Privacy policy
Your work stays yours.
Who is responsible
Micheal David Sawyer doing business as Apathy Records, based in Denver, Colorado, USA, operates this site. Use the contact form for privacy questions, access, correction, deletion, consent withdrawal or accessibility assistance. The service is intended for adults acting for artists or businesses. Do not submit information about children.
What we collect
We store application drafts and submitted answers, including names, email, artist and project details, audience links, budget, rights and contributor information, AI disclosures and consent choices. Client accounts store a password hash, not a readable password. Projects contain uploaded files, tasks, approvals, rights declarations and payment-status records. We also retain proposal terms and acceptance records, service communications, support requests and administrative audit records. Request headers and limited security signals are used to control abuse; hosting services may keep access logs. Do not upload unnecessary sensitive personal data.
Purpose and sharing
We use this information to evaluate fit, prepare and administer agreements, operate projects, provide support, track payments and approvals, prevent misuse, respond to requests and meet legal obligations. Access in this build is limited to the account holder’s projects and the owner/admin. Hosting and necessary operational providers may process data for those purposes. Stripe receives checkout information if test checkout is configured; card entry occurs on Stripe, not in our forms. No card number or CVC is stored by this application. Outbound email is stored in an internal outbox; Resend is used only when separately enabled. We may disclose information when legally required or to protect legal rights, limiting disclosure where practicable. We do not sell personal data, use targeted advertising or share it with advertising networks.
Music, AI and confidentiality
Apathy does not use private application answers, audio, artwork, lyrics or voice materials to train models. This application has no generative-AI processing integration. Submitting an application or buying services does not authorize transfer of private work to an AI tool. A separate, informed written authorization identifying the material, provider, purpose and relevant data terms is required before such a transfer. Public use of your work, identity or results requires separate permission. You control material you independently submit to other services under their own terms.
Storage and safeguards
The current implementation stores operational records in a server-side SQLite database and uploads in a private server directory outside public assets. File downloads require an authenticated ownership check. Passwords are hashed with scrypt, session tokens are hashed in the database, and session cookies use Secure on HTTPS deployments. Local development may use HTTP; public deployment must use HTTPS. We do not claim that the current build has database-at-rest encryption, automated malware scanning, verified backup deletion or signed expiring local download URLs. No system is perfectly secure. We investigate incidents and provide notices required by applicable law.
Retention and deletion
Retention is currently administered manually; there is no automatic purge job in this build. Records remain in active storage until an authorized deletion is performed. We review necessity when an application is closed, a project ends or a deletion request arrives. We retain information only as reasonably needed for the purposes above, including contracts, tax records, disputes and legal holds, and minimize retained information when a record no longer needs to identify you. A deletion request may therefore result in deletion, anonymization or restricted retention with an explanation. We cannot promise that every copy, including provider records subject to separate obligations, disappears immediately. Keep your own copies of deliverables.
Requests and your choices
You can submit an access, correction, deletion, consent-withdrawal or appeal request at /contact without buying a service. Authenticated clients can also download their account and project records at /api/account/export; private uploaded files are available individually through their project. We verify identity proportionately before disclosing or changing personal data, and do not request your password to do so. If law grants additional access, portability, correction, deletion, opt-out or appeal rights, we honor those rights and their applicable response periods. We explain a denial and how to appeal through the same form. We do not penalize you for exercising applicable privacy rights. Business-to-business information is not necessarily subject to the same statutory rights as consumer information.
Changes and contact
The policy was updated September 13, 2026. We post revisions with an updated date and provide additional notice or obtain consent where required for a material new use. Changes do not retroactively authorize unrelated uses of your private materials. Use /contact for a recorded request or a question about this policy.