Trust
Last updated: July 31, 2026
How Lystrela handles your public portfolio, your private pitches, and the engagement signals you see - in plain language.
Public portfolio vs private pitch
Lystrela keeps two separate things apart. Your public portfolio is a website you choose to publish, showing only the works and credits you mark as public. A private pitch is a link you send to a specific person; it is not listed on your public site and is not indexed by search engines.
Private songs, private lyrics, unreleased demos, recipient links, and engagement data are never reachable through your public site.
A private link can be forwarded
A private pitch link is private in the sense that it is not publicly listed - but anyone who has the link can open it, and the person you sent it to can forward it. Lystrela cannot guarantee that only the intended recipient will access a link.
You decide what to share and with whom. Disabling a link or letting it expire stops future access, but it cannot undo anything that was already viewed, copied, recorded, or forwarded.
Lyrics first, demo optional
Lystrela is built around the words. A pitch always centers on the lyrics; an audio demo is optional. You never need a finished recording to prepare or send a pitch.
What an Open means
An Open is counted once per short access session when a private link is opened. It tells you the page was loaded - nothing more. It does not confirm who opened it.
What a Qualified listen means
A Qualified listen is a client-reported playback event, recorded at most once per song per access session, after forward playback of the demo crosses a threshold: at least 10 seconds, normally about a quarter of the demo, and never more than 30 seconds.
It is an engagement signal that someone let the audio play, not a measurement of attention.
What Opens and Qualified listens do not prove
These are signals, not proof. They do not identify a named person, confirm a specific individual’s identity, prove human attention, guarantee the audio was actually heard, or rule out automated access.
The short signed access session
When a private link is opened, Lystrela sets a signed session cookie that lasts up to 30 minutes and is scoped to that specific link. It is used to count one Open per session, to avoid double-counting a Qualified listen, and to authorize playback of a pinned demo.
It is pseudonymized technical data. It does not identify a named recipient and is not used to track anyone across other websites.
The session is also scoped to the single web address the link was opened on. If your workspace uses a custom domain, the same link can exist on more than one address - and opening it on two different addresses creates two separate sessions, so one person may show up as two Opens. Lystrela does not connect sessions across addresses: that would require an identifier following a recipient between sites, which we deliberately do not create. If you want one clean count, send one address.
Owner preview creates no recipient analytics
When you preview your own link from the dashboard, nothing is recorded: no Open, no Qualified listen, and no lifecycle event. What you see is a faithful preview, not a tracked visit.
Pinned lyrics and demo history
Each link pins the exact version of the lyrics - and, when included, the exact demo - at the time you prepared it. A recipient always sees that pinned version, not whatever you edit later. This preserves an honest record of what you actually sent.
Private audio and storage
Demo audio is stored in private storage. A recipient can only stream the specific demo pinned to their link, through a short-lived signed link generated on request. The underlying file location is never exposed, and private demo objects are not directly published anywhere.
Disable, expiry, archive - and their limits
You can disable a link, set an expiry date, cap the number of views, or require a PIN. Archiving is for your own organization and history; it does not delete anything. These controls govern future access only - they cannot reach content that has already been viewed or forwarded.
Service providers
Lystrela runs on a small set of infrastructure providers: Supabase (authentication, database, and private file storage), Vercel (hosting and delivery), and, for platform email, Hostinger. Emails you send from your own workspace use an SMTP provider you configure in your settings.
Privacy, support, and deletion
You can read how we handle data in the Privacy Policy, get help on the Support page, and ask a privacy or data question any time.
You can request deletion of your account from your account settings; it is handled manually during the current invitation-only phase.
Privacy and data requests: privacy@lystrela.com
Reasonable safeguards, honest limits
Lystrela applies reasonable technical and organizational safeguards - server-side authorization on every request, signed private-link access, and encryption of sensitive stored secrets. No online service can be perfectly safe, and Lystrela cannot promise that a shared link will reach only the person you intended.
Operator
- Operated by
- NEBOJŠA SMRZLIĆ PR KALTECH SOFTWARE
- Registration number (Matični broj)
- 65275791
- Tax ID (PIB)
- 111233739
- Registered seat
- Grocka, City of Belgrade, Republic of Serbia
The operator’s full registered address is recorded in the public register maintained by the Serbian Business Registers Agency and may be provided where necessary for exercising legal rights or complying with applicable law.
- Supportsupport@lystrela.com
- Privacy and data requestsprivacy@lystrela.com
- General contactinfo@lystrela.com