CybermoonLeylines
FeaturesDownloadDocsForumAboutBlogRoadmap
Log in

Privacy Policy

Last updated: August 2026

Leylines is currently in an open beta. This policy applies now, and we may update it as the product develops and will post changes here.

1. Who we are

Cybermoon LLC, a Colorado limited liability company with its registered office at 1500 N Grant St Ste R, Denver, CO 80203, is the data controller for Leylines. Email is how you reach us: privacy@cybermoonaudio.com. This policy describes what data the Leylines plugin, the Leylines web services, and this website collect, why, and what happens to it.

2. Data we collect

2.1 Email address and sign-in credentials

We collect your email address when you join the waitlist, apply for the beta, buy or are issued a license, or sign in to your account. Your license is tied to this address. You can sign in two ways: with a magic link sent to your email, or with a password you set on your account.

If you set a password, we never store the password itself. We store a salted, heavily iterated one-way hash of it (PBKDF2-HMAC-SHA256), which cannot be turned back into your password. Sign-in links, password-reset links, and email-confirmation links are stored the same way, as a hash of the link's secret rather than the secret itself. They are single-use and expire quickly. We record the IP address that requested a sign-in or password-reset link so we can investigate abuse of those flows.

2.2 Machine fingerprint hash (activation)

When you activate Leylines on a machine, the plugin computes a one-way hash derived from machine characteristics and sends it to our activation service. We store the hash (not the underlying hardware details) to enforce per-license activation limits and let you deactivate machines from your account dashboard.

2.3 Peer-to-peer connectivity (WebRTC)

Leylines sessions connect peer-to-peer by default. As with any peer-to-peer technology, peers in the same session can see each other's IP addresses. This visibility is mutual and inherent to direct connections. Only join sessions with people you trust. When a direct connection is not possible, traffic may pass through a relay we operate; relay servers forward encrypted traffic and are not a listening point for your audio content. We log limited connection metadata (timestamps, coarse data volume, and your license identifier) to operate relays, enforce usage limits, and prevent abuse. We do not log or listen to the content of your audio.

2.4 Optional cloud chunk storage (Cloud tier)

If you use the optional Cloud tier, audio chunks from your sessions are stored with our storage provider so offline collaborators can catch up. Paid Cloud subscriptions are not offered during the beta.

Your Cloud data is deleted when you ask us to delete it. During the beta that request is handled by our support team: email privacy@cybermoonaudio.com and we remove your uploaded chunks. A self-serve control in your account dashboard is being added during the beta and will do the same thing without the email. We also delete Cloud data on our own schedule: while your Cloud access is valid we do not delete any of your Cloud audio, and if your Cloud access ends we keep it for 90 days from the day it ended and then delete it. Cloud data that no longer belongs to any account is deleted 90 days after it becomes ownerless. If you have bought a license from us, we do not delete your Cloud audio on this schedule at all.

2.5 Payments

Payments are processed by Paddle, our reseller of record. We receive transaction metadata (amount, product, billing country) but never see or store your full card details.

2.6 Website & diagnostics

Today this website runs no third-party analytics or advertising tags, and sets no advertising cookies. Our host collects aggregate, privacy-preserving traffic metrics. We may add analytics or advertising measurement in future, including a social-platform measurement tag. If we do, we will name the provider in the subprocessor list in section 4 and update this section before it goes live, and where the law requires consent for it we will ask you first. Server logs are retained for a short period for security and debugging.

The Leylines plugin includes optional crash reporting that is off by default and only sends data if you turn it on in the plugin's settings. When enabled, a crash report contains the same one-way machine-fingerprint hash described in section 2.2, a stack trace of where the plugin crashed, and the product name, plugin version, and operating system. It does not include your audio, session content, or the underlying hardware details behind the hash. We keep crash reports for as long as we need them to diagnose and fix the crash and to see whether it comes back.

The plugin also includes an optional bandwidth statistics report that is likewise off by default and only sends data if you turn it on. When enabled, it reports every few minutes: a scrambled session identifier (a one-way salted hash of the session code, never the code itself), whether the connection went direct or through a relay, the number of bytes sent and received, how many people were connected, and the start and end time of the reporting period. That is the complete list. It contains no audio, no session content, no file or track names, no IP address, and no machine fingerprint, and it is not linked to your account or licence. We use it only to measure how much session traffic needs a relay, so we can size and price that capacity. These reports are deleted after 90 days.

2.7 Beta application answers

If you apply for the beta, we store the answers you give on that form: which DAW you use and, if you choose “something else”, the name you type; what you produce on (Windows, Linux or macOS); what you tell us you produce and are working on, which is a free-text box of up to 1000 characters; how many people you make music with; whether any of them would install it too; how you heard about Leylines; and whether you agreed to be asked for feedback. We also record that you ticked the early-beta acknowledgement, so that your agreement to it is evidenced rather than assumed.

Applying and confirming your email gets you into the beta directly. If you apply more than once from the same email address, the later answers replace the earlier ones rather than creating a second record.

We use these answers to understand who is testing Leylines and to prioritise what we build, and for nothing else. They are not sold, not shared, and not used for advertising or ad measurement. They are kept while the beta programme runs; there is no automatic deletion schedule for them yet, so if you want yours removed sooner, email privacy@cybermoonaudio.com and we will delete them.

2.8 Applications you have not confirmed yet

When you submit the beta form we do not store your application straight away. We hold your email address and your answers in a temporary record and send you a link asking you to confirm the address is yours. This is so that nobody can put someone else’s email address into a public form and have us store their details, or send them mail they never asked for.

If you click the link, that temporary record becomes a real application, and section 2.7 describes what happens to it from then on. If you do not click it, the temporary record is deleted automatically within 24 hours and nothing about you is kept. You do not need to ask us, and there is nothing you need to do.

While it exists, that record is used for one thing only: sending you the confirmation link and, if you click it, creating your application. It is not read for any other purpose, not shared, and not used for advertising.

3. How we use data

  • Deliver and activate your license.
  • Operate session connectivity, relays, and optional cloud sync.
  • Send transactional email (receipts and magic sign-in links).
  • Prevent fraud and enforce license limits.
  • Internal operations reporting: we compile the data described in section 2 into a daily summary for our own operations team (for example, which accounts were recently active and aggregate usage counts). This stays inside Cybermoon and its email subprocessor and is never shared further.
  • Understand who is testing Leylines and prioritise what we build, from the application answers described in section 2.7.
  • Send you beta announcements and, if you opt in, occasional product updates. Every non-transactional email has a one-click unsubscribe. We do not sell your personal data.

4. Subprocessors

We share data with the following service providers:

  • Cloudflare: hosting, edge network, and cloud storage.
  • Paddle: payment processing and tax as reseller of record.
  • Resend: transactional email delivery.

Each subprocessor is bound by a data-processing agreement and processes data only to provide its service to us.

5. Data retention

Account and license records are kept while your account exists. Stopping your use of Leylines does not delete your account and does not delete anything attached to it: your account record, purchase history, license records, activated machines and their names, and any forum posts all stay, so that coming back works and so that we keep the transaction records we are required to keep. We do not delete your data because you have been away.

A machine’s name starts as the computer name the plugin reads from that machine, which often contains a person’s own name. We never delete it on a schedule, and you can change or remove it yourself at any time from the license page in your account dashboard. Once you do, the plugin no longer overwrites it. Removing a name does not free that machine’s seat and does not change your license.

There is exactly one thing we delete on a schedule, and it is your Cloud-stored audio. If you have bought a license from us, we never delete it on a schedule. Otherwise: while your Cloud access is valid nothing is deleted, and once your Cloud access ends we keep your Cloud audio for 90 days from that day and then delete it. Cloud audio that no longer belongs to any account is deleted 90 days after it becomes ownerless. If we cannot tell whether your Cloud access is still valid, we keep the audio.

You can delete your account and its data at any time from your account dashboard. If you ask us to erase your data under section 6, we do not wait for those 90-day windows: we delete everything we hold about you straight away, and your account record itself is deleted last, after the data attached to it is gone. Cloud-stored audio chunks follow section 2.4. Server logs are retained for a short period.

6. Your rights

Wherever you live, you may request access to, correction of, export of, or deletion of your personal data by emailing privacy@cybermoonaudio.com. We will respond within the timeframes required by applicable law.

7. Security & breach notification

We use industry-standard measures to protect data in transit and at rest. If a breach affects your personal data, we will notify affected users and regulators as required by law. Report suspected security issues to security@cybermoonaudio.com. We will notify affected users and regulators within the timeframes required by applicable law.

8. Children

Leylines is not intended for anyone under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us data, contact privacy@cybermoonaudio.com and we will delete it.

9. Changes to this policy

We will post changes here and update the "Last updated" date. Material changes will be announced by email where required.

10. Contact

Privacy questions: privacy@cybermoonaudio.com.

Cybermoon

Make music together across DAWs and time zones. Share one code. Hear everyone's latest work.

© 2026 Cybermoon LLC. All rights reserved.

Product

  • How it works
  • Features
  • Download
  • Docs
  • Log in
  • Join the waitlist

Company

  • About
  • Roadmap
  • Changelog
  • Blog
  • Community

Legal

  • Privacy
  • Terms
  • EULA
  • Refunds

Built on open-source foundations:

JUCElibopuslibdatachannelMbed TLSFull attribution →

VST® is a registered trademark of Steinberg Media Technologies GmbH, registered in Europe and other countries. AU (Audio Unit) is a trademark of Apple Inc. CLAP is an open plugin standard. All other product names, DAWs, and trademarks are the property of their respective owners and are used for identification only.