CompareFeaturesProPricingLog in
audiotoggle logo

Privacy Policy

In effect from 25 July 2026

Draft — not yet in force. This document is missing the operator’s registered details (legalName, address, registrationNumber, jurisdiction, supervisoryAuthority). Fill them in apps/web/app/(legal)/legal-config.ts and have the text reviewed by a qualified lawyer for your jurisdiction before relying on it or accepting payments.

This policy explains what personal data audiotoggle collects, why, and what you can do about it. The short version: the free compare tool at /compare does not upload your audio anywhere, and we collect no more account data than the service needs to work.

1. Who is responsible

The controller of your personal data is TODO — registered legal name, TODO — registered address (TODO — registration number). For any privacy question or request, email hello@audiotoggle.com.

2. Your audio files

The compare tool does not upload anything. When you use /compare without saving, your files are read directly by your browser and played locally. They never reach our servers, so we cannot access, store or analyse them.

Files leave your device only when you explicitly choose Save & Share or upload into a project. Those files are stored on our object storage in order to stream them back to you and to anyone you share the link with. We do not re-encode, analyse, fingerprint or train anything on your audio. You keep all rights to it, and deleting a project deletes the underlying files.

3. What we collect and why

DataWhyLegal basis
Email address, display nameCreate and identify your account, send account emailsPerformance of a contract
Password (stored only as an Argon2 hash)Log you in. We never store or can read your actual passwordPerformance of a contract
Google account id and verified email (only if you use Google sign-in)Link your Google login to your accountPerformance of a contract
Login sessions (a rotating token hash, expiry, revocation time)Keep you logged in and detect stolen or reused tokensLegitimate interest (account security)
Project data: titles, track labels, level settings, player customization, share slug, published stateProvide the service you are usingPerformance of a contract
Uploaded audio: file name, format, size, storage location, storage usedStore and stream your files, and enforce your plan’s quotaPerformance of a contract
Profile picture and studio logo (Pro, optional)Display your branding on your share pagesPerformance of a contract
Billing: Stripe customer and subscription id, plan, status, renewal dateRun your subscription and unlock Pro featuresPerformance of a contract
Play events on public comparisons: type of event, country, timestamp, and a salted hash of the visitor’s IP addressShow the project owner play and A/B-switch counts, and stop one visitor inflating them. We do not store raw IP addresses for analytics, and the salt rotates daily so the hash cannot be used to follow a visitor over timeLegitimate interest (product analytics for the owner, abuse prevention)
Server logs (including IP address, transiently)Operate the service, debug faults, rate-limit abuseLegitimate interest (security and reliability)
Google Analytics usage dataUnderstand which pages and features get usedYour consent — denied until you accept, and revocable at any time

We do not sell personal data, we do not run advertising, and we do not use your data to train machine-learning models.

4. Listening to a shared link

You do not need an account to listen to a comparison someone shared with you. When you do, we record that a play or A/B switch happened, the country the request came from, and a daily salted hash of your IP address. The project’s owner sees aggregate counts per day — never your IP address, and nothing that identifies you personally.

5. Who else processes your data

We use a small number of processors, each only for what it says here. They act on our instructions under a data-processing agreement.

  • Stripe — payments and subscriptions. Card details go directly to Stripe; they never touch our servers, and we only ever see a customer id, a plan status and a renewal date.
  • Google — optional Google sign-in, and Google Analytics 4 (consent-gated, with Consent Mode defaults set to denied).
  • Our email provider — sending verification, password-reset and account emails.
  • Our hosting and object-storage provider — running the application and storing your uploaded files.

Some of these process data outside your country. Where that happens, transfers rely on the European Commission’s standard contractual clauses or an equivalent safeguard.

6. How long we keep things

  • Account and project data — until you delete the project or your account.
  • Uploaded files — until you replace or delete them, or delete your account. Uploads that never complete are swept automatically within about 24 hours.
  • Login sessions — refresh tokens expire after 30 days, and are revoked immediately on logout, password reset or suspected token reuse.
  • Email verification and password-reset tokens — 24 hours and 1 hour respectively; single use.
  • Play events — kept as long as the project exists, and deleted with it.
  • Billing records — retained as long as tax and accounting law requires, even after account deletion.

7. Your rights

Under the GDPR and equivalent laws you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it over in a portable format. You can also withdraw analytics consent at any time.

  • Deleting your account — do it yourself at any time from your account settings. That permanently removes your account, projects, uploaded files and play events. It cannot be undone.
  • Withdrawing analytics consent — use the cookie settings link in the footer, or clear this site’s data in your browser.
  • Everything else — email hello@audiotoggle.com and we will respond within one month.

If you think we have handled your data badly, please tell us first — but you always have the right to complain to a data-protection authority (TODO — supervisory authority).

8. Security

Passwords are hashed with Argon2. Sessions use short-lived access tokens plus rotating refresh tokens in HTTP-only cookies, and presenting an old refresh token revokes the whole session family. Traffic is served over HTTPS, requests are rate-limited, and your files are readable only by you unless you publish the comparison.

One thing to be aware of: a published share link is protected by being unguessable, not by a password. Anyone who has the link can listen. Unpublish the project when you want it private again.

9. Children

audiotoggle is not aimed at children and you must be at least 16 to create an account. If you believe a child has given us personal data, contact us and we will delete it.

10. Changes

If we change this policy in a way that materially affects you, we will email registered users and update the date at the top before the change takes effect.

Terms of ServicePrivacy PolicyCookie Policy