Marya Labs / Legal

Legal document

Privacy Policy

This website collects your email address when you download, subscribe, apply for the beta, or contact support. The DAWN and MeterStack software is different: it has no Marya Labs server behind it and sends us nothing. But DAWN does send data — including screenshots of your screen — to whichever AI provider you connect it to. That distinction is the most important thing on this page, so it is covered in detail below.

Last updated 27 August 2026 · Governed by the laws of England and Wales

Contents

  1. 01Who we are
  2. 02The short version
  3. 03What this website collects
  4. 04What the DAWN and MeterStack software sends us
  5. 05What DAWN sends to your AI provider
  6. 06Data DAWN keeps on your own computer
  7. 07How long we keep website data
  8. 08Your rights
  9. 09Who else sees this data
  10. 10International transfers
  11. 11Children
  12. 12Changes to this policy

01Who we are

Marya Labs ("we", "us") is the data controller for the personal data described in this policy. We are a small independent studio building music production software. We are not currently incorporated as a limited company.

You can reach us about anything in this policy at support@maryalabs.io. We aim to reply within a few working days, and we handle formal data rights requests within the one-month statutory deadline.

This policy is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

02The short version

Because the honest summary is unusually favourable to you, it is worth stating plainly before the detail:

  • This website collects your email address and, if you write to us, your name and message. It sets no tracking cookies and runs no analytics.
  • The DAWN and MeterStack software does not send us your data. There is no Marya Labs account system, no licence server, and no usage tracking switched on in the shipped build. DAWN does not phone home to check whether it may run.
  • Your API keys are encrypted on your own machine and are never transmitted to us.
  • Your audio never reaches us. Raw audio does not leave your computer through anything we build.
  • However: when you use DAWN, the content of your work — and, if you use Mac control, screenshots of your screen — is sent to the AI provider you chose and paid for. We are not in that path, but you should understand it clearly. See What DAWN sends to your AI provider.

The sections below are the operative text. This summary is written for clarity, not as a substitute for it.

03What this website collects

Everything below is collected only when you actively submit it or download something. We do not build advertising profiles, we do not sell data, and we do not share it with data brokers.

WhenWhat we storeWhyLawful basis
You subscribe to release notesEmail address, the page you subscribed from, a pseudonymised IP hash, browser user-agent, timestampTo send you the updates you asked for, and to stop automated abuse of the formConsent (UK GDPR Art. 6(1)(a))
You download DAWN or MeterStackEmail address (where given), product and file name, platform, pseudonymised IP hash, user-agent, referring page, timestampTo deliver the download, count installs, and prevent abuse of our bandwidthLegitimate interests (Art. 6(1)(f)) for delivery and abuse prevention; consent for any resulting emails
You apply for the betaEmail address, name (optional), intended use, operating system, the page you applied fromTo manage beta participation and contact you about itConsent (Art. 6(1)(a))
You contact supportName (optional), email address, the message you wrote, pseudonymised IP hash, user-agent, timestampTo answer you, and to keep a record of the conversationLegitimate interests (Art. 6(1)(f)) in responding to enquiries
We send you an emailDelivery status and the address it went toTo diagnose failed deliveryLegitimate interests (Art. 6(1)(f))

About the IP hash

We do not store raw IP addresses in our database. We store a SHA-256 hash of the address combined with a secret salt, which lets us count unique downloads and apply rate limits without holding the address itself.

We describe this as pseudonymised, not anonymised, and that distinction is deliberate. A salted hash is still personal data under UK GDPR, because it can be linked back to an individual by someone holding the salt. We are not going to call it anonymous when it is not.

What we do not collect

  • No advertising or analytics cookies. See the Cookies and Tracking Notice.
  • No third-party trackers, pixels, or session recording.
  • No payment details — we do not currently sell anything.
  • No special category data (health, biometrics, beliefs, and so on). Please do not send any in a support message.

04What the DAWN and MeterStack software sends us

The answer is: nothing

There is no Marya Labs backend behind either product. This is a design decision, not an oversight, and it is worth being specific about what it means.

  • No account and no licence server. DAWN never contacts a server to decide whether it may run. There is no login, no entitlement check, no subscription, and no activation.
  • No analytics in the shipped build. DAWN contains an optional product-analytics feature which is switched off by default. Even when switched on, the released build has no delivery endpoint configured, so it transmits nothing.
  • No crash reporting in the shipped build. The same applies to crash telemetry, which additionally requires you to consent to a specific version of the wording. If the wording changes, prior consent is invalidated rather than carried over. Crash records never read the text of the error message, only its type and a sanitised stack outline.
  • No auto-update. There is no background updater, no auto-download, and no scheduled check. With no update feed configured, the update check performs no network activity at all — not even a DNS lookup.
  • No audio. Raw audio never leaves your machine through our software. Where MeterStack passes measurements to DAWN, it does so over a local socket on your own computer, and the receiver actively rejects raw audio if anything tries to send it.

The one exception

When DAWN starts, it requests a time sample from `time.cloudflare.com` to check the current date against the beta expiry date. This is a network request, so Cloudflare will see your IP address, as it would for any internet request. It carries no information about you, your projects, or your usage. If it fails, DAWN carries on regardless.

Where your API keys are kept

Provider credentials — API keys and, if you use ChatGPT login, your OAuth tokens — are stored in an encrypted vault on your own machine. DAWN’s configuration file holds only opaque references to those records, never the credential itself. Keys are stripped from logs, error messages, and audit records before anything is written to disk. They are never sent to us.

Because we never hold them, we cannot recover them for you if you lose them, and we cannot disclose them to anyone else.

05What DAWN sends to your AI provider

Read this section

This is the most significant privacy consideration in the product, and it is the one people are most likely to be surprised by.

DAWN is a bring-your-own-key product. It has no models of its own. When you use it, it sends your request to whichever provider you connected — OpenAI, Anthropic, Google, OpenRouter, ElevenLabs, Google Lyria, MiniMax, OpenCode, or ChatGPT via account login.

In that exchange, the provider receives:

  • What you type to the agent.
  • Context about your session — including track names and project and arrangement structure.
  • The results of actions the agent takes, so it can decide what to do next.
  • For audio generation, your text prompt and settings such as duration, key, and tempo.
  • If you use web search, your search query, which is passed to search engines through an intermediary that queries several backends.
  • If you use Mac control: a screenshot of your screen.

The screenshot point, specifically

DAWN’s Mac control lets the agent see your screen and operate macOS applications on your behalf. To do this it captures a screenshot and attaches it to the next request to your AI provider, where the provider supports images. That screenshot is a picture of whatever was on your screen — which may include applications, documents, messages, or other content that has nothing to do with music.

Two things limit this, and both are real, but neither makes it risk-free:

  • DAWN refuses to capture an unredacted screenshot when it detects a password or other secure input field visible on screen, and it refuses to type into one.
  • The image is used for that single turn and then discarded. Screenshot data is never written into DAWN’s audit log, its saved history, or its log files, and text recognition runs locally on your Mac rather than in the cloud.

What those protections do not do is prevent the image reaching your provider in the first place. That is the purpose of the feature. If you work with confidential material on the same machine, consider whether Mac control should be enabled while you do. It can be switched off in settings, and there is a kill switch.

We are not a party to that exchange

When DAWN talks to your provider, it uses your account under your contract with them. We are not an intermediary and the traffic does not pass through us. What the provider does with your data — whether it retains it, how long for, and whether it uses it to train models — is governed by your agreement with that provider, not by this policy.

For the same reason, those providers are not our sub-processors. We do not choose them, we do not pay them, and we cannot instruct them on your behalf. Please read the privacy terms of any provider before connecting it. See the Sub-processors page for how we draw this line.

06Data DAWN keeps on your own computer

DAWN stores a fair amount locally, in a folder called `.dawn` in your home directory. This is your data on your machine; we have no access to it. It is listed here so you know what exists and can delete it if you want to.

WhatKept for
Settings and encrypted credential vaultUntil you remove them
Chat transcripts and thread historyUntil you delete them
Your profile and learned preferencesUntil you delete them
Action audit log — a redacted record of every change DAWN made to your projectRetained deliberately, rotated by file size rather than age, so the record of what was changed is not silently lost
Developer trace log3 days by default
Diagnostic logsRotated files kept 3 days
Optional local analytics queue30 days by default, adjustable
Local learning databaseRaw detail is compacted after 30 days, leaving aggregates
Generated audio and analysis filesUntil you delete them

The audit log deliberately redacts what it records: text you typed, window and screen text, and any shell or AppleScript commands are replaced with a redaction marker and a character count. The record shows that something happened and what kind of thing it was, without preserving the content.

Local learning is on by default, with a first-run notice. It records how you rate and correct the agent’s work so it improves for you, and it is explicitly barred from capturing credentials, screenshots, raw audio or MIDI, or your full session state. You can pause it, inspect what it holds, export it, or tell it to forget.

Deleting the `.dawn` folder removes all of it. Since none of it reaches us, we cannot delete it for you.

07How long we keep website data

These periods apply to the data this website holds. They are set out in code alongside the deletion routine, so the published schedule and what actually happens stay in step.

RecordRetention
Newsletter and release-note subscribersUntil you unsubscribe, and in any case no more than 3 years of inactivity
Download notification signups2 years
Download records365 days
Download links30 days (they expire long before this)
Email delivery log90 days
Beta applications2 years
Support conversations2 years

We may keep a record longer where we have to — for example, if it is relevant to a legal claim. If we do, we keep only what is necessary for that purpose.

08Your rights

Under UK GDPR you have the following rights over personal data we hold about you. Exercising them is free, and you do not need to give a reason.

Access (Art. 15)
Ask for a copy of the personal data we hold about you.
Rectification (Art. 16)
Ask us to correct anything inaccurate.
Erasure (Art. 17)
Ask us to delete it. For marketing data we will simply do so.
Restriction (Art. 18)
Ask us to stop using it while a dispute about it is resolved.
Portability (Art. 20)
Ask for it in a machine-readable format, or ask us to send it elsewhere.
Objection (Art. 21)
Object to processing based on legitimate interests. You can object to direct marketing at any time and we must stop.
Withdraw consent (Art. 7(3))
Where we rely on consent, withdraw it at any time. Every email we send includes an unsubscribe link.

To exercise any of these, email support@maryalabs.io. We will respond within one month. We may ask you to confirm your identity, but only to the extent needed to be sure we are not disclosing your data to someone else.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk. We would appreciate the chance to put it right first, but you are not obliged to come to us before going to them.

09Who else sees this data

We keep the list short on purpose. The full detail, including what each party does and where they are located, is on the Sub-processors page.

  • Our hosting provider, which runs the server and database this website uses.
  • Our email provider, which delivers the messages you asked for.
  • That is the whole list for website data.

We do not sell personal data, we do not share it for advertising, and we do not transfer it to anyone for their own purposes. We may disclose data if we are legally required to, and we will tell you if that happens unless we are prohibited from doing so.

10International transfers

Our infrastructure providers may process data outside the UK. Where that happens, we rely on UK adequacy regulations or on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, as appropriate.

If you connect an AI provider to DAWN, your data goes wherever that provider processes it. That transfer is under your contract with them, not ours.

11Children

Our products are not directed at children. You must be at least 16 years old to use them, as set out in the Terms of Service. DAWN requires your own paid accounts with AI providers and can operate your computer, which is not appropriate for a child.

If you believe a child has given us personal data, contact support@maryalabs.io and we will delete it.

12Changes to this policy

We will update this policy when what we do changes. The date at the top always reflects the current version.

If we make a change that materially affects your rights — for example, if we start collecting something new or begin transmitting data from the software — we will say so clearly rather than quietly revising the text, and we will notify subscribers by email.

Questions about this document? Email support@maryalabs.io.

See all documents in the legal index.

ML / DAWN · SYSTEM FOOTER NETWORK STABLE
Primary system

DAWN BY MARYA LABS

A first-of-its-kind AU/VST3 plugin with an AI agent inside it. It works Ableton Live and your Mac for you, while you keep the creative call.

Public beta · AU / VST3 · macOS
Explore
  • Capabilities↗
  • Provider Ecosystem↗
  • Autonomy & Trust↗
  • Provider Choice↗
  • DAWN Changelog↗
  • MeterStack Page↗
Access
  • Download DAWN↗
  • Download MeterStack↗
  • Support↗
  • support@maryalabs.io↗

Subscribe

Quiet DAWN beta notes and important release updates.

We use your address only to send these updates. Unsubscribe any time. See our Privacy Policy.

© 2026 Marya Labs
Terms·DAWN EULA·Privacy·Cookies·All legal
DAWN · An AI agent in your plugin slot.