1surfaceBack

Privacy Policy

Last updated 11 September 2026

1surface is currently pre-release and is not yet publicly available. This policy covers our website and describes the current pre-release implementation of the desktop app and cloud features. It will be updated to reflect the verified production configuration before users are given access.

Who is responsible

1SURFACE LTD, registered in Scotland with company number SC898747, has its registered office at Unit 33, Morris Park, 37 Rosyth Road, Glasgow, United Kingdom, G5 0YD. We are the controller of personal information described here. Contact contact@1surface.com with privacy questions or requests.

Account and access information

We process your email address, account identifier, chosen handle, profile details, password authentication records, access-review status and security events to create, review and secure your account. We also store whether cloud AI access is enabled and your plan or subscription tier. Without the necessary account information, we cannot provide account-based features.

If you choose Google sign-in, Google supplies an account identifier and basic profile information, such as your email address, name and profile picture. This does not give us access to Gmail, Drive or other Google content. We send verification codes, security messages and access decisions by email. Access requests are reviewed by a person; contact us if you want a decision reconsidered.

What stays on your device

1surface discovers and indexes Ableton Live projects on your device. Its local library includes project locations, names, dates, track and musical metadata, tags and scan preferences. Conversation history, app preferences and session credentials are also stored locally. Local indexing does not upload your complete project files or audio recordings to our servers.

Local storage does not mean all project information stays local: when you use cloud AI, the relevant information described below leaves your device. Your own backup or file-sync services may also copy files independently of 1surface.

What cloud AI receives

When you send a message, we send it, relevant conversation history and Ableton Live context to our servers and AI providers. Depending on the request, this can include project and file paths, track and clip names, MIDI notes, device and mixer settings, library search results, proposed actions and their results. Responses and instructions return to the app, which can make changes in Live. Conversation titles and summaries can also use cloud AI.

Our server holds active requests and short-lived conversation context in memory to complete work and support continuation or reconnection. This is separate from your locally saved chat history and from provider logs or caches. Avoid including passwords or other information that is unnecessary for your music task.

AI training and provider retention

We route AI requests through Vercel AI Gateway. Our standard route requests providers that do not use prompts for model training. Longer conversations can use an OpenAI continuation route, whose API data is not used for training by default; we request that responses on that route are not stored as retrievable response objects.

These controls do not mean that all processing has zero retention. Providers can retain information for abuse prevention, legal requirements and prompt caching under the arrangements applicable to the route. 1surface is not yet publicly available. Before access is opened to users, we intend to enable and verify Zero Data Retention across the AI routes used by the product. This policy will be updated to reflect the verified production configuration before users are given access. See Vercel’s training controls and OpenAI’s data controls.

Analytics, error reports and AI diagnostics

Where enabled, product analytics record feature-use events, app and operating-system details, performance information and an account or anonymous identifier. Our app configuration disables automatic click capture, automatic page-view capture and session recording. Error reports can include stack traces, breadcrumbs, technical context and an account identifier. We apply filtering for common sensitive information, but cannot guarantee that every piece of personal information is removed.

AI interaction traces are currently disabled in our pre-release service. The implementation supports operational metadata such as model, timing, usage, action types and outcomes, associated with an account and run identifier. The production configuration will be verified before users are given access. Older diagnostic records or material deliberately supplied for support and evaluation may contain conversation or project content.

Contact contact@1surface.com to object to analytics or error-report processing or ask about available controls. Local opt-out preferences apply to the device and telemetry they control; they do not stop the processing needed to answer a cloud request or erase information already held by providers.

Website, support and payments

The website does not use advertising cookies or behavioural analytics. Our hosting providers still process connection information, including IP addresses and request details, to deliver and secure the site. The app uses local storage for sessions, preferences and feature data.

If you contact us, we process your email address, correspondence and any files or diagnostic information you choose to provide. The current app records plan and access information but does not collect payment-card details or provide an in-app checkout. If paid services are introduced, we will explain payment processing before you purchase. We do not sell personal information or use it for third-party advertising.

Why we process information

We use account information, messages and the context needed for your requests to provide the service and take steps at your request before entering a contract. We rely on legitimate interests for proportionate access review, service security, abuse prevention, support and reliability analysis, balanced against your rights. We use information to meet legal obligations where required. Where consent is required, we will seek it; you may withdraw consent without affecting earlier lawful processing.

Service providers and international transfers

Our pre-release setup uses Supabase for authentication and account databases; Resend for service email; Railway for the cloud service; Vercel for website hosting and AI routing; PostHog for product analytics; and Sentry for error reporting. Langfuse is our AI diagnostics provider, with tracing currently disabled. Google processes Google sign-in information under its own policy. Support correspondence is handled through our email service, Proton.

The pre-release AI routes use OpenAI models and a DeepSeek model fallback, with OpenAI, Amazon Bedrock, DeepInfra and Baseten on the approved processing-provider list. A model’s creator is not necessarily the company hosting a particular request. Only the providers involved in a route receive its content.

Providers and their subprocessors may process data outside the UK. The location, retention and transfer arrangements depend on the service and route. Contact us for information about the countries, applicable safeguards and how to obtain a copy. We may also disclose information when required by law or necessary to protect legal rights and service security.

Retention and account deletion

We keep account information for the life of the account and as needed for access review, security, support and legal obligations. Local chat history and library data remain until removed or cleared on that device. Server request state is temporary; provider logs, diagnostics, caches and backups have separate retention rules. We assess retention by the information’s purpose, operational need and legal requirements, rather than treating every category as having the same deadline.

You can request account deletion in the app or contact us. The app schedules permanent account deletion after a 30-day recovery period, restricts account access and clears account-scoped local chat data and credentials on devices that process the request. Contact contact@1surface.com before the scheduled date to request recovery. Recovery does not restore local data already cleared.

An offline device may retain its local account data until it reconnects and processes the deletion status. Device-local library indexes, preferences and your original Ableton projects and audio are not deleted by account deletion. Remove these separately on devices or backups you control if you no longer want them.

After the recovery period, the account and profile are queued for permanent removal. Failed processing is retried, so the scheduled date is not a guarantee that every copy has been erased at that instant. Provider-held telemetry requires separate tracked erasure work; signing out or clearing a device does not delete it. Some legacy records may not be attributable to an account. Security records, deletion evidence and backups can remain for their applicable purpose and retention period. We will explain relevant limitations when responding to an erasure request.

Your rights

Depending on the circumstances, you may ask for access, correction, deletion, restriction, objection or a portable copy of personal information. You can object to processing based on legitimate interests. Send requests to contact@1surface.com. We may need to verify your identity. You may also complain to the UK Information Commissioner’s Office or your local data protection authority.

Changes

We will update this page when our practices change and show the revision date above. We will communicate material changes where appropriate and seek consent where required. This is the canonical privacy policy linked from the desktop app.

Terms of Use