Your audio files never leave your browser unless you use the optional Pro lyrics transcription feature. What we do store on our servers is limited to your account record: email, display name, credits balance, subscription status, and (for password accounts) a securely hashed password.
| Data | Why | Where it lives |
|---|---|---|
| Audio files, mastered output, project/version history | So you can master, save, and manage your tracks | Your browser only (IndexedDB) — never uploaded to our servers |
| Email address, display name | Account identity, receipts, support replies | Our server database |
| Password (hashed) | Sign-in for email/password accounts — we never store or see your plaintext password | Our server database, salted + hashed (scrypt) |
| Google account ID (not your Google password) | Sign-in for Google accounts | Our server database |
| Credits balance, Pro status, Stripe customer/subscription ID | So purchases and your plan are tracked correctly | Our server database |
| A session cookie | Keeps you signed in | Your browser; the token itself is stored in our database only as part of your session, never logged elsewhere |
Starting a free trial creates an account with no email or password — just a random ID tied to a browser cookie. We can't identify you personally from a trial account beyond that cookie, and there's no way for us (or you) to recover a trial account if the cookie is lost. If you later sign in for real, your trial account's credits and record are merged into your real account and the trial identity is discarded.
We use a small number of service providers, each only for the specific job listed:
We don't sell your data, and we don't share it with anyone else for advertising or marketing purposes.
We keep your account record for as long as your account exists. If you delete your account (available any time in Settings), we erase your email, name, credits, and subscription linkage from our servers immediately, and cancel any active subscription. Locally saved audio/projects in your browser are not affected by server-side account deletion — those are yours to manage separately (e.g. by clearing your browser's site data).
Passwords are hashed with scrypt and a per-account random salt — we never store plaintext passwords. Session cookies are HTTP-only and marked Secure in production, so they can't be read by page scripts or sent over an unencrypted connection. We keep periodic same-server backups of the account database to guard against data loss from a bug or bad write. These backups currently live on the same server as the live database, not a separate off-site location — they protect against a bad write or software bug, not against loss of the server itself.
You can access, correct, or delete your account data at any time from Settings. If you're in a jurisdiction with additional data rights (like the EU's GDPR or California's CCPA), contact us using the details below and we'll honor applicable requests, including data export or erasure beyond what the in-app account deletion already covers.
Questions about this policy or your data: use the Support option inside the app, or email [email protected].
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
See also our Terms of Service.