Privacy Policy

Last updated: August 16, 2026

TrackScore.AI™ ("we," "us," or "our") operates the TrackScore.AI™ web application (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By accessing or using the Service, you agree to the terms of this Privacy Policy.

1. Audio Data & Zero-Storage Architecture

We designed TrackScore.AI™ with a zero-storage audio architecture. This is the most important thing to understand about how we handle your music:

  • Your audio file is streamed directly from your browser to our analysis server over an encrypted connection (TLS).
  • The audio is held in volatile memory (RAM) only for the duration of the analysis — typically under 60 seconds.
  • Once analysis is complete, the audio data is immediately discarded from memory. It is never written to disk, copied, cached, or backed up.
  • We have no ability to play back, reconstruct, or retrieve your audio after analysis completes.
  • We do not use your audio files to train machine learning models, improve our algorithms, or for any purpose other than generating your analysis report.
  • Your audio is never sent to any AI provider or other third party. The Klaus™ features work from your analysis measurements, not from your audio.

2. Analysis Results & Metadata

While we do not store your audio, we do store the analysis results generated from it. This includes:

  • Numerical scores: hit potential, danceability, mix quality, frequency balance, energy, and structure scores.
  • Technical metadata: BPM, musical key, loudness (LUFS), duration, dynamic range, crest factor, stereo width, and spectral characteristics.
  • Feedback & diagnostics: textual feedback, Klaus™ engineer comments, and actionable recommendations.
  • File metadata: file name and artist tag (as embedded in your audio file). We do not extract or store any other ID3/metadata tags.
  • Klaus™ Live conversations: if you use Klaus™ Live, we store the messages you send, the replies you receive, and the analysis each conversation belongs to, together with per-message technical telemetry (for example response time, error status and message-size metrics). Conversations are visible only to you in the product. Our staff may access them to operate the Service, investigate abuse or errors, and review answer quality.

Analysis results are stored in our database and associated with your account so you can access your track history on the dashboard. You may request deletion of your analysis history at any time by contacting us.

3. Account Information

When you create an account, we collect:

  • Email address: used for account authentication, transactional emails (purchase receipts, password resets), and critical service announcements. Marketing newsletter subscription is covered separately below ("Newsletter (The Mixdown)").
  • Password: stored as a cryptographic hash. We never store or have access to your plaintext password.
  • Google sign-in: if you create your account or sign in with Google, Google sends us your email address and a Google account identifier so we can create and match your account. We never receive your Google password.

We do not require your name, phone number, address, or any other personally identifiable information to use the Service.

Approximate location: when you sign up, run an analysis or make a purchase, we derive an approximate location (country and city) from your IP address. We store that derived location, not the IP address itself, with your account, your analyses and your payments, and use it for tax compliance, fraud prevention and aggregate geographic reporting. IP addresses themselves are used for rate limiting and abuse prevention, and to record newsletter consent as described below.

Newsletter (The Mixdown)

We send marketing emails ("The Mixdown") via Klaviyo, a third-party email service provider. There are two ways you may end up subscribed:

  • Footer signup form: opt-in via an explicit consent checkbox. We record your consent (timestamp + IP address at submission) for compliance purposes.
  • Account creation: when you sign up for a TrackScore.AI™ account, you are automatically subscribed. You can unsubscribe immediately via the link in any email — unsubscribing does not affect your account or past analyses.

You can unsubscribe at any time using the link in any email, or by emailing privacy@trackscore.ai.

Aggregate Insights

If you choose to opt in, we may use anonymous, aggregate insights derived from your analyses to understand broad trends in electronic music production and to improve the Service for everyone. This is opt-in only — it is off unless you turn it on, and you can opt out at any time.

  • Never your audio: your uploaded audio is processed in memory and never stored, so it is never part of any insight. Only anonymized, aggregated characteristics of your analysis results are ever used.
  • Never anything that identifies you: insights are combined across many producers and reported only in aggregate. We do not expose anything tied to you or any individual track.
  • Never to train generative AI: these insights are not, and will not be, used to train any music-generation or other generative AI model. TrackScore.AI™ analyzes music — it does not generate it.

You can opt out at any time from the Data & Privacy section of your dashboard, or by emailing privacy@trackscore.ai.

4. Payment Information

All payment processing is handled by Stripe, Inc. We never receive, process, or store your credit card number, CVV, or full payment details. Stripe provides us with a transaction reference, the amount paid, and a timestamp — nothing more. Stripe's privacy policy is available at stripe.com/privacy.

5. Developer API

If you use the TrackScore.AI™ Developer API, we keep records of how your integration calls the Service. This is usage metadata about the requests themselves. It is a separate category from your audio, and it does not change our audio commitment in any way: audio submitted through the API is processed in memory and never stored, exactly as it is on the website.

  • API keys: we store a hashed form of each key, never the key itself, along with its label, creation date, and the time it was last used. A key is shown to you once at creation and cannot be retrieved afterwards.
  • Usage records: for each API request we record the time, the endpoint called, the response status, how long it took, and which billing mode applied. We use these to enforce rate limits and quotas, to bill correctly, to investigate errors, and to detect abuse.
  • Webhooks: if you register a webhook endpoint, we store the URL you provide, its signing secret in encrypted form, and a log of delivery attempts. Because a delivery log records what we sent you, it includes the analysis results contained in that webhook. It never includes audio.
  • Analyses created through the API: these are marked as API-originated and are linked to the key that created them. If you supply your own reference identifier for a track, we store it so we can return it to you. Analyses created with a sandbox test key are automatically deleted within 48 hours.

These records are covered by the same rights described in Your Rights below, and by the retention terms in Data Retention. The API Terms of Service describe the same commitments in the contractual language that applies to API use.

6. Contact Form

If you contact us through the contact form, we keep a record of your submission so we can respond and keep track of support history. This includes the name and email address you provide, your message, the inquiry type you select, any optional details you add (phone number, website, a screenshot or analysis link), your approximate location derived from your IP address, and your browser type. We use this information only to respond to you and to detect spam. You can ask us to delete a submission at any time (see Your Rights).

7. Cookies & Tracking Technologies

We use cookies and similar technologies to operate the Service, measure performance, and deliver relevant advertising. Here is a breakdown by category:

Strictly Necessary

  • Authentication cookies: keep you logged in and maintain your session. These cannot be disabled without breaking core functionality.

Analytics & Performance

  • Google Analytics 4 (GA4): measures traffic sources, page views, conversion funnels, and aggregate usage patterns. GA4 uses first-party cookies and transmits pseudonymized data to Google. You can opt out via the Google Analytics Opt-out Browser Add-on.
  • PostHog: records product engagement events (e.g., analysis completed, feature used) so we can understand how the Service is used and improve it. PostHog receives pseudonymized event data which, for signed-in users, is linked to your account. We do not use PostHog session recording.
  • Error monitoring: an error-monitoring service captures JavaScript errors and performance data to help us diagnose and fix bugs. It may receive your IP address (which is not stored) and browser/device metadata alongside error reports.

Advertising & Conversion Tracking

  • Meta Pixel (Facebook/Instagram): tracks conversions from Meta ad campaigns and may build audience segments for retargeting. The Meta Pixel sends page view and conversion events to Meta Platforms, Inc. (via the browser pixel and, for signups and purchases, a matching server-side event that is deduplicated against it). You can manage your ad preferences at facebook.com/adpreferences.
  • Google Ads Conversion Tracking: measures the effectiveness of our Google search ad campaigns by recording when a user who clicked an ad completes a signup or purchase. Data is sent to Google and subject to Google's Privacy Policy.
  • TikTok, X and OpenAI ads: we also measure conversions from campaigns on TikTok, X (Twitter) and OpenAI's advertising platform. Each uses a browser pixel plus a matching server-side conversion event (deduplicated so a conversion is counted once), sent to the platform when you sign up or purchase. You can manage ad preferences in each platform's own settings.

Email Marketing

  • Klaviyo: powers our marketing email campaigns (welcome series, product updates, re-engagement). Klaviyo tracks email opens and link clicks to measure campaign performance. You can unsubscribe from marketing emails at any time via the link in every email. Transactional emails (receipts, password resets) are sent separately from our marketing list and are not affected by your marketing preferences.

Referral & Attribution

  • UTM parameters & referral links: we use URL parameters (e.g., ?ref=, ?utm_source=) to attribute signups to marketing channels, referral partners, and content creators. These parameters are logged alongside your signup event but do not contain personally identifiable information.

Surveys & Feedback

  • In-app surveys: we may show short optional surveys inside the Service (for example, asking about your role and production experience) to understand who uses TrackScore.AI™ and improve it. Responses are stored with your account and used solely to improve the Service. Participation is always optional.

You can control or disable most tracking technologies through your browser settings, platform-specific opt-out tools linked above, or industry opt-out programs such as the Digital Advertising Alliance or Your Online Choices (EU). Disabling non-essential cookies will not affect core Service functionality.

8. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service.
  • Process your audio analyses and deliver results to your dashboard.
  • Generate Klaus™ diagnostic feedback and Klaus™ Live replies, using a third-party AI infrastructure provider as described in Data Sharing & Disclosure below.
  • Respond to your support and contact requests.
  • Process payments and manage your credit balance.
  • Send transactional communications (receipts, password resets, account confirmations).
  • Send marketing communications (product updates, tips, promotions) if you have opted in. You can unsubscribe at any time.
  • Measure the effectiveness of our advertising campaigns and attribute signups to marketing channels.
  • Display relevant ads to you on third-party platforms (Meta, Google, TikTok, X, OpenAI) based on your interactions with our Service.
  • Detect, prevent, and address abuse, fraud, or technical issues.
  • Comply with legal obligations.

We do not sell your personal data to data brokers or use it for automated decision-making that produces legal effects.

9. Data Sharing & Disclosure

We do not sell, rent, or trade your personal information. We share data only with service providers that process it on our behalf, only to the extent necessary to operate the Service, and under contracts that restrict how they may use it. By category:

  • Infrastructure & core services: hosting, database and authentication, and payment processing. Our payment processor is Stripe (see Payment Information).
  • AI processing: to generate Klaus™ diagnostic feedback and Klaus™ Live replies, we send the technical measurements of your analysis and, for Klaus™ Live, the text of your conversation to a third-party AI infrastructure provider located in the United States. These requests carry no account identifier, email address, file name or artist tag, and never include your audio. Under our agreement with the provider, this data is not used to train AI models and is retained by the provider for no more than 30 days, except where a longer period is required by law or by the provider's safety systems.
  • Analytics, error monitoring & advertising measurement: the analytics and advertising providers described in Cookies & Tracking Technologies, plus an error-monitoring provider that receives error reports and performance telemetry.
  • Email & communications: our marketing email provider (Klaviyo, see Newsletter) receives your email address and engagement segments. Transactional emails are sent through a standard business email service and are not part of any marketing list.

The current list of providers that process personal data on our behalf is maintained on our Subprocessor List.

We may also disclose information if required by law, court order, or governmental regulation, or if disclosure is necessary to protect our rights, property, or safety, or that of our users or the public.

10. Data Retention

  • Audio files: not retained. Discarded from memory immediately after analysis.
  • Analysis results: retained as long as your account is active, or until you request deletion.
  • Account data: retained until you delete your account. Upon deletion, we remove your personal information within 30 days, except where retention is required by law.
  • Payment records: transaction references are retained as required for tax and financial reporting obligations.
  • API usage records: request logs and webhook delivery logs are retained while your account is active, and are removed when you delete your account on the same schedule as your other account data. Analyses created with a sandbox test key are deleted automatically within 48 hours.
  • Klaus™ Live conversations: retained with the analysis they belong to. Deleting an analysis deletes its conversations; deleting your account deletes all of them.
  • Contact form submissions: retained for as long as needed to respond to you and keep a record of support history, or until you ask us to delete them.
  • Rate-limiting records: IP-based rate-limiting counters are kept only for abuse prevention and are not linked to your account.

11. Data Security

We implement industry-standard security measures including encryption in transit (TLS), encrypted data at rest, secure authentication with hashed passwords, and row-level security policies on our database to ensure users can only access their own data. While no system is 100% secure, we take reasonable and appropriate measures to protect your information from unauthorized access, alteration, disclosure, or destruction.

12. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete data.
  • Deletion: request deletion of your personal data, analysis history and Klaus™ Live conversations.
  • Portability: request an export of your analysis data and Klaus™ Live conversations in a machine-readable format.
  • Objection: object to certain processing of your data.

To exercise any of these rights, contact us at the email address below. We will respond within 30 days.

13. International Data Transfers

Our Service is hosted in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other jurisdictions where our service providers operate. By using the Service, you consent to the transfer of your information to these jurisdictions, which may have different data protection laws than your country of residence.

14. Children's Privacy

The Service is not directed to individuals under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will delete that information promptly.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. If we make material changes, we will notify you by email or by posting a prominent notice on the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: privacy@trackscore.ai