Privacy Policy
Last updated: July 5, 2026
This Privacy Policy explains how TrackStemLab ("we", "us", "our") collects, uses, shares, and protects personal data when you use our website and audio stem-separation service (the "Service"). We are committed to processing your data lawfully and transparently.
1. Who we are (Data Controller)
The data controller responsible for your personal data is Aleksei Cheshkov, an individual entrepreneur registered in Georgia (registration number 145855232), with the principal place of business at Georgia, Kobuleti region, village Kveda Kvirike, 1st street, N 3, apartment N45.
For any privacy question or to exercise your rights, contact us at [email protected].
2. Data we collect
- Account data: email address and a hashed password (for email sign-up), or your Google account identifier, email, name and profile picture (for Google sign-in).
- Audio content: the audio files you upload and the separated stems we generate from them.
- Usage data: records of your separation jobs, minute balance, and limits.
- Billing data: if you purchase minutes or a subscription, our payment provider (Creem) processes your payment. We receive only limited billing metadata — such as your country, the card type and last four digits, and the status of your transactions and subscription. We never receive or store your full payment card number.
- Technical data: IP address and request metadata, used for security and rate limiting.
- Device identifier: a fingerprint computed in your browser and a derived identifier sent to us, used to enforce free-tier limits and prevent abuse (for example, creating many accounts on one device to obtain extra free minutes).
- Advertising and conversion data: if you consent to advertising cookies, Google Ads sets cookies and processes identifiers in your browser to measure the performance of our advertising campaigns (for example, whether your visit followed an ad click). We do not combine this with your account data, and these cookies are not set unless you accept them.
3. How we use your data and legal bases (GDPR Art. 6)
- To provide the Service (account creation, processing your audio, delivering stems) — performance of a contract (Art. 6(1)(b)).
- To process payments and manage subscriptions — performance of a contract (Art. 6(1)(b)) and compliance with tax and accounting obligations (Art. 6(1)(c)).
- To secure the Service (rate limiting, abuse prevention) — legitimate interests (Art. 6(1)(f)).
- To enforce free-tier limits and detect abuse (device identifier) — legitimate interests in preventing fraud and fair use of free minutes (Art. 6(1)(f)). The identifier is used solely for this purpose; we do not use it for advertising or cross-site tracking.
- To send transactional emails (email verification, password reset, billing notices) — performance of a contract / legitimate interests.
- To measure our advertising campaigns (Google Ads cookies) — your consent (Art. 6(1)(a)), which you give via our cookie banner and can withdraw at any time. We do not set these cookies before you accept.
- To comply with legal obligations where applicable — Art. 6(1)(c).
We do not use your audio content to train AI models, and we do not sell it. We do not claim any ownership of, or rights to, the audio you upload — it remains yours.
4. Data retention
- Uploaded files and generated stems are automatically deleted from storage approximately 2 days after processing.
- Transcription files (MIDI, Guitar Pro and MusicXML files generated by the transcription feature) are automatically deleted from storage approximately 30 days after they are created.
- Account data is kept while your account is active. When you delete your account, your account data and associated jobs are removed.
- Billing and transaction records may be retained for longer than your account, separately, where this is required to comply with tax and accounting law.
- Some minimal logs may be retained for a limited period for security and legal compliance.
5. Sub-processors and international transfers
We rely on the following service providers, which act as our processors and may process data outside your country (including in the United States). Where required, such transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses (SCC):
- Cloudflare — website hosting (Pages), content delivery (CDN), and storage (R2) of uploaded files and generated stems.
- Hetzner — cloud server hosting for our API and database (data centers in the European Union, Germany).
- RunPod — GPU compute that performs the audio separation.
- Creem — payment processing and Merchant of Record for purchases and subscriptions.
- Google (Google Identity Services) — authentication, if you sign in with Google.
- Google (Google Ads) — advertising-campaign and conversion measurement, only if you consent to advertising cookies.
- Resend — delivery of transactional emails.
- Sentry — error monitoring and diagnostics. We configure it not to send personal data (such as your email) by default.
- Grafana Cloud — collection of server and application logs for reliability and security.
- Plausible Analytics (self-hosted) — privacy-friendly, cookieless web analytics that we run on our own server infrastructure (Hetzner, EU). Analytics data is not shared with any third-party analytics provider and is not used to track you across sites.
6. Automated decision-making and profiling
We do not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing. The device identifier described above is used only to apply free-tier limits and prevent abuse; it does not build a profile of your personality, behavior or interests, and it is not used for advertising. If a limit ever affects you in error, you can contact us for a human review.
7. Your rights under the GDPR
If you are in the European Economic Area, you have the right to:
- access your personal data (Art. 15) — you can download a copy of your data at any time from your account page;
- rectify inaccurate data (Art. 16);
- erase your data (Art. 17) — you can delete your account at any time from your account page;
- restrict or object to processing (Art. 18, 21);
- data portability (Art. 20);
- withdraw consent where processing is based on consent.
To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with your local data protection supervisory authority.
8. Your rights under the CCPA/CPRA (California)
California residents have the right to know what personal information we collect and how it is used, to request deletion of their personal information, and to not be discriminated against for exercising these rights. We do not sell your personal information for money. We use advertising cookies (Google Ads) only if you consent via our cookie banner; to the extent the resulting measurement is treated as "sharing" for cross-context behavioral advertising under the CPRA, it occurs only with your consent and you can opt out at any time by choosing "Reject" or clearing this site's browser storage. To make a request, contact [email protected].
9. Cookies and local storage
Strictly necessary storage. We store authentication tokens in your browser's localStorage so you stay signed in; these are strictly necessary for the Service to function. We also compute a device fingerprint in your browser (using FingerprintJS) and send a derived identifier to enforce free-tier limits and prevent abuse, as described in sections 2 and 3; this is not used for advertising.
Advertising cookies (only with your consent). If you choose "Accept" on our cookie banner, Google Ads sets cookies to measure the performance of our advertising campaigns. We use Google Consent Mode with advertising and analytics storage denied by default: until you accept — and if you choose "Reject" — these cookies are not set. You can withdraw your consent at any time by clearing this site's browser storage, which will prompt the banner again.
Analytics and sign-in. Our self-hosted analytics (Plausible) is cookieless and does not track you across sites. If you sign in with Google, the Google Identity Services script is loaded from Google's servers.
10. Marketing communications
We send only transactional emails that are necessary to operate your account — such as email verification, password resets, and billing notices. We do not run marketing newsletters and do not send promotional email without your request.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
12. Security and data breaches
We use industry-standard measures to protect your data, including password hashing, encrypted transport (HTTPS), and access controls. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. In the event of a personal-data breach that is likely to affect your rights, we will notify the competent supervisory authority and, where required, you, within the timeframes set by applicable law.
13. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above reflects the latest revision. Material changes will be communicated through the Service.
← Back