AT Informatics

AfterTime — Privacy Notice

Last updated 10 September 2026 · applies to AT Informatics software and to atinformatics.com

Draft prepared in good faith for review. This is not legal advice and it has not been reviewed by a lawyer. See README.md in this folder for the list of clauses that need one.

Last measured against the code: 2026-09-10. Every statement below was checked in the source, not assumed. Where a statement could not be checked, it says so.


1. The short version

AfterTime runs on your computer. It works on the REAPER project you already have open.

Your audio never leaves your machine. Not to us, not to anyone.

If you connect AfterTime to a cloud AI provider, then text about your session — track names, tempo, measurements, file paths — is sent to that provider so the assistant can decide what to do next. You choose the provider. You can choose one that runs on your own computer, and then nothing leaves at all.

We do not run a server. We do not have your data.

2. What AfterTime does NOT do

3. What stays on your computer

All of it, unless you connect a cloud provider. AfterTime writes to:

You can delete any of it. It is your disk.

4. What leaves your computer, and only if you set it up

AfterTime needs a language model to understand what you ask for. You choose which one.

If you choose a local model (for example Ollama, running on your own machine): nothing leaves your computer.

If you choose a cloud provider, AfterTime sends that provider the conversation and the results of the measurements it took, so it can decide the next step. In practice that includes:

The providers AfterTime can be configured to use are, measured from the code:

providerhost
Groqapi.groq.com
Google (Gemini)generativelanguage.googleapis.com
OpenRouteropenrouter.ai
Ollamayour own machine

A provider you never configure receives nothing.

Their terms apply to what they do with it, not ours. Read the privacy policy of the provider you choose. We do not control it, and we do not receive a copy.

5. Legal basis and your rights (EU / UK — GDPR)

We do not operate a service that collects your data, so for the parts that stay on your machine there is no controller holding it but you.

When you configure a cloud provider, you are directing that transfer. The provider is the one processing it. If you are in the EU or UK and want the protections of the GDPR over that transfer, choose a provider whose terms give you them, or use a local model so no transfer happens.

Your rights over data on your own machine — access, deletion, portability — you exercise directly: the files are yours and you can read or delete them.

We cannot delete data held by a provider you chose. Ask them.

6. United States

We do not sell your personal information. We do not share it. We do not have it. AfterTime collects nothing from you and transmits nothing to us. There is no server for it to arrive at.

California (CCPA / CPRA)

The CCPA gives Californians the right to know what a business collects, to delete it, to correct it, and to opt out of its sale or sharing.

We hold nothing to disclose, delete or correct, so there is nothing to opt out of. If you want to exercise those rights over data on your own computer, you can: the files are yours, in your own folders, and you can read or delete them without asking us.

The maker is a single person selling a tool, and on the CCPA's own thresholds is very unlikely to be a "business" it applies to at all. That is stated as a fact about size, not as a reason to behave differently — the answer above would be the same either way, because the data is not collected.

Other US states

Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA) and the states that have followed them all work the same way: they govern what a controller collects and processes. AfterTime does neither. The position in this notice is the same in every one of them.

Health, finance, biometrics, children

AfterTime handles none of these. It reads a music project: track names, tempo, timings and audio levels. HIPAA, GLBA, BIPA and COPPA are not engaged, and no part of this product is directed at children.

Sensitive by accident

One honest caveat, because it is true and easy to miss: file paths usually contain your computer's user name, and if you send session context to a cloud AI provider you configured, that path goes with it. That is a transfer you direct, to a provider you chose. Use a local model and it does not happen at all.

7. Children

AfterTime is not directed at children and collects nothing from anyone.

8. Changes

If what the product does changes, this notice changes with it, and the "last measured" date at the top moves. If the date is old, trust the code.

9. Contact

Direct contact with the maker. This is a small release; there is no privacy team and pretending otherwise would be dishonest.