โ† Backline

Privacy Policy

Last updated 10 August 2026

The short version. Backline is software a band runs on its own server, and your band's data lives in your own database. We do not sell it, share it, or use it to train anything. But "self-hosted" does not mean "nothing ever leaves the machine": with the built-in AI, the text being drafted passes through our gateway to a model provider; the one-click Google and Instagram connections pass sign-in tokens through our broker; and a licensed install checks its license with us once a day. Every one of those is listed below: what it carries, when it happens, and how to turn it off. Run everything with your own keys and the license check is the only thing we ever see.

Who this covers

Backline is a band-management assistant. It is distributed two ways, and the difference matters for your privacy:

What leaves a self-hosted install

On a self-hosted install, these are the only things that reach us or anyone else. Each is listed with what it carries and how to switch it off:

A free-tier install with no connections configured sends nothing anywhere.

What Backline stores

How the data is used

Stored content is used to generate suggested text (replies, captions, emails), which is saved as a draft. Sending, posting or publishing a draft requires an action by a signed-in user; the software performs no outbound action on its own.

Generating a draft transmits the relevant content to an AI model provider. By default (self-hosted or managed), that request is routed through our inference gateway to OpenRouter under our account, as described above. If you configure your own provider, the request goes directly from your server under your own key, and we are not involved. We never use your content to train models. OpenRouter's published policy states it does not train on your prompts; it forwards each request to the model's host under that host's API terms. That commitment is theirs, not ours to make.

Disclosure

Personal data is not sold or rented. It is not used for advertising or shared with advertisers, and it is not combined across installations. Each installation holds one band's data only.

Data is disclosed only to the sub-processors listed below, and where disclosure is required by law.

Instagram and Meta

Backline uses the Instagram API with Instagram Login to read your own posts and their comments, and to publish posts you have approved. It only ever touches the account you connected, and only that account's own content. If someone comments on your post, Backline stores that comment so you can reply to it. It is the same information you already see in the Instagram app.

Removing Backline from your Instagram account revokes its access immediately. Backline also receives Meta's deauthorization notice and clears the stored credentials on its side.

Deleting your data

You can delete anything in the app at any time, and disconnecting an integration removes its stored credentials.

How long we keep it

For as long as you keep the install. We impose no retention period on your own data. Deleting it is your call, not a timer.

Sub-processors

A self-hosted install that brings its own AI provider and its own OAuth apps touches none of these except the daily license check. On the free tier, not even that.

Security

Passwords are hashed. Integration tokens are encrypted at rest. Sessions use HttpOnly cookies, and logging out invalidates the session server-side. Everything travels over HTTPS.

Children

Backline is a tool for working bands and is not directed at children under 13. We do not knowingly collect their data.

Changes

If this policy changes materially we will update the date above and, for managed customers, say so by email.

Contact

Questions, or a deletion request: privacy@backlineagent.com.