Version 2026-08-14 · TuneCheck policies

Privacy Policy

TuneCheck is built around unfinished music, so privacy is a product feature, not an afterthought. Here's what we store and who can reach it.

What we store

  • Your account: an email address (or Google identity) and the profile you choose to publish: username, display name, bio, avatar, instruments, genres.
  • Your Studio: private projects, takes, lyrics and notes. Only you can read them.
  • Your TuneChecks: the excerpt you chose to share, its waveform data, your question, and the responses it receives.
  • Participation: ratings, A/B votes, written feedback, follows, notifications.
  • Account operations: any invitation record, agreement acceptance (time and policy versions), feedback you send us, and administrative audit entries.

How audio is protected

Audio lives in non-public storage. Playback works through short-lived links that our server mints only after checking that your account may hear that particular recording. There are no permanent public URLs for protected recordings, and TuneCheck does not provide a download feature. Any audio that can be played can, in principle, be re-recorded by a determined listener, so we rely on rules as well as technology.

No AI training, no third-party analysis

  • Your uploaded music is not used to train AI models.
  • It is not sent to AI providers.
  • It is not transcribed.
  • No third party analyses it.

Who can hear your music

  • Private: only you.
  • Selected listeners: only the members you pick; access is tied to their signed-in account.
  • Community: every signed-in TuneCheck member. Anonymous visitors cannot browse or play member content.
  • Anonymous public web listening is not enabled.

Service providers

TuneCheck runs on hosting, database and storage infrastructure operated on our behalf. Those providers store the data needed to run the service; they do not analyse your music.

Google (Google Analytics) and Meta (Meta Pixel and Meta's Conversions API) receive measurement data as described in this section. What is sent depends on your consent choice: when consent is granted, the events below are sent; when consent is denied, Google's tag still loads and sends limited, cookieless measurement pings, and Meta's pixel sends nothing.

Site measurement and advertising

TuneCheck uses three measurement tools: Google Analytics, the Meta Pixel, and a server-to-server connection to Meta that reports when a new account is created. Their purposes are limited to understanding how visitors find and use TuneCheck and measuring whether our advertising leads to sign-ups.

Both Google Analytics and the Meta Pixel start with consent denied for every visitor. Visitors in the EU/EEA, the United Kingdom and Switzerland are shown a consent banner and decide for themselves; their choice is remembered in their browser's local storage so they are not asked on every visit. Outside those regions, measurement is switched on automatically by us — no banner is shown, so visitors there have not actively chosen anything and can still decline through the Cookie preferences control, the banner if it appears, or the browser signals below. If we cannot determine a visitor's region — for any reason — we show the banner rather than measure silently. If your browser sends a Do Not Track or Global Privacy Control signal, measurement is treated as declined for you regardless of any remembered choice.

Page views and consent-gated events behave differently. Google's tag loads on every page for all visitors; while consent is denied it operates in Google's restricted Consent Mode, sending limited, cookieless measurement pings. The Meta Pixel stays revoked and sends nothing. When consent is granted, page-view measurement includes the addresses (URLs) and titles of the pages you visit. Separately, the product and conversion events below are only sent while consent is granted.

When measurement is consented to, the following events are sent:

  • Google Analytics: product events such as creating an account (with the sign-in method, email or Google), publishing a first TuneCheck, submitting a rating, feedback, an A/B vote or a follow, and lyric-publishing steps (carrying only a TuneCheck id, whether it is audio or lyrics, its visibility and its declared origin). The parameters we explicitly construct for these product events never include anything a person wrote or is named: no titles, lyrics, feedback text, usernames or email addresses.
  • Meta Pixel: page views and a single sign-up (CompleteRegistration) event per account.
  • Server-to-server Meta reporting: the same sign-up event, sent from our server so Meta can count it once alongside the browser event. Each report contains exactly: the event name (CompleteRegistration), a matching event id shared with the browser event, the time the sign-up occurred, an action source of "website", the fixed TuneCheck site address as the event source, and — when available — Meta's own browser and click identifiers (the _fbp and _fbc values set by Meta's pixel after you consented). TuneCheck's server-side conversion reporting does not include email addresses or email hashes while email matching is disabled, and it is disabled.

Cookie preferences: your consent choice is stored in your browser's local storage, not in a TuneCheck account, so it applies per browser and device. Accept or decline measurement through the Cookie preferences control. A remembered decline is respected even outside the EU/EEA/UK/Switzerland banner regions, and declining measurement also removes Meta's _fbp and _fbc cookies and any stored campaign attribution from that browser. You can reset the choice by clearing your browser's site data for TuneCheck and reloading the page.

Retention and deletion: scheduled cleanup removes campaign attribution from measurement contexts when the campaign touch is more than 90 days old, and from event records when the event occurred more than 90 days ago. Meta browser/click identifiers stored in measurement contexts are cleared after 90 days without a context update. These server cleanup rules require the scheduled cleanup job to run. Declining measurement clears browser attribution and Meta cookies locally; after the decision successfully synchronizes, it also clears server-side attribution and matching identifiers and suppresses pending deliveries. Minimal milestone records, including occurrence timestamps, and delivery-attempt records remain for deduplication and diagnosis until account deletion. A browser delivery marked 'sent' records a receipt claim, not confirmation that Google or Meta received it. Deleting measurement data from TuneCheck does not delete data already delivered to Google or Meta; their own retention rules and privacy policies apply.

Deletion

Deleting a TuneCheck promptly removes it from the live service: its audio, its comments and written feedback, its ratings and votes, its listener permissions, its waveform data, and related notifications. Deleting a Studio project removes that project and its takes.

Operational backups expire on our infrastructure providers' verified retention schedule, which is separate from live deletion. We don't promise a specific backup-expiry window here, because that promise would need to be verified against every backup system involved.

Administrator access

Administrators can see account operations data (invitations, requests, feedback, audit entries) and account-level records. They do not listen to private TuneChecks during routine support; that would require your explicit temporary permission, and would be logged.

Contact

Questions? Use the “Share feedback” action inside the app. It reaches the same place.

This is an initial beta implementation written for clarity, not a final legal agreement. It should receive legal review before TuneCheck opens to the wider public.