Crema Software Meet VENS

Last updated: July 12, 2026

This policy covers VENS, an app published by Crema Software LLC ("Crema Software," "we," "us") for iPhone, iPad, Mac, and Apple Watch. It describes what information VENS collects, how it's used, who it's shared with, and the choices you have.

The short version: VENS doesn't run its own data-collection servers. Almost everything you create in VENS — your profile, festival library, setlists, and squad activity — syncs through your own iCloud account via Apple's CloudKit, the same infrastructure Apple provides to every app that supports iCloud sync. Crema Software never sees your Apple ID password, and payment is handled entirely by Apple — we never receive or store your card details.

Information We Collect

Account & Sync

VENS doesn't have its own sign-up or password system. It uses whichever iCloud account is already signed into your device to sync your data via CloudKit, and to identify your content to other users you interact with (for example, showing your display name on a shared squad). We receive an opaque CloudKit user identifier, not your Apple ID or email address.

Profile Information

You choose what to add to your profile: a display name, an avatar or a custom photo, and optionally your city, state, and country. None of this is inferred from your device's location — it's typed in by you, and a visibility toggle controls whether it appears on the leaderboard.

Photos & Camera

VENS uses your camera to photograph festival posters for scanning, and can read photos you choose to select for scanning a poster or attaching a "show memory." If you capture a photo at a show, VENS can save it back to your Photos library. VENS only accesses photos you explicitly select — it doesn't scan your photo library in the background.

Microphone & Track ID

Track ID uses your iPhone's (or Apple Watch's) microphone to identify a song playing live, similar to Shazam. VENS does not store or transmit the audio recording itself — only the result of the identification (song title, artist, genre, and a timestamp) is saved to your library.

Local Network & Nearby Interaction (Squad)

If you use Squad features to find friends at a show, VENS uses your device's local network and Nearby Interaction (Ultra Wideband) capability to estimate the distance to squad members you've specifically chosen to find. This does not use or collect GPS location — it only works for people already in your squad, at close range, and only while you're actively using that feature.

Connected Streaming Services

You can optionally connect Apple Music, Spotify, or YouTube Music to build playlists from a scanned lineup or captured setlist. Sign-in for these happens through each service's own login page — VENS never sees your password for these services — and the resulting access token is stored securely in your device's Keychain, not on any Crema Software server. Once connected, each service's own privacy policy governs how they handle your listening activity.

Connected music service data is kept separate from VENS social and community features. VENS does not share your Apple Music, Spotify, YouTube, or Google account data with friends, squads, leaderboards, public festival records, or other VENS users. If you choose to share something with friends — for example a playlist link, squad status, challenge, or show-related contribution — that sharing is initiated by you and limited to the feature you selected.

Apple Music & MusicKit

VENS uses Apple Music and MusicKit only after you grant Apple Music access on your device. VENS uses this access to search the Apple Music catalog, match songs from festival lineups and setlists, create playlists you request, and add selected tracks to those playlists in your Apple Music library.

VENS does not use Apple Music data for advertising, tracking, profiling, identifying users or devices, or resale. Apple Music data is used only to provide or improve the music features visible in VENS. You can review or revoke Apple Music access in your device settings. Apple Music is also governed by Apple Music & Privacy and the Apple Media Services Terms and Conditions.

Spotify Web API

VENS uses the Spotify Web API only if you choose Spotify as a playlist destination and sign in with Spotify. VENS requests playlist permissions, including the ability to manage public and private playlists, so it can create playlists and add matched tracks when you ask VENS to publish a festival lineup, setlist, or Track ID playlist.

VENS stores Spotify OAuth tokens securely in your device's Keychain. Crema Software does not receive your Spotify password, does not sell Spotify user data, does not use Spotify data for advertising or profiling, and does not use Spotify content or Spotify user data to train machine learning or artificial intelligence models. VENS processes Spotify access only as needed to provide the playlist feature you requested.

You can disconnect Spotify in VENS or revoke VENS's Spotify access from your Spotify account apps page at https://www.spotify.com/account/apps/. After access is revoked, VENS can no longer create or modify Spotify playlists unless you connect again. Spotify's own Privacy Policy, Terms and Conditions of Use, and Developer Policy also apply.

YouTube Data API Services & Google User Data

VENS uses YouTube Data API Services only if you choose YouTube Music as a playlist destination and sign in with Google. VENS does not access YouTube in the background and does not use YouTube or Google data for advertising.

When you connect YouTube Music, VENS requests YouTube permission scopes that allow the app to create and manage YouTube playlists you ask VENS to publish. VENS uses this access to validate your signed-in YouTube account, search YouTube for videos that match songs from your festival lineup or setlist, create a private playlist, and add matched videos to that playlist.

VENS stores the resulting Google OAuth access token and refresh token securely in your device's Keychain so the app can complete playlist publishing and reconnect without asking you to sign in every time. Crema Software does not receive your Google password, does not sell Google user data, does not use Google user data for ads or profiling, and does not transfer Google user data except as needed to provide the YouTube playlist feature you requested.

VENS does not upload videos to YouTube, does not download YouTube videos or audio, and does not embed a YouTube player. Playlist items remain in your YouTube account and are governed by Google's and YouTube's own policies.

You can disconnect YouTube Music in VENS or revoke VENS's access to your Google account from your Google Account permissions page at https://myaccount.google.com/permissions. After access is revoked, VENS can no longer create or modify YouTube playlists unless you connect again. You may also contact us at hello@cremasoftware.com for help removing VENS-created community-shared content or understanding how to disconnect a streaming service.

For more information, see the Google Privacy Policy, the YouTube Terms of Service, and the Google API Services User Data Policy.

Optional Cloud AI / Gemini

VENS can optionally use Google's Gemini API for the "Advanced & Powerful" scanning mode when you provide your own Gemini API key. In that mode, VENS may send the selected poster image or pasted lineup/setlist text to Gemini so it can extract artists, days, stages, times, and related show details. Choosing the "Fast & Private" scanning mode keeps photo OCR on-device through Apple's Vision framework.

Your Gemini API key is stored securely in your device's Keychain. Crema Software does not receive your Gemini API key. Gemini requests are governed by Google's applicable Gemini API terms and policies, including the Gemini API Additional Terms of Service and Gemini API usage policies.

Third-Party Music, Setlist & Reference Sources

VENS uses several third-party public data sources to help search, verify, enrich, and attribute festival and setlist information. These sources are used only to support user-facing app features such as finding a setlist, confirming an artist name, adding genre/artist context, or showing a short artist fact.

  • Public setlist and event sources: used to search for festival and artist setlists, load user-pasted public event/setlist links, and enrich show metadata. VENS may send artist names, festival names, dates, venues, cities, countries, or pasted public event/setlist URLs to those sources. Their content is governed by their own terms and API terms.
  • Last.fm: used for read-only artist search, top tracks, genre tags, and short artist biography context. VENS sends artist names to Last.fm and does not use Last.fm user accounts or scrobbling. See Last.fm API and Last.fm Terms.
  • MusicBrainz: used for read-only artist identity verification and MusicBrainz identifiers. VENS sends artist names to MusicBrainz and uses an identifiable VENS user-agent as requested by MusicBrainz. See MusicBrainz API.
  • Discogs: used for read-only artist verification, especially for niche, DJ, electronic, and underground artists. VENS sends artist names to Discogs. See Discogs API Terms of Use.
  • Wikipedia / Wikimedia: used for occasional short artist facts during scanning. VENS sends artist names to Wikipedia's public API and displays source attribution when Wikipedia-derived facts are shown. Wikimedia content and API use are governed by Wikimedia's terms, licenses, and API/user-agent policies. See Wikimedia API Usage Guidelines.
  • Search fallback: used only as a fallback to locate public event or setlist pages when a direct source lookup does not find a result. VENS does not use search-provider accounts or store search-provider credentials.

Third-party source data may be saved in your VENS library or, if you choose to contribute to a public/community record, in the shared VENS community dataset. VENS is not affiliated with or endorsed by these third-party data providers unless explicitly stated.

External Links for Maps & Tickets

VENS may open Apple Maps for venue/map links and SeatGeek search pages for ticket discovery. These links open outside VENS or in the system browser experience. VENS does not process ticket purchases, does not receive payment information from SeatGeek, and does not control third-party ticket terms, availability, pricing, refunds, or delivery. See SeatGeek Terms of Use and SeatGeek Privacy Notice.

Purchases

VENS offers optional subscriptions and a one-time purchase through Apple's In-App Purchase system (StoreKit). Apple processes all payments directly — Crema Software receives only your subscription status (active/expired/tier), never your payment card details.

Community & Social Content

Features like community setlist contributions, squad status, friend challenges, and shared show photos are visible to other users depending on the feature — for example, a squad you're part of, or the public community record for a festival. Anything you contribute to a shared/public record is visible to others using that same feature.

Friend and squad features are designed around temporary, user-directed sharing. For example, live squad status or nearby-friend assistance is meant to help people coordinate during a show or festival, not to publish connected music account data or create a permanent social profile from your streaming accounts.

How We Use Information

  • To sync your festivals, setlists, Track ID history, and profile across your own devices via iCloud.
  • To power features you opt into — Squad discovery, friend challenges, the leaderboard, and community contributions.
  • To identify songs via Track ID and build playlists in your connected streaming service.
  • To search, verify, enrich, and attribute public festival, setlist, artist, venue, genre, and song information using third-party sources.
  • To process subscriptions and purchases through Apple's StoreKit.
  • To send notifications you've enabled — squad invites, challenge updates, schedule reminders.

We do not use your information for advertising, and VENS contains no ad SDKs or ad tracking of any kind.

Limited Use of Connected Music Service Data

VENS uses connected music service data only to provide or improve user-facing music features that are prominent in VENS, such as matching songs and creating playlists you requested. VENS does not use Apple Music, Spotify, YouTube, or Google user data for advertising, tracking, profiling, resale, or training machine learning or artificial intelligence models.

VENS does not add connected music service account data to public community records, friend features, badges, leaderboards, or social stats. Any social or community sharing in VENS comes from information you intentionally enter, capture, or choose to share inside that specific feature.

VENS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How Information Is Shared

We do not sell your information. Information is shared only in these cases:

  • With other VENS users, for features that are inherently shared — squad membership, community setlist contributions, public festival records, leaderboards (if you've opted in).
  • With Apple, as the infrastructure provider for iCloud/CloudKit sync and StoreKit payments — governed by Apple's own privacy policy.
  • With a streaming service you've connected (Apple Music, Spotify, YouTube), only to the extent needed to create a playlist you requested.
  • With third-party data sources, only when needed for a feature you use — for example, sending an artist name to MusicBrainz, Last.fm, Discogs, Wikipedia, Spotify, or Apple Music for matching, or sending a festival/setlist query to a public event or setlist reference source.
  • Not with social features: connected music service account data is not shared with friends, squads, leaderboards, public records, badges, or social stats unless you separately choose to share a specific item such as a playlist link or show contribution.
  • If required by law, or to protect the rights, safety, and property of Crema Software, VENS users, or the public.

Data Storage & Security

The vast majority of VENS's data lives in Apple's CloudKit, secured under your own iCloud account and Apple's infrastructure-level protections. Streaming-service access tokens are stored in your device's Keychain, protected by iOS/macOS's own security model. Crema Software does not operate a separate backend database holding your personal data outside of Apple's systems.

Your Choices

  • Permissions: Camera, Photos, Microphone, Local Network, and Nearby Interaction access can be reviewed or revoked anytime in your device's Settings app.
  • Apple Music access: Apple Music permission can be reviewed or revoked in your device settings.
  • Spotify access: You can disconnect Spotify in VENS or revoke VENS's access to Spotify from your Spotify account apps page at https://www.spotify.com/account/apps/. Once revoked, VENS cannot continue using Spotify for your account unless you reconnect.
  • Profile visibility: the leaderboard visibility toggle in your VENS profile controls whether your profile appears publicly.
  • Google/YouTube access: You can disconnect YouTube Music in VENS or revoke VENS's access to YouTube from your Google Account permissions page at https://myaccount.google.com/permissions. Once revoked, VENS cannot continue using YouTube Data API Services for your account unless you reconnect.
  • Deleting your data: since VENS's data lives in your iCloud account, removing the app and disabling iCloud sync for VENS (Settings → [your name] → iCloud) removes VENS's access to that data. Contact us at hello@cremasoftware.com if you need help fully removing community-shared content (e.g., a public contribution) that another user's view of a shared feature might still reference.

Children's Privacy

VENS is rated 13+ on the App Store and is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe a child under 13 has provided us with information, contact us and we'll remove it.

Data Retention

Your personal library, profile, and settings persist for as long as your iCloud account retains them. Community-shared content (public festival records, contributed setlists) may persist as part of the shared record even after you stop using a feature, since it's part of a collective dataset other users rely on — the same way a contribution to any shared community record would.

Changes to This Policy

If this policy changes in a material way, we'll update the "Last updated" date above. Continued use of VENS after a change means you accept the updated policy.

Contact Us

Questions about this policy or your data? Email hello@cremasoftware.com — it goes straight to the person building VENS.