/privacy
Privacy, plainly.
The free labs run entirely on your device. Paid accounts process a small amount of personal data through Stripe and Supabase. Here is exactly what happens with each, and your rights over it.
Controller: AudioLaunch (KVK 54871204), Eindhoven, Netherlands · contact privacy@audiolab.tools.
The labs on this site (MixLab, VoiceLab, HearLab, SignalLab, CueLab, SkillLab, Ψ Lab) run entirely inside your browser. Audio you analyze there is not uploaded to any server.
When you open an audio file, it is decoded by your browser’s WebAudio API and analyzed as JavaScript on your own device. The file is never copied or transmitted, and is gone when you close the page. Live-microphone features (VoiceLab, HearLab, SkillLab) work the same way: captured and processed in place, nothing leaves the browser.
One exception with explicit notice: HearLab’s live-captions feature uses the browser’s built-in Web Speech API, which on most browsers routes audio to a provider (typically Google) for transcription. That is a browser-level integration, not an AudioLab choice; HearLab works without captions if you prefer to keep audio strictly local.
When you buy Pro or Founder, or sign in to /account, we process a limited set of personal data server-side. This list is written from what the code actually stores, and a build check keeps it that way:
- Email address: to create your account and send the magic sign-in link (legal basis: performance of a contract).
- Payment & subscription data: your Stripe customer/subscription id, plan, and status. Card details are handled entirely by Stripe; we never see or store them (legal basis: contract + legal obligation for invoicing).
- API key: we store only a SHA-256 hash of your key plus a short prefix, never the key itself, so you can call the API and MCP on any plan (including the free tier) (legal basis: contract).
- Usage & analysis metadata: for each API/MCP call we record which tool you used, the audio’s duration, and a few measurements (integrated LUFS, true-peak) to power your usage limits and account stats. If you gave the file a name (by analysing a URL, or by saving a result from a browser lab) that name is stored alongside the numbers, because it is what makes your history readable. You decide whether we keep it. The workbench asks once, before you save anything: choose to anonymise and your file names are replaced with a stable code such as “take-4f2a91c8.wav”, the same code every time for the same file, so your history still groups, but meaningless to anyone else and not comparable between accounts. With that setting on, the name is not even sent to us; the server enforces the same rule as a backstop. The choice lives on your account, so it applies on every device you sign in from, and you can change it at any time. Files you upload through a signed link get a generated name instead, and your own name for them is never sent to us (legal basis: contract + our legitimate interest in metering and abuse prevention).
- The audio itself: not kept. On a direct API call it is decoded, measured and discarded inside the request; nothing is written to disk. On the upload path (/account “Quick analyze”, and the API’s signed-upload route) the file does land in EU-hosted storage for a moment, because a browser cannot stream it straight into the function. It is deleted the instant the analysis reads it, and a sweep removes anything left over within the hour. The seven in-browser labs send no audio anywhere at all.
We do not sell personal data and do not use it for advertising.
- Stripe Payments Europe: payment processing & billing. (Ireland/EU; DPA in place.)
- Supabase: authentication & account database, hosted in the EU (Frankfurt).
- Vercel: website & API hosting/CDN and server request logs. Requests enter the network in Frankfurt, and the serverless functions that decode and measure uploaded audio run there too (region fra1, pinned in
vercel.json). Vercel is a US company, so its role as processor still rests on the EU-US Data Privacy Framework and the standard contractual clauses, but the audio itself is not processed outside the EEA. The seven in-browser labs are unaffected: they compute on your device and send no audio anywhere. - PostHog: product analytics, on the EU-hosted instance, cookieless. See section 04.
- GitHub: hosts the Psi Spectral VST download. Your IP reaches GitHub only if you download it. (US; DPF-certified.)
Each acts as a data processor under a data-processing agreement. Standard server-side request logs (IP, user-agent, referrer) may be retained briefly for security and abuse prevention; they are not joined to your account identity.
We do not use Google Analytics, Meta Pixel, or cross-site tracking, and we set no advertising or tracking cookies. The only browser storage we use is functional, and all of it stays on your device: a theme preference, your sign-in session, what the labs remember for you, and two IndexedDB stores that carry a decoded clip into the workspace. The complete list (twelve entries, each by its exact key name) is on the cookie & tracking policy, where a build check keeps it honest. It is deliberately kept in one place: a second summary here would be a second thing to keep in step, and this page used to name four of the twelve.
For product analytics we use PostHog on its EU-hosted instance (eu.i.posthog.com), configured with in-memory persistence: it sets no cookies and writes nothing to your device, so closing the tab ends the session. It records page views and interactions with the interface. Audio you analyse in the browser labs never leaves your device, so it is never sent to PostHog. If we introduce a tool that requires consent, we will ask for it first and update this page.
The Android measurement apps use PostHog differently: opt-in, off by default, and with on-device storage for their anonymous stats rather than in-memory. See section 05.
MicLab, LevelLab, RoomLab and NoiseLab are separate Android apps. Like the browser labs, they measure entirely on your device: the audio they record is analysed in place and discarded after measuring, and your recordings, your saved measurements and the names you give them never leave your phone.
They ship with one optional setting, “Share anonymous measurement stats”, which is off by default. Nothing is sent unless you switch it on. When you do, then for each measurement the app sends its numeric results (loudness, reverb, scores and the like) together with your device model, Android version, app version and language, so we can tune the apps to real devices. It is tied to a random identifier generated on your device, not to your name, and we ask PostHog to discard your IP address on arrival. We never send your recordings, your file or measurement names, or your location.
The legal basis is your consent: the switch is off until you give it, and turning it off withdraws it and stops all collection at once. The processor is PostHog (section 03), on its EU-hosted instance, under a data-processing agreement. These are anonymous product statistics, not linked to any account, and are kept no longer than twelve months. The rights in section 06 apply. Once the switch has been on, the app shows the random ID under Settings, Analytics; email it to privacy@audiolab.tools and we delete every record stored under it at PostHog. The switch itself stops any further collection immediately.
SignalLab, HearLab and TuneLab (the newer Android apps) go one step further: they contain no analytics at all. There is no stats switch and no analytics library in the app, so there is nothing to send. Tones, hearing checks and tuning happen on the device, and results stay there unless you export a PDF yourself.
Under the GDPR you have the right to access, rectify, export, restrict, and erase your personal data, and to lodge a complaint with the Dutch DPA (Autoriteit Persoonsgegevens).
- Erasure: delete your account and all associated data yourself from /account ("Delete account & data"), or email privacy@audiolab.tools. For the Android apps, email the same address with the random ID shown under Settings, Analytics in the app (section 05).
- Access / export: request a copy of your data at the same address; we respond within 30 days.
- Retention: account data is kept while your account is active. Invoicing records are retained as required by Dutch tax law (7 years). Everything else is deleted on account erasure.
This section is about the HearLab lab on this website. The Android app of the same name is covered by section 05 and contains no analytics at all.
HearLab is a non-medical companion. It does not diagnose, treat, or replace audiological care, and it does not collect medical information. What it captures (the captions of what was said and the check-ins you write) is kept on your own device in localStorage (hearlab-session) so a session survives a reload. It is never sent to us. Clearing it is up to you: use the lab’s own reset, or your browser’s “clear site data”. Until 22 August 2026 this paragraph said a refresh cleared those notes. It did not. They were kept, exactly as described here. Nothing left your device either way, but the description was wrong and we would rather say so than quietly fix it.
Last updated
22 August 2026: two changes you can check yourself. File names are now yours to keep or hide. The workbench asks before your first save, the answer lives on your account, and with it on the name never reaches us. And the functions that measure your audio now run in Frankfurt instead of Washington DC: request any page and read the X-Vercel-Id header, the middle field says fra1. Storage was already in the EU.
2 September 2026: added SignalLab, HearLab and TuneLab (Android). They carry no analytics at all, not even the optional switch the other four have; see section 05.
23 August 2026: NoiseLab (sound level meter) joined the Android apps; same rules as the other three, see section 05.
22 August 2026: added the Android measurement apps (MicLab, LevelLab, RoomLab). They are on-device by default, with one optional, off-by-default anonymous measurement-stats switch (PostHog, EU). See section 05.
22 August 2026: the Android apps now show the random analytics ID under Settings, Analytics, so you can email it to privacy@audiolab.tools and have the stats stored under it deleted.
22 August 2026: corrected three descriptions that did not match the code: the filename you give a file is stored next to the numbers, uploaded audio does briefly land in EU storage before it is read and deleted, and HearLab notes survive a refresh instead of being cleared by one.
3 July 2026: clarified what we store for API/MCP usage: per-call metadata (tool, duration, LUFS, true-peak) and never your audio.
2 July 2026: added accounts, payments, processors, and data-subject rights now that paid accounts are live.
The on-device labs are auditable in your browser’s devtools; nothing is obfuscated. See also our Terms of Service.