security · updated 7 October 2026
Security & data
Feedtracks stores the files you upload, your account details (email, display name, and the photo and studio branding you choose to add), and the activity around your tracks: comments, approvals, listens and shortlist picks. There is no advertising anywhere in the model. Every claim on this page is specific on purpose: providers, algorithms and time limits are named so you can hold us to them.
01
How your audio is handled
- Originals, never modified
- Your original file is stored as uploaded and never modified; every download returns it bit for bit. For playback we also compute AAC copies (and a FLAC copy of lossless files), which the player streams by default.
- Straight to storage
- Uploads go from your browser straight to storage over presigned URLs, and playback and single-file downloads come back the same way. Our own server reads each upload to scan it and compute its waveform and playback copies, and streams ZIP exports to you. No third party handles these bytes.
- Short-lived URLs
- Every stream and single-file download uses a signed storage URL that expires after 15 minutes — on shared links too. Upload URLs expire after 60 minutes.
- Scanned before shared
- Every upload is antivirus-scanned when it arrives. Until the scan comes back clean, the file is served to no one but you; if the scan can't run, it stays that way and you're told. Infected files are quarantined, you're notified, and quarantine purges after 30 days.
- No guessable paths
- Audio is stored under random keys, never your file names, and each file belongs to the account that uploaded it. Profile photos, studio logos, group photos and playlist covers live in a separate bucket: an image loads for anyone who has its URL, and the bucket cannot be listed.
02
Links you share
- Unguessable by construction
- Each link uses a 128-bit cryptographically random token. An item can have up to 50 links at a time, each with its own URL; turning a link off and on again keeps its URL.
- Out of search engines
- Every response of the shared-link API carries X-Robots-Tag: noindex, and the shared page adds a robots noindex tag. A link is reachable by the people you gave it to, not by a crawler.
- Passwords done right
- Link passwords are scrypt-hashed and compared in constant time. A correct password opens a 24-hour session for that link, in that browser. A link's password is set when the link is created and never changes; turning the link off locks everyone out, unlocked sessions included.
- Listen-only by default
- Downloads are unticked when you create a link, and a link keeps the settings it was created with. Turning a link off cuts access at once; turning it back on restores the same URL with the same settings.
- Rate-limited
- The shared-link API is capped at 120 requests a minute per IP, password attempts at 5 a minute, guest comments at 10 per 10 minutes and 100 a day — with spoof-resistant IP resolution.
- Abuse dies with the account
- Suspending an account turns off all the links it created, at once; none can be re-enabled or created while it stays suspended.
03
Your account
- Passwordless
- Sign-in is an email link or a six-digit email code (each valid 15 minutes, usable once, stored only as a hash; a code is void after 3 wrong tries), a passkey, or Google. There is no password database to steal; for a passkey we keep only its public key.
- Sessions that actually end
- Sessions last 90 days with no sliding renewal, and revocation is immediate — every request checks the session; nothing is cached.
- Separated keys
- Sessions, invitation grants and link grants are signed by independent secrets: leaking one can never mint the others. Production refuses to boot on development defaults, without a real email transport, or with the antivirus switched off.
- Signup friction where it belongs
- Disposable email domains are refused at signup. Requests for a sign-in link or code are capped at 5 a minute per IP, attempts to use one at 3 a minute.
- A locked-down server
- The database is reachable only from a private network and encrypted at rest. It is backed up every 6 hours and before each deploy; backups are kept 30 days, in Paris. The server accepts SSH keys only and installs security updates every night.
- Journaled
- Sign-ins and content operations — uploads, moves, trash, shares, comments — are recorded in an operation log.
04
Where your data lives
The rule: a US provider is tolerated only off the path of your audio. Your files and their processing stay in Paris, full stop. Here are the providers that touch your data, and what each one touches.
-
Your audio and its processing (waveform, playback copies, antivirus); the app's servers
Scaleway (fr-par) · Paris, France
Never leaves the EU. No US third party on this path.
-
Account data and the application database
Scaleway (fr-par) · Paris, France
Hosted in the EU; the exceptions are the rows below.
-
Transactional email (sign-in links, notifications)
Scaleway · Paris, France
An email never contains your files. A US fallback (Resend) exists in the code and is switched off.
-
Sign in with Google
Google · United States
Only if you choose it. Your Google photo is copied once to our storage in Paris.
-
Mail you send to a feedtracks.com address
Google Workspace · —
Our support and security mailboxes.
-
Beta feedback sent from the app
Anthropic · United States
The founder reads it with an AI assistant (Claude), which receives the message, its context, any screenshot, and the sender's name and email.
-
Domain names (DNS)
Cloudflare · Global
Resolves feedtracks.com. No app traffic passes through it.
-
Payments
None today · —
When paid plans open, card payments will run on Stripe (United States) — this table changes first. We will never see card numbers.
05
What we don't have
- No end-to-end encryption
- The service must read your audio to compute waveforms and playback copies — that's the product. Treat Feedtracks like a cloud drive, not a sealed vault: operators can technically access stored files and the database, and those reads are not recorded in the operation log. The database is encrypted at rest by its provider.
- No high availability
- One application server and one database node, both in Paris. If either goes down, Feedtracks is down until it's back. Backups live in the same region; a copy off our provider's account is not in place yet.
- No SOC 2 or ISO 27001
- We're a small product and we don't have certifications. Instead of renting a badge, this page names what we actually do — every claim on it maps to code.
- No bug bounty
- We don't run a paid program. We do read and answer every report — see disclosure below.
- No trackers here
- This website loads zero third-party resources: no analytics scripts, no fonts from a CDN, no pixels. You're reading a static page.
06
Your rights
- Take your files out anytime
- Individual downloads or a ZIP export — always the original files, bit for bit.
- 30-day trash
- Deleted items are restorable for 30 days, then purged automatically. Purged files leave our backup copies within a further 30 days.
- Delete your account
- From Settings, any time — first delete any group you host, and name another admin where you are the only one. Your private drive, sign-in methods, photo, studio logo and beta feedback are deleted at once, and leave our backups within 30 days. Your comments, approvals and uploads in shared groups stay with the group, under a random pseudonym. The operation log keeps past entries with your email and name removed. A suspended account can ask for deletion by email.
- Guests stay light
- Listening through a link needs no account, no name and no email. Commenting or picking favourites asks once for a name, which signs the contribution, and offers an optional email. Approving a version asks for a name and an email; reporting content asks for an email.
- Report content
- Anyone can report a shared page without an account. Reports are handled under the EU Digital Services Act notice-and-action rules.
07
Reporting a vulnerability
Found something? Write to security@feedtracks.com — a human reads it and answers within 2 business days. Good-faith research on your own account is welcome; don't touch other people's data. Machine-readable contact: /.well-known/security.txt.