Privacy Policy
Last updated 10 July 2026.
Who we are
TraxxTool ("we") is operated by Matt Brook. We are the data controller for the personal data described here. Contact: support@traxxtool.app.
What we collect, why, and on what legal basis
- Account data: your email address (and name, if you sign in with Google), received either from Google or by verifying a code we email you. Used to operate your account and entitlements, and to send you sign-in codes and other essential service messages. Basis: contract.
- Marketing email consent (optional): if, and only if, you tick the opt-in box, we record that you agreed to receive product-update emails, with the time and where you opted in. You can withdraw at any time from your account page or the unsubscribe link in any such email. We never add you to marketing without that opt-in. Basis: consent.
- Purchase & subscription records: what you bought (Pro, Cloud, credit packs) and subscription status. Card details go directly to Stripe; we never see or store them. Basis: contract; retention of transaction records: legal obligation.
- AI credits ledger: every credit grant and spend, with technical metadata (operation type, model id, token/character/second counts). We do not store the content of your AI requests. Prompts, lyrics and audio pass through to the provider and are not retained on our servers. Basis: contract (metering what you pay for).
- AI request content (transient): when you use TraxxTool AI, the text or audio of that job is forwarded to our processing providers (NanoGPT for language models, ElevenLabs for speech) and the result returned to you. We act as an intermediary and do not keep the content. Basis: contract.
- Cloud backups (optional): if you subscribe to Cloud, the library/settings snapshots you upload are stored (encrypted in transit, on EU servers) so you can restore them; the newest 20 versions are kept. The app excludes your API keys and site passwords from snapshots by design. Basis: contract.
- Problem reports (optional): when you use Help > Report a Problem or send a crash report, we store the report, its diagnostic bundle and, if you include one, a contact email. That address is used only to update you about your own reports: an acknowledgement, a note if a fix starts, and a note when the fix ships. Never marketing, and every such email carries a one-click opt-out. Reports are kept while we work on them; email support@traxxtool.app to have one deleted. Basis: legitimate interest (fixing the problem you reported).
- Server logs: standard technical logs (IP address, request path, timestamps) for security and debugging, rotated on a short schedule. Basis: legitimate interest (running a secure service).
- Update checks: when the desktop app checks for a new version it
tells us its version, its platform, and a random install identifier the app made up
on first run. That identifier is not derived from your hardware or linked to any
account; it only lets us count active installs without double-counting. Delete the
install_idfile in the app's data folder to reset it, or turn automatic update checks off in Settings, after which a check only happens when you ask for one from the Help menu. Basis: legitimate interest (knowing how many installs are alive and on what versions). - Setup milestones, only if you say yes: five one-time events that tell us whether an install ever got as far as real use: first launch, choosing a project folder, the first import, the first export, and signing in. Each one sends its name, the time it happened, and the same install identifier as an update check. Nothing else. No audio, no song titles, no file names, no lyrics, and no other properties of any kind. This is off unless you turn it on. We ask once at the end of the guided tour, and you can change the answer at any time in Settings. Until you answer, nothing is sent. Milestones are noted on your own machine as they happen so that turning it on later still reports the first import rather than the next one, and if you never say yes, those notes never leave your computer. Basis: consent (you can withdraw it in Settings at any time).
We do not use advertising trackers or analytics cookies, we don't profile you, and we never sell personal data.
Cookies
The website sets a single strictly-necessary session cookie when you sign in (it keeps you signed in; it is not used for tracking). Because we use no optional or third-party cookies, no cookie consent banner is required.
Processors we share data with
- Google: sign-in (OAuth). Receives your sign-in event.
- Resend (EU region): sends our transactional email (sign-in codes, problem-report follow-ups) and, if you opt in, product-update email. Receives your email address.
- Stripe: payments and subscriptions. Receives your email and payment details.
- Hetzner (Germany/EU): server hosting, including Cloud backup storage.
- NanoGPT: LLM processing for TraxxTool AI jobs (receives the text of those jobs, transiently).
- ElevenLabs: speech processing for TraxxTool AI jobs (receives the audio/text of those jobs, transiently).
Each processor receives only what it needs. Some (Google, Stripe, NanoGPT, ElevenLabs) may process data outside the EEA; transfers rely on their standard contractual clauses / adequacy frameworks.
Retention
- Account, entitlement and ledger data: for as long as your account exists.
- Cloud snapshots: newest 20 versions; all deleted when you delete your account.
- AI request content: not retained by us at all.
- Payment/transaction records: retained by Stripe and in our accounting records for the statutory period (typically 6 to 10 years) even after account deletion.
- Server logs: short rotation (weeks, not months).
Your rights (GDPR)
You have the right of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority.
- Erasure, self-service: delete your account (and all data listed above, except legally-retained payment records) from your account page.
- Access / portability / anything else: email support@traxxtool.app. We respond within 30 days.
The desktop app
TraxxTool runs on your machine and keeps your projects, audio, API keys and site logins locally (keys in your OS credential store). The app contacts our servers only for: account sign-in/entitlements, TraxxTool AI jobs (if you use credits), Cloud backups (if subscribed), the plugin/device catalog, and version checks. Bring-your-own-key AI calls go directly from your machine to the provider you configured. They never touch our servers.
Changes
Material changes to this policy will be posted here with a new "last updated" date.