This policy describes what Disbrow Productions, LLC (“we”) actually collects when you use Crewline, our church and production party-line intercom. It is not a certification, and it does not claim GDPR, SOC 2, COPPA, or any other compliance program.
Who we are
Crewline is a product of Disbrow Productions, LLC. Privacy and deletion requests go to Andrew@disbrowproductions.com.
Accounts and email
An organization account stores:
- Email address
- A bcrypt hash of the password. We do not store the password itself.
- An optional display name
- Role (owner, admin, operator, or crew), plan, and related limits
- A billing interval of month or year, when one is saved. That field is not a charge.
Creating an account is your agreement to the Terms and this policy. We do not store a separate timestamp of that agreement. Crew invited onto a show have their own email, display name, and a free crew account. That account does not carry a paid plan. The plan and the bill stay on the engineer's organization.
Crew names and shows
A show stores its name, channel names, and the seat names on the line (for example “Cam 1” or a person’s name), plus who can talk or listen on each channel. Those names are what the roster shows. They are not a separate user account unless that person also has a Crewline login.
Join links, PINs, and invites
- A seat link or PIN opens one seat on one show. We store the show, the seat name, expiry, and a nonce. The link and the 6-digit PIN are derived from a server secret. We do not store the raw link or PIN.
- A seat session cookie holds the pass id, show, seat name, and session id until the pass expires.
- A crew invite stores the invited email, role, and a hash of the invite token, not the raw link. Invites expire after 7 days.
- A password reset stores the account email and a hash of the reset token. The link expires after 60 minutes and works once.
Show audio
Party-line audio is routed through LiveKit Cloud, our real-time audio provider; Crewline does not record it. The app issues a LiveKit token and the seat connects to the LiveKit URL configured for this deployment.
Crewline does not record show audio. The application does not start LiveKit egress, a room composite, or a track recording, and it does not write an audio file of the line. Talking in the browser or in the iOS app uses the microphone only to send live audio to LiveKit. If someone records the line on their own device, that recording is theirs.
Usage minutes
When a Postgres database is configured (DATABASE_URL), we store participant sessions so we can count participant-minutes against the plan. A row can include the LiveKit room, participant identity, display name, account id, show id, join and leave times, and duration. These rows are not an audio recording. If the database is not configured, that ledger is off and nothing is written.
Password resets, crew invites, and an owner test message are sent through Resend when RESEND_API_KEY and CREWLINE_EMAIL_FROM are set. The message contains the address you gave us and, for a reset or invite, a one-time link. We keep a short log of the recipient address and whether the send succeeded (the last 200 sends). The log does not include the link or the API key. If Resend is not configured, production mail is not sent.
Where this runs
The Crewline web app is hosted on Railway. Account files, shows, sessions, and the email log live on that server’s disk. Usage minutes, when enabled, live in Postgres. LiveKit Cloud processes the live audio. Resend delivers mail when it is turned on. If a Sentry DSN is set, the app can send an error message (not audio) to Sentry. Error reporting is off when the DSN is unset.
Plans and payment
New accounts start on Free. No card is required to start. The site owner can still grant a plan. Paid plans can use Stripe Checkout when billing is turned on. Stripe collects card details; we store Stripe identifiers and subscription details (plan, price, billing interval, status, renewal date) and a webhook event id, never card numbers.
Cookies and on-device settings
Details are on the Cookies notice. In short:
crewline_sessionis an httpOnly, SameSite=Lax cookie that keeps you signed in. It holds your user id, email, and display name. The default life is 14 days (the site owner can set 1 to 14 days). It is marked Secure on HTTPS.crewline_seatis an httpOnly cookie for a guest seat. It lasts until that seat pass expires (12 hours, 48 hours, or 7 days).- The browser may store listen levels, the seat name, microphone and speaker choice, and similar panel settings in localStorage on that device. We do not use those values for advertising.
We do not run advertising cookies or cross-app tracking.
Sessions and technical data
A signed-in session record stores the account email, the browser user agent, and the IP address our server sees, so an admin can sign that session out. Behind Railway, that address is the one our proxy stamps. We also keep an audit log of account actions (sign-in, invites, show changes, and similar). The log stores the actor’s email and a short description, and it keeps the latest 5,000 entries.
How we use this
- Create accounts and sign people in
- Put crew on a show and open a seat from a link or PIN
- Carry live party-line audio and count participant-minutes
- Send reset and invite email when mail is configured
- Diagnose failures and abuse
- Answer an access or deletion request
We do not sell personal information. We do not show ads.
Who else processes it
Railway hosts the app. LiveKit Cloud carries the live audio. Stripe is the payment processor for paid checkout when billing is turned on. Resend sends email when configured. Sentry receives error text only if a DSN is configured. We share data with them so they can do that work. We may also disclose information if the law requires it, or to respond to abuse that threatens the service or its users. We do not name a specific data-center region, and we do not claim a transfer certification.
How long we keep it
- Account, show, and crew records stay while the account or show exists.
- The session cookie expires on the schedule above. Signing out clears that session.
- Seat passes that are expired or revoked are dropped after 30 days.
- Invite tokens expire after 7 days. Reset tokens expire after 60 minutes.
- The email log keeps the last 200 sends. The audit log keeps the last 5,000 entries.
- Postgres usage rows are not given an expiry by the app. They remain until someone deletes them outside the account-deletion flow below.
Access and deletion
While signed in, you can download a JSON file of your profile and the shows you created, or delete the account, at /account. Deletion asks you to type DELETE. It removes the user record, sessions, and password-reset tokens, ends shows that account owns, and revokes those seat links.
That delete does not erase Postgres usage rows, Stripe billing rows (identifiers, price, plan, billing interval, status, renewal date, and the cancel-at-period-end flag), the webhook event log, the audit log, or the email-send log. Email Andrew@disbrowproductions.com from the address on the account if you want those removed as well, or if you cannot sign in. We may need to confirm the request is yours.
Children and church crews
Churches and production crews use Crewline. We do not ask for a date of birth, and we do not direct the service at children under 13. An organization account is an email and a password created by the person who opens it. A youth volunteer can be a seat name with a link or PIN and still not have an account. If you believe we have an account for a child under 13, email us and we will delete it. This is not a claim that Crewline is COPPA certified.
iOS app
The Crewline iOS app, when you use it:
- Uses the microphone so your seat can talk on the show line, including while the phone is locked. iOS shows that purpose before the mic turns on.
- Uses background audio so the party line can stay up with the phone locked. The audio session is for the show, not for playing ads or other apps’ audio.
- Does not show advertisements, does not include an advertising SDK, and does not track you across other companies’ apps. The app privacy manifest sets tracking to off and lists no tracking domains.
The iOS app signs in to the same Crewline account and joins the same LiveKit line as the website. The account, audio, and usage sections above apply to that app as well.
Security
Passwords are hashed. Session and seat cookies are httpOnly. No method of transmission or storage is perfectly secure. Treat operator tokens, seat links, and PINs like booth keys.
Changes
If we start recording audio or collecting a new category of personal information, we will update this page and its effective date before relying on the new practice.
Contact
Disbrow Productions, LLC — Crewline privacy · Andrew@disbrowproductions.com