Privacy Notice

Last updated 4 September 2026.

Your catalog database stays on your Mac

PITTO keeps your songs, splits, audio, contacts, companies, writers, artists, briefings and pitches in a database file on your own computer. It is never uploaded to us, and we have no copy of it. What we do hold is your licence — described in section 2 — and individual features do call out to other services when you use them, listed in full in sections 3 and 4.

1. Who is responsible for your data

Tommy Advice B.V., trading as PITTO (KVK 83907718), of Postjesweg 1, 1057 DT Amsterdam, The Netherlands, is the data controller for the information described in this notice.

2. What we store, and the daily check-in

On our licence server we store:

  • your email address and your Paddle customer ID;
  • your licence key, and the status and current period end of your subscription;
  • for each Mac you activate: a device name, a hashed hardware identifier, when it was activated, and when it was last seen;
  • a log of activation and renewal attempts — the licence key and a timestamp, used for rate limiting and deleted after 24 hours.

About that device name. PITTO does not ask you for one. It sends your Mac’s own computer name, exactly as macOS reports it — which for most people is something like “Anna’s MacBook Pro” and therefore contains their real name. If you would rather it did not, rename your Mac in System Settings before you activate. The hardware identifier is hashed on your Mac before it is sent; we never receive the raw one.

The app checks in once a day. While PITTO is running it contacts our licence service every 24 hours to renew its entitlement, sending your licence key and that hashed hardware identifier and nothing else. Each check-in updates the “last seen” time for that Mac, so our records amount to a daily indication of whether you are using the app, and on which machine. No catalog data is included in that request.

Payment details are collected and held by Paddle, the merchant of record for your subscription. We never see or store your card details.

3. Features that use accounts you connect

Several features work by calling an outside service with an API key you enter yourself in Settings. Nothing is sent until you use the feature, and it goes under your own account with that provider, whose terms and privacy policy govern what happens to it next. Leave a key out and the feature simply refuses to run.

  • Anthropic (Claude), using your Anthropic API key, for four separate things: reading a briefing you upload; researching a writer, which uses Claude’s web search and so puts that writer’s name and known song titles into search queries; finding a company’s artist roster; and drafting a pitch email. For briefings, the PDF is converted to plain text on your Mac and only that text is sent — the file itself never leaves your computer.
  • Spotify, using your own Spotify credentials, to look up artists, songs and album art. Some of this is automatic rather than on a button press: opening a briefing sends its reference track titles to Spotify to find a playable version. Connecting Spotify for playback also loads Spotify’s player software from their servers.
  • Brave Search, using your Brave API key, to look up an artist’s management contacts and, as a fallback, a company’s roster. The artist or company name goes into the search.
  • Genius, using your Genius API key, to pull songwriter credits for an artist’s released tracks.
  • Postal, using your Postal API key, when you publish a song there. This sends the song’s title, artist credit, ISRC, lyrics and genre, plus a link Postal uses to fetch the audio file.

4. Calls that use no account at all

Three things PITTO does reach a third party directly, with no API key and no account of yours involved. That party sees the request coming from your computer:

  • YouTube. When a briefing’s reference list is displayed and a reference is a bare link with no title, PITTO asks YouTube for that video’s title so it can show something readable. This happens automatically as the briefing renders, not on a click.
  • Disco. Pasting a Disco share link to import tracks fetches that page from Disco.
  • A company’s own website. Asking PITTO to find a company’s roster makes it fetch pages from that company’s site directly, before any of it is sent on to Claude.

5. What does not leave your Mac

Your audio files stay local. The features that would send audio elsewhere — automatic audio analysis, artist signature generation and song matching — are not part of this version of PITTO, and their controls are not shown. The exception is publishing a song to Postal, which you start yourself and which is described in section 3.

6. Why we process this data

We use the account data in section 2 to issue and renew your licence, activate PITTO on your Macs, keep activation within the two-device limit, manage your subscription, and answer support requests — all of it necessary to provide the service you subscribed to.

7. Who we share it with

Paddle, who takes payment and manages subscriptions as merchant of record, and Resend, who delivers your licence key and account emails. That is the whole list. We do not sell your data. The services in sections 3 and 4 are not us sharing data with them — those are calls your copy of PITTO makes directly, under your own credentials where credentials are involved at all.

8. Cookies and tracking on this website

We run no analytics and no tracking scripts. One page is different: the checkout page loads Paddle’s payment script from Paddle’s servers, which is what makes paying possible. That script is Paddle’s, not ours, and it can set its own cookies and collect device information for fraud prevention under Paddle’s privacy policy. Every other page on this site loads nothing from anyone else.

9. How long we keep data

We keep licence and account data for as long as your subscription is active, and afterwards for as long as we need it to meet our legal and accounting obligations. Activation attempt logs are deleted after 24 hours.

10. Planned: a hosted tier (not yet available)

We are planning an optional, separately purchased hosted tier of PITTO. Unlike the product described above, that tier will involve storing your catalog data on infrastructure we operate and processing it with large language models, in order to provide features that require it. It does not exist today and nothing in the current product works that way. Before it launches we will update this notice with the specifics, including which sub-processors are involved.

11. Your rights

You can ask us to access, correct or delete the data we hold about you, to give you a copy of it, or to stop processing it, by writing to support@pitto.music. If you are unhappy with how we have handled it, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl.

12. Contact

Questions about this notice can be sent to support@pitto.music.