Skip to content
Berry FXBerry FX

Privacy.

What the plugins send

No telemetry, no analytics, no usage counts and no crash reports. Your license is verified on your own machine against a key compiled into the binary.

Licensed plugins check in with us periodically to confirm that the software is authorized for licensed use. A check-in sends the license key, the machine ID and the plugin version, and returns only whether that license is in good standing. Nothing about your projects, your audio or how you use the software is collected or transmitted.

When you activate a plugin you can paste a license from your account page, or let the plugin fetch it in one click. The one-click path sends your license key, the machine ID and a machine name — your computer’s name, so you can tell your seats apart — and receives the signed license in return. It is optional and only happens when you press the button: a machine with no internet activates by pasting instead, and either way the license is verified on your own machine.

What this website stores

WhatWhy
Your email addressTo send your license and sign-in links, and — if you opt in — occasional news about new plugins. You can opt out any time.
Your name, if you give oneTo print “Licensed to …” in the plugin. Optional.
Your ordersReceipts, and because tax law requires a seller to keep sales records.
Your license keys, machine IDs and machine namesTo count seats and let you tell them apart. A machine ID is a hash, not a hardware serial; a machine name is a label you can edit or remove.
Billing country, and VAT number if givenTo charge the right tax and file the right returns.
An IP address on activationRate limiting, so nobody can walk the license key space.
Download recordsWhich plugin you downloaded and the IP address you downloaded it from, so we can count downloads and see how many people go on to become customers, and a note of which addresses we have seen your email address used from, so a download can be matched to you. Kept 180 days, after which the address is erased and only the count remains.
An IP address on your account and ordersThe address you opened the account from and the one you last signed in from, so we can show you where your account is being used, and the address an order was placed from, for fraud checks. The sign-up and order addresses are erased after 180 days; the last-signed-in one is a single current address, overwritten each time you sign in, and goes when you close your account.
Check-in recordsLicense key, machine ID, plugin version and IP address, to confirm authorized use. Kept 90 days.
Your tester application, if you send oneYour name, email, which DAWs you use, how long you have been at it, what you told us you make, and any links you gave us to your own site or social accounts — so we can decide whether to send you a plugin, and so you can tell us where a review will appear. Also the IP address it was sent from, for rate limiting, which is erased after 90 days.
Your feedback reportsWhat you said about each plugin, including what you think a fair price for it would be, and which DAW and version you ran it in. We read these and act on them.
Files you attach to a reportPresets and screenshots you upload. They are not public: only you and we can open them, and they are held on our own server, never on the content network the installers come from.
A video link, if you give oneThe address of a video you made. We store the link and never the video, and we do not fetch it or watch it on your behalf.
Your permission to use your material, if you give itThe date you ticked the box and the exact wording you agreed to, so we can show you what you agreed to and you can take it back. The withdrawal is recorded separately rather than by deleting the permission, because the record of what was agreed is the thing that protects you if we ever disagree about it.

What we do not store

No card details. Payment happens on Stripe’s pages; the card never touches this server. We are told the last four digits and the country, and that is all.

No third-party analytics. No Google Analytics, no pixels, no tracking scripts of any kind, and nothing that follows you to another website. There is still no cookie banner on this site because there is still nothing to consent to: the one cookie is the session that keeps you signed in, which is strictly necessary and exempt.

We do count downloads. When you download a plugin we record which one and the address you asked from — on our own server, in our own database, and nowhere else. It is what tells us whether a plugin people download is a plugin people keep.

We link a download to a person where we can. Signing in, buying, subscribing to the newsletter or starting a trial tells us your email address was used from that IP address, and we match downloads from the same address to you — including ones made before you told us who you were, as far back as the 180-day window. A click token or a signed-in session is exact evidence. A match on the address alone is recorded as a guess, and once several people have used the same address we stop guessing: those downloads stay counted but attributed to nobody. The address is erased after 180 days, closing your account erases it immediately, and none of it is ever sold, shared, or used to build a profile of you anywhere but here.

No fonts from a CDN. Gelasio is served from this domain. Loading fonts from Google’s CDN transmits a visitor’s IP address to a third country, which a German court has already held to be unlawful without consent.

Marketing email

We send product news — a new plugin, a launch — only to people who asked for it. There is an unticked checkbox when you create an account and at checkout; leaving it unticked means you hear from us only about your own licenses and orders. Existing customers may also get the occasional note about a similar new plugin, which you can stop with one click. Every marketing email carries an unsubscribe link, and you can turn it on or off any time under account settings. We do not sell or share your address for anyone else’s marketing.

Who else sees it

  • Stripe: payment processing. They see your card and billing details; we do not.
  • Our email provider: to deliver receipts and sign-in links.
  • Klaviyo: our marketing-email platform. Only if you opt in, and only your email address and which products you bought, so we can send the product news you asked for. Nothing goes to them until you opt in, and an unsubscribe removes it.
  • Our hosting provider: because the database sits on their disk.

Nobody else. Your data is not sold, rented, shared with advertisers, or used to train anything.

Where your data goes

Some of the companies above are in the United States — Stripe, Klaviyo and our email provider among them — so if you are in the EU or the UK, some of your data is handled there as part of taking your order and running your license. Those transfers rely on the standard safeguards the law provides for them: Standard Contractual Clauses, and the EU–US Data Privacy Framework where a provider is certified under it. Wherever it is handled, it is used only for what this page describes.

How long

Orders are kept as long as tax law requires, which is years and is not our choice — but the IP address an order was placed from is erased after 180 days, and so is the address an account was opened from. The address you last signed in from is kept while the account is open, because it is what we show you on your security page, and it is overwritten each time you sign in rather than kept as a history. Check-in records are kept 90 days. The IP address on a download record, and the note of which addresses we have seen your email address used from, are kept 180 days, after which they are erased and an anonymous count is all that is left. Everything else is deleted when you close your account, download records included — the count survives, because by then it names nobody. Rate-limit rows are transient and disappear on their own. A tester application that was declined is deleted after a year, and a report you started and never sent after six months, along with anything attached to it.

On what basis

In the language of the GDPR, we hold what we hold for four reasons. Your orders and license records are a legal obligation — tax law — and part of the contract you enter by buying. Verifying a license, rate-limiting activation and preventing abuse are our legitimate interest in the software being used by the people who paid for it, and so is counting downloads and whether they lead to sales — a shop is entitled to know which of its products people actually take, which is why the window is short and the record holds nothing beyond the plugin and the address. Marketing email is consent, which you give by ticking the box and withdraw by unsubscribing. Taking part in the testing program is the contract you entered by asking to join and our agreeing — that is what holds your application and your reports. Letting us use your video, your screenshots or your presets in our own marketing is separate, and it isconsent: you give it by ticking a box, you can withdraw it at any time, and taking part does not depend on it. Nothing here rests on a basis you cannot see or undo.

Who is responsible

This site and the Berry FX plugins are run by Elefant Music LLC, 1 Industrial Way West, Eatontown, NJ 07724, United States. That company is the data controller for the data described here — the one accountable for it under the law.

Your rights

Under the GDPR and equivalent laws you can ask for a copy of what we hold, ask for corrections, ask us to delete it, ask for it in a portable form, or ask us to stop or limit a particular use. Where a use rests on your consent — marketing — you can withdraw it at any time. Email support@berryeffects.com and we will do it: no form to fill in, no department to be routed through.

The one thing we cannot delete on request is a record we are legally required to keep. We will say which, rather than quietly keeping it.

If you gave us permission to use something you made and later take it back, we stop using it and take down what is ours to take down. We cannot recall a copy somebody else has already shared, and we would rather say so plainly than promise otherwise.

If we get any of this wrong, you can also complain to your data-protection authority — in the EU, the regulator in your own country; in the UK, the Information Commissioner’s Office. We would rather you told us first, so we can put it right faster than they can.

Children

Berry FX is sold to adults and is not aimed at children. We do not knowingly collect anything from anyone under 16; if you think a child has given us their details, email support@berryeffects.com and we will remove them.

Changes

If this page ever changes in a way that matters, it will be in the changelog rather than silently edited.