Acceptance
By creating an account, signing in, or using vault.session.am, our iOS, Mac, or Chrome clients, or our APIs, you agree to these Terms and to our Privacy Policy. If you're using Vault on behalf of an organization (a label, studio, or management company), you represent that you have authority to bind that organization to these terms.
If you don't agree, don't use the service.
Your account
You must be at least 13 to use Vault, and at least 18 to enter a paid plan. You are responsible for your password and your recovery phrase. We strongly recommend turning on 2FA and setting up end-to-end encryption at first sign-in.
One human, one account. Bring collaborators in through Sharing, each on their own account. Selling, transferring, or sharing logins is not allowed and is grounds for termination.
If you forget your password and lose your recovery phrase, we cannot recover your encrypted files. That is the design. See how encryption works.
Your content
You keep ownership.
Every track, stem, lyric, cover, comment, and bit of metadata stays yours. Uploading to Vault transfers no copyright, no master rights, no publishing rights, no ownership interest of any kind.
The license you give us.
To run the service, you grant Capiscana a worldwide, non-exclusive, royalty-free license to store, transmit, encode, encrypt, decrypt (for you), and display your content, solely to deliver the service to you and the people you share with. The license ends when you delete the content or close your account.
What we won't do.
- Train any AI model on your audio, lyrics, or metadata.
- License, sell, or sub-license your content to third parties.
- Publish, broadcast, or stream your content outside the recipients you authorize.
- Access plaintext audio for any purpose other than fulfilling a feature you triggered (AI analysis, transcoding, watermarking, leak detection).
What you promise.
You confirm you have the rights to upload everything you upload: masters, stems, samples, vocals, the whole package. If you upload someone else's work without authorization, you are on the hook. We cooperate with valid takedown notices under our DMCA policy.
Acceptable use
Don't use Vault to:
- Host or distribute content that infringes copyright, including bootlegs and unauthorized samples.
- Host CSAM, non-consensual intimate content, or material that violates applicable law.
- Reverse engineer, decompile, or extract source code from our clients or service workers, except where law expressly permits.
- Scrape, mirror, or build derivative services from our APIs without a written agreement.
- Probe, attack, or load-test the service without our written permission. Responsible disclosure is welcome at [email protected].
- Use Vault to send unsolicited bulk email outside the consent-based mailing-list features.
We may suspend or terminate accounts that violate these rules. For most violations we'll warn first; for severe ones (CSAM, active abuse) we won't.
Plans & billing
Vault sells by tier. Public pricing as of this version:
FREE$0: 100 MB per upload, library, sharing inbox, 2FA
STARTER$12/mo: 500 MB, five-deep hierarchies, watermarked share, contacts
PRO$49/mo: 5 GB, unlimited hierarchies, paid upload analysis, on-demand lyrics, on-demand stems, AI Atmos, AI Mix Stereo, Session™ Files, downloadable stems, mailing lists, hover preview, encrypted text fields
MAX$199/mo: 10 GB, recipients drilldown, A&R hot leads, analytics + heatmap, leak lookup, blast email, CSV export, install desktop app
Billing. Subscriptions renew monthly via Stripe on the day of the month you signed up. Taxes are added where required by law.
Refunds. Cancel any time. We pro-rate refunds inside 14 days of a charge if you have used under 10% of the cycle's storage and bandwidth. Past that, refunds are at our discretion.
Downgrades. If you downgrade and exceed the lower tier's caps, your library is read-only until you free enough room. Existing files are never auto-deleted.
Non-payment. A failed charge starts a seven-day grace period with email warnings. After grace, your account is paused (read-only) for 30 days, then frozen. Frozen accounts retain data for 90 more days before scheduled deletion. Reactivate at any point inside the freeze window and pick up exactly where you left off.
Sharing & watermarks
Every share is a token. You set the policy: NDA gate, expiry, download lock, watermark, recipient list. We give you the tools. You pick the scope. The scope is your call.
Vault embeds inaudible per-recipient watermarks in downloaded copies on supported tiers. By using watermarking, you authorize us to attribute leaks to specific recipients in audit reports we generate for you alone. Leak Lookup is the inverse: a scan that surfaces your tracks where they shouldn't be.
Recipients who sign your NDA agree to its terms with you, not us. Vault stores the signed timestamp, IP, and email, not as a party, as a witness.
AI features
Vault ships AI built in-house: Atmos render, Mix Stereo, Multi-Stem, Cleans, semantic search, lyric transcription, genre classification, suggestions, bulk-edit parsing, cover art. Most of it runs on hardware we operate. Two pieces (cover art generation and bulk-edit intent parsing) use Gemini under a no-retention contract that prohibits training on your inputs.
Generative outputs (cover art, AI mixes, AI cleans) are your work product within the scope of the service. Publish them. Sell them. Destroy them. Your call.
You can opt out of any specific AI feature in Settings > Privacy > Compute. End-to-end encrypted tracks are encrypted before they leave your device; analysis runs against decrypted bytes that we never persist beyond the analysis itself.
Termination
You can close your account at Settings → Account → Delete account. We schedule deletion immediately and run a 7-day cooling-off period during which you can cancel; after that, your wrapping keys are destroyed and your ciphertext is shredded within 7 days.
Permanent deletion.
When an account is permanently deleted (either by you completing the cooling-off period, or by an admin action), we immediately purge your audio and metadata from our primary object storage. From that moment forward, nothing on our side can restore your data — not us, not you, not a recovery code. The deletion is one-way.
For disaster recovery purposes (so a server-side incident can't take other customers' data with it), our backup bucket retains encrypted ciphertext for up to 30 days after permanent deletion. We never restore from backup to undo a deletion — only to recover from operational failure. After 30 days, the backup copy is gone and even the encrypted bytes no longer exist on any of our systems.
We can terminate your account for material breach of these Terms, prolonged non-payment, or legal requirement. We'll give you at least 30 days' notice and a way to export your data, except in cases of severe abuse where shorter notice is warranted.
Disclaimers & limits
Vault is provided "as is". We work hard to keep it up, secure, and accurate, but we don't warrant that it will be uninterrupted, error-free, or that AI outputs will meet your subjective standards.
To the maximum extent permitted by law, neither party will be liable for indirect, incidental, or consequential damages. Our total liability for any claim arising from these Terms or your use of Vault is capped at the greater of $100 or the amount you paid us in the 12 months before the claim arose.
Nothing in this section limits liability for gross negligence, willful misconduct, or anything else the law won't let us limit.
Law & disputes
These Terms are governed by the laws of the State of California, USA, without regard to its conflict-of-laws rules. We agree to bring disputes in the state or federal courts located in the County of Los Angeles, California, except where local consumer protection law gives you the right to your home court.
No class actions. Disputes are resolved on an individual basis. You may opt out of this clause within 30 days of account creation by emailing [email protected].