privacy · updated 7 October 2026
Privacy
This page says what Feedtracks collects, what it deliberately doesn't, how long things are kept, and how to exercise your rights — in plain words, with real numbers. Where your data physically lives is on the security page. Feedtracks is operated from France by Bitmaker SAS (see the legal notice). The full policy, which this page summarises and which binds, is in the app.
What we collect
- Your account
- Your email, a display name (yours, your Google name, or a generated pseudonym), and the photo, studio name and logo you choose to add. For each session we keep its IP address and browser identifier until it ends. Sign-in is passwordless: links and codes are stored only as hashes and expire after 15 minutes; for a passkey we keep only its public key; with Google we keep your Google account ID and the tokens Google returns.
- Your files
- The audio (and other files) you upload, stored as untouched originals with their name, size and type, plus what the product computes from them: waveforms and playback copies.
- Activity on tracks
- Comments (with their timestamps), replies, approvals, shortlist picks, and listens — for each identified listener, how many times and when. The first listen of each link tells its creator, with the listener's name when known. An approval stores the name and email entered with it.
- An operation log
- Account and content operations — sign-ins, uploads, moves, trash, shares, comments — are journaled. The log records the IP address of sign-ins, uploads and guest contributions, as French law (LCEN) requires, and erases it after one year. It also keeps the email address of every sign-in request, file names, and the first 140 characters of each comment.
- Guests
- Listening through a link sets nothing. At a guest's first comment, shortlist pick or approval, the browser gets an anonymous key (a 30-day cookie) so their contributions group together. A comment or pick asks once for a name and offers an optional email, used only to announce a new version and to recover the guest's feedback if they create an account. We also store the guest's language and log the IP address of comments and approvals.
- Beta feedback
- When a member sends feedback from the app, we store the message, the page they were on, the track and second that was playing, their device type and screen size, the app version, the session's recent errors, and any screenshot attached. It is emailed to the team, read by the founder with an AI assistant (Claude, by Anthropic, in the United States), and deleted with the account.
- Usage counts
- Each night we compute usage counts and dates for each account — uploads, listens, comments, invitations, groups hosted — used only to decide whether to send one of two onboarding emails.
- Device type and arrival
- We record whether a sign-in or a visit to a shared page comes from a phone, a tablet or a computer — never the browser's full identifier, except on your active sessions. Nothing is left on a visitor's device to find out where they came from: if, within a day of signing up, your account takes over feedback you left as a guest on a shared page, we note that you came through a share; and in your first week the app may ask, optionally and once, how you found Feedtracks.
- Billing
- Nothing is billed today. When paid plans open, billing runs on Stripe: card numbers never touch Feedtracks, and we keep only the subscription state Stripe reports.
What we don't
- No advertising, no sale or sharing of data for marketing.
- No third-party analytics or tracking pixels — neither in the app nor on this site. This website loads zero third-party resources; the only thing it stores on your device is the theme you pick, if you pick one.
- No directory: collaborator search only ever suggests people you already share a group with.
How long things are kept
| Sign-in links and six-digit codes | 15 minutes, stored hashed (a code: 3 tries) |
| Signed streaming and download URLs | 15 minutes |
| Link-password sessions | 24 hours, one link in one browser; cut when the link is turned off |
| App sessions | 90 days, no sliding renewal, revocable immediately |
| Deleted files (trash) | restorable 30 days, then purged |
| Quarantined uploads | purged after 30 days |
| IP addresses in the operation log | erased after one year |
| Database backups | 30 days |
Some records have no automatic expiry yet: guest identities, content reports, in-app notifications and beta-feedback screenshots stay until the account or the content they belong to is deleted.
Cookies and your device
The app uses functional cookies only: your session (90 days), the anonymous guest key set at a guest's first contribution (30 days), a 24-hour unlock cookie on password-protected links, and two five-minute cookies during Google or passkey sign-in. No advertising or third-party analytics cookies.
On your device, the app also keeps your language, volume and audio-quality choice, the date of the last “What's new” you saw, and — for up to six hours — a copy of the lists you viewed so they open without a network. Signing out clears that copy. All of it is there for the app to work: nothing on your device serves measurement, which is why there is no consent banner.
Your rights
- Access & export
- Your files download bit for bit, individually or as a ZIP, on every plan, at any moment. For a copy of your other data, write to us.
- Rectification
- Change your display name, photo and studio branding in Settings. To correct your email address, write to us.
- Deletion
- Delete your account yourself from Settings (first delete any group you host). Your private drive and identity are erased at once and leave our backups within 30 days; contributions to shared groups stay with the group, under a pseudonym. The security page has the details.
- Email control
- Notification emails switch off per type in Settings, and each carries a one-click unsubscribe — so do the two onboarding emails and every email to a guest. Sign-in, invitation and safety emails have no unsubscribe: they are the service itself.
- Complaint
- You can lodge a complaint with the CNIL (the French data-protection authority) at any time.
For any privacy request: contact us — a human answers within 2 business days.