Crema Software Meet VENS

Last updated: July 31, 2026

This policy covers VENS, an app published by Crema Software LLC ("Crema Software," "we," "us") for iPhone, iPad, Mac, and Apple Watch. It describes what information VENS collects, how it's used, who it's shared with, and the choices you have.

The short version: your private VENS library and settings sync through your own iCloud account using Apple's CloudKit. Features you deliberately use with other people — such as public event records, community contributions, profiles, your group, challenges, and leaderboards — use CloudKit's shared or public databases. Crema Software never sees your Apple ID password, and Apple handles payment details. We also operate a stateless relay for Gemini scanning and requested nearby-show searches; the relay forwards those requests without storing their content in application code.

Information We Collect

Account & Sync

VENS doesn't have its own sign-up or password system. It uses whichever iCloud account is already signed into your device to sync your data via CloudKit, and to identify your content to other users you interact with (for example, showing your display name to your group). We receive an opaque CloudKit user identifier, not your Apple ID or email address.

Profile Information

You choose what to add to your profile: a display name, an avatar or a custom photo, and optionally your city, state, and country. None of this is inferred from your device's location — it's typed in by you, and a visibility toggle controls whether it appears on the leaderboard.

Photos & Camera

VENS uses your camera to photograph event posters for scanning, and can read photos you choose to select for scanning a poster or attaching a "show memory." If you capture a photo at a show, VENS can save it back to your Photos library. VENS only accesses photos you explicitly select — it doesn't scan your photo library in the background.

Microphone & Track ID

Track ID uses your iPhone's (or Apple Watch's) microphone to identify a song playing live, similar to Shazam. VENS does not store or transmit the audio recording itself — only the result of the identification (song title, artist, genre, and a timestamp) is saved to your library.

Local Network & Nearby Interaction (Group)

VENS lets you form a group with friends to coordinate at a show. "Pod" is the default display name, but it's yours to relabel — Squad, Crew, Tribe, or anything else you choose in Settings. This policy uses "group" throughout to describe that feature regardless of what you've named it.

If you use group features to find friends at a show, VENS uses your device's local network and Nearby Interaction (Ultra Wideband) capability to estimate the distance to group members you've specifically chosen to find. This does not use or collect GPS location — it only works for people already in your group, at close range, and only while you're actively using that feature.

Location While Using the App

VENS requests foreground location only when you use a location feature. Totem Mode takes a fresh location fix so you can navigate toward a friend's Totem or deliberately share the rally point when you become the Totem. Nearby Show Alerts sends the artist, the foreground latitude/longitude, and the radius you choose through Crema Software's stateless relay to Ticketmaster. VENS does not request Always Location access or continuously track you in the background.

Connected Streaming Services

You can optionally connect Apple Music, Spotify, or YouTube Music to build playlists from a scanned lineup or captured setlist. Sign-in for these happens through each service's own login page — VENS never sees your password for these services — and the resulting access token is stored securely in your device's Keychain, not on any Crema Software server. Once connected, each service's own privacy policy governs how they handle your listening activity.

Connected music service data is kept separate from VENS social and community features. VENS does not share your Apple Music, Spotify, YouTube, or Google account data with friends, groups, leaderboards, public event records, or other VENS users. If you choose to share something with friends — for example a playlist link, group status, challenge, or show-related contribution — that sharing is initiated by you and limited to the feature you selected.

Apple Music & MusicKit

VENS uses Apple Music and MusicKit only after you grant Apple Music access on your device. VENS uses this access to search the Apple Music catalog, match songs from event lineups and setlists, create playlists you request, and add selected tracks to those playlists in your Apple Music library.

VENS does not use Apple Music data for advertising, tracking, profiling, identifying users or devices, or resale. Apple Music data is used only to provide or improve the music features visible in VENS. You can review or revoke Apple Music access in your device settings. Apple Music is also governed by Apple Music & Privacy and the Apple Media Services Terms and Conditions.

Spotify Web API

VENS uses the Spotify Web API only if you choose Spotify as a playlist destination and sign in with Spotify. VENS requests playlist permissions, including the ability to manage public and private playlists, so it can create playlists and add matched tracks when you ask VENS to publish an event lineup, setlist, or Track ID playlist.

VENS stores Spotify OAuth tokens securely in your device's Keychain. Crema Software does not receive your Spotify password, does not sell Spotify user data, does not use Spotify data for advertising or profiling, and does not use Spotify content or Spotify user data to train machine learning or artificial intelligence models. VENS processes Spotify access only as needed to provide the playlist feature you requested.

You can disconnect Spotify in VENS or revoke VENS's Spotify access from your Spotify account apps page at https://www.spotify.com/account/apps/. After access is revoked, VENS can no longer create or modify Spotify playlists unless you connect again. Spotify's own Privacy Policy, Terms and Conditions of Use, and Developer Policy also apply.

YouTube Data API Services & Google User Data

VENS uses YouTube Data API Services only if you choose YouTube Music as a playlist destination and sign in with Google. VENS does not access YouTube in the background and does not use YouTube or Google data for advertising.

When you connect YouTube Music, VENS requests YouTube permission scopes that allow the app to create and manage YouTube playlists you ask VENS to publish. VENS uses this access to validate your signed-in YouTube account, search YouTube for videos that match songs from your event lineup or setlist, create a private playlist, and add matched videos to that playlist.

VENS stores the resulting Google OAuth access token and refresh token securely in your device's Keychain so the app can complete playlist publishing and reconnect without asking you to sign in every time. Crema Software does not receive your Google password, does not sell Google user data, does not use Google user data for ads or profiling, and does not transfer Google user data except as needed to provide the YouTube playlist feature you requested.

VENS does not upload videos to YouTube, does not download YouTube videos or audio, and does not embed a YouTube player. Playlist items remain in your YouTube account and are governed by Google's and YouTube's own policies.

You can disconnect YouTube Music in VENS or revoke VENS's access to your Google account from your Google Account permissions page at https://myaccount.google.com/permissions. After access is revoked, VENS can no longer create or modify YouTube playlists unless you connect again. You may also contact us at hello@cremasoftware.com for help removing VENS-created community-shared content or understanding how to disconnect a streaming service.

For more information, see the Google Privacy Policy, the YouTube Terms of Service, and the Google API Services User Data Policy.

Cloud AI / Gemini Scanning

When you scan an event poster photo or paste a messy lineup or setlist, VENS automatically tries Google's Gemini API to extract artists, days, stages, times, and related show details — this is the default behavior, not a separate mode you choose. VENS sends the request through a small relay service Crema Software operates, which adds our own Gemini credentials so you don't need an API key of your own. If Gemini can't be reached — no network, an outage, or a failed request — VENS automatically falls back to on-device OCR through Apple's Vision framework, and nothing leaves your device.

Our relay is stateless: it forwards your request to Gemini and streams the response back without storing or logging the poster image, pasted text, or Gemini's reply anywhere on our side. Gemini requests are governed by Google's applicable Gemini API terms and policies, including the Gemini API Additional Terms of Service and Gemini API usage policies.

Third-Party Music, Setlist & Reference Sources

VENS uses several third-party public data sources to help search, verify, enrich, and attribute event and setlist information. These sources are used only to support user-facing app features such as finding a setlist, confirming an artist name, adding genre/artist context, or showing a short artist fact.

  • Public setlist and event sources: used to search for event and artist setlists, load user-pasted public event/setlist links, and enrich show metadata. VENS may send artist names, event names, dates, venues, cities, countries, or pasted public event/setlist URLs to those sources. Their content is governed by their own terms and API terms.
  • Last.fm: used for read-only artist search, top tracks, genre tags, and short artist biography context. VENS sends artist names to Last.fm and does not use Last.fm user accounts or scrobbling. See Last.fm API and Last.fm Terms.
  • MusicBrainz: used for read-only artist identity verification and MusicBrainz identifiers. VENS sends artist names to MusicBrainz and uses an identifiable VENS user-agent as requested by MusicBrainz. See MusicBrainz API.
  • Discogs: used for read-only artist verification, especially for niche, DJ, electronic, and underground artists. VENS sends artist names to Discogs. See Discogs API Terms of Use.
  • Wikipedia / Wikimedia: used for attributed artist summaries and representative artist images on Taste Cards and artist information screens. VENS sends artist names to Wikipedia's public API. Wikimedia content and API use are governed by Wikimedia's terms, licenses, and API/user-agent policies. See Wikimedia API Usage Guidelines.
  • Search fallback: used only as a fallback to locate public event or setlist pages when a direct source lookup does not find a result. VENS does not use search-provider accounts or store search-provider credentials.

Third-party source data may be saved in your VENS library or, if you choose to contribute to a public/community record, in the shared VENS community dataset. VENS is not affiliated with or endorsed by these third-party data providers unless explicitly stated.

External Links for Maps & Tickets

VENS may open Apple Maps for venue/map links and SeatGeek search pages for ticket discovery. These links open outside VENS or in the system browser experience. VENS does not process ticket purchases, does not receive payment information from SeatGeek, and does not control third-party ticket terms, availability, pricing, refunds, or delivery. See SeatGeek Terms of Use and SeatGeek Privacy Notice.

Purchases

VENS offers optional subscriptions and a one-time purchase through Apple's In-App Purchase system (StoreKit). Apple processes all payments directly — Crema Software receives only your subscription status (active/expired/tier), never your payment card details.

Community & Social Content

Features like community setlist contributions, group status, friend challenges, and shared show photos are visible to other users depending on the feature — for example, a group you're part of, or the public community record for an event. Anything you contribute to a shared/public record is visible to others using that same feature.

Friend and group features are designed around temporary, user-directed sharing. For example, live group status or nearby-friend assistance is meant to help people coordinate during a show or event, not to publish connected music account data or create a permanent social profile from your streaming accounts.

How We Use Information

  • To sync your events, setlists, Track ID history, and profile across your own devices via iCloud.
  • To power features you opt into — group discovery, friend challenges, the leaderboard, and community contributions.
  • To identify songs via Track ID and build playlists in your connected streaming service.
  • To search, verify, enrich, and attribute public event, setlist, artist, venue, genre, and song information using third-party sources.
  • To process subscriptions and purchases through Apple's StoreKit.
  • To send notifications you've enabled — group invites, challenge updates, schedule reminders.

We do not use your information for advertising, and VENS contains no ad SDKs or ad tracking of any kind.

Limited Use of Connected Music Service Data

VENS uses connected music service data only to provide or improve user-facing music features that are prominent in VENS, such as matching songs and creating playlists you requested. VENS does not use Apple Music, Spotify, YouTube, or Google user data for advertising, tracking, profiling, resale, or training machine learning or artificial intelligence models.

VENS does not add connected music service account data to public community records, friend features, badges, leaderboards, or social stats. Any social or community sharing in VENS comes from information you intentionally enter, capture, or choose to share inside that specific feature.

VENS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How Information Is Shared

We do not sell your information. Information is shared only in these cases:

  • With other VENS users, for features that are inherently shared — group membership, community setlist contributions, public event records, leaderboards (if you've opted in).
  • With Apple, as the infrastructure provider for iCloud/CloudKit sync and StoreKit payments — governed by Apple's own privacy policy.
  • With a streaming service you've connected (Apple Music, Spotify, YouTube), only to the extent needed to create a playlist you requested.
  • With third-party data sources, only when needed for a feature you use — for example, sending an artist name to MusicBrainz, Last.fm, Discogs, Wikipedia, Spotify, or Apple Music for matching, or sending an event/setlist query to a public event or setlist reference source.
  • Not with social features: connected music service account data is not shared with friends, groups, leaderboards, public records, badges, or social stats unless you separately choose to share a specific item such as a playlist link or show contribution.
  • If required by law, or to protect the rights, safety, and property of Crema Software, VENS users, or the public.

Data Storage & Security

VENS data lives primarily in Apple's CloudKit: private records for your personal sync and public/shared records for community and social features. Streaming-service access tokens are stored in your device's Keychain. Crema Software does not maintain a separate advertising, analytics, or data-broker profile about you; the relay services described above process requests transiently.

Your Choices

  • Permissions: Camera, Photos, Microphone, Location, Local Network, and Nearby Interaction access can be reviewed or revoked anytime in your device's Settings app.
  • Apple Music access: Apple Music permission can be reviewed or revoked in your device settings.
  • Spotify access: You can disconnect Spotify in VENS or revoke VENS's access to Spotify from your Spotify account apps page at https://www.spotify.com/account/apps/. Once revoked, VENS cannot continue using Spotify for your account unless you reconnect.
  • Profile visibility: the leaderboard visibility toggle in your VENS profile controls whether your profile appears publicly.
  • Google/YouTube access: You can disconnect YouTube Music in VENS or revoke VENS's access to YouTube from your Google Account permissions page at https://myaccount.google.com/permissions. Once revoked, VENS cannot continue using YouTube Data API Services for your account unless you reconnect.
  • Deleting your data: you can remove saved events, setlists, tickets, photos, and related personal items inside VENS. Deleting the app removes its local data; iCloud copies remain subject to your iCloud settings and Apple's retention behavior. Contact us at hello@cremasoftware.com for help identifying or removing community-shared content that may still be referenced by other users.

Children's Privacy

VENS is intended for users age 13 and older and is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe a child under 13 has provided us with information, contact us and we'll remove it.

Data Retention

Your personal library, profile, and settings persist for as long as your iCloud account retains them. Community-shared content (public event records, contributed setlists) may persist as part of the shared record even after you stop using a feature, since it's part of a collective dataset other users rely on — the same way a contribution to any shared community record would.

Changes to This Policy

If this policy changes in a material way, we'll update the "Last updated" date above. Continued use of VENS after a change means you accept the updated policy.

Contact Us

Questions about this policy or your data? Email hello@cremasoftware.com — it goes straight to the person building VENS.