Legal

Privacy Policy

Effective date: September 24, 2026

Notice of change (posted September 17, 2026)

We are starting to advertise the service, so the Meta (Facebook/Instagram) and TikTok advertising pixelsare being added. “Third Parties” and “Cookies & Local Storage” below have been updated accordingly. The change takes effect on September 24, 2026; until then no advertising pixel is installed. The pixels never receive your name, email address, or your audio — see Cookies below for how to opt out.

This Privacy Policy describes how Anti-AI Master (“we”, “us”, “our”) collects, uses, and protects your information when you use antiaimaster.com. By using the Service, you agree to the practices described here.

#Summary (TL;DR)

  • Mastering runs in your browser, and we never keep your audio. It reaches our server only as a rescue when your browser cannot finish the render, plus for AI detection scanning and the partner API — and in every case it is deleted the moment processing ends (see “Your Audio Files” below).
  • Mastered Charts is opt-in and separate. Only if you tick the consent box do we publish 30 seconds of the master and 30 seconds of your raw upload, for 30 days, and you can take it down at any time.
  • We collect only what we need: Google account info (if you sign in), credit balance, and transaction history.
  • We use PostHog for product analytics, which sets its own cookies, and — while we are running ads — the Meta and TikTok advertising pixels, which count whether an ad led to a sign-up or purchase. They never receive your name, email, or audio. We do not sell your data.
  • You can request deletion of your account and all data at any time.

#Your Audio Files

Our principle has not changed: your music is yours, and we do not keep it. Mastering runs in your browser — every mastering mode we offer processes audio locally using WebAssembly and the Web Audio API — so in normal use your file stays in your browser.

There is one situation where we do process your audio on our server, and it exists for your benefit: if your browser cannot finish the render — not enough memory, an unsupported browser, a tab that crashed mid-render — we would rather finish the job for you than hand you a failure. So the file is sent to our server, mastered there, and deleted the moment it is done, in the same request.

The same rule applies to the two other times audio reaches our server:

  • AI detection scanning — the scanner analyses the file on our server and returns a score to your browser. The upload is temporary.
  • Partner API — if you use our B2B mastering API, processing is server-side by design.

In every one of those cases the file is processed and then deleted immediately. It is never stored, never used to train anything, and never reviewed by a human. We tell you this plainly rather than claiming “we never touch your audio”, because the fallback is real and you deserve to know it is there.

Mastered Charts is a separate, opt-in feature. The rule above — we do not keep the audio you master — is unchanged. The chart is a place to show your track to other people, and nothing is stored unless you open “Add to chart” yourself and tick the consent box. When you do, 30 seconds of the master and the same 30 seconds of your raw upload are published so listeners can compare before and after. The raw 30 seconds is published exactly as you uploaded it, with no processing.

  • Published for 30 days. Before that runs out we email you; unless you ask us to take it down it stays published, and you can remove it yourself at any time. When it comes down the audio and cover art are deleted immediately.
  • Stored on Cloudflare R2, in Cloudflare’s Asia-Pacific region. Anyone who knows the file URL can download it without signing in.
  • You can take it down at any time, and the audio and cover art are deleted from storage immediately.
  • If you never add a track to the chart, none of your audio is stored.
  • Comments. Signed-in users can comment on chart tracks. We store the display name you choose (separate from your account name), the comment text, emoji reactions and the time it was written. Comments are public. They are deleted when the track comes down, and the author or the person who uploaded the track can delete them at any time.
  • Backups: the audio storage is not backed up, so clips have no backup copy. Chart metadata and usage records may remain in encrypted database backups for the backup retention window (daily backups 30 days, weekly backups up to 8 weeks) after a track comes down.

We do store a fingerprint of your file — a SHA-256 hash — alongside your job history, so we can recognise a re-render of the same track and avoid double-charging you. A hash cannot be turned back into audio.

#Data We Collect

We collect the following categories of information:

Account information. When you sign in with Google, we receive and store: your Google account ID, email address, display name, and profile photo URL.

Billing information. Credit balance, subscription status, and transaction history (PayPal order IDs, amounts, dates). We never receive or store your payment card details — those are handled exclusively by PayPal.

Mastering history. For each render we store what was rendered, not the audio: the preset used, track duration, output format, credits charged, the time, and a SHA-256 fingerprint of the input file (used to recognise a re-render and avoid charging you twice).

Technical logs. Standard server logs including IP address, user agent, request paths, response status codes, and timestamps. We also record IP-keyed rate-limit counters and security events (for example repeated failed sign-ins). Used for security monitoring, abuse prevention, and debugging.

Support correspondence. If you email us or use the contact form, we store the message content and your reply address so we can help you.

#How We Use Data

We use the data we collect only to:

  • Operate the Service (authenticate you, track credit balance, deliver downloads)
  • Process payments and issue refunds
  • Respond to support requests
  • Detect and prevent abuse, fraud, and security incidents
  • Comply with legal obligations

We do not train machine-learning models on your data, and we do not use it for any purpose unrelated to operating the Service. While we are running ads, the pixels described under “Cookies & Local Storage” measure whether an ad led to a sign-up or a purchase, and Meta and TikTok may use those records for their own ad targeting under their own policies. You can opt out — see that section.

#Cookies & Local Storage

We use a small number of cookies and browser storage entries — only what is necessary to operate the Service:

  • Session cookie — keeps you signed in. HTTP-only, SameSite=Lax, secure.
  • CSRF token — protects against cross-site request forgery on form submissions.
  • Local storage — stores your UI preferences (language toggle, last-used preset). Never sent to our servers.
  • Attribution cookie (ciel_ft) — records once, on your first visit, how you reached us (the referring address and any campaign tags on the link). It holds no advertising identifier and nothing that identifies you personally, and it expires after 90 days. If you sign up, the value is stored once on your account so we can understand which channels bring people here. If you arrive directly, without a search or link, no such cookie is created.
  • PostHog analytics cookie — set on the Studio and account pages to recognise a returning visitor and group their page views into one session. Stored as a cookie and a matching local-storage entry.
  • Advertising pixel cookies (Meta _fbp, TikTok _ttp and similar) — set by Meta and TikTok while we are running ads, so they can count whether someone who saw an ad went on to sign up or buy. Their contents and lifetime are set by those companies. See below to opt out.
  • Conversion flag (ciel_px) — a short-lived cookie (up to 30 minutes) that tells the advertising pixel, once, that a sign-up or payment has just completed. It holds the amount, currency and plan name — never your name or email — and is deleted the moment it is read.

We use PostHog for product analytics. It records page views and interaction events (clicks, form submissions) so we can see which parts of the Service are used and where they break. If you are signed in, those events are linked to your account ID. PostHog does not run session replay on our site. PostHog is a US service, so this data is transferred to the United States.

Advertising pixels. While we are running ads, the Meta (Facebook/Instagram) and TikTok pixels are installed on our pages to count whether an ad led to a sign-up or a purchase. They receive request metadata (IP, user agent), the page address, whether a sign-up or payment completed, the amount and currency, and their own cookie identifier — never your name, email address, or your audio. Meta and TikTok may use these records for personalised advertising under their own policies. If you visit from the UK, the EEA, or Switzerland, the pixels are installed only after you consent — a banner asks you first. Everywhere else they are on by default and you can turn them off at any time on Your Privacy Choices (also reachable as “Do Not Sell or Share My Personal Information”); once off, no advertising pixel is installed in that browser. You can also block third-party cookies in your browser, or turn off personalised ads in Meta ad settings and TikTok’s settings. Blocking them does not limit the Service in any way. We do not use PostHog analytics data for advertising or profiling. If you would rather not be counted at all, email us at [email protected] and we will exclude your account.

#Third Parties

We share limited data with the following third-party processors, only as required to operate the Service:

  • Google (US) — for OAuth sign-in. Google receives a request from you to authenticate; we never share data with Google beyond what their OAuth flow requires.
  • PayPal (US) — international payment processing. PayPal receives the order amount and your PayPal account email. We never see your card details.
  • PortOne / KakaoPay (Korea) — payment processing for Korean customers. They receive the order amount and the identifiers needed to charge and to run recurring billing. We never see your card details.
  • Lemon Squeezy (US) — payment processing and merchant-of-record billing for some purchases.
  • Resend (US) — transactional email delivery (receipts, magic sign-in links, support replies). Resend receives your email address and the message content.
  • PostHog (US) — product analytics. Receives page views, interaction events, and your account ID when signed in. See “Cookies & Local Storage” above.
  • Cloudflare (US) — CDN, DDoS protection, and TLS termination. Cloudflare may log standard request metadata (IP, user agent, path).
  • Hetzner (Germany) — our hosting provider. Server logs are stored on infrastructure they operate.
  • Meta Platforms, Inc. (US) — advertising measurement and ad delivery, while we are running ads. Receives request metadata (IP, user agent), the page address, whether a sign-up or payment completed with its amount and currency, and its own cookie identifier.
  • TikTok Pte. Ltd. (Singapore) — advertising measurement and ad delivery, while we are running ads. Receives the same fields as above.
  • Telegram — we receive our own operational alerts here (error rates, failed jobs, backup status). When you contact support, the alert we receive includes your email address and the text of your message, so that we can read and answer it from a phone. Telegram is the transport; the ticket itself lives in our own database.

We do not sell, rent, or trade your personal data to any third party.

#Data Retention

We retain your account data for as long as your account is active. After you delete your account, we remove personal information within 30 days, except where a legal obligation (tax records, dispute resolution) requires longer retention.

Server logs are retained for up to 30 days, then automatically deleted. Support correspondence is retained for 12 months by default.

Mastered Charts. A published track stays up for 30 days. When it comes down — automatically, or the moment you take it down yourself — the audio and cover art are deleted from storage and the track’s title, artist name and the accompanying play, like, share and report records (including the one-way hash of the IP address used to de-duplicate plays) are erased with it. Only the aggregated numbers already snapshotted into the weekly ranking remain. Two different clocks apply here: the audio you master is deleted the moment processing ends and is never in a backup, while chart metadata, comments and usage records (including the one-way IP hash) are kept only for the publication window (up to 30 days), erased from the live database as soon as the track comes down, and may persist in encrypted database backups until the backup retention window passes (daily backups 30 days, weekly backups up to 8 weeks).

#Your Rights (GDPR / CCPA)

If you are located in the European Union, United Kingdom, California, or another jurisdiction with comprehensive privacy law, you have the following rights:

  • Access — request a copy of the data we hold about you
  • Correction — ask us to fix inaccurate data
  • Deletion — ask us to delete your data (“right to be forgotten”)
  • Portability — receive your data in a machine-readable format
  • Objection — object to certain types of processing
  • Withdraw consent — for any processing based on consent

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

California residentsadditionally have the right to opt out of the “sale” of personal information under the CCPA. We do not sell personal information, so this right does not apply, but you may still contact us with any concerns.

#Security

We protect your data with industry-standard measures: TLS 1.3 for all traffic, encrypted storage at rest, principle-of-least-privilege access controls, and regular security review.

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at [email protected].

#International Transfers

Anti-AI Master is operated from infrastructure located in Europe. If you access the Service from outside the European Economic Area, your data may be transferred to, stored, and processed in countries with different data protection laws than your own. We rely on Standard Contractual Clauses or equivalent legal mechanisms to ensure adequate protection during international transfers.

#Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal information from children under 18. If we learn we have collected such information, we will delete it. If you believe a child has provided us with personal information, please contact us at [email protected].

#Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy at this URL with an updated effective date. For material changes, we will make reasonable efforts to notify active users by email.

#Contact

For privacy questions, data requests, or to report a concern: