Second Chair

Legal

Privacy Policy

Last updated: July 2026

By accessing or using the Service, including visiting this website, installing the Second Chair plugin, or subscribing to a plan, you acknowledge that you have read and understood this Privacy Policy and agree to the collection and use of your information as described here.

1. Who we are

Second Chair (“we”, “us”, “our”) is operated by Fruit Market Ventures Ltd, a company registered in England and Wales. We are the data controller for personal data collected through secondchair.studio and the Second Chair plugin.

Contact: support@secondchair.studio

2. What data we collect

We collect the following categories of personal data:

  • Account data: your name, email address, artist or producer name, and Spotify artist page URL (if provided) when you apply for beta access or create an account.
  • Usage data: which analysis types you use, how many analyses you perform per month, and which machines you run the plugin on (stored as SHA-256 hashes, not raw identifiers).
  • Feedback data: responses to our feedback surveys, including testimonials you choose to share.
  • Payment data: billing information processed by Stripe. We do not store card numbers or payment credentials directly.
  • Technical data: your IP address (used for rate limiting and security), and plugin version.
  • Marketing engagement data: where you have consented to marketing communications, we collect data about how you interact with them, such as whether an email was delivered, opened, or clicked, via our marketing platform Brevo.

3. What we do not collect

We do not store any audio you capture using the Second Chair plugin. Audio is transmitted directly to Google Gemini for analysis and is not retained on our servers. We do not use your audio for any purpose other than generating the feedback you requested.

Google processes audio submitted through our integration in accordance with its API data-use commitments applicable to our service tier, under which submitted content is not used to train Google's models. For details, see Google's applicable API terms and privacy documentation.

4. Lawful basis for processing

We process your personal data on the following lawful bases under UK GDPR:

  • Contract: processing necessary to provide the Second Chair service you have signed up for, including licence management and usage tracking.
  • Legitimate interests: security and fraud prevention, improving the product, and communicating with beta users about their access. We have assessed that these interests are not overridden by your rights.
  • Consent: for optional testimonials, marketing communications, and advertising cookies and related profiling, where we ask for your explicit agreement. You can withdraw consent at any time.

5. How we use your data

  • To create and manage your account and licence
  • To enforce usage limits and reset monthly quotas
  • To send transactional emails (licence keys, feedback requests, payment receipts)
  • To improve the Second Chair plugin and service based on aggregated usage patterns
  • To display approved testimonials on our website (only with your explicit consent)
  • To send marketing communications about Second Chair, such as product news, feature announcements, and offers, where you have consented (you can unsubscribe at any time via the link in any marketing email)
  • To manage our marketing contact lists, segment audiences, and personalise the marketing content we send you
  • To measure the effectiveness of our marketing, including whether emails are delivered, opened, or clicked
  • To detect, investigate, and prevent abuse of the Service
  • To comply with legal obligations

6. Third-party processors

We share your data with the following sub-processors, each bound by their own privacy commitments:

  • Google Gemini: receives audio and prompts for analysis, subject to Google's API data-use commitments described in section 3. Google Privacy Policy
  • SendGrid (Twilio): email delivery for transactional emails. Twilio Privacy Policy
  • Brevo: marketing platform and contact management (CRM). Brevo processes your name, email address, and marketing preferences to send marketing communications you have consented to, to manage and segment our contact lists, to run marketing automations, and to measure engagement with our emails (such as delivery, opens, and clicks). Brevo may also be used to send service and account communications. Brevo is based in the European Union and primarily stores data on servers in the EU. Brevo Privacy Policy
  • Stripe: payment processing. Stripe Privacy Policy
  • Railway: hosting of our database and API server. Data is stored in their US infrastructure. Railway Privacy Policy
  • Vercel: hosting of our website. Vercel Privacy Policy
  • Google (Ads and YouTube): where you have consented to advertising cookies, we use the Google Ads global site tag (gtag.js) to measure conversions from Google Search, Display Network, and YouTube campaigns, and to enable remarketing. Google LLC, USA. Google Privacy Policy · Ad settings
  • Meta (Facebook and Instagram): where you have consented to advertising cookies, we use the Meta Pixel to measure conversions from Facebook and Instagram campaigns and to enable remarketing audiences. Meta Platforms Inc., USA. Meta Privacy Policy · Ad preferences

7. International transfers

Some of our sub-processors store or process data outside the United Kingdom. Brevo stores data primarily in the European Economic Area, which is covered by UK adequacy regulations, meaning no additional safeguard is required. Other providers process data in the United States (for example, Railway hosts our database in US infrastructure, and Google may process audio in data centres outside the UK).

Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place as required by UK GDPR. Depending on the provider, this is one or more of:

  • the UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”), where the provider is certified;
  • the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; or
  • an adequacy decision covering the destination country.

You can contact us at support@secondchair.studio for more information about the safeguards applied to a specific transfer.

8. Data retention

  • Account and licence data: retained for the duration of your account, plus 2 years after closure for legal and financial record-keeping.
  • Usage events: retained for 12 months then aggregated and anonymised.
  • Feedback submissions: retained indefinitely unless you request deletion. Approved testimonials may be retained for marketing purposes with your consent.
  • Marketing contact and engagement data: retained until you unsubscribe or withdraw consent, after which we retain a minimal suppression record (your email address only) to ensure we do not contact you again.
  • Audio: not retained by us. Discarded immediately after analysis.

9. Your rights under UK GDPR

You have the following rights regarding your personal data:

  • Access: request a copy of the data we hold about you.
  • Rectification: ask us to correct inaccurate data.
  • Erasure: ask us to delete your data where there is no compelling reason for us to keep it.
  • Restriction: ask us to restrict processing of your data in certain circumstances.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, email support@secondchair.studio. We will respond within one month, as required by UK GDPR.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

10. Cookies and similar technologies

Essential cookies (always active): these are required for the Service to function and do not need your consent:

  • Session cookies: keep you logged into the portal. These expire when you close your browser or after 30 days.
  • Admin session cookie: used to authenticate admin users. Expires after 8 hours.

Advertising cookies (only with your consent): we use the following advertising technologies when you consent:

  • Google Ads / YouTube (gtag.js): measures conversions from Google Search, Display Network, and YouTube campaigns; enables remarketing. Set by Google LLC (USA). Cookie names include _gcl_au, _gads, and Google Analytics cookies (_ga, _gid). Retention up to 13 months. Google cookie policy
  • Meta Pixel (Facebook and Instagram): measures conversions from Facebook and Instagram campaigns; enables custom and lookalike audiences. Set by Meta Platforms Inc. (USA). Cookie names include _fbp and fr. Retention up to 90 days. Meta privacy policy

These cookies may collect information such as your IP address, device identifiers, and pages visited. Our advertising partners may combine this data with other information they hold about you.

Advertising cookies are set only if you consent via the cookie banner when you first visit the site. You can change your mind at any time using the Cookie settings link in the website footer, and you can also block or delete cookies through your browser settings. Withdrawing consent does not affect the lawfulness of processing before withdrawal, and essential cookies will continue to operate as they are required for the Service to work.

The lawful basis for advertising cookies and the associated processing of personal data is your consent (UK GDPR Article 6(1)(a) and Regulation 6 of the Privacy and Electronic Communications Regulations).

Email tracking: marketing emails sent via Brevo may contain a tracking pixel and tracked links that tell us whether an email was delivered, opened, or clicked. This applies only to marketing emails you have consented to receive. You can stop this at any time by unsubscribing, and many email clients also allow you to block remote images, which prevents open tracking.

11. Security

We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), hashed storage of machine identifiers, and access controls on our admin systems. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

12. Children

The Service is not intended for anyone under 16, and we do not knowingly collect personal data from anyone under 16. If you believe we hold data about someone under 16, please contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will notify active users of material changes by email before they take effect. The date at the top of this page reflects the most recent revision.