Privacy Policy
Version 2026-10-07 · Last updated
This policy explains how [OPERATOR FULL LEGAL NAME], a sole proprietor (Osek) registered in Israel under number [OSEK NUMBER], of [CITY], Israel, trading as MixSongs (“we”), processes personal data when you use mixsongs.app and app.mixsongs.app (the “Service”). We are the controller of the personal data described here, except where we say that another company is an independent controller.
Contact for privacy matters: [email protected]
1. The short version
- Mixing, editing and exporting happen in your browser. Your songs are not sent to us for those features.
- No account is needed for the free features, and the marketing site sets no cookies of its own.
- If you sign in, we receive your name, email address and Google account ID from Google.
- If you use AI stem separation, the file you choose is processed on a cloud GPU and deleted within about an hour, usually as soon as the stems reach your browser. We never use it to train AI.
- Payments are handled by Paddle as Merchant of Record. We never see your card details.
- We do not sell or share personal data for advertising, and we have no advertising trackers.
2. What we collect, why, and on what legal basis
| Data | When | Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|---|---|
| Technical request data: IP address, browser user agent, requested URL, time | Every visit (processed by Cloudflare, our host) | Delivering the site, security, preventing abuse and bots, rate limiting | Legitimate interests (security and operation of the Service) |
| Aggregated, cookieless analytics: page views, referrer, browser type, country | Every visit (Cloudflare Web Analytics) | Understanding which pages are useful | Legitimate interests |
| Account data: Google account ID, email address, display name, account creation time | When you sign in | Creating and running your account, support, important service notices | Performance of a contract |
| Session data: a random session identifier (we store only a cryptographic hash), creation and expiry time | While signed in | Keeping you signed in securely | Performance of a contract; legitimate interests (security) |
| Legal acceptance records: which versions of our documents you accepted, and when | At sign-up, on updates, at purchase | Proving the agreement and your consents | Legal obligation; legitimate interests (establishing and defending legal claims) |
| Credit and purchase records: credit balance and history, Paddle transaction and customer IDs, amount, currency, status | When you buy or use credits | Granting and accounting for credits, refunds, fraud prevention, bookkeeping | Performance of a contract; legal obligation (accounting) |
| Separation job records: job ID, file size, status, timestamps, error code (no file name, no audio) | When you use AI separation | Running the job, refunding failed jobs, preventing abuse, capacity planning | Performance of a contract; legitimate interests |
| Audio files for AI separation and the resulting stems | Only when you start a separation | Performing the separation you asked for | Performance of a contract |
| Bot-check signals (Cloudflare Turnstile) | When you sign in | Preventing automated abuse | Legitimate interests |
| Support correspondence: your email address and message | When you email us | Answering you | Legitimate interests; performance of a contract |
What we do not collect: we do not receive your audio for mixing or export, your local projects, your full payment card details, your contacts or your location beyond a country derived from your IP address. We do not store IP addresses in our own database.
Data on your device only. The app saves your projects (including audio) and preferences (language, theme) in your browser’s local storage on your own device. We have no access to it. You can delete it at any time by clearing the site’s data in your browser.
3. Audio you send for AI separation
When you start a separation, the selected file is sent over an encrypted connection (HTTPS) through our server to our GPU provider (Modal Labs), processed by machine-learning models, and the resulting stems are streamed back to your browser. The original upload is deleted once processing ends. The stems are deleted as soon as your browser has downloaded them, and an automatic process deletes anything left after at most about one hour. Our logs record only a random job ID, sizes, timings and error codes, never file names or audio. We do not listen to, share, publish or sell your audio, and we do not use it or the stems to train any model.
4. Who receives personal data
We use the following service providers (processors), bound by data-processing terms, only to run the Service:
| Provider | Role | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, content delivery, security, database (D1), bot protection (Turnstile), web analytics, email routing | Global network; USA |
| Modal Labs, Inc. | GPU processing of AI separation jobs | USA |
| Google LLC | Sign-in (Google OAuth). Our forwarded support mail is also delivered to a Google Workspace / Gmail mailbox | USA |
Paddle (Paddle.com Market Limited and affiliates) is our Merchant of Record. When you buy credits, Paddle collects and processes your payment, billing and tax information as an independent controller under its own privacy policy, and shares with us the transaction details listed above. Google also processes your sign-in under its own privacy policy.
We may also disclose data to professional advisers (lawyers, accountants) under confidentiality, to a successor in a merger or acquisition, or where required by law, court order or to protect rights and safety. We do not sell personal data and do not share it for cross-context behavioural advertising.
5. International transfers
We operate from Israel, which the European Commission recognises as providing an adequate level of data protection. Our providers process data in the USA and elsewhere. Where personal data from the EEA, UK or Switzerland is transferred to a country without an adequacy decision, we rely on the EU–US Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses (and the UK Addendum), together with the providers’ security measures.
6. How long we keep data
| Data | Retention |
|---|---|
| Account data | Until you delete your account |
| Sessions | 30 days, or until you sign out |
| Separation audio and stems | Deleted after download, at most about 1 hour |
| Separation job records, credit history, purchase records, legal acceptance records | For the life of the account. After deletion they are kept only under a random pseudonymous ID, with no name or email, for up to 7 years to meet accounting obligations and to establish or defend legal claims |
| Webhook event records (event ID and type, no personal data) | Up to 2 years |
| Support emails | Up to 2 years after the conversation ends |
| Cloudflare request logs and analytics | According to Cloudflare’s retention, typically short-term and aggregated |
7. Your rights
Depending on where you live (for example under the GDPR, UK GDPR, the Israeli Protection of Privacy Law, or US state laws such as the CCPA/CPRA), you may have the right to:
- access your personal data and receive a copy (signed-in users can download it instantly: account menu → Download my data);
- portability: the same export is machine-readable JSON;
- erasure (account menu → Delete account, or email us);
- rectification of inaccurate data (your name and email come from your Google profile; update them there and sign in again);
- restriction of, or objection to, processing based on legitimate interests;
- withdraw consent where we rely on consent (we currently do not rely on consent for any processing);
- not be subject to decisions based solely on automated processing with legal effects (we make none);
- complain to a supervisory authority, such as your EU/EEA data protection authority, the UK Information Commissioner’s Office, or the Israeli Privacy Protection Authority.
To exercise a right, use the in-app tools or email [email protected]. We will respond within one month, which may be extended where the law allows, and we may need to verify your identity. We will not discriminate against you for exercising your rights. California residents: we do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes that would require a right to limit.
8. Children
The Service is not directed to children under 16, and accounts and purchases are for adults (18+) only. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
9. Security
We use encryption in transit (HTTPS/TLS everywhere, HSTS), store only hashed session identifiers, apply strict access controls and secret management, keep processing ephemeral, and minimise the data we collect. No system is perfectly secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.
10. Cookies and similar technologies
See our Cookie notice. In short: no advertising or tracking cookies; analytics are cookieless; the app uses only a strictly necessary sign-in cookie if you sign in.
11. Changes
We will update this policy when our practices change. The version date at the top shows the latest update. For material changes we will notify signed-in users in the app.
12. Contact
[OPERATOR FULL LEGAL NAME] (MixSongs), [CITY], Israel · [email protected]