Privacy Policy
Last updated 10 July 2026.
Who we are
TraxxTool ("we") is operated by Matt Brook. We are the data controller for the personal data described here. Contact: support@traxxtool.app.
What we collect, why, and on what legal basis
- Account data: your email address (and name, if you sign in with Google), received either from Google or by verifying a code we email you. Used to operate your account and entitlements, and to send you sign-in codes and other essential service messages. Basis: contract.
- Marketing email consent (optional): if, and only if, you tick the opt-in box, we record that you agreed to receive product-update emails, with the time and where you opted in. You can withdraw at any time from your account page or the unsubscribe link in any such email. We never add you to marketing without that opt-in. Basis: consent.
- Purchase & subscription records: what you bought (Pro, Cloud, credit packs) and subscription status. Card details go directly to Stripe; we never see or store them. Basis: contract; retention of transaction records: legal obligation.
- AI credits ledger: every credit grant and spend, with technical metadata (operation type, model id, token/character/second counts). We do not store the content of your AI requests. Prompts, lyrics and audio pass through to the provider and are not retained on our servers. Basis: contract (metering what you pay for).
- AI request content (transient): when you use TraxxTool AI, the text or audio of that job is forwarded to our processing providers (NanoGPT for language models, ElevenLabs for speech) and the result returned to you. We act as an intermediary and do not keep the content. Basis: contract.
- Cloud backups (optional): if you subscribe to Cloud, the library/settings snapshots you upload are stored (encrypted in transit, on EU servers) so you can restore them; the newest 20 versions are kept. The app excludes your API keys and site passwords from snapshots by design. Basis: contract.
- Server logs: standard technical logs (IP address, request path, timestamps) for security and debugging, rotated on a short schedule. Basis: legitimate interest (running a secure service).
We do not use advertising trackers or analytics cookies, we don't profile you, and we never sell personal data.
Cookies
The website sets a single strictly-necessary session cookie when you sign in (it keeps you signed in; it is not used for tracking). Because we use no optional or third-party cookies, no cookie consent banner is required.
Processors we share data with
- Google: sign-in (OAuth). Receives your sign-in event.
- Amazon SES (AWS, EU/London): sends our transactional email (sign-in codes) and, if you opt in, product-update email. Receives your email address.
- Stripe: payments and subscriptions. Receives your email and payment details.
- Hetzner (Germany/EU): server hosting, including Cloud backup storage.
- NanoGPT: LLM processing for TraxxTool AI jobs (receives the text of those jobs, transiently).
- ElevenLabs: speech processing for TraxxTool AI jobs (receives the audio/text of those jobs, transiently).
Each processor receives only what it needs. Some (Google, Stripe, NanoGPT, ElevenLabs) may process data outside the EEA; transfers rely on their standard contractual clauses / adequacy frameworks.
Retention
- Account, entitlement and ledger data: for as long as your account exists.
- Cloud snapshots: newest 20 versions; all deleted when you delete your account.
- AI request content: not retained by us at all.
- Payment/transaction records: retained by Stripe and in our accounting records for the statutory period (typically 6 to 10 years) even after account deletion.
- Server logs: short rotation (weeks, not months).
Your rights (GDPR)
You have the right of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority.
- Erasure, self-service: delete your account (and all data listed above, except legally-retained payment records) from your account page.
- Access / portability / anything else: email support@traxxtool.app. We respond within 30 days.
The desktop app
TraxxTool runs on your machine and keeps your projects, audio, API keys and site logins locally (keys in your OS credential store). The app contacts our servers only for: account sign-in/entitlements, TraxxTool AI jobs (if you use credits), Cloud backups (if subscribed), the plugin/device catalog, and version checks. Bring-your-own-key AI calls go directly from your machine to the provider you configured. They never touch our servers.
Changes
Material changes to this policy will be posted here with a new "last updated" date.