seeaud.io Privacy Policy
Last updated: September 8, 2026
What data this app collects (short version)
- Google sign-in may provide your identifier, name, email address, avatar, and account linkage.
- Email magic links use single-use verification data instead of a password.
- We store account and sign-in information to provide access to your account and protect it against misuse. We use essential cookies to keep you signed in and secure the sign-in process.
- We store Stripe customer and payment-entitlement identifiers, but not your card details.
- Basic cookieless visit statistics and technical diagnostics via PostHog remain active even if you reject optional tracking.
- Usage analytics with a browser identifier and masked editor session replay are optional, with separate choices in Privacy settings.
- Your opened audio files and background images stay in your browser. They are excluded from session replay.
1. Data Controller
The controller of personal data processed in the seeaud.io app is Codeart Kamil Kaminski, Polish Tax Identification Number (NIP): 8982248130, correspondence address: Kamienskiego 202/42, 51-126 Wroclaw (the "Controller").
For privacy-related matters, contact: contact@seeaud.io.
2. Scope and Purposes of Processing
We process personal data only to the extent necessary to operate the app, provide secure passwordless account access, process payments, and understand and improve reliability as described below.
- Google sign-in: Google account identifier, name, email address, avatar, and account linkage. seeaud.io never receives your Google password. Any credentials we retain to maintain the connection to your Google account are encrypted.
- Magic-link sign-in: your email address and single-use magic-link verification data are processed to send and verify a passwordless sign-in link.
- Account and sign-in security: We store information about your signed-in sessions, connected sign-in accounts, sign-in verification, and attempts to misuse the service. This helps us provide account access and protect your account.
- Payments: We store Stripe customer and payment-entitlement identifiers. During checkout, card details are provided directly to Stripe and are not received or stored by seeaud.io.
- Basic statistics and diagnostics: page visits, browser and device information, and limited technical error and export diagnostics help us understand traffic and maintain reliability. This collection does not use a stored analytics identifier or your account details. PostHog processes request information, including an IP address and browser information, to derive a short-lived identifier for cookieless measurement. We do not retain the raw IP address in browser analytics events. This is not a claim that all cookieless data is anonymous.
- Optional usage analytics: if you agree, we collect selected editor actions, such as opening audio, starting a preview, changing a visualizer, starting or completing an export, and opening the upgrade flow, creating a checkout session, and completing a purchase. A browser identifier links these actions. We do not attach your name, email address, or account identifier.
- Optional session replay: if you separately agree, PostHog reconstructs interactions in a sample of editor sessions from page changes and clicks. Text and input values are masked, and audio, images, the visualizer canvas, file names, account details, and payment screens are excluded. We do not record network request bodies, authentication headers, or console logs. Replay helps us investigate usability and technical problems.
We use this data for account access, authentication security, transactional email and entitlement delivery, payment and accounting, abuse prevention, diagnostics, service improvement, and compliance with legal obligations.
3. Legal Bases (GDPR)
- Article 6(1)(b) GDPR: performance of a contract (account, login, and service operation),
- Article 6(1)(c) GDPR: compliance with legal obligations related to billing and accounting,
- Article 6(1)(f) GDPR: our legitimate interests in security, limited cookieless measurement, and diagnosing reliability problems, balanced against your rights.
- Article 6(1)(a) GDPR: your consent for optional usage analytics and session replay.
4. Cookies and Browser Storage
We use essential cookies to keep you signed in, protect sign-in, and return you safely from Google sign-in. The seven-day rolling sign-in session can be extended by active use; signing out or invalidating the session may end it sooner. Restricted testing access can also use a cookie lasting up to 24 hours.
Functional storage remembers whether to open the editor on a return visit (up to one year), your editor preferences, and whether you have seen the welcome message. Preferences stored in local storage remain until you reset them or clear browser data.
Your privacy choice and its date and version are stored for 180 days in a first-party cookie and local storage. When you enable either optional purpose, PostHog can use a browser identifier in first-party cookies and local storage, plus session storage. Optional cookies have a maximum lifetime of 180 days; local identifiers are removed when you withdraw both optional purposes or when the app detects that your privacy choice has expired.
We ask for optional choices in the editor, after introductory or payment confirmation dialogs close. We do not start optional analytics or replay before your choice. Replay operates only in the editor; consented checkout and purchase events are sent by our server. The public landing page uses basic cookieless measurement.
You can accept or reject optional tracking, or choose usage analytics and replay separately. Open Privacy settings in the editor to change or withdraw your choices at any time. Rejection does not affect your account, purchase, or app features. Basic cookieless statistics and technical diagnostics remain enabled after rejection. Withdrawal stops future optional collection; it does not automatically erase data already collected or affect the lawfulness of processing before withdrawal.
For consented payment measurement, Stripe checkout metadata includes the optional browser identifier, the privacy choice and its date, browser information, and an internal-testing flag. We send no account identifiers, email addresses, card details, or Stripe payment identifiers to PostHog in these events. When you withdraw usage analytics, we store a hash of the browser identifier and the withdrawal time to suppress pending purchase events. This record expires after 180 days and is removed during subsequent withdrawal requests. If the withdrawal cannot reach our server, the app asks you to retry; optional browser tracking remains off in that tab.
An optional internal-browser setting stores a local preference so the app owner and testers can label their activity and exclude it from reports. It remains until switched off or browser storage is cleared, and does not grant analytics or replay consent.
5. Stripe Payments
Payments are processed by Stripe, Inc., which may act as an independent controller and/or processor depending on the processing stage and legal context.
Payment information such as card details is sent directly to Stripe and is not received or stored in our database. We keep only the identifiers needed to associate your customer and payment entitlement with your seeaud.io account.
Stripe may use cookies and similar technologies on payment pages to operate its services and detect or prevent fraud. See Stripe's Cookie Policy for information about its storage and choices.
For more information about how Stripe processes data: https://stripe.com/privacy.
6. Data Recipients
Your data may be shared with the following categories of recipients:
- Cloudflare hosts our app and stores account, sign-in, and security data on our behalf. Privacy policy: https://www.cloudflare.com/privacypolicy/.
- Google is our sign-in identity provider. Privacy policy: https://policies.google.com/privacy.
- Resend is our transactional-email processor. Privacy policy: https://resend.com/legal/privacy-policy.
- Stripe is our payment processor.
- PostHog processes basic statistics and diagnostics, and optional analytics and replay on our behalf. We use its EU cloud region. Privacy policy: https://posthog.com/privacy.
7. Transfers Outside the EEA
Because we use global providers, including Google, Cloudflare, Resend, Stripe, and PostHog, personal data may be transferred outside the European Economic Area. Where this happens, appropriate GDPR transfer safeguards are applied, such as Standard Contractual Clauses.
8. Data Retention
- session replay: up to 30 days, unless you ask us to retain a specific recording to investigate a reported problem,
- analytics and diagnostic events: while needed to assess usage and investigate reliability problems; we review their continuing need and delete data that no longer serves these purposes,
- browser storage: as described in section 4; clearing storage does not delete data already sent to our providers,
- account data: until account deletion or a successful deletion or objection request,
- Google account linkage and retained OAuth tokens: while the connection is active, or until unlinking where available or account deletion,
- session data: for the seven-day rolling session lifetime, or less when you sign out or the session is invalidated,
- magic-link verification data: until the single-use link is consumed or expires; related security and abuse-prevention records are kept only as long as needed to protect the service,
- payment-related identifiers: for as long as your account is active. After account deletion, we delete them unless a longer retention period is required by law, including tax or accounting obligations (typically up to 5 years from the end of the calendar year in which the tax payment deadline fell), or needed to establish, exercise, or defend legal claims.
9. Your Rights
You have the right to:
- access your data,
- rectify your data,
- erase your data,
- restrict processing,
- data portability,
- object to processing based on legitimate interests, including basic cookieless measurement,
- withdraw consent to optional analytics or replay at any time through Privacy settings,
- lodge a complaint with your competent supervisory authority.
To request account and data deletion or exercise another right, email contact@seeaud.io. We may need to verify your identity before completing a request.
10. Policy Updates
We may update this Privacy Policy when app functionality or legal requirements change. The current version is always available on this page. If we materially change the purposes of optional tracking, we will ask for a new choice before starting that processing.