Setcraft
Features Themes Download Free
← Back to Setcraft

Privacy Policy

Last updated: July 27, 2026

Setcraft is a setlist app for musicians. This policy explains what data the app touches, where it goes, and who else is involved. We have tried to keep it short and honest.

The short version: Setcraft runs on your Mac, and your songs, lyrics, charts, shows, setlists, and notes stay on your Mac. You do not need an account to use it. Almost nothing leaves your device. The exceptions are spelled out below.

1. Who we are

Setcraft is made by Setcraft LLC, a Pennsylvania limited liability company, registered at 5588 East Texas Rd, East Texas, PA 18046.

For privacy questions, contact us at [email protected].

Setcraft is a native macOS app (Apple Silicon and Intel, macOS 12 and later). It is signed, notarized, and sold directly from getsetcraft.com, not through the Mac App Store. We also run a small hosted backend (for photo import, licensing, and free-trial metering) and a marketing website.

2. Setcraft is local-first

Your song library, lyrics, chord charts, shows, setlists, and notes are stored in a database on your own Mac, in ~/Library/Application Support/Setcraft/.

No account is required to use the app. We do not receive or store copies of that content. Two features send your content off the device, and both run only when you use them: photo import and the in-app bug reporter. Beyond those there are a few operational connections for licensing, the free-trial status check, optional Bandsintown sync, and software updates. Each is covered below.

3. What the app processes, and why

3a. Setlist photo import

This is one of the two features that send your content off your Mac, and it only runs when you choose to use it.

When you import a photo of a paper or handwritten setlist, the image is sent to Setcraft's server (hosted on Render), which forwards it to an Anthropic vision model to read the text in the image. Only the extracted text comes back to the app, where it is matched against your local library.

  • What is sent: the photo itself, along with either your license key or, during the free trial when no license key exists yet, your random install identifier (described in 3f). Our server uses it to confirm you are entitled to the feature and to count your monthly imports. Your song library, lyrics, and charts are not part of the request and never leave your Mac.
  • Sub-processors: Render (hosting) and Anthropic (reading the image).
  • How we handle the photo: the photo is held only for the time it takes to process your request. It is not stored, not added to any database, and not logged. During processing it may be briefly written to a temporary file and is deleted automatically when the request completes. The only lasting record we keep is a monthly upload count tied to a one-way hash of your license key. That record contains no image, no email, and no readable license key.
  • Abuse limits: our server applies a request-size cap, per-address rate limits, and a shared daily ceiling on trial imports. These record standard request metadata only, never the image.
  • What Anthropic does with it: Anthropic does not use data sent to its commercial API to train its models. By default, Anthropic automatically deletes API inputs and outputs within 30 days, with limited exceptions (for example, content flagged for policy violations, or where a legal hold applies).
  • Requirements: photo import is included in the paid tiers (20 imports per month) and in the free 30-day trial (5 imports per month). It needs an internet connection.
  • Legal basis (GDPR): performance of the contract, meaning the feature you asked us to run.

3b. Licensing and purchase

Purchases run through Lemon Squeezy, which acts as the merchant of record. They collect your email and payment details and issue your license key. We never see or store your card details.

Your license key is stored locally on your Mac, in the macOS Keychain. When the app activates, deactivates, or periodically re-validates your license, it communicates directly with Lemon Squeezy and transmits the license key plus a device identifier, since activation is limited by device seat. Our own server is not involved in that exchange and does not receive your device identifier.

Your license key does reach our server in two cases: when you use photo import (your key is sent to authorize and meter the request, as described above), and when you use "deactivate all other computers" to reclaim seats. In both cases our server only ever stores a one-way hash of the key, never the key itself.

  • Data involved: your email (collected at purchase by Lemon Squeezy), your license key, a device identifier (held by Lemon Squeezy), and activation count.
  • Legal basis (GDPR): performance of the contract.

3c. Bandsintown sync (optional)

If you supply your own Bandsintown API key, the app uses it to pull your upcoming shows from the Bandsintown API. This is something you start, using your own Bandsintown account.

  • Data involved: your Bandsintown API key and the show data it returns.
  • Legal basis (GDPR): consent and/or performance of the contract.

3d. Software updates

Automatic update checks are opt-in. If you turn them on, the app checks getsetcraft.com/appcast.xml (hosted on Cloudflare Pages) using Sparkle, and downloads updates from GitHub Releases. A lightweight fallback check may call the GitHub API.

These requests carry standard network metadata to the update and CDN hosts: your IP address, the app version, your OS version, and a user-agent string. This is true of any network request, not something extra we collect.

Sparkle's optional anonymous system profiling is turned off, so no anonymized profile of your system is sent with update checks.

3e. Analytics and tracking

Setcraft has no advertising trackers, no third-party analytics SDKs, no telemetry, and no crash reporting in the app. We do not build a profile of you or your usage. If this ever changes, we will update this section before adding any such tool.

3f. Free trial and the install identifier

So the free 30-day trial can run without an account, the app generates a random install identifier the first time it runs. This is a random token stored locally on your Mac. It is not derived from your hardware, and it is not linked to your name, email, or any other personal information.

The app sends this identifier to Setcraft's server (hosted on Render) in three situations. First, a throttled background check, at most a few times a day while the app is running, records and returns your trial start date. Anchoring the start date on the server is what keeps the trial honest: reinstalling the app or rolling the system clock back does not restart it. The app keeps making this check while it is unlicensed, during and after the trial. Once you activate a paid license and your start date is on record, it stops. Second, during the trial, photo import sends the identifier in place of a license key to authorize and count your imports, as described in 3a. Third, if you submit a bug report, the identifier rides along so we can rate-limit reports, as described in 3g.

  • What our server stores: the install identifier, the date it was first seen, a monthly trial photo-import count, and a per-day bug-report count. No image, no email, and no personal data. The install identifier is operational metadata, not your content; your songs, lyrics, charts, and setlists stay on your Mac.
  • How long we keep it: the trial record is what stops a wiped and reinstalled app from starting a fresh trial, so we keep it for as long as we offer the trial. The usage counters are small tallies of dates and counts. We do not purge them on a schedule; only the current month or day is ever consulted.
  • Legal basis (GDPR): performance of the contract, meaning running the trial you asked for, and our legitimate interest in preventing abuse of the free trial.

3g. In-app bug reports

The app has a bug reporter you can open from any page. Nothing is sent unless you submit a report.

A report contains what you type, an optional reply-to email address if you want an answer, and an optional attachment such as a screenshot. Check a screenshot before you attach it; it shows whatever was on screen. The report also carries context that helps us reproduce the problem: the page you were on, the app version and theme, your macOS version and chip, your license tier, and your install identifier (described in 3f), which we use to rate-limit reports.

The report travels through Setcraft's server (hosted on Render) and arrives as an email in our support mailbox, hosted by Zoho Mail. Our server does not keep a copy of the report or the attachment. The only lasting record it holds is a per-day count of reports per install, to prevent abuse.

  • Sub-processors: Render (relay) and Zoho (mailbox).
  • Retention: the report lives in our support mailbox like any other support email. We keep it while it is useful for fixing the problem it describes; there is no automatic deletion.
  • Legal basis (GDPR): consent, meaning the report you chose to send.

4. Third parties and sub-processors

ProviderRoleWhat they receive
AnthropicReads the setlist photo for photo importthe setlist photo
RenderHosts the photo-import proxy, the licensing and trial backend, and the bug-report relaythe photo and bug reports (in transit only), your license key (hashed for metering), the install identifier and trial start date, usage counters, request metadata
ZohoHosts our support mailbox; bug reports arrive there as emailyour message, optional reply-to email, optional attachment, page and app context, the install identifier
Lemon SqueezyMerchant of record, issues license keysemail, payment data, license and device info
BandsintownOptional show sync, using your own keyyour API key, show queries
CloudflareHosts the website and update feedupdate-check metadata (IP, version)
GitHubHosts release downloadsdownload request metadata

Our support address, [email protected], is a mailbox hosted by Zoho Mail. We answer it ourselves and do not use a third-party helpdesk service.

Each of these providers may rely on its own sub-processors, such as major US cloud-hosting and payment-infrastructure providers, under its own data-processing terms.

5. International transfers

Your data may be processed in the United States and wherever the providers listed above operate. We rely on those providers' own data-transfer safeguards (such as Standard Contractual Clauses or Data Privacy Framework participation) for any transfer of personal data out of your region.

6. Your rights

If you are in the EU or UK, you have the right to access, correct, erase, restrict, and port your data, to object to processing, and to withdraw consent. You also have the right to complain to your local data protection authority.

If you are in California, you have the right to know what we collect, to delete and correct it, and to opt out of any "sale" or "sharing" of personal information. Setcraft does not sell or rent personal information. We will not discriminate against you for exercising these rights.

To exercise any of these, email [email protected]. Keep in mind that most of your content lives locally on your Mac and is under your direct control. You can delete the local database, and the in-app Backup, Restore, and snapshot tools all operate locally.

7. Retention

  • Local content: kept on your Mac and controlled by you. We do not hold it.
  • Photo-import images: not stored. The photo exists on our server only for the duration of the request and is then gone. Anthropic deletes API data within 30 days by default.
  • Monthly upload count: we keep a per-license monthly upload counter, tied to a one-way hash of your license key, to enforce fair use of photo import. It contains no image, email, or readable key.
  • Trial records: we keep your random install identifier, the date it was first seen, a monthly trial photo-import count, and a per-day bug-report count, so the trial can run without an account and within fair-use limits. These contain no image, email, or personal data. The trial record is kept for as long as we offer the trial, since it is what prevents trial resets. The counters are not purged on a schedule.
  • Bug reports: kept as email in our support mailbox, not in a database, until we delete them. There is no automatic deletion.
  • Purchase and license records (via Lemon Squeezy and our backend): kept for as long as tax and accounting law requires, which can be up to about seven years.

8. Children

Setcraft is not directed to children under 13, and we do not knowingly collect their data.

9. Security

Your local data sits inside your macOS user account, and your license key is stored in the macOS Keychain on your device. Data sent to our server and to the providers above travels over HTTPS. Our server keeps very little data. It identifies paid usage by a one-way hash of your license key, never the key itself, and trial usage by the random install identifier. Hosting and infrastructure security are provided by Render, which maintains recognized security certifications. No method of transmission or storage is completely secure, but we use appropriate measures to protect the limited data we handle.

10. Changes and contact

If we change this policy, we will post the new version on our site and update the "Last updated" date above.

Questions: [email protected].

Setcraft

The setlist app for working musicians. Built for the stage.

Product
Features Download Version History Help
Legal
Privacy Policy Terms Open-Source Licenses
Talk to us
[email protected]
© 2026 Setcraft LLC. Setcraft is a trademark of Setcraft LLC. getsetcraft.com