Privacy Notice

How we collect, use, and protect your information.

Effective Date: 30 July 2026

1. Controller Details

Red Hammer Limited trading as Locker ("Locker", "we", "us", "our") is the controller of personal data processed in connection with the website and the Services, except where we act as a processor on behalf of business customers (see DPA).

Address: Willowbank, Main Street, Hanwell, Banbury, Oxfordshire, OX17 1HP, UK
Contact: support@getlocker.co
Website: www.getlocker.co

2. Categories of Personal Data

We may collect and process the following categories of personal data:

2.1 Account and identity data

Email address, display name, authentication identifiers, and related account information. Passwords are stored hashed and are not stored in plain text.

2.2 Content and collaboration data

Content you upload or create (including audio files), associated metadata, and communications/messages within the Services, as well as sharing and collaboration activity.

2.3 Usage, device, and technical data

Service usage analytics, device/browser information, and diagnostic data including error and performance logs (e.g., via Sentry).

2.4 Share recipient data

When someone opens a link that a Locker user has shared with them, we record that the link was opened, played or downloaded, along with the time and a randomly generated identifier stored in that person's own browser so repeat visits from the same device can be recognised. We also record the type of device used (for example iPhone or Mac) and the approximate country of the connection, both derived at the time of the visit. We do not store the IP address of share visitors for this purpose, and we do not use device fingerprinting.

If the person who created the link turned on the option to ask who is listening, the recipient is asked to give a name before playing or downloading, and that name is stored alongside those same records and shown to the sender. Recipients are told on the page, before they play anything, that the sender can see when they open, play and download the content. The name is self-declared and we do not verify it. Where the name matches a contact already saved by the sender, we associate the activity with that contact so the sender can see it in one place.

2.5 Billing and transaction data

Subscription status, invoices, and payment confirmations (payment card data is processed by our payment provider and not stored by us in full).

3. Purposes of Processing

We process personal data to:

  1. provide, operate, secure, and maintain the Services;
  2. create and administer accounts;
  3. process subscriptions and payments;
  4. provide customer support and troubleshooting;
  5. monitor performance, prevent abuse, and ensure security;
  6. tell a user who has opened, played, or downloaded content they shared, where they have enabled that; and
  7. develop and improve the Services, including analytics.

4. Legal Bases

We rely on the following legal bases (as applicable):

  • Contract: to provide the Services and perform our obligations to you.
  • Legitimate interests: to secure the Services, prevent fraud/abuse, ensure reliability, and conduct proportionate analytics and improvement.
  • Legal obligation: to comply with applicable laws (e.g., tax/accounting).

5. Disclosures; Processors

We may disclose personal data to vendors and service providers acting as processors, including:

  • Supabase, London, United Kingdom (Database, authentication, and file storage)
  • Vercel, Global edge network (Website and application hosting)
  • Google Cloud, London, United Kingdom (Audio analysis service (tempo, key, and audio characteristics))
  • OpenAI, United States (AI assistant features (text only, audio files are never sent))
  • Resend, United States (Transactional and notification email)
  • Stripe, United States and European Union (Subscription payments and billing)
  • Sentry, United States (Error and performance monitoring)

The current list is always published on our Subprocessor List page.

We do not sell personal data.

6. AI Processing

Where you use AI features, we transmit only the data necessary to provide the feature (typically user prompts and limited relevant context such as metadata). For Kii, audio files are not sent to OpenAI as part of the feature design.

We do not use your music to train AI models. We do not provide your audio recordings, lyrics or catalogue content to any third party for the purpose of training, fine-tuning or improving their models, and we do not train models of our own on your content. Audio analysis (such as tempo, key and audio characteristics) is performed to describe your own recordings back to you within your own account, and its results are not pooled into any shared or public model.

7. International Transfers

Your audio files, catalogue database and account records are stored in the United Kingdom, and audio analysis is performed in the United Kingdom.

Some supporting services (payments, email delivery, error monitoring and AI assistant text) are provided by processors located outside the UK, as identified in Section 5. Where personal data is transferred outside the UK, we use appropriate safeguards (e.g., standard contractual clauses or UK transfer instruments) and other measures required by law.

8. Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Notice, including legal, regulatory, security, and operational requirements. Where no fixed period is stated, we determine retention based on criteria such as data sensitivity, legal obligations, security needs, and dispute risk.

Baseline (current):

  • AI conversation/tool logs: 90 days
  • Admin audit logs: 2 years
  • Active account data: for the duration of the account
  • Share open/play/download records, including any name a recipient gave: retained with the share they belong to, and deleted when that share is deleted

9. Security

We implement technical and organisational measures designed to protect personal data, including encryption, access controls, monitoring, and audit logging. Additional information is available on our Security page.

10. Your Rights

Subject to applicable law, you may have rights including access, rectification, erasure, restriction, objection, and portability. Requests may be submitted to support@getlocker.co.

11. Complaints

Where applicable, you may lodge a complaint with your supervisory authority. In the UK, this is the ICO.

12. Contact

support@getlocker.co


© Red Hammer Limited 2026. All rights reserved.