows, connections and selected profile details—to infer possible collaboration or rights links and improve the ranking of "Is this you?" suggestions. This optional use is based on your consent, is off by default and is not required to use Find My Money. You can withdraw your consent as easily as you gave it in the Sessio app under Settings → Privacy & Data, without affecting processing that lawfully took place before withdrawal.

Aggregated product-usage statistics

To decide what to improve next, we count how Sessio's features are used in aggregate: how many times a day a feature was used within an organisation's workspace - never who used it. These statistics are stored as daily counts per organisation and per feature; they contain no names, no message or search content, and no user-level identifier at all, so individual usage profiles cannot be built from them. Where an organisation's workspace is a single person, we treat its counts as personal data: they are deleted if the organisation is deleted, and daily counts are kept for at most 24 months before being reduced to monthly totals. We rely on our legitimate interest (Art. 6(1)(f)) in improving Sessio; these statistics are internal to Sessio, never sold, and never shared.

Email you send us

We use AI tools to sort the email that arrives in our own inboxes and to prepare draft replies - a person always reads and sends. These tools keep only neutral labels and short summaries (never sensitive content, which stays in the mailbox itself), deleted within 180 days, and nothing is ever used to train any model. We rely on our legitimate interest (Art. 6(1)(f)) in handling our correspondence - the same processing an assistant would do.

Fixing our own mistakes

We use AI tools to spot when our documentation or product copy is wrong or out of date - including by transiently reading conversations with our built-in assistant and email you send us. What we store is only a note of which page needs fixing, phrased neutrally - never your words, and never anything that identifies you. These notes are deleted once the fix is decided, or after 90 days at the latest.

6. Who we share data with

We work with the following subprocessors. Each is bound by a Data Processing Agreement that obliges them to act only on our instructions and apply appropriate security measures.

  • Marketing site + web hosting (sessio.io) — Vercel Inc. (US company; EU regions used; Standard Contractual Clauses).
  • Backend application hosting — Fly.io Inc. (US company; EU regions used; Standard Contractual Clauses).
  • Relational database (accounts, sessions, messages) — Neon Inc. (US company; EU region used; Standard Contractual Clauses).
  • File storage (profile photos, session cover images, any uploaded files) — Cloudflare, Inc. (US company; EU regions used; Standard Contractual Clauses).
  • Push notifications + mobile app build pipeline — Expo (650 Industries, Inc.) (US; Standard Contractual Clauses).
  • Transactional email (account verification, password reset, magic-link invites, session reminders, in-app notifications) — Postmark, a service of ActiveCampaign LLC (US; Standard Contractual Clauses).
  • Waitlist signup + marketing newsletter delivery — EmailOctopus Ltd (UK / EEA; UK adequacy decision).
  • Web analytics (cookieless) — Vercel Web Analytics (Vercel Inc.) (EU; Standard Contractual Clauses).
  • AI features (Ask Sessio, publisher workspace, royalty and profile hunts) — Anthropic, PBC (US company; provider of the Claude models behind these features; Standard Contractual Clauses). Receives the prompt and the context needed to generate a response. For a royalty or profile hunt that includes the professional name and identifiers being searched, and Anthropic's own web-search and page-fetch tools carry out the external lookups the hunt needs. Inputs and outputs sent through the API are not used to train Anthropic's models.
  • Google Calendar integration (optional workspace availability and session sync) — Google Ireland Limited / Google LLC (EU / US company; Standard Contractual Clauses). Google acts as the provider of your own connected calendar account rather than solely on Sessio's instructions — see the note on connected calendars below.
  • Billing and subscription payments (publisher subscriptions) — Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (US company; Standard Contractual Clauses). Handles checkout, card processing, and recurring billing; Sessio does not store full card numbers.
  • Cookie consent banner (sessio.io) — implemented in-house; no third-party vendor.

Note on push notifications. When we send a push notification, the message is routed through Expo's push service, which then delivers it to Apple Push Notification service (APNs) for iOS devices or Firebase Cloud Messaging (FCM, a Google service) for Android devices. Apple and Google act as upstream subprocessors of Expo for this purpose; their own privacy practices apply to the delivery leg.

Note on connected calendars. Where you connect a Google account (Section 3.4), Sessio exchanges data with the Google Calendar API — provided by Google Ireland Limited / Google LLC — to read availability from and write your Sessio session events to the calendars you map. Google processes that data as the provider of your own calendar account, under Google's own terms and privacy policy, and is not a subprocessor acting solely on Sessio's instructions.

A current list of subprocessors is available on request at [email protected]. We update this list whenever processor relationships change and will notify users by email of material changes.

Other disclosures

  • Legal obligation: we may disclose data if compelled by a court order, subpoena, or legal authority.
  • Business transfer: if Sessio is acquired or merges with another company, your data may transfer to the new entity. We will notify you before any change of controller affects you.
  • With your consent: if you ask us to share your data with a third party for a specific purpose.
  • Organisations you have authorised: an organisation holding your approved representation grant receives only the hunt results and supporting information permitted by that grant. It is a separate controller for its own use of those results.
  • External sources we search: when a hunt runs, the name and professional identifiers being searched are sent to the register or data provider being searched.
  • Collecting societies and registers: we disclose only the claim information you choose to submit outside Sessio.

7. International data transfers

Where possible, we use European data-centre regions to keep your data within the EEA at rest. Our backend hosting (Fly.io), database (Neon), and file storage (Cloudflare) all hold Sessio's data in EU regions, and our marketing site (Vercel) is configured for EU regions.

Where a subprocessor is established outside the EEA — for example, US-based companies operating EU regions, or US-based services that we cannot avoid for technical reasons (Expo for push notifications and app builds; Postmark for transactional email) — we rely on the European Commission's Standard Contractual Clauses (SCCs) as the lawful transfer mechanism. For EmailOctopus (UK), we rely on the UK adequacy decision.

International hunt searches. When you ask us to run a hunt, the search may send terms such as your professional name or identifiers to a register or collecting society outside the EEA. If that specific transfer is not covered by an adequacy decision or another transfer safeguard, we make it only where necessary to perform the service you requested, take steps at your request, or conclude or perform a contract in your interests (Article 49(1)(b) or (c)). Sessio's own storage of your data sits with the providers, in the regions and under the transfer mechanisms listed in Section 6.

A complete and current list of subprocessors, the regions they use, and the applicable transfer mechanism is set out in Section 6 above and available on request at [email protected].

8. How long we keep your data

When you close your account we keep it for a 30-day grace period so you can change your mind, and then we hard-delete your active data. Encrypted backups are held with our infrastructure providers as recovery points and age out within six months; if we ever restore from a backup, we re-apply every deletion made since that backup was taken.

  • Account credentials (email, password hash) — until account closure, then deleted at the end of the 30-day grace period.
  • Profile information (photo, bio, professions, etc.) — until account closure, then deleted at the end of the 30-day grace period.
  • Uploaded images (profile photos, session cover images) — until you delete them; otherwise deleted with your account at the end of the 30-day grace period.
  • Sessions, messages, chat threads — until you delete your account, then deleted at the end of the 30-day grace period (subject to other collaborators' active participation).
  • Hunt findings and claim drafts — for as long as your account is open, because claim windows can run for years and the finding is your own evidence record. You can delete any finding or draft at any time.
  • Rejected suggestions — removed from your active results immediately. We keep only the source, the identifier and the fact that you rejected it, for as long as your account is open, so the same suggestion does not come back.
  • Anonymous find-my-money scans on sessio.io (no account) — not stored: we do not save the name typed or the results returned.
  • Accepted agreements and authorisations (splits, mandates, claim authorisations) — for the life of the agreement plus the applicable limitation period.
  • External-invite emails — 30 days from invite if the recipient has not signed up; longer if the recipient signs up and joins the session.
  • Connected Google Calendar tokens and calendar-mapping data — until you disconnect the calendar or delete your account, then revoked and deleted promptly.
  • Server logs (IP, request data) — 30 days.
  • Analytics in identifiable form — maximum 14 months.
  • Analytics aggregated or anonymised — indefinitely.
  • Support emails and tickets — 3 years (statute of limitations).
  • Cookie consent records — 12 months.
  • Marketing email subscribers — until you unsubscribe.
  • Tax and financial records — 7 years (Danish tax law).

After the retention period, data is deleted or irreversibly anonymised.

9. Your rights under GDPR

You have the following rights regarding your personal data:

  • Access — receive a copy of the data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — request deletion, subject to retention obligations described in Section 8.
  • Restriction — ask us to limit how we use your data while a dispute or correction is pending.
  • Portability — receive your data in a structured, commonly used, machine-readable format.
  • Object — object to processing based on legitimate interest, including direct marketing (see below).
  • Withdraw consent — where we rely on consent, you can withdraw it at any time.
  • Lodge a complaint about our use of your personal data with Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark (www.datatilsynet.dk), or with another EU supervisory authority.

Your right to object. You can object at any time to processing we base on legitimate interest, including direct marketing. Three of these have their own controls. Collaboration-signal ranking (section 5): if you object in the Sessio app under Settings → Privacy & Data, we stop using your data for ranking entirely. Hunts an organisation runs for you (section 3.5): if you object in the same place, we stop future organisation-run hunts about you and stop organisations receiving further results from them, and hunts you start yourself are unaffected. Discoverability and session suggestions (section 5): turn "Discoverable" off in the app or under Settings on the web and you stop appearing in Discover and in suggestions immediately; you can also object at the address in section 16 without turning discoverability off.

To exercise these rights, email [email protected] with "GDPR Request" in the subject line. We respond within 30 days. If your request is complex, we may extend by up to two further months and will explain why. For collaboration-signal ranking and for hunts an organisation runs for you, you can also use Settings → Privacy & Data in the app. Sessio answers these requests for everything held in Sessio, including hunts an organisation started for you; you do not need to go through the organisation.

Limits on erasure

We cannot fully delete information where:

  • It is required by law (e.g. tax records for 7 years).
  • It is needed to establish, exercise, or defend legal claims.
  • Other users actively rely on it — for example, your participation history in a session you co-hosted. In such cases your name may be replaced by an anonymous identifier ("Former Collaborator") on shared records while the activity history remains.
  • It is a record that you rejected a suggestion, kept only so the same suggestion does not return. You can ask us to delete it, but the suggestion may then reappear.
  • It is a name inside a saved hunt finding, where removing it would destroy another person's record of the work or recording.

Supervisory authority

You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet):

  • Datatilsynet — Carl Jacobsens Vej 35, 2500 Valby, Denmark
  • Email: [email protected]
  • Phone: +45 33 19 32 00
  • Website: www.datatilsynet.dk

10. Cookies and similar technologies

On sessio.io, we use cookies in three categories: strictly necessary, analytics (optional), and marketing attribution (optional). The cookie banner controls non-essential categories. Preferences can be changed at any time via "Cookie settings" in the footer.

We do not use cookies for cross-site advertising, behavioural retargeting, or the sale of data to third parties.

The cookie banner on sessio.io is implemented in-house — there is no third-party consent management vendor.

Our chosen web analytics provider (Vercel Web Analytics) is cookieless: it does not set any cookies, does not use local storage, and does not assign persistent identifiers to visitors. It uses a daily-rotating salted hash of IP + user agent for de-duplication only, which cannot be linked back to an individual visitor across days. We therefore do not place analytics cookies on your device.

The mobile app does not use browser cookies. It uses platform-standard SDK identifiers (e.g. Apple's IDFA, Google's Advertising ID) only if you grant permission via the iOS/Android consent prompt, and only for the purposes disclosed in this Privacy Policy.

11. Children's privacy — 18+ only

Sessio accounts are for people 18 or older, and we do not knowingly accept sign-ups from anyone under 18. External music-industry records we process for a hunt can name people of any age; we use those names only as described in section 3.5. If you believe we hold a child's data, contact [email protected] and we will remove it.

12. Security

We apply reasonable technical and organisational measures to protect your personal data from loss, misuse, unauthorised access, alteration, and disclosure, including:

  • In transit: HTTPS / TLS encryption for all connections to the Platform.
  • At rest: industry-standard encryption applied by our hosting providers to data stored on their infrastructure.
  • Authentication: passwords are stored as salted hashes only — never in plaintext.
  • Access controls: access to production systems and user data is limited to authorised staff who need it to perform their roles.
  • Patching: we apply security updates and patches to our systems as they become available.

No security system is completely perfect. If you believe your account or our security has been compromised, contact [email protected] immediately.

13. Third-party links and embeds

The Platform contains links and embeds from third-party services — including Spotify, SoundCloud, App Store, Google Play, partner organisations, and links to the external sources behind hunt results (section 3.5). Their privacy practices are governed by their own policies:

  • Spotify: https://www.spotify.com/legal/privacy-policy/
  • SoundCloud: https://soundcloud.com/pages/privacy
  • Apple (App Store, APNs): https://www.apple.com/legal/privacy/
  • Google (Play, Firebase): https://policies.google.com/privacy

Embedding a Spotify or SoundCloud track on your profile causes those services to load content directly when other users view your profile. They may set their own cookies or process IP addresses according to their policies.

14. Marketing and communications

We send marketing emails only to people who have opted in, for example via the waitlist signup on sessio.io or an in-app preference. You can unsubscribe at any time using the link in any marketing email or by emailing [email protected].

The find-my-money deep-scan waitlist is separate and single-purpose. If you join it, we use your email address only to send one availability notice and then delete it, unless you explicitly opt in to further waitlist communications. Our marketing newsletter is separate and requires its own consent.

We will continue to send transactional emails — account verification, password reset, session invitations, session reminders, request approvals — regardless of marketing-email status, because they are necessary for the Platform to function. Finer-grained notification controls will be added to in-app settings in a later release.

15. Changes to this Privacy Policy

We may update this Privacy Policy as our practices evolve or as required by law. If we make a material change to this policy, we will notify you in the product or by email before the change takes effect. Routine or non-material changes take effect when the updated policy is posted, with the effective date shown above.

Where the law requires us to tell you individually about a new use of your information, including the royalty and profile hunts described in section 3.5, we notify you individually before that processing starts. That notice is not subject to the qualification above.

16. Contact

For privacy questions or to exercise GDPR rights:

For general support: [email protected].