Privacy Policy
Last updated: August 1, 2026
1. Who we are
SoundCron is operated by Raphael Guillot, a sole trader registered in France (micro-entreprise), acting as the data controller under the GDPR. If you have any questions about this policy, contact us at [email protected].
2. What data we collect
Account data (from SoundCloud OAuth)
- Your SoundCloud numeric user ID
- Your SoundCloud display name
- Your SoundCloud OAuth access and refresh tokens — stored encrypted at rest (AES-256-GCM). We never store or log these in plaintext.
Track classification cache
When we classify a track, we store the result: track ID, genre, sub-genre, and confidence score. This avoids re-classifying the same track twice and is tied to your account.
Email address (Pro users only)
If you subscribe to Pro, your email is collected by our payment processor Polar at checkout and may be shared back to us for account communications (e.g., billing receipts). Free users have no email stored.
Standard server logs
IP addresses, request paths, and timestamps — retained for up to 30 days for security and debugging purposes.
3. What we do NOT collect
- Audio files — we never access or store your audio
- Passwords — authentication is via SoundCloud OAuth only; we never see your SoundCloud password
- Financial data — payment details (card numbers, etc.) are handled entirely by Polar; we never see them
- Playlist or track content beyond what is needed for classification
4. How we use your data
- To authenticate you via SoundCloud and maintain your session
- To read your SoundCloud playlists and sort tracks into sub-genre playlists on your behalf
- To send track metadata (title, artist, existing genre tags) to an AI provider for classification — see section 6
- To cache classification results so tracks are not re-analyzed
- To manage your subscription plan (Free or Pro)
5. Legal basis for processing (GDPR Art. 6)
For each category of data we process, the legal basis is:
- Account data and OAuth tokens — contractual necessity (Art. 6(1)(b)): required to provide the sorting service you signed up for.
- Track classification cache — contractual necessity (Art. 6(1)(b)): caching avoids re-classifying tracks you have already sorted and is integral to the service.
- Server logs — legitimate interests (Art. 6(1)(f)): security monitoring and debugging. We balance this against your privacy rights by limiting retention to 30 days.
- Analytics (Umami) — consent (Art. 6(1)(a)): collected only if you click Accept on the cookie banner. You may withdraw consent at any time via Settings.
- Email (Pro users) — contractual necessity (Art. 6(1)(b)): required for billing communications.
6. Third-party data processors
Polar Software Inc. (payments)
Polar is our Merchant of Record: it collects payment details, issues invoices, and remits EU VAT. Polar processes your email and payment information under their own privacy policy. We receive a customer ID and subscription status only.
Anthropic PBC or Mistral AI (track classification)
Track metadata (title, artist name, and existing genre tags from SoundCloud) is sent to an AI provider for genre classification. No audio data is sent. The active provider depends on deployment configuration; by default we use Anthropic (Claude). Both providers process data under their respective API terms and data processing agreements.
International transfer note: Anthropic PBC is based in the United States. Sending track metadata to Anthropic constitutes a transfer of personal data outside the EU/EEA. This transfer takes place under Anthropic's API Data Processing Agreement and applicable Standard Contractual Clauses. Mistral AI is based in France (EU) and involves no cross-border transfer.
SoundCloud (identity provider)
We access SoundCloud's API on your behalf using the OAuth tokens you grant us. SoundCloud's privacy policy governs the data held on their platform.
7. Cookies & analytics
We use a single sc_session cookie — an httpOnly, secure session token that keeps you logged in. It is not accessible to JavaScript and cannot be read by third-party scripts.
We also store your analytics preference (Accept / Decline) in localStorage so we remember your choice across visits. This is not a cookie and is never sent to our servers.
If you click Accept on the cookie banner, we load Umami Analytics — a privacy-first tool that collects anonymised page-view and event data (page URL, referrer, browser type, OS, device type, screen size, country). Umami does not set cookies, does not track individuals across sites, and does not share data with third parties. If you click Decline, no analytics script is loaded.
You can change your analytics preference at any time on the Settings page.
8. Data retention
- Account data (OAuth tokens, sort history, sync schedules): deleted immediately when you delete your account, and in any case within 7 days of disconnecting your SoundCloud account, as required by the SoundCloud API Terms of Use
- Track classification cache: retained independently (not tied to your account); contains only derived genre labels and confidence scores, not personal data
- OAuth tokens: automatically rotated on each refresh; old tokens are immediately overwritten
- Payment and billing data: retained by Polar per their data retention policy
- Server logs: up to 30 days, then deleted
9. Your rights (GDPR)
If you are in the EU/EEA, you have the following rights under the General Data Protection Regulation:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Portability — receive your data in a structured, machine-readable format
- Restriction — request that we limit processing of your data
- Objection — object to processing based on legitimate interests
- Withdraw consent — for analytics, revoke consent at any time via Settings without affecting the lawfulness of prior processing
To exercise any of these rights, email [email protected]. We will respond within 30 days. You may also lodge a complaint with the French data protection authority (CNIL) or the supervisory authority in your country of residence.
10. Security
OAuth tokens are encrypted at rest using AES-256-GCM before being written to the database. All connections use HTTPS/TLS in production. We follow security best practices and conduct regular dependency audits. No system is 100% secure — in the event of a breach we will notify affected users within 72 hours as required by GDPR.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via the email on file (Pro users) or via a notice on the site. The "Last updated" date at the top of this page reflects the most recent revision.
12. Governing law
This policy is governed by French law and the EU General Data Protection Regulation (GDPR). For unresolved disputes, you may lodge a complaint with the French data protection authority (CNIL).
Also see: Terms of Service · FAQ · Legal Notice · Cookie Settings
Questions? [email protected]