Quick Answer
Sending the file is the easy part. The part that matters later is being able to show who you sent it to and when.
Before you send: date the work (register it with SongSecure, and add a U.S. Copyright Office registration for anything high-stakes). When you send: send it to a named individual, not a role inbox, and use something that produces a dated per-recipient record — SendSecure is built for exactly this, at $9.95/month or $97/year. After you send: keep the reply, including a no, and write down who that person was and who they were working with.
What that record is, precisely: a dated note of a file going to a named person, and of that file being opened. What it is not: proof anyone listened, proof of access, or a guarantee of any legal outcome. Access is a finding a court makes on the whole record. An open event is a file being fetched — not a person hearing a song.
Every guide to this subject spends its length on how to stop the file being stolen. That is the wrong end of the problem. Files do not usually get intercepted; songs get sent to somebody, and then years later nobody can prove the send happened, or to whom.
This page is about the second thing, because it is the one that decides how the conversation goes if it ever turns bad — and because the cases are unusually clear about it.
Updated August 2026. This is a substantive rewrite of an article first published in April 2026. Two claims in the original version have been removed rather than softened: a security claim about SendSecure that we cannot stand behind — SendSecure is a delivery-record product, and we make no claim about its security properties — and an offer to give testimony in a dispute, which we do not do and which our own terms disclaim.
Why does proof of receipt matter more than the file being "safe"?
Because of what a US copyright claim actually has to establish.
Owning the copyright is automatic; it exists from the moment the work is fixed. What is not automatic is the second element of an infringement claim: that the other side had access to your work. The Ninth Circuit's model civil jury instruction defines it for jurors like this:
"You may find that the defendant [name] had access to the plaintiff [name]'s work if [the defendant [name]] [whoever created the work owned by the defendant [name]] had a reasonable opportunity to [view] [read] [hear] [copy] the plaintiff [name]'s work before the defendant [name]'s work was created."
— Manual of Model Civil Jury Instructions for the District Courts of the Ninth Circuit, Instruction 17.18, "Copyright Infringement—Copying—Access Defined" (revised September 2025)
Two things are being asked for: an opportunity, and a sequence. Both are facts about a send.
The same instruction's supplemental text spells out the route that most musicians are actually on, and it describes the demo-to-label situation almost word for word. Access may be shown by:
"a chain of events connecting the plaintiff [name]'s work and the defendant [name]'s opportunity to [view] [hear] [copy] that work [such as dealings through a third party (such as a publisher or record company) that had access to the plaintiff [name]'s work and with whom both the plaintiff and the defendant [name] were dealing]"
A chain of events. Not a vibe, not a coincidence — a chain, and a chain is only as good as the links you can name and date. That is what a record of a send is for, and it is the whole argument of this page.
For a fuller treatment of the element itself, see what is access in copyright law and the longer piece on how to prove someone heard your song.
Does it matter who at the label you send it to?
More than anything else about the record. This is the single most useful thing in this article, and it comes from a case where the delivery was never in dispute.
In Loomis v. Cornish, 836 F.3d 991 (9th Cir. 2016), Will Loomis's band was asked for their song "Bright Red Chords" by Sunny Elle Lee, an Artists and Repertoire representative at UMG Recordings. The Ninth Circuit's finding on the send is one sentence:
"In May of 2010, Lee emailed Loomis's mother, Kristin Loomis, who acted as administrative coordinator for the band, to request a copy of Bright Red Chords. The band furnished Lee a copy of the song."
Solicited. Delivered. Accepted as fact. And the claim failed:
"We disagree. On the record before us, there is no evidence of a nexus between Lee and the Domino songwriters that would be sufficient to raise a triable issue of access."
Quoting Jorgensen v. Epic/Sony Records, the court stated the rule: "Bare corporate receipt …, without any allegation of a nexus between the recipients and the alleged infringers, is insufficient to raise a triable issue of access." Loomis did not dispute that "[t]he five Domino Writers do not know, have never met, and have never received anything from Sunny Elle Lee," or that "Lee was not part of the work unit that created Domino."
A delivery record proves delivery to the person you sent it to. It proves nothing about anyone else. That is not an argument against keeping one. It is an instruction about how:
- Send to a named individual, not
demos@. A role inbox produces a record of delivery to a company, and Loomis is what that is worth. - Write down what they do and who they work with, on the day you send. If you learn three years later that the person you sent it to moved to the team that made a record you recognise, that fact is worth more than the delivery — and you will only be able to connect it if you noted where they were at the time.
- Keep what came back. A reply is the recipient confirming receipt in their own words, which is something no log will ever give you. A rejection is often the most useful document of all, because it is dated, specific, and written by them.
Does the date on the record matter?
It can decide the point on its own, and the demonstration is Bowen v. Paisley, M.D. Tennessee, 25 August 2016.
Amy Elizabeth Connor Bowen, who writes in Nashville as Lizza Connor, wrote a song called "Remind Me" between autumn 2007 and March 2008 and registered it effective 3 September 2008. In 2011 Brad Paisley, Kelley Lovelace and Chris DuBois released a song of the same name as a duet with Carrie Underwood.
Among Bowen's access evidence was an email chain with an actual recording of her song attached to it — her brief called it "perhaps the most compelling point of access." Judge Aleta A. Trauger:
"…she fails to acknowledge that this communication took place in October 2011, well after both the creation and public release of the Paisley Work. The email exchange therefore could not establish access for purposes of copyright infringement."
Real evidence. Uncontested. Containing the work itself. Worth nothing, because of a date.
Two things belong beside that, and the second is the honest one.
Bowen did not lose on access. She had sung the song for Lovelace in person at a songwriting workshop on 3 March 2008, and that carried her past the element: "the plaintiff has adequately raised a disputed issue of fact as to access." The lesson is not that documentation failed her — it is that a record made at the time is the only kind that can settle sequencing, because it cannot be assembled after the dispute begins.
She lost anyway, on substantial similarity. The only thing the two songs shared was the unprotectable phrase "remind me." Her documentation answered when and who. Those were not the questions she lost on. Anyone who tells you a good record wins cases is selling you something; what a good record does is stop you losing on the one question it can answer.
What should you do before you send anything?
Four things, in this order. Two of them are free.
1. Keep the sequence, not just the bounce. The voice memo, the first session file, the lyric draft with the crossings-out, the stems, then the master — in order, undeleted, un-tidied. In Batiste v. Lewis the defendants met a sampling claim with Ryan Lewis's sworn declaration, quoted by the district court in his own words: "As part of the discovery in this lawsuit, I, at the direction of counsel, turned over all of the audio files I had that documented the process of creating the Macklemore & Lewis Songs." What made the statement worth something was being able to produce the archive behind it. A single finished MP3 is a claim. A dated chain of artefacts is a story. More on this in how to prove you wrote a song first.
2. Date the file before it leaves your machine. Not after somebody starts asking questions. A registration record with SongSecure takes minutes and hashes the file to a public chain, producing a dated record that this exact file existed by this date. What that does and does not establish is set out at length in is a blockchain timestamp legal proof of song ownership — short version: it evidences possession at a time, and it does not prove you wrote what is inside.
3. Register with the U.S. Copyright Office for anything high-stakes. This is the only item on the list that a subscription cannot substitute for. Circular 1:
"Before an infringement suit may be filed in court, registration (or refusal) is necessary for U.S. works."
"When registration is made prior to infringement or within three months after publication of a work, a copyright owner is eligible for statutory damages, attorneys' fees, and costs."
And the statute behind the second sentence, 17 U.S.C. §412:
"In any action under this title … no award of statutory damages or of attorney's fees, as provided by sections 504 and 505, shall be made for— (1) any infringement of copyright in an unpublished work commenced before the effective date of its registration; or (2) any infringement of copyright commenced after first publication of the work and before the effective date of its registration, unless such registration is made within three months after the first publication of the work."
A demo you have pitched but not released is an unpublished work, which puts clause (1) squarely in front of it. Current fees: $45 for a single work by a single author-claimant, not for hire; $65 standard; $85 for a group of unpublished works; $65 for a group of works published on an album of music.
4. Decide who you are actually sending to, and write it down. Name, job title, company, how you were introduced, what they are working on. Thirty seconds now. It is the Loomis link, and no product captures it because it is not in the file transfer.
What should the record of the send contain?
Six fields. If your method produces these, it is doing its job.
| Field | Why it matters |
|---|---|
| Named recipient | Loomis. A company is not a person, and a record of delivery to a company is a record of the thing Loomis had |
| Date and time of the send | Bowen. Sequencing is the one thing a delivery record genuinely settles |
| Which version | "Which mix did they have" is a real question in a real dispute. Send each revision as a separate send |
| Whether and when their copy was opened | Useful, and narrower than it sounds. See the honesty section below |
| What came back | The recipient's own words. Nothing beats it, and no log produces it |
| Who they were, in context | Their role, their team, who they were working with. Written by you, that week |
Which sending method should you use?
Honestly: several of them work, and the differences are smaller than vendors imply. Here is a fair reading.
| What it is good at | What to know | |
|---|---|---|
| Email with the file attached | Free. Carries the recipient's own reply. Universally accepted. Genuinely the best record most people already have | No open event. Attachment size limits. Reconstructing it from a mailbox years later is real work, and only if you still have the account |
| WeTransfer | Fast, ubiquitous, and it does track. Its own documentation describes a preview count on every transfer, plus a per-recipient log "showing exactly who previewed the files and when" when access control is enabled, and separate download tracking | The per-recipient part is opt-in; the always-on part is an aggregate count, not a person. A link shared with anyone-who-has-it names no recipient at all. And its framing is engagement — how a transfer "is performing" — rather than a record designed to be produced years later |
| Dropbox / Google Drive | Excellent for working files, versions and collaboration. Everyone already has one | A shared link is a record about a link. What is logged, and for whom, varies by plan and setting — check yours before relying on it, and note that "anyone with the link" records no named recipient |
| SoundCloud private links | The music industry's normal way of hearing something. Frictionless for the recipient | Built around plays, not per-recipient records. SoundCloud's own description of Insights is that it "gives you a real-time look at how your music is performing — plays, likes, reposts, comments, and downloads", with listener-level features ("Top Fans", "First Fans") depending on your plan. None of that is a record of which named person you sent a private link to opened it. Check what your tier gives you before relying on it |
| SendSecure | Built for this specific job: one dated record per named recipient, with the file version, delivery time and each open, written on the day of the send. Included in a SongSecure subscription | It records delivery and opening. Nothing else. No reported US music copyright decision we are aware of has assessed a record of this kind, from us or anyone |
The fair summary: WeTransfer and Dropbox are good products and there is nothing wrong with using them. They are built to move files, and they do it better than almost anyone. The gap is not capability — it is purpose. Their tracking exists so you know whether to chase a client, and it is optional, aggregate by default, and tied to a transfer rather than to a dated file. What we built SendSecure for is the other job: a per-recipient record, on by default, attached to a specific version, that you can still produce when the question arrives four years late.
If you only ever do one thing, though: keep the email. It carries their words. That is worth more than any log.
Do you actually need an NDA?
Sometimes, and less often than the internet suggests.
An NDA is a contract in which the recipient agrees not to share or use your material without permission. It is worth asking for when you are dealing with someone new whom you have no basis to trust, when the material is unusually valuable, or when the recipient's track record gives you pause.
It is worth not asking for when you are pitching an established label, publisher or producer. Companies that receive unsolicited material routinely decline to sign NDAs before hearing it, for reasons that have nothing to do with you — and insisting can simply end the conversation. That is a trade-off to make deliberately rather than a rule.
If you do use one, the things people usually put in it are: a definition of what is confidential (the recording, the lyrics, the arrangement); the usual exclusions for material that is already public or independently developed; who at the recipient may hear it and for how long; how long the obligation lasts; and what happens on a breach.
One distinction worth having clear. An NDA governs secrecy. It is not how rights move. 17 U.S.C. §204(a), in full:
"A transfer of copyright ownership, other than by operation of law, is not valid unless an instrument of conveyance, or a note or memorandum of the transfer, is in writing and signed by the owner of the rights conveyed or such owner's duly authorized agent."
If a conversation turns from "can I hear it" to "can I use it," that sentence is the one to read the paperwork against. What any given agreement means for you is a question for a lawyer, not for us.
Should you watermark the demo?
It is a trade-off, and it is worth being clear about both sides.
For: an audible tag or a subtle tonal marker makes a leaked file traceable, and makes casual reuse awkward. It is the standard practice for beats sent to strangers for a reason.
Against: it degrades the listen. A&R staff, producers and sync supervisors listen to a great deal of music and a watermark every eight bars is a real obstacle to hearing the song. There is a version of caution that costs you the opportunity you were being careful about.
Where the line usually falls: watermark unsolicited sends to people you do not know. Do not watermark material going to someone you are actually collaborating with, or a mix somebody has to work on. And do not treat a watermark as a substitute for the record of the send — it tells you a file leaked, not who you gave it to.
Sharing with labels vs producers vs collaborators
Different relationships, different sensible defaults. This table is about proportion, not paranoia.
| Recipient | What to do every time | What to add | What to skip |
|---|---|---|---|
| Labels and publishers | Date the file first; send to a named A&R or creative person; note their role and team; keep the reply | Copyright Office registration for anything you would be upset to lose | Insisting on an NDA before they have heard it — most will decline, and it can end the pitch |
| Producers and beatmakers | Date the file first; named recipient; agree in writing what they are allowed to do with it | A watermark if you have not worked together before; a short written scope of what they may do with the stems | Watermarking a mix they have to actually work on |
| Collaborators and co-writers | Date the file first; write the split sheet at the session; send from an account you will still control in five years | A short dated message confirming what you agreed, and keep whatever comes back | NDAs and formality that damage the working relationship. The split sheet does the real work |
On split sheets, because they matter more than any of this. A split sheet is one page: the song and the date, everyone in the room, what each person contributed, the percentage each takes of the composition, and each writer's performing-rights society and IPI number. Everybody signs. It is filed nowhere and has no official status. It is a record of what people agreed while they still agreed, and it is the cheapest insurance in music.
If someone will not sign one, act while it is fresh: write down what you understood the splits to be, send it by a method that leaves a record — "here's what I have us at, shout if that's wrong" — and keep whatever comes back, including nothing. A dated, unanswered message beats two memories.
Red flags worth taking seriously
- They want rights before they have heard it. Nobody legitimate needs ownership to decide whether they like a song.
- They will not put the arrangement in writing at all. Not an NDA — the basics. What are you giving them, for how long, to do what.
- The deadline is theirs and the urgency is manufactured. "We need it exclusively by Friday" from someone you met last week is a negotiating tactic, not an opportunity.
- They ask you to remove the tag "just to hear it properly." Sometimes reasonable. Note who asked, and when.
- No trace anywhere. No credits, no releases, no other writers who will speak to you. Search before you send.
- The paperwork does not match the pitch. If the contract transfers more than the conversation described, the contract is the deal.
What a delivery record does not prove
This section exists because most of this category will not write it.
A record of a send establishes that a named recipient was sent a specific file on a specific date, that the file was opened and when, and which version they got. That is the list. It does not establish:
- That they listened. An open event is a file being fetched by a browser or a client. It is not a person hearing a song. We write opened, never heard, because only one of those is in the log.
- That the named recipient was the person who opened it. The record shows their copy being fetched. No software sees who was at the keyboard.
- That they understood, remembered, or were influenced. No log reaches the mind of a recipient.
- That they, or anyone, later copied anything.
- That anyone else at their organisation ever saw it. That is Loomis, and it is the trap.
- That a court has found access. Access is a finding made on the whole record; a delivery record is one piece of evidence a court may weigh toward it.
- That the record is admissible. Admissibility is a ruling a judge makes about a specific exhibit in a specific case, after both sides have argued about it. No product is admissible in advance and we do not describe ours as one.
One more, and it applies to us as much as to anyone selling in this space. We read every US music copyright decision we could find from 2015 to 2026 — 197 decisions, 108 of them merits rulings across 82 disputes, screened independently by two coders (κ = 0.8297, n = 203, 95% CI 0.7502–0.9010). Not one discussed a blockchain record, a cryptographic timestamp or a trusted timestamping service, and we are not aware of a reported US music copyright decision assessing a delivery record produced by a service of this kind. That is not evidence a court would accept one, and not evidence a court would reject one. No court in that set was asked.
What if it has already gone wrong?
Everything above is about the window before a dispute. If you have already heard your song on someone else's release, the order of operations changes and that is a different page: someone stole my song — what can I actually do about it, which covers preserving evidence, registering after discovery, the Copyright Claims Board, demand letters and platform takedowns, with the statutes quoted.
If it is specifically a beat you sent to somebody who then used it, the send itself changes what you have, and that has its own page: someone stole my beat after I sent it to them.
FAQ
Do I need copyright registration before sharing a demo?
No. Copyright exists from the moment the work is fixed, and nothing has to be filed before you send anything. What registration governs is what happens afterwards: under Circular 1, "Before an infringement suit may be filed in court, registration (or refusal) is necessary for U.S. works," and under §412 statutory damages and attorney's fees are unavailable for infringement of an unpublished work "commenced before the effective date of its registration." Date the file before you send it either way — that costs minutes.
How do I prove a label received my demo?
Keep a dated record naming the individual, and keep whatever came back. An email you still have is already a strong record because it carries the recipient's own words. A delivery service adds a per-recipient open event and a record you do not have to excavate from a mailbox years later. Neither shows anyone listened.
What's the best way to send a demo?
The one the recipient will actually open. Email, WeTransfer, a private stream and a purpose-built delivery record all work; the differences are about what is left behind afterwards, not about whether the file arrives. Send to a named person, send each revision separately, and keep the reply.
Should I watermark every demo?
No. Watermark unsolicited sends to people you do not know. Skip it for collaborators and for anything somebody has to work on.
Can a label make me sign away my rights before hearing the song?
Nobody legitimate needs ownership to decide whether they like a song. If a document transfers more than the conversation described, read §204(a) again and take advice before signing.
Does an "opened" event mean they listened?
No. It means something at their end fetched the file. It is not a person hearing a song.
The short version
Send the song. Keep the receipt. Write down who they were.
The cases are unusually consistent about which half of that is hard. Loomis had the delivery and lost on the distance between the recipient and the writers. Bowen had an email containing her own recording and it was worthless because of its date. Neither lost because the file was insufficiently protected in transit.
So: date the file before it leaves. Send it to a person, not an inbox. Send each version separately. Keep the reply, especially a no. Note what that person did and who they worked with, the week you sent it. Register anything you would be upset to lose.
None of that requires a lawyer, and most of it does not require a product. The one part worth paying for is the part you will not do by hand in four years' time — and that is what SendSecure is, stated no higher than that.
Last updated: 13 August 2026. Previously published 15 April 2026.
Legal disclaimer
This article is informational and is not legal advice. It quotes statutes, court decisions and official Copyright Office guidance; it does not tell you how any of them apply to your situation, and no reader should act on it without consulting a qualified attorney in the relevant jurisdiction. Copyright law differs by country and changes over time. SongSecure is not a law firm and does not provide expert testimony. No record, timestamp or certificate, from SongSecure or anyone else, guarantees any legal outcome.
Sources
Primary authority. Loomis v. Cornish, 836 F.3d 991 (9th Cir. 2016) · Jorgensen v. Epic/Sony Records, 351 F.3d 46 (2d Cir. 2003) · Bowen v. Paisley, No. 3:13-cv-0414 (M.D. Tenn. 25 August 2016) (Trauger, J.) · Batiste v. Lewis, 976 F.3d 493 (5th Cir. 2020), and the summary-judgment order below, Batiste v. Lewis, No. 2:17-cv-04435 (E.D. La. 23 April 2019), in which Ryan Lewis's sworn declaration is quoted · 17 U.S.C. §§ 204(a), 411(a), 412.
Official guidance. Manual of Model Civil Jury Instructions for the District Courts of the Ninth Circuit, Instruction 17.18, "Copyright Infringement—Copying—Access Defined" (revised September 2025), including the supplemental instruction on chain-of-events access · U.S. Copyright Office, Copyright Basics (Circular 1) · U.S. Copyright Office fee schedule (copyright.gov/about/fees.html).
Third-party product descriptions. WeTransfer, "See who's viewed your shared files" (wetransfer.com/resources/file-view-tracking), retrieved 13 August 2026 · SoundCloud, "SoundCloud Analytics & Insights" (soundcloud.com/getstarted/insights), retrieved 13 August 2026. Quotations are each company's own; what any plan includes changes, so check the current terms rather than relying on this page.
Data. SongSecure frozen decision universe, 2015–2026: 203 records covering 197 distinct decisions, 108 in-scope merits decisions across 82 disputes, two independent coders, κ = 0.8297 (95% CI 0.7502–0.9010), measuring the inclusion screen and not any outcome variable.