Legal
Privacy Policy
What personal data Setlyst processes, why, who it is shared with, how long it is kept and how you exercise your rights under the LGPD.
In force since September 23, 2026Version 2026-09-23
On this page
1.Controller
1.1The controller of the personal data processed in Setlyst is [RAZÃO SOCIAL], registered under CNPJ [CNPJ], with its registered office at [ENDEREÇO].
1.2This Policy explains how we process personal data under the Brazilian General Data Protection Law (Law 13,709/2018, “LGPD”) and the Brazilian Civil Rights Framework for the Internet (Law 12,965/2014). Questions can be sent to our Data Protection Officer at support@setlyst.app.
2.Data we collect
2.1We only process the data needed to provide the service:
- Registration data: username, e-mail address, first and last name (optional), password (stored only as a hash), language, account creation date, accepted terms version and acceptance date, referral code and, if any, the account that referred you.
- Profile data: bio, location, instruments and the address (URL) of the profile picture you provide. We do not store the image file, only its address.
- Sign in with Google: Google account identifier, e-mail address and name, received from Google when you choose that sign-in method.
- Content: songs, lyrics, chords, notes, setlists, gigs, tours, bands, suggestions, votes, reminders and links you add.
- Usage and security data: IP address, date and time of access, sign-in attempts, security events (password change, two-step verification turned on) and audit records of administrative actions.
- Preferences: theme, language, Live Mode and interface settings, communication preferences and pinned items.
- Communications: e-mails sent to you (verification, security, notices), notifications and messages you send to support.
- Subscription data: plan, subscription status, credits, redeemed promo codes and referrals. Once billing is active, also payment data processed by the payment processor; Setlyst does not store full card numbers.
2.2Data saved for offline use stays in your own browser's storage and is erased when you sign out.
3.Purposes and legal bases
3.1We process personal data for the purposes below, with the corresponding legal bases of article 7 of the LGPD:
- Creating and maintaining the account, authenticating you, providing the contracted service, syncing bands and generating exports: performance of a contract (art. 7, V).
- Keeping access records for 6 months: compliance with a legal obligation (art. 7, II, and art. 15 of the Civil Rights Framework for the Internet).
- Preventing fraud and abuse, limiting sign-in attempts, moderating usernames and profile pictures, keeping the platform secure and improving the service with aggregated statistics: legitimate interest (art. 7, IX), always respecting your rights and expectations.
- Sending product news and offers by e-mail: consent (art. 7, I), which you can withdraw at any time.
- Sending security communications and essential account notices: performance of a contract and legitimate interest.
- Meeting tax obligations related to payments, once billing is active: legal obligation (art. 7, II).
- Defending rights in judicial, administrative or arbitration proceedings: regular exercise of rights (art. 7, VI).
3.2Automatic checks of usernames and images only flag cases for review. Any moderation measure is decided by a member of Staff, and you may ask for a review of decisions based on automated processing (art. 20 of the LGPD).
5.International transfer
5.1Some processors, such as Vercel and Google, keep servers outside Brazil, mainly in the United States. These transfers are based on article 33 of the LGPD, through contractual clauses that ensure a level of protection compatible with Brazilian law, as regulated by the National Data Protection Authority (ANPD).
6.How long we keep data
6.1Retention periods are:
- Registration, profile, preference and content data: while the account exists. After the account is deleted, they are erased, except as described below.
- Access records (IP, date and time): 6 months, under article 15 of the Civil Rights Framework for the Internet.
- Audit records of administrative and security actions: for as long as needed to investigate incidents and defend rights, up to 5 years.
- Items in the trash: 30 days; after that they are permanently deleted.
- E-mails in the delivery queue: the content of sensitive e-mails (such as codes) is erased after sending, and delivery records are removed after 30 days.
- Verification codes: expire in 15 minutes and are erased daily.
- Database backups: up to 30 days, on rotation; deleted data disappears from backups at the end of that period.
- Payment tax data: for the period required by tax law, usually 5 years.
7.Your rights
7.1Under article 18 of the LGPD, you may request:
- confirmation that processing takes place;
- access to the data;
- correction of incomplete, inaccurate or outdated data;
- anonymisation, blocking or deletion of unnecessary or excessive data, or data processed in breach of the LGPD;
- portability of the data to another provider;
- deletion of data processed on the basis of consent;
- information about the entities we share data with;
- information about the possibility of not giving consent and its consequences;
- withdrawal of consent;
- review of decisions based solely on automated processing.
7.2You may also lodge a complaint with the National Data Protection Authority (ANPD).
8.How to exercise your rights
8.1Many rights can be exercised directly in the platform:
- Access and correction: in My account and in Settings.
- Portability: export all your content in Settings, in the backup section.
- Consent to e-mails: adjust your preferences in Settings, in the Communications section, or use the unsubscribe link in the e-mails.
- Deletion: delete your account in Settings.
8.2For other requests, write to support@setlyst.app from the e-mail address registered on your account. We may ask for additional information to confirm your identity. We reply within 15 days.
9.Data Protection Officer
9.1The Data Protection Officer (Encarregado) is the communication channel between you, Setlyst and the ANPD. Contact: support@setlyst.app.
10.Data security
10.1We adopt technical and administrative measures to protect personal data, as required by article 46 of the LGPD, including:
- encryption in transit (HTTPS/TLS) on every connection;
- passwords stored only as Argon2 hashes;
- optional two-step verification (TOTP), with secrets encrypted at rest (AES-256-GCM) and recovery codes stored as hashes;
- e-mail verification codes stored as HMAC with a limited number of attempts;
- sign-in attempt limits and temporary account lockout;
- role-based access control, least privilege and an audit log of Staff actions;
- profile pictures loaded through our server, with validation, so your IP address is not exposed to third-party sites.
10.2No system is completely immune to failure. That is why we recommend a strong password and two-step verification.
11.Security incidents
11.1If a security incident occurs that may cause relevant risk or harm, we will notify the ANPD and the affected data subjects within the time and in the manner set by regulation, under article 48 of the LGPD, stating the nature of the affected data, the risks involved and the measures taken.
12.Children and teenagers
12.1Setlyst is intended for people aged 18 or over. Teenagers aged 16 and 17 may use the platform only with the consent of a parent or legal guardian, in the teenager's best interest (article 14 of the LGPD).
12.2The platform is not intended for anyone under 16. If we identify an account belonging to someone under 16, or without the required consent, the account may be closed and the data deleted.
14.Updates to this Policy
14.1This Policy may be updated to reflect changes in the service or the law. The effective date is shown at the top of the document, and relevant changes will be communicated by e-mail or a notice in the platform. General questions: support@setlyst.app.
If the versions of this document in other languages differ, the Portuguese (Brazil) version prevails.