Privacy
This website collects one thing: an email address, and only if you type it into the waitlist form. There is no other field, no tracking and no account. This page says what happens to the address, who else touches it, and how to get it back or get rid of it.
Last updated
Who we are
IONIK Labs publishes ioniklabs.app and decides what happens to anything collected here — in data-protection language, we are the controller. You can reach a person at support@ioniklabs.app.
IONIK Labs is new and its registered company details are not published yet. They will appear here before IONIK goes on sale. We would rather say that than print a placeholder that looks like a fact.
What we collect
Your email address, and only because you typed it into the waitlist form and pressed a button. Stored next to it are four things, all of them generated by us rather than asked of you:
- the date and time you joined;
- your place in the queue, which is just a number;
- which part of the page you joined from — currently there is only one, so this always says the same thing;
- whether the confirmation email was accepted for delivery, and later, whether your code has been sent.
We also store a second, tidied copy of your address with anything after a + removed. That copy exists for one job: counting one person as one place in the queue, so the 300 discount places cannot be taken by one person filing 300 variations of the same address. Your mail still goes to the address exactly as you wrote it.
There is no field for your name, your country, your job or anything else, and we do not infer any of them. We never see a password, because there is nothing here to log in to.
Cookies, analytics and tracking
There are none. This site sets no cookies. It runs no analytics, no tag manager, no advertising pixel, no session recorder and no third-party script of any kind. Every page but the form endpoint is a static file. You do not have to take our word for it — open your browser’s developer tools, load any page here, and look at the network and storage tabs.
Not one cookie, and no exception to hedge that with. The customer account area is not open yet, so the one piece of this site that would ever look at a cookie — the header check that shows a returning customer a link to their account — is not running at all. When the store opens and it does run, that check will happen inside your browser, write nothing, and send nothing anywhere; this page will say so on the day it becomes true and not before.
Your IP address
When you submit the form, the server sees the internet address the request came from, as every server does. It uses it to count how many submissions have arrived from that address recently, and refuses the form if there have been too many. That is the only defence this list has against a script filling it with junk.
That count is kept in two places. One is the server’s memory, which forgets within the hour and forgets entirely whenever the server restarts — which is exactly why there is a second.
The second is our database, and what goes there is not your address. It is a fingerprint of it: your address is put through a one-way function together with a secret key, and only the result is stored. Somebody who stole the database and not the key could not read your address out of it.
Two honest limits on that, because the difference matters. We hold the key, so we could take a particular address and check whether it matches a stored fingerprint — we cannot read an address out, but we could confirm a guess. And the fingerprints are timestamped just as the signups are, so the times could be lined up to associate one with the other. It is a pseudonym, not anonymity, and the law treats it as information about you. We are describing it that way rather than telling you it is untraceable.
What limits it is that the fingerprints do not survive. They are deleted once they are more than an hour old — by the next request that arrives, and failing that by a scheduled job that runs every hour whether anyone visits or not. The longest one can exist is therefore two hours: an hour inside the window, and at most another waiting for that job. Nothing is archived, nothing is used to work out where you are, and nothing else about the request is kept.
What ends up in a server log
What our own code writes down is a short fingerprint of your address, never the address. It happens on a few paths: when the rate limit stops a submission, when one trips the hidden field that catches automated form-fillers, and when a signup succeeded but the confirmation email could not be sent. We do not intentionally include your email address in our application logs.
That sentence is deliberately about our application. Two other kinds of processing sit around it and are worth separating out, because they work differently and we control them to different degrees. Our hosting provider handles the request before our code runs and keeps its own operational records of that traffic. Our email provider must necessarily receive your address in full — that is what delivering a message to you means — and processes it under its own terms. Neither is our application log, and we would not describe either as something we can make promises about line by line. Both are named in full further down, under who else touches your address.
If a submission of yours was refused and you write to ask why, we can still find it: the fingerprint is worked out the same way every time, so we put the address you give us through the same function and look for the result. That is also the honest limit of it — a fingerprint that we can match against an address you supply is not anonymous, it is a stand-in for you that happens not to be readable at a glance.
When something upstream of us fails, our code records the kind of failure and not the failing data: an error code and the name of the database rule that was broken, which is enough to tell a duplicate signup from a database being unreachable. The parts of an error message that might quote the offending row are not read at all.
Those lines go to our hosting provider’s log, where they are kept for a short period and then discarded. We do not export them, build profiles from them, or use them for anything except answering the question “why did this submission fail?”
What we do with your address
We send two emails. The first arrives within seconds of you joining and confirms you are on the list. The second arrives on release day. If you were one of the first 300 to join, that second email carries your discount code.
That is the entire plan. There is no newsletter, no drip campaign, no “we thought you’d like to know”. We will not sell, rent, share or trade your address, we will not hand it to an advertising network, and we will not use it to find you anywhere else.
Who else touches it
Three companies, each paid to do exactly one job. None of them is permitted to use your address for anything of their own.
- Vercel
- Serves this website and runs the one function the form posts to. United States.
- Supabase
- The database the address is stored in. United States.
- Resend
- Sends the two emails. United States.
All three operate in the United States, which means your address is stored and processed there. If you are in the UK or the EU, that is a transfer outside your home jurisdiction, and it happens on the basis of the standard contractual terms each of those companies publishes.
How long we keep it
Until the release mailing has gone out and the 14 days a code stays valid have passed. At that point the waitlist has done the only job it was created for, and we delete it.
If you ask us to remove you sooner, we do it when you ask — in practice the same day, and never more than thirty days later.
Getting your address out, or getting rid of it
Reply to either email, or write to support@ioniklabs.app. Ask us what we hold and we will send you the row. Ask us to correct it and we will correct it. Ask us to delete it and we will delete it. There is no account to log into, no form to fill in and no reason required.
If you are in the UK or the EU, those are your rights under the GDPR — access, correction, erasure, restriction, objection and portability — and the basis we rely on to hold your address at all is your consent: you typed it in and pressed a button. You can withdraw that consent at any time by the same route, and doing so costs you nothing except your place in the queue. You also have the right to complain to your national data-protection authority.
Children
This site is not aimed at children, and a waitlist for an unreleased music plug-in is not something we expect a child to join. We do not knowingly keep an address belonging to one. If you believe we have one, write to us and it will be deleted.
If this page changes
The date at the top is the last time it changed in a way that mattered. If we ever change what we do with an address that is already on the list, we will say so in an email rather than quietly editing this page — which, given that we have promised you only two emails, tells you how unlikely we intend that to be.