Indiewright
Operated by K2MStudios

Privacy Policy

Last updated 10 September 2026

Indiewright is operated by K2MStudios ("we", "us"). This policy describes what we collect, why, who else sees it, and how to get it removed. It describes what the software actually does.

What we collect

DataWhy we have it
Email address and display nameTo create your account, sign you in, and contact you about your account
PasswordStored only as a salted scrypt hash. We cannot read it, and neither can anyone who obtains our database.
Session tokensTo keep you signed in. Stored as SHA-256 hashes, not in usable form.
Payment and transaction recordsTo account for each purchase and pay creators accurately. Required for tax and accounting.
Purchases and entitlementsTo know which editions you own and may open
What you were shown before buyingThe price, fee and total you confirmed, kept as the record that answers a card dispute
Listening time per episodeTo show creators how much of their work is heard, and to meter video
Works, episodes and audio you uploadTo publish and stream them
Reports you submit about contentTo review and act on them
IP address, brieflyRate limiting, to stop abuse and automated attacks

What we do not collect

Who else sees your data

Only the providers required to operate the service:

ProviderWhat they handle
StripePayments, payouts, and identity verification for creators receiving money
NeonDatabase hosting (United States)
Cloudflare R2Storage and delivery of uploaded audio and images
CloudflareApplication hosting, and delivery of the site itself (United States)
Our email providerAccount emails: verification, password resets, receipts, payout notices

We will also disclose information where we are legally required to, such as a valid court order. We disclose only what is actually demanded.

What creators and other listeners can see

Your display name and anything you publish or post publicly is visible to others. Your email address and purchase history are not — not to other readers or listeners, and not to creators, including creators whose work you buy. A creator sees that a sale happened and aggregate listening figures, never who you are.

How long we keep it

Your rights

Wherever you live, you can ask us to:

Two of these you can do yourself, without asking anyone and without waiting: Settings → Privacy → Download my data gives you a file containing your account, what you agreed to and when, what you bought, what you published and every movement of money on your behalf. Settings → Privacy → Close my account closes it immediately. If you never bought or published anything, the account is deleted outright. If you did, the personal details are erased and the financial records remain without naming you — because a record of money that can be rewritten later is not a record of anything, and tax law requires us to keep it.

For anything else, write to privacy@indiewright.com. We respond within 30 days and we do not charge for it. Residents of California, the EU, the UK and other regions with specific statutory rights may exercise them through the same address; we apply these rights to everyone rather than only where required.

Security

No system is perfectly secure. If we discover a breach affecting your personal data, we will tell you what happened, what was exposed, and what we are doing — promptly and without minimising it.

Children

Indiewright is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact privacy@indiewright.com and we will delete it.

Cookies and local storage

We use browser storage for one purpose: keeping you signed in and remembering interface preferences such as your last-used tab. There are no advertising or analytics cookies, and no third-party trackers.

International transfers

Our providers are located in the United States. If you use Indiewright from outside the US, your data is processed there.

Changes

If we change this policy materially, we will email registered users rather than quietly updating the date at the top.