Våld Labs

Privacy Policy

Last updated: 3 September 2026

This policy explains what information Våld Labs ("we", "us") collects and how we handle it across our products, applications, audio plugins, and websites (collectively, the "Services").

We aim to collect as little personal data as possible. We do not use third-party advertising, we do not track you across other apps or websites, and we do not sell your data.

Data controller

The data controller responsible for the Services is:

Jaime Paiva
Operating under the brand name Våld Labs
Largo da Graça 127, 3D
1170-296 Lisbon
Portugal
Tax ID: 236072064
Email: vald.labs.lisbon@gmail.com

Våld Labs is a brand name and is not a separate legal entity. Jaime Paiva is an independent software developer based in Lisbon, Portugal, who develops and operates the Services under that brand.

Our apps and plugins

Our instruments and plugins — including TRESSE, VEKTE, KURARE and others — run locally on your device. Your audio, MIDI, presets and projects are not sent to us as part of normal use. Settings and presets you create are stored locally on your device or within your host application's project files.

To operate and improve the Services, our apps contact our own server (hosted on Vercel) for a small set of purposes, and send only what each purpose needs. The sections below describe our current desktop builds and our iOS apps; where a behaviour applies to one platform only, we say so.

Installation identifier

The first time an app runs, it generates a random installation identifier and stores it in a small file on your device. This identifier is pseudonymous: it contains no name or email and does not by itself identify you, but it is stable for that installation, and if you register an email address in the app the records described below become associated with that email. It is not used for advertising or for tracking across other apps or websites.

Update, news and beta-status check

When the app starts or the plugin window is opened, the app asks our server whether an update, a product announcement or a change in beta status is available. This request includes the app version, operating system and processor architecture, the host application and plugin format (for a plugin), the product name and the installation identifier. Our server records the time of the request and an approximate location (country and city) that our hosting provider derives from the IP address of the request; the IP address itself is not stored with this record.

Activity signals

While the plugin window is open, the app may send a short "still open" signal, and when you interact with the interface it sends a short "in use" signal, in each case at most about once per minute and with the same fields as the check above. We use these signals to see that a version works in the wild and to estimate roughly how long it is used. They contain no audio, MIDI, presets or other content.

Email registration for beta access

Our current desktop beta builds ask you to register an email address and confirm it through a verification link before the beta is unlocked. In TRESSE for iOS, registration is optional (Menu → Register) and nothing is locked without it. When you register, we receive the email address together with the app version, operating system, architecture, host application, plugin format, product and installation identifier, and we store the email with the installation identifier. We use the address to send the verification email, to administer beta access, and to send you the product updates and beta news you signed up for. No purchased product requires an account, and you can ask us to remove a registration at any time.

Feedback and diagnostic reports

If you use an in-app feedback form, we receive the message you write together with the app version, operating system, architecture, host application, plugin format, product and installation identifier, so that we can reply and reproduce problems. Feedback is forwarded to our mailbox by email.

The apps also send an automatic diagnostic report when they hit an internal error, for example when the interface fails to load or a script error occurs. A report contains the error type and message, the app version, operating system, architecture, host application, plugin format, product and installation identifier. Our server records the IP address of the request with the report and gives crash reports a short reference code so that a problem can be traced back to a specific installation. If the installation is linked to a registered email, the report is linked to that email too.

Licence check-in (paid desktop licences)

Paid desktop licences are verified offline on your computer using a signed licence key; the software does not need our server to keep working. When your computer is online, the software may occasionally (at most once a day) confirm its licence with our server, sending the licence identifier, product, version, operating system, architecture and the installation identifier. For this purpose our server stores the installation identifier only as a salted hash, never the raw value, and uses the data solely to detect abuse such as one key being used on an unusual number of machines or forged keys. Any alert is reviewed by a person; nothing is disabled automatically, and a check-in can never lock or restrict the software.

Notifications

Reminders in our iOS apps are scheduled locally on your device and send us nothing. News notifications in TRESSE for iOS work by the app fetching the latest announcement from our server in the background (iOS decides when, at most about every 12 hours); that request carries only the product name and platform, no identifier, and nothing is stored from it beyond the hosting provider's standard server logs. The notification itself is then scheduled locally on your device.

Purchases through Lemon Squeezy

Paid desktop products on valdlabs.com are sold through Lemon Squeezy, which acts as merchant of record. Lemon Squeezy processes your payment-card or other payment details, checkout information, applicable taxes, invoices, refunds and chargebacks under its own privacy policy. Våld Labs does not receive or store complete payment-card details.

After a purchase, Lemon Squeezy notifies our server so that we can issue your licence. From that notification we keep:

The notification may contain further order details, such as your name or billing country; we do not store those. We use the order and licence data to deliver the product and licence key, to administer and re-send licences, to provide customer support, to prevent fraud, to process refunds, and to comply with tax and accounting obligations. Your licence key is emailed to your purchase email through our email provider (see "Service providers and recipients" below).

Apple App Store and other marketplaces

Our iOS apps are distributed through the Apple App Store, and some offer a paid unlock as an in-app purchase (for example, the TRESSE "Pro" unlock). These purchases are processed entirely by Apple under Apple's privacy policy. We never see or store your payment details, we do not issue licence keys for App Store purchases, and restoring a purchase is handled by Apple. We may receive aggregate, non-identifying sales information from the store.

App Store in-app purchases are separate from desktop purchases made through Lemon Squeezy, and the licence check-in described above does not apply to our iOS apps.

Website, waitlists and support

Waitlist and notify-me forms. When you submit your email address to a waitlist or notify-me form on valdlabs.com, the form is delivered through FormSubmit (formsubmit.co), a form-to-email service, which forwards it to our mailbox. We use the address solely to send you the release notes, launch updates or replies you asked for about the product you signed up for. We may also keep waitlist addresses in our backend and add them to a contact list at our email provider so that we can send those updates. We do not sell or rent your email address. You can unsubscribe at any time using the link in any email we send, or by contacting us at the address below.

Support and correspondence. When you email us, whether for support, a refund, a licence question or anything else, we receive your email address, the contents of your message and any information you choose to include. Our mailbox is provided by Google (Gmail). We use correspondence to answer you, to resolve support and order issues, and to keep appropriate records of those issues.

Emails we send (licence keys, beta verification links, product updates and discount codes) go out through Resend, our email delivery provider.

Downloads. Installers are hosted as release files on GitHub. When you download one, GitHub receives standard request information such as your IP address, under GitHub's privacy policy.

Cookies, embeds and logs

Our websites are served as static pages. We do not run analytics, and we do not set advertising or cross-site tracking cookies. We do not use cookies or browser storage for tracking at all, which is why our sites show no cookie banner.

Some pages load resources from third parties, which receive your IP address and standard request information when the page loads:

The Meteor web app at valdlabs.com/meteor can be installed as an offline web app; it stores its own files in your browser's cache so that it works offline, and sends nothing to us.

Our hosting provider (Vercel) may process standard server-log information, such as IP address and request details, for security and operational purposes. Our backend server also uses the country and city that Vercel derives from the IP address, as described above, and stores the IP address with diagnostic reports.

Legal bases

Where the EU General Data Protection Regulation (GDPR) applies, we rely on the following legal bases:

Service providers and recipients

We share personal data only with providers that help us run the Services, and each receives only the information required for its function:

We do not sell or rent personal data, and we do not share it with advertisers.

International transfers

Several of these providers (Lemon Squeezy, Vercel, Resend, FormSubmit, Google, GitHub and Apple) are based in, or operate infrastructure in, the United States and other countries outside the European Economic Area, so your personal data may be processed outside the EEA. Where that happens we rely on the safeguards recognised by the GDPR, such as an adequacy decision (including the EU–US Data Privacy Framework where a provider is certified under it) or the European Commission's Standard Contractual Clauses included in the provider's data-processing terms. We do not claim that all data stays within the EU.

Data retention

Your rights

Where the GDPR applies, you have the right to:

Deletion may not apply where we must keep information to meet legal obligations (for example, order records for tax purposes), to prevent fraud, to establish or defend legal claims, or to administer a continuing software licence.

To exercise any of these rights, email vald.labs.lisbon@gmail.com. We may need to confirm your identity, for example by asking you to write from the email address on the record.

You can also complain to your local supervisory authority. In Portugal this is the Comissão Nacional de Proteção de Dados (CNPD): www.cnpd.pt. Complaints can be submitted at www.cnpd.pt/cidadaos/participacoes/.

Automated decisions

We do not use personal information for automated decision-making or profiling that produces legal or similarly significant effects. Licence-abuse alerts generated by our server are reviewed by a person before any action is taken.

Children

Our Services are not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal data from them.

Security

We take reasonable technical and organisational measures appropriate to the scale of the Services: connections to our websites and server use HTTPS, administrative access to our backend is protected by secret credentials, licence keys are cryptographically signed, installation identifiers in licence check-ins are stored only as salted hashes, and backups are kept in a private, access-controlled repository. No system is completely secure and we cannot guarantee absolute security, but we work to limit the data we hold and to protect it.

Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be posted on this page.

Contact

Questions about this policy or your data? Contact the data controller:

Jaime Paiva
Operating under the brand name Våld Labs
Largo da Graça 127, 3D
1170-296 Lisbon
Portugal
Tax ID: 236072064
Email: vald.labs.lisbon@gmail.com

Våld Labs is a brand name under which Jaime Paiva operates the Services; it is not a separate legal entity.