Privacy
This website
If you join the waitlist, we keep your email address, the devices you ticked and whether you want a beta invite, and use them only to tell you about Everdust. They are stored privately with our hosting provider, Vercel. Ask us at seth@decosa.ai and we’ll delete them. The site sets no cookies and runs no analytics or advertising code. Like any website, our host processes standard request logs (such as IP addresses) to serve and protect it.
The Everdust app
Everdust (previously called "Particles") is an app that turns music into light: particle art that moves with whatever is playing. It runs on Apple Vision Pro, iPhone, iPad, Mac and Apple TV. It's made by Decosa, Inc. ("Decosa", "we", "us"). This policy explains what information the app handles, what stays on your device, what leaves it and who receives it.
The short version
- The visuals are made on your device. The microphone, the music you play, your hands and your room are analysed live on your device to drive the visuals. We never record, store or receive your audio, your camera image, your hand movements or a map of your room.
- No ads, no tracking, no analytics companies. The app contains no advertising, no third-party analytics or tracking tools, and doesn't use your device's advertising identifier. We don't sell or share your personal information, and we don't follow you across other companies' apps or websites.
- No sign-in. You don't need an account to use Everdust.
- Some features use the internet, and then some information does leave your device:
- Mixes streams music from Audius, an independent music service. Audius receives your requests (including the search words the app sends for "Find music") and your IP address.
- Create (making your own scene from a description, where available) sends your description to our server and to the AI company that designs the scene, currently Anthropic. Your scenes and credit balance are kept on our server.
- The app checks a small settings file on our website that can switch features on or off.
- Test builds are different. Beta builds we distribute through Apple's TestFlight also send us crash and diagnostic reports. Builds from the App Store don't. See "Beta (TestFlight) builds" below.
1. What stays on your device
These features work entirely on your device. Nothing they handle is sent to us or to anyone else.
- Microphone ("Listen to the room"). If you allow it, the app listens to music playing around you and measures its loudness in a few frequency bands, many times a second, to move the visuals. The sound is analysed as it arrives and then discarded. It's never recorded, saved or sent anywhere. You can turn microphone access off at any time in your device's Settings.
- System audio on Mac. If you allow it, Everdust on Mac listens to the sound other apps play (for example a music app or your browser) in the same way, using macOS audio capture or screen-capture permission for audio only. To let you pick one app to listen to, it lists the apps currently playing sound. It never captures your screen image, and the sound is never recorded or sent.
- Your music. Songs you open from Files are played and analysed on the device. On Apple Vision Pro they're copied into the app's own storage so they keep playing offline (deleting the app removes them); on iPhone, iPad and Mac they're played from where they are. On Apple Vision Pro, if you allow access to your media library, the app lists songs you bought from the iTunes Store and downloaded to the device, and plays and analyses them on the device. Nothing about your music or your library is sent anywhere.
- Hands and room (Apple Vision Pro). If you allow hand tracking, the app reads your hand positions each frame so the particles can flow around your hands. If you allow world sensing, it uses the surfaces and shape of your room (floors, tables, walls) to place the visuals and let light rest on surfaces. Apple's system provides this data to the app only while it's running. We use it live, on the device, and never record, store or send it. The app never receives camera images or passthrough video from Apple Vision Pro.
- Camera (iPhone and iPad, "Place in your room"). If you allow it, the camera view is shown with the scene placed in your room, and on devices with a LiDAR scanner the shape of the room lets particles bounce off surfaces. The camera image and the room's shape stay on your device and are never recorded or sent.
- Motion (iPhone and iPad). Some scenes use the device's orientation so you can look around them by moving the device. This is read live and never stored or sent; the app doesn't use your location.
- Your choices and settings, such as your favourite scenes, the last sound source you chose and the words you typed into "Find music", are saved on your device so the app remembers them.
- Diagnostics log. The app keeps a short technical log on the device (for example which scene was showing and any errors), and stores crash reports that Apple's system provides to the app. They stay on your device unless you choose to send them (see "If you contact us" in section 2).
2. What leaves your device, and who receives it
Mixes and music from Audius
Mixes plays full-length tracks from Audius, an independent, open music platform where artists upload music to stream for free. When you play a mix or use "Find music":
- Your device connects directly to Audius' servers. Audius receives the requests the app makes: searches (including words and artist names from what you typed into "Find music"), requests for popular tracks in a genre, and the tracks and artwork you play. It also receives the information every internet request carries, such as your IP address and the type of device and software making the request. The app identifies itself to Audius by its name, not by any information about you.
- Working out what music you might like happens on your device. The app sends Audius search words, not the full text you typed together with anything else about you.
- Tracks are downloaded only to play them, and the app clears them automatically (on Apple Vision Pro, every time the app starts). On Apple TV, Mixes uses only the moods you pick, not typed words.
- We don't receive any of this information. Audius handles it under its own policies: Audius Privacy Policy, Audius API Terms and Audius Terms of Use. Links to Audius' terms and privacy policy are also at the bottom of the Mixes tab.
- When you tap "Open on Audius", the track's page opens in your browser, under Audius' policies.
Create: scenes you describe (where available)
Create lets you describe a scene in words ("a jellyfish made of light that pulses with the bass") and have it designed for you. It isn't available in every version of the app. Where it is:
- Your account. The first time you use Create, the app makes a random identifier for this installation, stores it in your device's keychain, and uses it to open an anonymous account on our server. We store only a scrambled (hashed) form of that identifier. You don't give us your name, email address or Apple Account details.
- What we receive and keep:
- the descriptions and changes you type ("prompts") and the scenes made from them (titles, settings and a preview image);
- your credit balance and its history;
- your IP address, which we use to limit abuse (for example how many accounts and creations can come from one address) and keep with your account's records;
- the type of device (Apple Vision Pro or iPhone/iPad), and when you last used Create;
- for purchases: the information Apple sends us to prove a purchase (see "Purchases" below).
- Who designs the scene. Our server sends your prompt (and, when you refine a scene, the scene and your earlier prompt) to an AI model provider to design the scene. Today that's Anthropic (the Claude models), under Anthropic's commercial terms, under which Anthropic doesn't use this data to train its models (Anthropic Privacy Policy). We may also use other providers: open models reached through OpenRouter (OpenRouter Privacy Policy), such as DeepSeek or Qwen models, which may be hosted by companies in other countries, or Decosa's own models on our own servers. We send these providers only the text needed to design the scene, never your account identifier, IP address or purchase details.
- Sharing. If you tap "Share", the scene gets a public link. Anyone with the link can see the scene, its title and its settings (not your prompt as typed). Don't share a scene if you don't want others to see it.
- What we don't do. We don't use your prompts or scenes to train AI models, and we don't feature your scenes publicly unless you choose to (see the End-User License Agreement).
- Content rules. Prompts are checked automatically, by our own filters and the AI provider's, to refuse content that breaks our rules.
Purchases
Credits and subscriptions are sold through Apple's App Store. Apple handles payment; we never see your payment card or your Apple Account details. When you buy or restore, the app sends us Apple's signed record of the transaction (for example the product, its date, Apple's transaction numbers and the storefront), so our server can check it with Apple and add your credits. Apple also tells our server about renewals, refunds and cancellations. We keep these records to run your account and for our accounting and legal obligations. Apple's handling of your purchase is covered by Apple's Privacy Policy.
Feature settings file
When the app starts (on Apple Vision Pro, iPhone, iPad and Mac), and now and then while it's open, it downloads a small settings file from our website (decosa.ai, hosted by Vercel) that lets us switch a music source off without an app update, for example if a provider changes its terms. The request contains no identifier and nothing about you. Like any web request, it reveals your IP address to the website's hosting provider, which may keep it in short-lived server logs.
Your own devices on your network
- Play from your phone. When this sound source is on (or "Stay visible to your phone" is on), the app appears on your local network as a speaker, so you can play music to it from an iPhone or Mac. It receives the audio your device sends, plus the track's title and the sending device's name to show on screen, plays it and analyses it. Nothing is recorded or sent onward. The first time, your device asks for Local Network permission. While it's on, other people on the same network can see the speaker's name (on Mac it includes your computer's name, such as "Everdust on Alex's MacBook") and could play to it, as with other AirPlay speakers; turn it off when you're on a shared network.
- Sharing the beat between your devices ("Mac as the ears", "Send to TV"). One of your devices can send another the live loudness levels of the music (a handful of numbers, many times a second) over your local network. No audio is sent.
- Films from your Mac (where available). The app can find a Mac on your network that's running our film server and download or stream films from it, or use a film list or film server address you enter. Those downloads go directly between your devices, or to the address you entered.
If you contact us
If you email us, or use "Send diagnostics" to share the app's diagnostics log and crash reports, we receive what you send (including your email address) and use it only to answer you and fix problems.
3. Beta (TestFlight) builds
If you test a beta build through Apple's TestFlight, that build also sends us diagnostics automatically, to a server we run:
- After the app closes unexpectedly (a crash, or the system stopping it), and in reports the system delivers: the app's recent actions (which buttons and settings were used, and which scene or film was showing), memory and performance readings, Apple's crash and performance reports (MetricKit), the device model, software version and time zone, and the app's technical log. The log can include names of songs and films you played or imported, the name of a device that played music to the app, the name of the app you chose to listen to (Mac), and words from "Find music".
- When a tester presses Record in the developer menu: a recording of the app's state (for example frame rate, hand tracking status and how many hand joints were tracked, which scene was showing) and still images of what the app drew. These images show only the app's own visuals, never your camera or your room.
We use these reports only to find and fix problems in beta builds. They aren't linked to your name or Apple Account (TestFlight shares testers' details with us separately, under Apple's terms). We delete them when they're no longer needed to fix a problem, and within 12 months at the latest. The App Store version of Everdust doesn't contain this reporting.
4. How long we keep information
| Information | How long |
|---|---|
| Everything in section 1 (on your device) | Until you delete it in the app or delete the app. We never have a copy. |
| Create: your account, prompts, scenes, preview images | While your account is in use. We delete accounts that haven't been used for 24 months, and anything you ask us to delete (section 5). |
| Create: IP addresses | Up to 90 days. |
| Credit and purchase records | As long as tax and accounting law requires (generally up to 7 years), then deleted. |
| Records of AI requests (time, cost and the provider's request number; not your prompt) | Up to 24 months. |
| Beta diagnostics | Until the problem is fixed, and no longer than 12 months. |
| Emails and diagnostics you send us | As long as needed to help you, and no longer than 24 months. |
| Audius, Anthropic, OpenRouter, Apple, Vercel | Under their own policies, linked above. |
5. Your choices and rights
- Permissions. You can allow or deny the microphone, hand tracking, world sensing, camera, media library and local network access when asked, and change them later in your device's Settings. The app works without any of them; only the feature that needs it stops.
- Delete on your device. Deleting the app deletes everything it stored on the device. The Create install identifier in the keychain may stay on the device after the app is deleted, but it isn't sent anywhere until you use Create again.
- Your Create data. You can ask us for a copy of your prompts, scenes and account records, to correct them, or to delete your account and everything in it. Email us from the app (or tell us your scene's share link) so we can find your anonymous account. We'll answer within 30 days (45 days where California law allows).
- California (CCPA/CPRA). You have the right to know what personal information we collect and how we use it, to get a copy, to correct it and to delete it, and not to be treated differently for using these rights. We don't sell or "share" personal information (for cross-context behavioural advertising), and we don't use sensitive personal information to infer characteristics about you. In the last 12 months we've collected only the categories described in section 2 (identifiers such as a random account ID and IP address, purchase records, the content you submit to Create, and, in beta builds, technical diagnostics), from you and your device, for the purposes described there. We disclose them only to the service providers named above.
- Europe and the UK (GDPR). Decosa, Inc. is the controller of the data in section 2 that reaches us. Our legal bases are: performing our contract with you (running Create, your credits and purchases), our legitimate interests (keeping the service secure and preventing abuse, fixing bugs, and diagnostics from beta testers), and our legal obligations (accounting records). You can ask for access, correction, deletion, restriction, portability, and object to processing based on legitimate interests. You can also complain to your local data protection authority. Our providers may process data in the United States and other countries; where the law requires, we rely on safeguards such as the EU Standard Contractual Clauses.
- To use any of these rights, email us at the address below. We may need to confirm the request comes from the person whose data it is.
6. Children
Everdust isn't directed to children under 13, and we don't knowingly collect personal information from children under 13. The features that send information to us (Create, and beta testing) aren't meant for children. If you believe a child under 13 has given us personal information, email us and we'll delete it. (In some regions the age is higher, such as 16; the same applies.)
7. Security
Information sent to our servers travels encrypted (HTTPS). Our servers are access-controlled, secrets are kept out of the app and our code, and we keep as little as we need. No system is perfectly secure, so we can't promise absolute security, but we'll tell you and the authorities about a breach where the law requires.
8. Changes to this policy
We'll update this policy when the app changes what it handles. The date at the top says when it last changed. If a change is significant (for example a new kind of information, or a new company that receives it), we'll say so in the app or in the App Store release notes before it takes effect, and where the law requires your consent, we'll ask for it.
9. Contact
Decosa, Inc. Email: seth@decosa.ai