Detune.

Privacy Policy

Effective Date: September 8, 2026 • Version 2.4

1. Overview & Data Controller Identity

Detune develops algorithmic music discovery, acoustic feature extraction, and playlist curation technologies accessible via our web application and associated services (collectively, the “Service”).

We recognize the vital importance of digital privacy and data autonomy. This Privacy Policy sets forth the principles, legal bases, and technical measures governing how we collect, process, store, and protect your personal information in compliance with the European Union General Data Protection Regulation (EU GDPR), the United Kingdom General Data Protection Regulation (UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the California Online Privacy Protection Act (CalOPPA), and other applicable global data privacy statutes.

For the purposes of applicable data protection law, Detune operates as the Data Controller with respect to personal information collected through your engagement with the Service.

2. Categories of Information We Collect

We adhere strictly to the principle of data minimization: we collect only data strictly necessary to deliver, secure, and improve our audio discovery platform. The categories of information we collect comprise:

A. Account Credentials & Identification Data When you register for a Detune account, we collect your email address, chosen username, and a cryptographically salted password hash. Passwords are never stored in plaintext and are securely hashed using industry-standard cryptographic algorithms before reaching persistent database storage.
B. Musical Curation & Usage Preferences To preserve your musical curation across sessions, our systems record playlists you assemble, tracks you bookmark, acoustic seed weights, and custom textual vibe prompts (e.g., “late-night rainy ambient synthwave”). This curation data is tied to your account identifier to enable seamless cross-device synchronization.
C. Technical & Infrastructure Telemetry When connecting to our web servers, our infrastructure logs standard technical metadata: truncated IP addresses (anonymized at ingestion), browser user-agent strings, operating system, referring URL headers, and request timestamps. These logs are maintained strictly for security auditing, DDoS prevention, and rate limiting.
D. Optional Diagnostic Health Metrics If you explicitly grant permission via our Cookie Preferences settings, our web client captures non-identifiable client health signals—such as API response latency, audio stream preview dropouts, and connection timeout rates. This telemetry contains no browsing history outside Detune and is completely decoupled from your identity.
E. Payment & Subscription Transaction Data All payment processing is handled off-site by our payment gateway, Stripe, Inc. Detune never sees, collects, transmits, or stores full payment card numbers, bank account details, or CVV codes on our servers. We receive only transaction confirmations, subscription tier indicators, renewal dates, and billing country metadata necessary for tax and accounting compliance.
Absolute Microphone & Environmental Audio Disclaimer

Detune does not access, record, monitor, analyze, or intercept audio signals from your device microphone, ambient listening hardware, or personal audio inputs. All acoustic feature extraction (tempo, rhythm, harmonic balance, spectral centroid) is executed strictly on public music catalog audio files residing on remote servers. We have zero technical capacity or interest in listening to your physical environment.

3. Legal Bases for Processing (GDPR & UK GDPR)

Under Article 6 of the General Data Protection Regulation, we process personal data only when a recognized legal basis applies:

  • Contractual Necessity (Art. 6(1)(b)): Processing necessary to perform our contractual commitments to you under our Terms of Service—including generating audio recommendations, maintaining authenticated user sessions, saving your playlists, and delivering paid tier features.
  • Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate commercial interests in defending platform security, preventing abuse or unauthorized scraping, diagnosing infrastructure faults, and maintaining high availability, provided such interests are not overridden by your fundamental privacy rights.
  • Explicit Consent (Art. 6(1)(a)): Processing based on your affirmative, informed consent—specifically regarding optional client diagnostics and non-essential cookies. You retain the absolute right to revoke consent at any time via the Cookie Preferences panel.
  • Legal Obligations (Art. 6(1)(c)): Processing required to comply with statutory corporate, taxation, anti-fraud, and financial reporting mandates.

4. How We Utilize Your Data

Your information is utilized solely to support and elevate the Detune listening experience:

• Executing acoustic similarity algorithms to recommend songs tailored to your prompts.

• Authenticating your login sessions and verifying subscription access permissions.

• Preventing repetitive playback loops through ephemeral in-session track tracking.

• Providing direct customer support and resolving technical issues promptly.

• Detecting, mitigating, and prosecuting fraudulent activity, denial-of-service vectors, and malicious bots.

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects concerning users.

5. Prohibition on Sale or Sharing of Personal Data

Detune does not sell, rent, monetize, or trade your personal information. We have never sold personal data to data brokers, advertising aggregators, or marketing syndicates, and we will never do so.

Furthermore, under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), Detune certifies that it does not “share” personal data for cross-context behavioral advertising. Our platform is entirely free of behavioral advertising trackers, ad-network SDKs, and third-party surveillance scripts.

6. Third-Party Service Providers & Subprocessors

We share personal data only with vetted subprocessors bound by strict data processing agreements, data confidentiality obligations, and security warranties:

Database & Authentication: Supabase, Inc. Our PostgreSQL database and authentication infrastructure are hosted by Supabase with Row Level Security (RLS) policies enforcing cryptographic isolation between user accounts.
Payment Processing: Stripe, Inc. Subscription checkout, recurring billing, and merchant fraud detection are processed securely via Stripe. All payment card data is tokenized directly on Stripe's PCI-DSS Level 1 certified servers.
Streaming Metadata & Previews: Deezer API We query licensed music APIs (such as Deezer) to retrieve 30-second audio previews, track metadata, and album artwork. These requests are server-side or public client queries that transmit no personal user identities to the music catalog provider.
Playlist Export Services: Google LLC & Spotify AB If you explicitly elect to export curated playlists to YouTube Music or Spotify, authentication tokens are utilized exclusively for the explicit scope of creating that playlist in your target library.
Statutory & Law Enforcement Disclosures We disclose records only when strictly compelled by an enforceable court order, valid subpoena, or statutory mandate issued by a court of competent jurisdiction.

7. International Data Transfers & Technical Safeguards

Detune operates infrastructure located primarily in the United States. If you access the Service from the European Economic Area (EEA), the United Kingdom, or Switzerland, your information may be transferred to and processed in jurisdictions outside your home territory.

Whenever cross-border transfers occur, we implement approved transfer mechanisms recognized under EU and UK law, including European Commission Standard Contractual Clauses (SCCs). Our technical security measures encompass Transport Layer Security (TLS 1.3) encryption in transit, AES-256 encryption at rest, principle-of-least-privilege access controls, and routine vulnerability scanning.

8. Retention & The Right to Erasure (Account Deletion)

We retain personal data only for as long as your account remains active or as needed to provide the Service. You maintain absolute control over your digital footprint:

One-Click Account Deletion: You can delete your account at any time via your Account Settings. Triggering deletion permanently expunges your email, username, password hashes, playlists, saved tracks, and session tokens from our live production databases within thirty (30) days.

Statutory Tax & Accounting Exception: Historical financial transaction logs (invoice numbers, subscription dates, amounts paid) are retained strictly to satisfy mandatory statutory corporate accounting and revenue audit requirements, typically for up to seven (7) years.

9. Your Global Privacy Rights (GDPR, UK GDPR, CCPA/CPRA)

Regardless of your geographic location, Detune extends robust privacy protections to all registered listeners. You have the right to:

Right of Access

Request a comprehensive copy of all personal information Detune maintains concerning you.

Right to Rectification

Request immediate correction of inaccurate, obsolete, or incomplete personal data.

Right to Erasure

Request permanent deletion of your personal data under the Right to be Forgotten.

Right to Portability

Receive your curation history and playlist data in a structured, machine-readable format.

Right to Restrict or Object

Object to processing based on legitimate interests or request temporary restriction of processing.

Non-Discrimination

Exercise any privacy right without retaliation, denial of service, or disparate pricing.

To exercise any of these rights, submit a verified request to privacy@detune.audio. We will acknowledge and resolve your request without fee within thirty (30) calendar days.

10. Children’s Online Privacy (COPPA & GDPR Art. 8)

Detune is not directed toward or intended for children. In compliance with the United States Children’s Online Privacy Protection Act (COPPA) and Article 8 of the GDPR, we do not knowingly solicit, collect, or process personal data from individuals under thirteen (13) years of age (or under sixteen (16) years of age within the EEA).

If we become aware that personal information of a minor below these thresholds has been inadvertently collected without verified parental consent, we will promptly delete the data and terminate the associated account. Parents or guardians who believe a child has provided us with personal information should contact us immediately at privacy@detune.audio.

11. Revisions to this Policy & Privacy Contact

We may periodically update this Privacy Policy to reflect technical evolutions, feature enhancements, or statutory amendments. When changes are made, the revised date at the top of this document will be updated. We encourage listeners to review this document periodically.

For legal inquiries, Data Protection Officer communications, or questions concerning our acoustic algorithms, contact us directly:

Detune Data Privacy & Legal Team

privacy@detune.audio

Response SLA: Within 30 calendar days