Privacy policy

What we collect, why we collect it, and the rights you have over your data. We've tried to write this plainly — every section opens with a short summary in your own language before the formal text. If something here is unclear, ask us.

// Last revision02 May 2026
// Versionv 05
// Sections15
// FrameworkGDPR EU 2016/679
01·Currently reading/Overview & your rights at a glance
01

Overview & your rights at a glance

#
tl;dr

We collect the minimum we need to run our software and talk to you. You can see, export and delete your data at any time. No selling. No sharing without your say-so.

This Privacy Policy explains what personal information Imaginando Lda ("Imaginando", "we", "us") collects when you use our website, our desktop and mobile software, or talk to us through support — and what we do with it.

The short version is below; each section unpacks the detail. This policy is governed by the General Data Protection Regulation (EU 2016/679⁠, "GDPR") and Portuguese data-protection law.

  • AAccess — get a copy of everything we hold on you.
  • BRectify — fix anything that's wrong or out of date.
  • CDelete — close your account and erase your data.
  • DPort — export your data in a machine-readable format.
  • EObject — opt out of marketing or specific processing.
  • FComplain — to your local data-protection authority.

To exercise any of these rights, contact us. We respond within 30 days⁠, free of charge.

02

Information you provide

#
tl;dr

Your email and password (to create an account) and anything you send us via support chat. That's it.

2.1 — Account creation

Activation and use of any of our desktop products requires the creation of an Imaginando account, using an email address⁠ and a password⁠. This is the only data strictly required for the licence system to work.

Optionally, you may add a name, country, profile picture, and newsletter preference. None of these are required to use the software.

2.2 — Support & chat

Our website chat is provided by Crisp⁠. If you write to us through the chat widget, you may submit an email address so we can identify you and continue the conversation outside the widget. Whatever you type into the chat is processed by Crisp on our behalf — see third parties below.

2.3 — Purchases

When you buy something from our store, your billing details are processed by our payment provider (Stripe⁠ or PayPal⁠) — we never see or store your full card number. We keep an order record (your name, email, what you bought, when, and the invoice amount) for accounting purposes, as required by Portuguese tax law.

03

Information collected automatically

#
tl;dr

Basic device info, app version, OS — so we can support you when something breaks. Approximate location from IP address. No tracking of what you make in the software.

3.1 — Device attributes

When you use our software or website, we collect details of your device hardware and software properties — system specification, operating system, app version, locale. This helps us debug crashes and decide which platforms to keep supporting.

3.2 — IP address & approximate location

The website chat functionality provided by Crisp uses your IP address⁠ to determine approximate location and timezone, so support replies arrive at a reasonable hour and in a sensible language. We do not use IP for advertising or build location profiles.

3.3 — What we don't collect
// The software is not a telemetry pipe

Our desktop and mobile software does not record your audio, MIDI, projects, presets, samples, or anything you create with it. None of that ever leaves your device unless you explicitly share or sync a file using a feature you opt into.

04

How we use this information

#
tl;dr

To make the software work (licensing, sync), to talk to you (support, the occasional product email if you opted in), and to keep things secure. Each use case has its own GDPR legal basis.

Under GDPR we have to tell you not just what we do with your data but why we're allowed to⁠. Here's the breakdown:

// Purpose// Data used// Legal basis (GDPR Art. 6)
Account & licensing. Run the licence server, sync activations across your devices.Email, password hash, device IDContract
Customer support. Reply to your messages, route them to the right person.Email, chat content, support ticket historyContract / legitimate interest
Billing & tax. Issue invoices, comply with Portuguese tax law (10-year retention).Name, billing address, invoice amountLegal obligation
Newsletter. Send product news, releases, occasional offers.Email, name, opt-in recordConsent (you can opt out any time)
Push notifications. Sent from our apps: new releases of apps you have installed, account events, and — with your consent — product news and offers.Device push tokenConsent (OS-level)
Product analytics. Aggregate counts of feature use, crashes, install base.App events, crash logs (no content)Legitimate interest
Fraud & abuse. Catch licence-key sharing, refund fraud, account takeover.Activation patterns, IP, device IDsLegitimate interest

If you'd rather we stopped any of the legitimate-interest uses above, contact us and we will, unless we have to keep that processing for one of the other reasons listed.

05

Third-party services

#
tl;dr

Three vendors get a peek at parts of your data so we can run the service: OneSignal for push, Crisp for support chat, payment processors for orders. We don't sell or share for advertising.

The following third-party processors handle data on our behalf. Each is bound by a data-processing agreement that obliges them to handle your data to GDPR standards.

OneSignal// Push notifications

Some of our apps make use of OneSignal, a third-party messaging service provided by Lilomi, Inc. OneSignal allows us to send messages and push notifications to users across Android, iOS, and the web — for example, to tell you a new release of an app you've installed is available.

Data shared: device push token, app identifier, OS version, language. No content of any push is stored beyond delivery.

Crisp// Support chat

Crisp powers the live chat on our website. When you message us, it processes what you send — your email if you choose to share it, and your approximate location from IP — so we can identify you and reply.

Data shared: anything you type into the chat, your email, your IP, the page you were on when you opened the chat.

Stripe & PayPal// Payments

When you buy something on our website, your card or PayPal details are processed directly by Stripe or PayPal. We receive a payment-confirmation token and an invoice record — never your full card number.

Meta Pixel// Marketing analytics

Our website uses the Meta (Facebook) Pixel to measure the performance of advertising campaigns. The pixel only fires if you accept non-essential cookies on the consent banner.

06

Cookies & analytics

#
tl;dr

We use a few essential cookies (login, cart) and, with your permission, analytics + marketing cookies. You set the rules at the consent banner and can change your mind any time.

A cookie is a small file stored on your device by the browser. We use them in three categories — only the first runs without asking you:

  • 6.1Essential cookies. Keep you signed in, remember what's in your cart, store your theme and language. These can't be turned off because the site won't work without them.
  • 6.2Analytics cookies. Aggregate counts of which pages get visited, which products people look at. We use this to decide what to build next. Optional — defaults to off.
  • 6.3Marketing cookies. Measure ad performance and avoid showing you the same ad twice. Optional — defaults to off.
// You stay in control

The first time you visit the site you'll see a cookie consent banner⁠. You can accept all, reject non-essential, or fine-tune by category. Your choice is remembered for 12 months, and you can re-open the panel any time from the footer link "Cookie settings".

07

Push notifications opt-out

#
tl;dr

Push comes from our apps only — never from the website. On iOS you're always asked before any are sent, and you can turn it off at the OS level any time, app by app.

You can opt out of push notifications by visiting your device settings — the notification settings on your phone or computer — and switching them off for the relevant app, either entirely or by category. Different OS versions surface this control in slightly different places; if you can't find it, our support chat will help.

We send push notifications from our apps (never from the website) for:

  • 7.1Releases. A new version of an app you have installed is available.
  • 7.2Account events. Sign-in from a new device, password reset, billing-related notices.
  • 7.3Product news. With your consent, occasional news about our products, expansions and offers.

On iOS you're always asked to allow notifications before we send any, and you can withdraw consent at any time in your device settings. We don't send push from the website.

08

Your rights under GDPR

#
tl;dr

Six rights you can exercise at any time, free of charge. Contact us — we answer within 30 days.

If you're in the European Economic Area, the United Kingdom, or any jurisdiction with comparable consumer-protection law, you have the rights listed below. Imaginando Lda is the data controller⁠. Some rights may be limited where another law (e.g. Portuguese tax retention rules) requires us to keep specific records.

  • 8.1Right of access. Ask us for a copy of the personal data we hold about you, in a readable format. We will respond within 30 days.
  • 8.2Right to rectification. Ask us to correct anything that's wrong or out of date. Most fields you can edit yourself in your account settings.
  • 8.3Right to erasure ("be forgotten"). Ask us to delete your account and the personal data tied to it. We'll keep the minimum we have to (invoices, fraud records) for the period the law requires, and erase the rest.
  • 8.4Right to restriction. Ask us to stop processing your data while we sort out a query, dispute, or rectification request.
  • 8.5Right to data portability. Get your data in a structured, machine-readable format (JSON or CSV) so you can take it elsewhere.
  • 8.6Right to object. Tell us to stop processing your data for direct marketing or for any purpose based on legitimate interest.
// How to make a request

Contact us⁠ with the right you want to exercise and a way to verify your identity (the email tied to your account is usually enough). We respond within 30 calendar days⁠, at no charge.

If you're unhappy with how we handled your request, you have the right to complain to your local Data Protection Authority. In Portugal, that's the CNPD⁠ (cnpd.pt).

09

Data retention

#
tl;dr

Account data: as long as your account is active. Invoices: 10 years (Portuguese law). Support tickets: 3 years. Marketing data: until you opt out.

We keep different categories of data for different lengths of time, based on what each is for:

  • 9.1Account data⁠ — for as long as your account is active. We delete it within 30 days of you closing the account, except where retention is legally required.
  • 9.2Invoices & tax records⁠10 years⁠, as required by Portuguese accounting law (Decreto-Lei 28/2019⁠).
  • 9.3Support tickets⁠ — 3 years, so we have context if you come back with a follow-up.
  • 9.4Newsletter consent record⁠ — until you unsubscribe, plus 12 months as proof of the unsubscribe.
  • 9.5Crash logs & aggregate analytics⁠ — 18 months, then aggregated and anonymised.
  • 9.6Fraud / abuse records⁠ — up to 5 years, where there is a legitimate interest in preventing repeat misconduct.
10

International data transfers

#
tl;dr

Some of our processors (OneSignal, Stripe) operate in the US. Transfers happen under the EU-US Data Privacy Framework or Standard Contractual Clauses.

Imaginando is based in Portugal and most of your data is stored in the European Union. However, several of our processors — OneSignal, Stripe, Meta — operate from the United States and may store data there.

Where data leaves the EU, we rely on one of the following lawful transfer mechanisms required by GDPR Articles 44–49:

  • 10.1EU-US Data Privacy Framework⁠ — for processors that have self-certified.
  • 10.2Standard Contractual Clauses⁠ — the European Commission's pre-approved contract template, signed with each processor.
  • 10.3Supplementary measures⁠ — encryption in transit and at rest, plus pseudonymisation where the use case allows.
11

Security & breach notification

#
tl;dr

Encrypted in transit and at rest, hashed passwords, regular audits. If something goes wrong and your data is at risk, we'll tell you and the regulator within 72 hours.

We protect personal data with technical and organisational measures appropriate to the risk:

  • 11.1Transport encryption⁠ — TLS 1.2+ on every endpoint.
  • 11.2Storage encryption⁠ — at-rest encryption on databases and object storage.
  • 11.3Password hashing⁠ — passwords are stored as bcrypt hashes; we never see the plain text.
  • 11.4Access controls⁠ — least-privilege access for staff, MFA on every administrative account.
  • 11.5Audits⁠ — annual review of access logs, processor agreements, and retention periods.
// Breach notification

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the CNPD⁠ within 72 hours⁠ and inform affected users without undue delay, as required by GDPR Article 33–34.

12

Children

#
tl;dr

Our software is intended for users aged 16+. We don't knowingly collect data from anyone younger.

Our products are intended for users aged 16 and over. We do not knowingly collect personal data from children under 16. If you believe a child has created an account, please contact us and we will delete the account and any associated data.

14

Contact & data controller

#
tl;dr

The data controller is Imaginando Lda, Braga, Portugal. Privacy questions go through our contact page — a real human reads them.

// Data controllerImaginando Lda⁠
// Registered officeBraga, Portugal
// Privacy enquiriesContact us
// General supportimaginando.pt/contact
// Supervisory authorityCNPD — Comissão Nacional de Proteção de Dados (Portugal)

We don't currently have a formally designated Data Protection Officer because the size of our processing doesn't require one under GDPR Article 37 — but the privacy mailbox is monitored by a member of the engineering team and answered within 30 days.

15

Changes to this policy

#
tl;dr

We can update this policy. The revision date at the top tells you when. If a change is material we'll email account holders.

We may update this Privacy Policy from time to time, for example to reflect new processors, new product features, or changes in the law. The revision date at the top of the page indicates when the latest version was published.

For material changes⁠ — anything that meaningfully expands what data we collect or how we use it — we will email account holders before the change takes effect, so you have time to review and, if you prefer, close your account.

Want a copy of your data⁠?

Or you'd like us to delete it, fix it, or stop processing it. Contact the privacy team — a real human at Imaginando reads it and replies within 30 days.