Last updated 1 October 2026: sharing a song to the community, below.
The short version. Adam Studio runs on your computer, and your samples, your projects and your music stay on it. Nothing you make leaves your computer until you press SHARE on a song; then that one song goes to our server and becomes public, as Sharing a song describes. We do not track what you make and we cannot hear anything you have not shared. The only account that exists is the buyer account that hands you your licence key.
Adam Studio makes four kinds of network request. Three of them never carry your music. The fourth is SHARE, and it happens only when you press it.
When you buy Adam Studio we keep what is needed to have sold you something: your name and email address, the licence key issued to you, and the date. We use it to send you your key, to help you if something goes wrong, and to tell you about updates to the app. We do not sell it, we do not share it for marketing, and we do not add you to anything you did not ask for.
Payments are handled by PayPal, or arrive as a crypto payment you send directly. Your card or account details go to PayPal and never to us. We never see them and never store them. What we do keep is the order reference PayPal hands back and the amount, so that a payment can be matched to the licence it paid for, and refunded under the refund policy. With the order we also keep which version of the terms you ticked your agreement to at the checkout, and the date.
The account is opened at the checkout, before you pay rather than after, and that order is deliberate: your licence key is issued in your name to that address and cannot be reissued to an address you mistyped. It holds exactly what the paragraph above lists, your name, email address, order reference, licence key and purchase date, and nothing accumulates in it afterwards: no activity, no usage, no history. If you start a checkout and do not finish it, the account simply sits there empty; write to us and we will delete it.
You sign in with a link sent to your email address; there is no password for anyone to steal. If you sign in with Google instead, Google confirms to us that the address is yours and passes on your name and email address. Nothing else, and we ask for nothing else. Download links are personal and expire within minutes of being issued.
The account system runs on Supabase and this website is served by Vercel, two providers that hold that data on our behalf and are not permitted to use it for anything of their own. The app never signs in to your account. Your licence is verified on your own computer, on every launch. A registered computer holds a four-day pass, and while it is online the app quietly renews that pass, a few seconds after launch and about once an hour, by sending our shop your licence key and the same hashed machine id described above, nothing more. What we keep from that, for each computer, is its name as your computer reports it, when it was first activated, when it last checked in, to the hour, and on how many different days it has checked in. Not what you played, not your projects, not your samples, not your IP address. We use that record for two things only: to run the one-computer-at-a-time licence, and to answer a refund request or a payment dispute, in which case we may give it to PayPal or to your card issuer. A computer that cannot reach us keeps working until its pass runs out, and picks up again the moment it connects.
The app contains no analytics, no telemetry, no crash reporting and no advertising identifiers. It counts page views with Vercel Web Analytics, anonymous, cookieless counts of which pages were seen, with nothing that identifies you and nothing that follows you to other sites.
The two public pages also keep their own short log of what was used on them: how long a page was on screen, which sections were scrolled to, which shared songs were played, liked, shared or reported, whether the playable groovebox and its players were pressed, which questions were opened and which buttons were clicked. Each visit is tagged with a random id that lives only in that browser tab and is gone when the tab closes. The log holds no IP address, no browser fingerprint and no account, and it is kept by us, on the same service as the account system, and read by nobody else.
Only while advertising cookies are on (the section below says exactly when that is), that log also carries a second random id which stays in your browser between visits, so that one person who comes back twice counts as one person and not as two strangers. It is a random string and nothing else: it is not your name, your email, your address or your IP, none of which we have from a visit. If you say no, or switch it off from the Cookies link in the footer, it is deleted from your browser and the log goes back to counting your visits without knowing they are yours. The pages still work exactly the same either way.
We advertise Adam Studio on Facebook and Instagram, and we would like to know which advert brought you here so we stop paying for the ones that bring nobody. That is done with the Meta pixel, a small piece of Meta’s code on the home page, the play page, the getting-started guide, the articles, the workflow page, the manual, the checkout and the thank-you page after a purchase, and it sets a cookie.
In the European Union and the United Kingdom, nothing happens until you say so. When you first arrive, a card in the middle of the page asks. Nothing is fetched from Meta, no cookie is written and nothing is sent to our own server before you answer, and if you say no you are not asked again. The thank-you page after a purchase never asks that question: if you have not already answered it, nothing loads there. Which of the two you get is decided by your own browser’s time zone setting, read on your device; we do not look your address up anywhere and no request leaves your browser to make that decision.
Everywhere else, the pixel runs when the page opens, and the Cookies link in the footer of every page switches it off. Pressing it stops us sending anything further at once, deletes the cookies Meta had set and deletes the random visitor id described in the section above. What it cannot do is unload Meta’s code from a page it is already running on, so the link says off from the next page rather than pretending otherwise.
What is sent while it is on. Five things happen on this site and each is sent once: the page you opened, reaching step 3 of how it works on the home page, pressing a buy button, signing in at the checkout, and a completed purchase. Each carries the price and the currency, and nothing about what you played, typed or listened to on the page.
It is sent twice, once from your browser and once from our server. The second
copy goes through Meta’s Conversions API, from the server that runs this shop, and it exists
because browsers and ad blockers often stop the first one; both copies carry the same event
reference so that Meta counts one event and not two. The server copy carries: your
email address, scrambled into a one-way hash, and, when you buy, the
name on your licence, scrambled the same way, both only once you have signed in
at the checkout; Meta’s own _fbp and _fbc cookie values and the
identifier from the advert you clicked; the random visitor id this site gave your browser; your
IP address; and your browser’s user agent, which is the line every website
you visit receives saying what browser and device you are using. The hashing is done on our
server, and the plain values reach it only from the checkout page, over an encrypted connection.
The copy your browser sends carries the same email and name, scrambled by Meta’s own script
before it leaves your browser.
Nothing else goes to Meta. Not your licence key, not your order reference, and nothing whatsoever about your music, your samples or your projects. The app itself has no advertising code in it at all.
If it is off, none of that happens, no cookie is set, nothing is sent from your browser or from our server, the page works exactly the same, and you may still buy.
Nothing leaves your computer until you press SHARE. SHARE is on a SONG row of the SNAPSHOT sheet. It asks for a title and an artist name, and for one tick: that you have the rights to the samples in the song and that it will be public. Only then does the app send that one song to our server, and this is all it sends:
A shared song is public. It is listed on adam-studio-ai.com/play with its title, artist name, tempo and date. Anyone can play it, take its players in and out, and share its link, and the audio and MIDI files the page plays can be downloaded by anyone who has their address. Share only what you would publish. The files and the list are kept with Supabase, the same provider as the shop, on our behalf.
Likes. A like is stored with a random id that your browser makes for likes alone and keeps in its own storage, so that one browser counts once. It is not your name, your email, your IP address or the visitor id described above, and nothing else reads it. Clearing this site’s data in your browser forgets it.
Comments. Only someone signed in can comment. Signing in works the way the account page does: you give an email address, we email you a link, and there is no password. The address is kept with Supabase, on our behalf, so that you can sign in again; it is never shown to anyone. Your first comment asks for a display name, and that name is shown with every comment you write, with what you wrote and when, to anyone who opens /play. Links cannot be posted. You can delete your own comments on the page: the text goes, and a record that a comment was there stays, so the hourly limit on comments still counts it. A comment can be reported like a song, and one that is reported may be hidden. To delete your sign-in and every comment you wrote, write to the address at the foot of this page.
Reports. Every shared song has a REPORT button, for samples used without permission, a copyright, or anything else. A report holds the reason, what the reporter wrote, and a way to reach them only if they chose to give one. It is stored with the song it is about and emailed to us, and it does not record the reporter’s IP address. We read every one, and a song that a report shows is infringing is taken down within a few days.
Taking a song down. To remove a song you shared, write to the address at the foot of this page from the email address on your licence and name the song; we delete its files and its listing. When a song comes down for any reason, its files leave the public storage as well as the list: a song that has come down cannot still be fetched by its old address.
You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Deleting it does not switch off software you have already bought. Your licence keeps working, because it is verified on your own machine rather than looked up on ours. Write to the address below.
Adam Studio is made by Guy Hashpia. For anything on this page, write to guy@adam-studio-ai.com.
Terms of Service · Licence Agreement
← Back to Adam Studio