Legal
Privacy Policy
Last updated: September 14, 2026
What ChordLine is
ChordLine is a booking and money-tracking tool for working bands: a venue/gig pipeline, payment tracking, and an AI booking assistant. This page explains what data is collected, why, and how you can control it.
Account and sign-in
ChordLine uses Clerk for authentication. When you sign in, ChordLine stores your name, email address, and the bands, gigs, venues, and songs you create — this data is scoped to your account and is not visible to other users unless you invite them to your band.
Google Calendar (optional, read-only)
If you choose to connect a Google Calendar, ChordLine requests read-only access (calendar.readonly) to the one calendar you select. This access is used only to detect gigs from your calendar events and add them to your ChordLine pipeline.
- ChordLine never writes to, edits, or deletes anything in your actual Google Calendar. This is a one-way, read-only connection.
- ChordLine stores an encrypted refresh token to read your calendar on your behalf, and a small amount of metadata about events already processed (title, date, location) to avoid re-importing the same event twice and to explain why an ambiguous event was skipped.
- ChordLine does not read attendee lists, event descriptions beyond what is needed to detect a gig, or any calendar other than the one you explicitly select.
- You can disconnect Google Calendar at any time from ChordLine, which revokes access and stops any further reading. Disconnecting does not delete gigs already created from a prior sync — those remain in your account for you to keep or remove.
AI assistant
ChordLine's AI features send relevant band context (upcoming gigs, venues, money summary, and your message) to a large language model to generate suggestions and draft messages. Because gigs are detected from your Google Calendar, some of that context is derived from Google user data. Google Calendar credentials and raw calendar events are never sent to any AI provider.
Requests go through OpenRouter (OpenRouter, Inc.), which routes each request to one of the following model hosts. This is the complete list:
- Novita AI — hosting
inclusionai/ling-3.0-flash-vl(a zero-data-retention endpoint) - AtlasCloud — hosting
dots-studio/dots-3-note-preview - Cohere — hosting
cohere/north-mini-code
Every request is sent with OpenRouter's data_collection: "deny" routing policy. This restricts routing to endpoints whose published data policy is that prompts are not retained or used for model training; if no such endpoint is available the request fails rather than being sent elsewhere. ChordLine does not train, fine-tune, or otherwise improve any AI model with your data, and prohibits its providers from doing so through this configuration.
Google API Services Limited Use disclosure
ChordLine's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, the use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements: Google user data is used only to provide and improve the user-facing calendar-to-gig feature, is never sold, is never used for advertising, and is never used to create, train, or improve generalized or foundational AI or machine-learning models.
Who we share data with
ChordLine does not sell your data and does not share it with third parties for their own purposes, advertising, or data brokerage. Your data is transferred only to the service providers below, only to the extent needed to run the feature named, and each is bound by its own terms to process it only on our behalf:
- Amazon Web Services (us-east-1) — hosts the ChordLine backend and database, where your account data and encrypted Google Calendar token are stored.
- Vercel — hosts the ChordLine web app and provides aggregate, cookie-free page-view analytics.
- Clerk — sign-in and account management (name, email).
- OpenRouter, Novita AI, AtlasCloud, Cohere — AI assistant requests as described above. This is the only path by which data derived from your Google Calendar leaves ChordLine, and only when you use the assistant.
- LocationIQ — the venue address you type when you use address search. No Google data is sent.
Google user data is never shared with anyone other than the AI providers listed above, and never for any purpose other than the assistant feature you invoke. We may also disclose data if required by law.
How we protect your data
- Encryption in transit: every connection to ChordLine, to Google, and to each provider above uses HTTPS/TLS.
- Encryption at rest: your Google Calendar refresh token is encrypted with AES-256-GCM using a key held only in the backend's configuration before it is written to the database. Short-lived access tokens are held in memory for the duration of a request and never stored. All database storage is additionally encrypted at rest by AWS.
- Server-side OAuth: the Google authorization code is exchanged on the server by a confidential client; no Google token is ever sent to the browser. The OAuth
stateparameter is signed and expires after ten minutes. - Least privilege: ChordLine requests read-only calendar access, reads one calendar you select, and never writes to Google.
- Access control: every request is authenticated, and every query is scoped to your account and the bands you belong to. Calendar data is never visible to other users. Production credentials are held in server configuration, not in code, and access to production systems is limited to the ChordLine operator.
- Minimization: only the event fields needed to detect a gig are read, and only a small record of processed events (title, date, location) is kept.
Other third-party services
ChordLine uses LocationIQ for venue and address search, only when you use that feature.
ChordLine uses Vercel Web Analytics to count page views and see which sites and campaigns visitors arrive from. It sets no cookies, does not track you across other websites, and stores no personal or identifying information — only aggregate counts.
Data retention and deletion
Your data is retained as long as your account exists. You can delete a band and its data, or your entire account, at any time from within the app; this removes the associated gigs, venues, songs, and any connected-calendar records.
Contact
Questions about this policy or your data can be sent to omegajlightning@gmail.com.