/privacy
Privacy, plainly.
The free labs run entirely on your device. Paid accounts process a small amount of personal data through Stripe and Supabase. Here is exactly what happens with each, and your rights over it.
Controller: AudioLaunch (KVK 54871204), Eindhoven, Netherlands · contact privacy@audiolab.tools.
The labs on this site (MixLab, VoiceLab, HearLab, SignalLab, CueLab, SkillLab, Ψ Lab) run entirely inside your browser. Audio you analyze there is not uploaded to any server.
When you open an audio file, it is decoded by your browser’s WebAudio API and analyzed as JavaScript on your own device. The file is never copied or transmitted, and is gone when you close the page. Live-microphone features (VoiceLab, HearLab, SkillLab) work the same way: captured and processed in place, nothing leaves the browser.
One exception with explicit notice: HearLab’s live-captions feature uses the browser’s built-in Web Speech API, which on most browsers routes audio to a provider (typically Google) for transcription. That is a browser-level integration, not an AudioLab choice; HearLab works without captions if you prefer to keep audio strictly local.
When you buy Pro or Founder, or sign in to /account, we process a limited set of personal data server-side:
- Email address: to create your account and send the magic sign-in link (legal basis: performance of a contract).
- Payment & subscription data: your Stripe customer/subscription id, plan, and status. Card details are handled entirely by Stripe; we never see or store them (legal basis: contract + legal obligation for invoicing).
- API key: we store only a SHA-256 hash of your key plus a short prefix, never the key itself, so you can call the API and MCP on any plan (including the free tier) (legal basis: contract).
- Usage & analysis metadata: for each API/MCP call we record which tool you used, the audio’s duration, and a few measurements (integrated LUFS, true-peak) — numbers only — to power your usage limits and account stats. We never store your audio. It is decoded, measured, and discarded within the request; nothing is written to disk or kept (legal basis: contract + our legitimate interest in metering and abuse prevention).
We do not sell personal data and do not use it for advertising.
- Stripe Payments Europe: payment processing & billing. (Ireland/EU; DPA in place.)
- Supabase: authentication & account database, hosted in the EU (Frankfurt).
- Vercel: website & API hosting/CDN and server request logs.
Each acts as a data processor under a data-processing agreement. Standard server-side request logs (IP, user-agent, referrer) may be retained briefly for security and abuse prevention; they are not joined to your account identity.
We do not use Google Analytics, Meta Pixel, or cross-site tracking, and we set no advertising or tracking cookies. The only browser storage we use is functional: your theme preference, your Supabase sign-in session, and local SkillLab progress, all stored on your device. See the cookie & tracking policy for the full list.
If we ever add product analytics, it will be a privacy-respecting, cookieless tool. If any tool that requires consent is introduced, we will ask for it first and update this page.
Under the GDPR you have the right to access, rectify, export, restrict, and erase your personal data, and to lodge a complaint with the Dutch DPA (Autoriteit Persoonsgegevens).
- Erasure: delete your account and all associated data yourself from /account ("Delete account & data"), or email privacy@audiolab.tools.
- Access / export: request a copy of your data at the same address; we respond within 30 days.
- Retention: account data is kept while your account is active. Invoicing records are retained as required by Dutch tax law (7 years). Everything else is deleted on account erasure.
HearLab is a non-medical companion. It does not diagnose, treat, or replace audiological care, and it does not collect medical information. Notes logged in the HearLab demo live only in your browser session; refresh to clear them.
Last updated
3 July 2026: clarified what we store for API/MCP usage — per-call metadata (tool, duration, LUFS, true-peak), numbers only, never your audio.
2 July 2026: added accounts, payments, processors, and data-subject rights now that paid accounts are live.
The on-device labs are auditable in your browser’s devtools; nothing is obfuscated. See also our Terms of Service.