Skip to content
DUETA
Legal

Privacy policy

Last updated August 19, 2026

DraftUnder legal review and not yet binding. Contact us with questions about anything here.

What we collect

Account data. Your email address, and a hash of your password. If you log in with Google we store the identifier Google gives us and your email address; we never see your Google password.

Audio you upload. The files you submit, and the tracks we produce from them.

Job and billing records. For each job: its type, status, timings, the durations and file names of your inputs, the seconds billed and the amount charged for them, and any error. Plus your credit ledger and any top-up orders.

Operational logs. Ordinary server logs, including IP addresses, which are also what our rate limiting works from.

How we use it

To run the service: process your jobs, meter and bill them, show you your history, keep the system available, and prevent abuse; we also use your email to reach you about your account. We do not sell your data, and we do not use it for advertising.

We do not train on your audio

Our models are pre-trained and run inference only, so your audio is processed and returned rather than added to a training set, and it is not reviewed by us as a matter of course. If you ask us to investigate a specific failed job, we may look at that job's audio to diagnose it, and only that.

How long we keep things

Uploaded audio and the tracks we produce are stored under the job that created them, and are deleted automatically. A daily cleanup job removes job directories older than 7 days, so a file's real lifetime is that window plus up to about a day, depending on when the cleanup next runs.

Deletion removes both what you uploaded and what we returned, so download anything you want to keep. You can ask us to delete specific jobs or your whole account sooner.

Rejected uploads are discarded immediately rather than stored. Job and billing records are kept after the audio is gone, because we need them for accounting.

Who else sees it

Your audio is processed on our own infrastructure, and we do not send it to third-party processing APIs. Our hosting provider necessarily stores the data our servers hold, and we may disclose data where the law requires it.

Security

Traffic is served over HTTPS, passwords are stored hashed, and API keys are stored hashed and shown to you in full only once. Access to a job is checked against the account that owns it.

Your session is set as an httpOnly cookie, and the same token is also kept in your browser’s local storage so the console can send it as a bearer. That second copy is readable by scripts running on this site, so the httpOnly protection does not cover it.

No system is perfectly secure, and we have not yet been through an external audit or a formal certification. We will not claim compliance we do not hold.

Your choices

You can see your jobs, usage, and credit ledger in the console at any time. You can ask us for a copy of your data, for corrections, or for deletion of your audio or your entire account, by contacting us; deleting your account removes your ability to reach any audio still stored for it.

Children

The service is not intended for children, and accounts are for adults.

Changes

We will update this page when our practices change and revise the date at the top. If the retention window above changes, this page changes with it.