Blackwires Band operations app
Use cases Workflow App views Plans App Store Google Play
Privacy

Blackwires privacy notice.

Blackwires is a private workspace for musicians, bands and crews. This notice explains what personal data we use, why we use it, how long we keep it and the choices available to you.

Blackwires band profile and brand screenshot

1. Who is responsible

Strider Solutions e.U., Austria, is the data controller for the Blackwires website, app, accounts and service operations described in this notice.

Privacy, account, export and deletion requests can be sent to blackwires@strider.solutions. Please include the email address used for your Blackwires account and enough information for us to understand the request. We may ask for reasonable proof of identity before disclosing or changing account data.

2. Where personal data comes from

We receive personal data directly from you when you register, use the service, upload content or contact support. We may also receive it from a workspace owner or member who invites you or adds collaboration details; from the app, browser or device used to access Blackwires; and from Apple, Google or another authorised store when it confirms a purchase or subscription entitlement.

3. Data we process and why

Account and authentication data

Email address, display name, internal user id, login and session identifiers, invitation status, workspace role and membership details. We use these to create and secure accounts, sign users in, deliver invitations, apply access controls and administer the service.

Workspace and collaboration content

Songs, setlists, event and venue details, tasks, notes, band profiles, member information, media references and other content that users choose to add. We process this content to store, sync, display, share and organise it for authorised workspace members.

Files, images and recordings

Logos, photographs, documents, audio recordings and related files are processed only when a user uploads, records, imports or attaches them. Users are responsible for having permission to submit personal data about other people.

Subscription and transaction references

Store, product, subscription, renewal, expiry and entitlement identifiers are used to confirm paid access, prevent misuse and provide subscription support. When a purchase is made through Apple or Google, the store processes payment-card and billing details; Blackwires does not receive or store the complete payment-card number.

Venue and map information

Addresses, coordinates and venue notes entered by users can be used to provide event and map context. Precise device location is not required for the core workspace workflow.

Technical, security and support data

IP address, device and browser type, operating system, app version, requested page or API route, timestamps, session and security events, crash or error context, support messages and relevant account state may be processed to operate the service, diagnose problems, protect accounts, prevent abuse and answer support requests.

4. Legal bases

Contract and steps requested by you

We process account, workspace, upload, sync, entitlement and requested support data where this is necessary to provide Blackwires, administer your subscription or take steps you request before entering a contract (Article 6(1)(b) GDPR).

Legitimate interests

We process limited technical, diagnostic, security and administrative data to keep Blackwires reliable and secure, prevent fraud and abuse, enforce access controls, establish or defend legal claims and improve service operation (Article 6(1)(f) GDPR). These interests are balanced against the rights and expectations of users.

Legal obligations

We process and retain information where necessary to comply with accounting, consumer-protection, tax, regulatory or lawful authority requirements (Article 6(1)(c) GDPR).

Consent

Where an optional activity is specifically based on consent, we ask before processing and you may withdraw that consent at any time (Article 6(1)(a) GDPR). Withdrawal does not affect processing that was lawful before it. Device permissions are also controlled through the operating-system settings.

5. Required and optional information

An email address, authentication information and the minimum account and entitlement records are required to create and secure an account and provide paid features. If these are not provided, we cannot provide the relevant service. Workspace content, uploads, microphone access, photo-library access, file-picker access and most profile details are optional, but a feature selected by the user may not work without the data or permission it needs.

Microphone access supports features such as tuner and practice recording. Photo-library and file access are used when a user selects media or documents. Network access is required to authenticate and sync with the Blackwires service.

6. Google user data

This section applies only when a user chooses Sign in with Google or deliberately connects Google Drive to Blackwires. Blackwires does not receive Google user data merely because the app is installed or because a user signs in or stores files by another method.

Google data Blackwires accesses

For Sign in with Google, Blackwires requests the openid, email and profile permissions. Google may return the user's unique Google account identifier, primary email address and email-verification status, display name, given and family names, profile picture, and other basic profile claims included by Google in that response.

For an optional Google Drive connection, Blackwires requests the drive.file permission. Blackwires may access the OAuth access and refresh tokens issued for the connection; the connected account label; and the identifiers, names, MIME types, sizes, timestamps, links, folder information and content of only the Google Drive files and folders that the user selects, creates, opens or otherwise uses with Blackwires. Blackwires does not request unrestricted access to every file in the user's Google Drive.

How Blackwires uses Google data

Google account data is used to authenticate the user, create or link the correct Blackwires account, display the user's chosen name or profile image, secure the sign-in flow and provide account support. Google Drive data is used only to establish and maintain the connection and, at the user's direction, list relevant files, preview or download content, attach documents or media to Blackwires records, upload or export files, and perform requested file organisation operations.

Blackwires does not use Google user data for advertising, retargeting, behavioural profiling, creditworthiness or lending decisions, sale to data brokers or information resellers, or training general-purpose artificial-intelligence or machine-learning models.

What Blackwires stores

For Google sign-in, Blackwires stores the Google account identifier and the account and profile claims needed for account linkage, authentication, security and support. For Google Drive, Blackwires stores the encrypted OAuth tokens, authorised scope and expiry information, connection settings, and references and metadata for files deliberately used with Blackwires.

Google Drive file content is normally accessed on demand. If a user deliberately imports or copies a Drive file into Blackwires, the imported copy becomes Blackwires workspace content and follows the ordinary workspace visibility and retention rules in this notice. The original file remains in Google Drive and is controlled through the user's Google account.

Sharing, transfer and disclosure

Blackwires does not sell Google user data. Google account profile information and Google Drive data are disclosed to other Blackwires users only when needed for an authorised workspace feature and according to the relevant workspace role, connection ownership, visibility setting and the user's deliberate sharing or attachment action. A personal Drive connection is not made available to other workspace members unless the user chooses a band-visible workflow; a band-owned connection is available only to authorised members according to their permissions.

Google user data may be processed by contracted hosting, database, storage, networking, security, monitoring and support providers acting for Strider Solutions e.U. and subject to appropriate instructions and confidentiality obligations. Data may also be disclosed when required by law or necessary to investigate abuse, protect users or defend legal rights. Google receives the API requests necessary to provide Google Sign-In and Google Drive. We do not transfer Google user data to advertising platforms, data brokers or information resellers.

Data protection

Google user data is protected in transit using HTTPS/TLS. Google Drive OAuth access and refresh tokens are encrypted at rest using authenticated AES-256-GCM encryption. Blackwires also uses authenticated sessions, role- and ownership-based access controls, the limited drive.file permission, restricted server access, security logging and protected backup procedures designed to prevent unauthorised access, alteration, disclosure, loss or destruction.

Retention, disconnection and deletion

Google sign-in identifiers and profile claims are kept while the Google identity remains linked to an active Blackwires account and as needed for authentication, security and support. They are removed from active systems when the Blackwires account is validly deleted or a valid deletion request requires their removal, subject to legal requirements and the protected backup rotation described below.

Google Drive tokens and connection metadata are kept only while the connection exists and is needed to provide the requested feature. They are removed from active systems when the connection or its owning account or workspace is deleted, or when a valid deletion request requires removal. A user may also revoke Blackwires access at any time in the security settings of their Google account; revocation prevents further access through the revoked authorisation. Disconnecting Blackwires does not delete original files from Google Drive. Any copy deliberately imported into a shared Blackwires workspace follows the shared-workspace retention rules below.

To request access, disconnection or deletion, use the account controls available in Blackwires or email blackwires@strider.solutions from the address associated with the account.

Blackwires' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Who receives personal data

We disclose only the data needed for the relevant purpose to these recipient categories:

Workspace participants

Owners, administrators and members of a workspace can access content and member information according to their role and permissions.

Service providers

Contracted hosting, database, storage, content-delivery, networking, security, monitoring, email and customer-support providers process data for us under appropriate instructions and confidentiality obligations.

Stores and connected services

Apple, Google or another authorised store processes purchases and returns entitlement information. If a user deliberately opens or connects a map, cloud-storage, file-sharing or other external service, the information needed for that action may be sent to the chosen provider under its own privacy terms.

Professional and legal recipients

Professional advisers, courts, regulators, law-enforcement bodies or other authorities may receive data when necessary to meet a legal obligation, protect rights and safety, or establish, exercise or defend legal claims.

Blackwires does not sell personal data and does not use personal data for third-party advertising or cross-service advertising tracking.

8. International transfers

Some providers or connected services may process information outside Austria or the European Economic Area. Where GDPR transfer restrictions apply, we rely on an adequacy decision or appropriate safeguards such as the European Commission's standard contractual clauses, together with supplementary measures where required. Users who intentionally connect an external service should also review that provider's location and privacy terms. Further information about relevant safeguards can be requested at blackwires@strider.solutions.

9. How long data is kept

Accounts and workspaces

Account and active workspace data is kept while the account or workspace is active and as needed to provide the service. When an account or workspace is validly deleted, personal data under our control is deleted or anonymised unless continued retention is required for another lawful reason.

Shared workspace content

Content shared with a band or crew may remain available to that workspace after one member leaves. Where activity or authorship history must remain understandable for the other members, the departing member's personal attribution may be anonymised instead of deleting the shared operational record.

Subscriptions and legal records

Entitlement records are kept while needed to provide subscription access, handle store reconciliation, resolve disputes and meet applicable accounting, tax and legal-retention requirements. They are then deleted or anonymised.

Support, security and diagnostics

Support correspondence, error information and security logs are kept only for as long as reasonably needed to resolve the request, maintain service and account security, investigate misuse, and establish or defend legal claims. Information that is no longer needed is deleted or anonymised.

Backups

Residual copies may remain in protected backups until they are overwritten through the ordinary backup rotation. Backups are isolated from routine use and are used only for security and disaster recovery.

When law or a dispute requires longer retention, the relevant information is restricted to that purpose and kept only until the applicable obligation or limitation period ends.

10. Your data-protection rights

Subject to the conditions and exceptions in the GDPR, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing and delivery of data you provided in a portable format. You may object to processing based on legitimate interests, and you may withdraw consent where consent is the legal basis.

Send a request to blackwires@strider.solutions. We will respond without undue delay and normally within one month, although the GDPR allows an extension for complex or numerous requests. You also have the right to lodge a complaint with the Austrian Data Protection Authority or the competent supervisory authority where you live or work.

11. Account deletion and shared work

Account deletion can be requested in the app where available or by emailing blackwires@strider.solutions. A request may require the user first to transfer workspace ownership or resolve an active subscription. Cancellation of a store subscription and deletion of a Blackwires account are separate actions.

Deleting an account removes or anonymises the account holder's personal profile and access, subject to the retention rules above. It does not automatically erase material that belongs to a shared workspace or copies independently exported by other authorised members.

12. Website logs and cookies

The public Blackwires website does not use third-party advertising trackers. The website and its infrastructure may process standard request information such as IP address, browser type, requested page, timestamp and security events for delivery, troubleshooting and protection against abuse. If strictly necessary cookies or local storage are used, they support functions requested by the visitor and are not used for advertising.

13. Automated decisions

Blackwires does not make decisions based solely on automated processing that produce legal or similarly significant effects for users, and it does not use personal data for behavioural profiling or targeted advertising.

14. Children

Blackwires is not specifically directed at children. A minor should use the service only with the involvement and authorisation of a parent, guardian or responsible organisation where required by law. Contact us if you believe a child's personal data was submitted without proper authority.

15. Security

We use technical and organisational safeguards designed to protect personal data against unauthorised access, alteration, disclosure, loss and destruction. No internet or storage system can be guaranteed completely secure, so users should protect their credentials and promptly report suspected account misuse.

Changes to this notice

We may update this notice when Blackwires, its providers or legal requirements change. The current version is published at this URL, and material changes will be highlighted in the app or through another appropriate channel when required.

Last updated: 27 July 2026.

Blackwires | A Strider Solutions e.U. product | blackwires@strider.solutions | Support | Terms | Privacy