Privacy Policy
Last updated: March 2026
trakd ("we", "our", or "us") operates the trakd mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Information We Collect
We collect information in the following ways:
- Account Information: When you create an account, we collect your email address, username, and display name. If you sign in with Apple or Google, we receive your name and email address from the respective provider.
- Profile Photos: If you upload a profile photo, we access your device camera or photo library (with your permission) and store the image on our servers.
- Audio Data: When you use the track identification feature, we temporarily capture a short audio sample from your device microphone. This sample is sent to our audio fingerprinting provider for identification purposes only. Audio samples are processed in real-time and are not permanently stored by us.
- Usage Data: We automatically collect information about how you interact with the app, including sets viewed, tracks saved, contributions, and social interactions (follows, likes).
- Device Information: We collect device type, operating system version, and anonymous crash/performance data to improve the app.
- Spotify Data: If you connect your Spotify account, we access your profile information and the ability to create and modify playlists on your behalf. Your Spotify credentials are stored securely on your device and are never sent to our servers.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the trakd Service
- Identify music tracks using audio fingerprinting
- Personalize your experience and deliver relevant content
- Send you updates, marketing communications, and other information related to the Service (you may opt out at any time)
- Monitor and fix bugs, crashes, and performance issues
- Respond to your comments, questions, and support requests
Legal Basis for Processing (EEA/UK Users)
If you are in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
- Contractual Necessity: Processing your account information and usage data is necessary to provide you with the trakd Service as described in our Terms of Service.
- Legitimate Interest: We process device information, crash reports, and usage analytics to improve our Service, detect bugs, and ensure platform security.
- Consent: We rely on your consent for marketing communications and microphone access for track identification. You can withdraw consent at any time.
Third-Party Services
We use the following third-party services to operate trakd. Each may receive data as described:
- Supabase: Database hosting and authentication. Your account data and usage data are stored on Supabase infrastructure. Supabase Privacy Policy
- ACRCloud: Audio fingerprinting and track identification. When you use the identify feature, a short audio sample is sent to ACRCloud for music recognition. ACRCloud processes the audio to match it against their music database. Raw audio is not permanently retained. ACRCloud Privacy Policy
- Sentry: Error monitoring and crash reporting. We collect anonymous crash reports and performance data (no personally identifiable information) to identify and fix bugs. Sentry Privacy Policy
- Spotify: Music data integration and playlist export. When you connect your Spotify account, we interact with the Spotify API on your behalf. Spotify Privacy Policy
- Apple Music: Music catalog data. We use the Apple Music API to provide track metadata, album artwork, and audio previews. Apple Privacy Policy
- Apple Sign-In: If you sign in with Apple, we receive your name and email address (or Apple's private relay email) as authorized by you. Apple Privacy Policy
- Google Sign-In: If you sign in with Google, we receive your name, email address, and profile photo from your Google account. Google Privacy Policy
- Vercel: Web hosting and serverless functions. Vercel processes web requests to deliver our Service. Vercel Privacy Policy
- Expo: App update delivery. Your device may contact Expo's servers to check for over-the-air updates. Expo Privacy Policy
RevenueCat
We use RevenueCat to manage in-app subscriptions and purchases. RevenueCat processes your purchase history, subscription status, and a pseudonymous app user ID to manage your subscription. RevenueCat does not receive your name or email address. For more information, see RevenueCat's Privacy Policy.
International Data Transfers
Your data may be transferred to and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from your jurisdiction. When we transfer data outside the European Economic Area, we rely on Standard Contractual Clauses and our service providers' compliance with recognized data protection frameworks to ensure appropriate safeguards are in place.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our Service. You can delete your account at any time from the Settings screen within the app. When you delete your account, we permanently remove your profile data, contributions, and associated records from our systems. Some anonymized or aggregated data may be retained for analytics purposes. If you are unable to delete your account through the app, you may contact us at privacy@trakthat.app and we will remove your data within 30 days.
Data Security
We implement appropriate technical and organizational measures to protect your personal information, including encryption in transit (TLS) and secure credential storage on your device. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- The right to access the personal data we hold about you
- The right to request correction of inaccurate data
- The right to request deletion of your data
- The right to restrict processing of your data
- The right to object to processing based on legitimate interest
- The right to data portability
- The right to withdraw consent at any time
- The right to opt out of marketing communications
- The right to lodge a complaint with your local data protection supervisory authority
To exercise any of these rights, contact us at privacy@trakthat.app.
Your California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions.
- Right to Opt-Out of Sale: We do not sell your personal information to third parties.
- Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
To exercise these rights, contact us at privacy@trakthat.app. We will respond within 45 days.
Do Not Track: Our Service does not currently respond to "Do Not Track" browser signals.
Children's Privacy
trakd is not intended for use by children under the age of 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@trakthat.app. We will take steps to delete such information from our servers.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
Contact
If you have any questions about this Privacy Policy or our data practices, please contact us at: