Privacy Policy
Last updated August 12, 2026
This policy explains what Arixova collects, why, and the control you have over it. The short version: your music files never leave your device, we store only the data the service needs to work, and you can export or delete everything yourself from Account → Privacy & Data.
1. What we collect
- Account data — email address, plan, and authentication state (managed by Supabase Auth).
- Library metadata — track titles, artists, and analysis results (BPM, key, energy, structure) that you import or generate.
- Your work — set briefs, generated set plans, cue maps, edits, templates, venue notes, and performance history you choose to save.
- Billing data — handled by Stripe; we store your plan status and Stripe customer ID, never your card number.
- Usage data — aggregate feature usage and AI token consumption used to enforce plan limits and keep the service reliable.
2. What we never collect
- Audio files. BPM/key/structure analysis runs locally in your browser with on-device technology. Audio is analyzed on your device and is never uploaded to our servers.
- Payment card numbers. All card data goes directly to Stripe, PCI-compliant by design.
- Data for advertising. We do not sell, rent, or share your personal data with advertisers. There are no third-party ad trackers in the product.
3. How we use data
- Provide the service: generate set plans, store your sets, sync across your devices.
- Personalize: adapt future plans to your library, venues, and crowd-response history (only within your account).
- Operate: enforce plan limits, prevent abuse, debug failures, and meter AI usage costs.
4. AI processing
Set generation sends your brief, relevant library metadata, and research context to the large-language-model providers that power the Architect. We minimize what is sent to what each request needs, and we do not include your email or account identifiers in generation prompts. LLM providers process this data per their own API terms and do not use it to train public models.
5. Sub-processors
- Supabase — database and authentication (data stored in their US region).
- Stripe — payments and subscription management.
- Vercel — application hosting and delivery.
- LLM API providers — set-plan generation, as described above.
6. Retention
We keep your data while your account is active. Database backups are retained for 7 days for disaster recovery, then rotated out. When you delete your account, your data is removed from the live system immediately and from backups within that rotation window.
7. Your rights and controls
From Account → Privacy & Data you can, at any time:
- Export a copy of your data (JSON).
- Clear personalization — reset learned preferences without losing saved sets.
- Delete your account — removes your data from the live system.
If you are in the EEA/UK (GDPR) or California (CCPA), these self-serve tools cover the access, portability, and deletion rights those laws provide; you can also email support@arixova.app for any privacy request.
8. Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted to operational need. No method is 100% secure, but we design for the worst case: least-privilege access, per-account data isolation, and audit-logged admin actions.
9. Children
Arixova is not directed at children under 18, and we do not knowingly collect their data.
10. Changes and contact
We will post any changes here and update the date above; material changes will be announced in-app or by email. Privacy questions or requests: support@arixova.app.