Privacy Policy
Effective date: September 9, 2026
In short: We collect what we need to run Tonamorph: your email and a hashed password (held by our authentication provider), the audio clip you choose to process, the stems and MIDI we generate, a record of your credits and purchases, and technical logs. Your audio and results are deleted from our servers 24 hours after upload. We never train AI models on your audio. Payment card details go to Paddle, never to us. We send marketing email only if you opt in, and crash reports only if you opt in. You can ask us to access, correct, export or delete your data at support@tonamorph.com. We are based in Israel and use service providers in the EU and the United States under approved transfer safeguards.
1. Who is responsible for your data
1.1 The data controller (in Israel, the "database owner") is Tonamorph Audio, a sole proprietorship registered in Israel under number , ("we", "us").
1.2 Privacy contact: support@tonamorph.com. Postal address: .
1.3 We have not appointed a Data Protection Officer because we are a small business whose core activity does not involve large-scale monitoring or special-category data.
1.4 Paddle is a separate, independent controller of the personal data you give it at checkout (name, billing address, payment details, tax data). Its privacy policy governs that data. We receive from it only what we describe in section 3.
2. Scope
This policy covers the Tonamorph plugin, the website at https://tonamorph.com, the API and our support channels. It does not cover third-party websites or services we link to, or the digital audio workstation in which you run the plugin.
3. What data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Email address; password (stored only as a salted hash by our authentication provider — we never see it); optional display name; user ID; plan type; account creation and update times | You, at sign-up and in account settings |
| Audio you upload ("Input") | The audio clip you choose to process (up to 10 MB; only the first 60 seconds are processed), encoded by the plugin before upload | You, when you press "process" in the plugin or call the API |
| Generated results ("Output") | Separated stems (bass, drums, other, vocals), a MIDI file, and analysis data (tempo, key, note statistics, suggested envelope settings) | Generated by our processing pipeline |
| Job metadata | Job ID, status and stage, timestamps, processing options you chose, technical metadata about the Input (duration, sample rate, channels, whether it was truncated), result metadata (stem names, tempo, key), error codes | Generated by our systems |
| Credit ledger | Every grant, reservation, capture, release, refund, expiry and adjustment of credits, with a timestamp, the job it relates to and its source (for example an order number) | Generated by our systems |
| Purchase and subscription records | Plan bought, amount and currency, net amount after fees, the merchant of record's order and subscription IDs, subscription status and renewal date, any referral code used, and the raw payment-confirmation event from Paddle (which may contain your name and email as given at checkout) | Paddle |
| API keys | A hash of each key, its first characters (for display), the name you gave it, creation and last-use times | You, when you create a key |
| Referral and affiliate data | Your referral code, how often it was used, commissions earned, and — for approved affiliates — payout details you give us | You, and generated by our systems |
| Technical and log data | IP address, request ID, route, HTTP status, timestamps, your user ID and job ID, plugin name and version (sent as the user-agent), and standard web-server logs for the website | Your device, automatically |
| Crash and diagnostic reports (only if you opt in) | Stack traces, plugin and operating-system versions, DAW name and version, device model; never audio | Your device, only after you enable crash reporting |
| Marketing data (only if you opt in) | Email address, consent record, and whether you open or click our emails | You, when you subscribe; our email provider |
| Support communications | What you write to us, and the metadata of your messages | You |
| Website cookies and similar | See the Cookie Policy (/legal/cookies) | Your browser |
We do not collect: payment card or bank details; precise location; contacts; the contents of your DAW project; any audio other than the clip you choose to process. Please do not upload audio that contains sensitive personal information (for example recordings of medical or legal conversations); the Service is designed for music.
4. Why we use your data and on what legal basis
| Purpose | Data used | Legal basis (GDPR / UK GDPR Art. 6) |
|---|---|---|
| Creating and managing your account, signing you in, sending service emails (for example password resets, receipts, notice of changes) | Account data, technical data | Contract (Art. 6(1)(b)) |
| Processing the audio you submit and returning stems, MIDI and analysis | Input, Output, job metadata | Contract (Art. 6(1)(b)) |
| Charging for the Service: reserving, capturing and granting credits, applying purchases and renewals | Credit ledger, purchase records | Contract (Art. 6(1)(b)) |
| Running the referral and affiliate programmes and paying commissions | Referral and affiliate data, purchase records | Contract (Art. 6(1)(b)) |
| Keeping the Service secure: authentication, rate limiting, abuse and fraud prevention, detecting misuse of API keys, protecting against credential attacks | Technical and log data, API keys, account data | Legitimate interests (Art. 6(1)(f)) — keeping the Service and other users safe |
| Improving reliability and fixing bugs | Job metadata, crash reports (opt-in) | Consent (Art. 6(1)(a)) for crash reports; legitimate interests for aggregated job metadata |
| Accounting, tax and legal record-keeping | Purchase records, credit ledger | Legal obligation (Art. 6(1)(c)) |
| Marketing email about Tonamorph | Marketing data | Consent (Art. 6(1)(a)); you can withdraw at any time |
| Responding to your requests and complaints | Support communications | Contract and legitimate interests |
| Establishing, exercising or defending legal claims; complying with lawful requests from authorities | Whatever is relevant | Legitimate interests and legal obligation |
We do not use your data for automated decisions that produce legal or similarly significant effects on you. The AI processing of your audio is automated, but its only effect is to give you the result you asked for.
5. How long we keep data
| Data | Retention | Why |
|---|---|---|
| Input audio and Output (stems, MIDI) | Deleted 24 hours after upload by an automatic storage rule. The download links expire at the same time. | You keep the copy the plugin downloaded; we do not need the files after delivery |
| Job metadata (IDs, timestamps, options, tempo, key, error codes, result metadata) | For as long as you have an account, then deleted with it (subject to the row below) | Shows your job history and supports billing disputes |
| Credit ledger, purchase and subscription records, raw payment-confirmation events | Retained for the life of your account and for 7 years after the transaction | Accounting and tax law require us to keep transaction records |
| Account data | Until you delete your account, plus up to 30 days for backups to cycle | Providing the Service |
| API key hashes | Until you revoke the key or delete your account | Authentication |
| Technical and application logs (including IP addresses) | 14 days | Security and troubleshooting; short by design |
| Crash reports (opt-in) | 90 days | Bug fixing |
| Marketing data | Until you unsubscribe or withdraw consent; a suppression record of your withdrawal is kept so we do not email you again | Respecting your choice |
| Support communications | 2 years after the last message | Continuity of support and evidence in case of dispute |
| Referral and affiliate records | As purchase records above | Commission accounting |
When you delete your account, we delete or anonymise everything except the records we must keep by law.
6. Who we share data with
We do not sell your personal data and we do not share it with anyone for their own marketing. We share it only with the service providers below, who act on our instructions as processors (unless stated otherwise), and in the situations in section 6.2.
6.1 Sub-processors
| Provider | What it does for us | Data it handles | Location |
|---|---|---|---|
| Supabase, Inc. | Authentication, database, and (depending on deployment) file storage | Account data, job metadata, credit ledger, purchase records, API key hashes, referral data; Input and Output when Supabase Storage is used | EU or United States — see note below |
| Amazon Web Services, Inc. | Object storage for uploads and results, queueing, hosting of the API and GPU workers, logs | Input, Output, job metadata, technical logs | United States (primary region) and/or EU |
| Modal Labs, Inc. | Serverless GPU processing of audio | Input, Output (transiently, during a job) | United States |
| RunPod, Inc. | Serverless GPU processing of audio | Input, Output (transiently, during a job) | United States and EU data centres |
| Vercel, Inc. | Website hosting and cookieless web analytics | Website request data (IP address processed transiently, anonymised analytics) | United States |
| Paddle | Seller of record: checkout, payment, tax, invoicing, refunds (independent controller) | Name, email, billing details, payment data, order history | See its own privacy policy |
| Klaviyo, Inc. | Marketing email (only if you opt in) | Email address, consent record, email engagement | United States |
| Sentry (Functional Software, Inc.) — planned | Crash and error reporting (only if you opt in) | Crash reports | United States (EU region available) |
We keep the current list at https://tonamorph.com/legal/privacy and will update it before adding a provider that handles your personal data.
6.2 Other disclosures
We may disclose personal data: to our professional advisers (accountant, lawyers) under confidentiality; to a buyer or successor if our business is sold or transferred (we will tell you); to comply with a legal obligation, court order or lawful request from a public authority; to enforce our Terms or protect the rights, property or safety of us, our users or others; and with your consent.
7. International transfers
7.1 We are established in Israel. The European Commission and the UK government have each decided that Israel provides an adequate level of data protection, so transfers of your data from the EEA and the UK to us in Israel do not need additional safeguards.
7.2 Our providers process data in the United States and in the EU. For transfers from the EEA/UK to the US we rely on the EU–US Data Privacy Framework (and its UK Extension) where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum), together with supplementary measures where needed. You can ask support@tonamorph.com for a copy of the relevant safeguards.
7.3 Transfers of data from Israel abroad are made in accordance with the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations 5761-2001, on the basis that the recipient country provides adequate protection or that the recipient has undertaken in writing to apply the Israeli data-protection conditions.
8. Your rights
8.1 Under the GDPR and UK GDPR (and similar laws elsewhere) you have the right to: access the personal data we hold about you; have it corrected; have it deleted ("right to be forgotten"); restrict its processing; object to processing based on our legitimate interests, including at any time to direct marketing; receive a copy in a portable format; and withdraw consent at any time (this does not affect processing already done). You also have the right not to be subject to solely automated decisions with legal or similarly significant effects; we make none.
8.2 How to exercise them. Email support@tonamorph.com from the address on your account, or use the options in your account settings (where available). We may ask you to confirm your identity. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need longer. Requests are free unless they are manifestly unfounded or excessive.
8.3 Complaints. You can complain to a supervisory authority: in the EEA, the authority of the member state where you live or work (list at edpb.europa.eu); in the UK, the Information Commissioner's Office (ico.org.uk); in Israel, the Privacy Protection Authority (gov.il/en/departments/the_privacy_protection_authority). We would appreciate the chance to address your concern first.
9. Notice under the Israeli Protection of Privacy Law
This section is the notice required by section 11 of the Protection of Privacy Law 5741-1981, as amended by Amendment 13 (in force from 14 August 2025), to everyone from whom we collect personal data.
9.1 Duty to provide data. You are not legally required to give us any personal data. However, without an email address and password we cannot create an account, and without the audio you choose to upload we cannot process it. Marketing email and crash reporting are optional.
9.2 Purposes. The data is collected and held for the purposes listed in section 4: operating the account and the Service, billing, security and abuse prevention, accounting, support, and — only with your consent — marketing and crash reporting.
9.3 Recipients. The data will be delivered to the providers listed in section 6.1 (for the purposes stated there) and disclosed in the situations in section 6.2, and to no one else.
9.4 Your rights. You have the right to inspect the data held about you in our database (section 13 of the Law) and to request that incorrect, incomplete or outdated data be corrected or deleted (section 14). Requests: support@tonamorph.com.
9.5 Database owner and holder. The database owner is Tonamorph Audio, . Our providers in section 6.1 hold data on our behalf.
9.6 Direct mailing. If we ever use your data for direct mailing within the meaning of section 17C of the Law, each message will identify us and tell you how to have your data removed from the mailing list. You can request removal at any time at support@tonamorph.com.
10. United Kingdom
If you are in the UK, the UK GDPR and the Data Protection Act 2018 apply to our processing of your data. Your rights are as set out in section 8 and you may complain to the Information Commissioner's Office. Transfers to us in Israel are covered by the UK's adequacy regulations; onward transfers to the US are covered by the UK Extension to the Data Privacy Framework or the UK International Data Transfer Addendum, as stated in section 7.
11. California and other US states
If you are a California resident, this section supplements the rest of this policy in line with the California Consumer Privacy Act as amended by the CPRA ("CCPA"). Residents of other US states with comprehensive privacy laws have similar rights.
11.1 Categories collected in the last 12 months: identifiers (email, user ID, IP address); commercial information (purchases, credits, subscription); internet or network activity (logs, plugin version); audio information (the clips you upload and the results); and, if you opt in, electronic diagnostic data. Sources and purposes are in sections 3 and 4.
11.2 Disclosure. We disclose these categories to the service providers in section 6.1 for business purposes only. We do not sell personal information and we do not share it for cross-context behavioural advertising. We have no actual knowledge that we sell or share the personal information of consumers under 16.
11.3 Sensitive personal information. We do not collect account log-in credentials in a form we can read, and we do not use or disclose sensitive personal information for purposes other than providing the Service.
11.4 Your rights. You may request to know what personal information we have collected, used and disclosed; to delete it; to correct it; and to limit the use of sensitive personal information (not applicable, see 11.3). We will not discriminate against you for exercising these rights. Submit requests to support@tonamorph.com or through your account. An authorised agent may submit a request with your written permission; we will verify the request by asking you to confirm from the email address on your account.
11.5 We honour Global Privacy Control signals from your browser as an opt-out of any sale or sharing, even though we make none.
12. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child under 16 has created an account, contact support@tonamorph.com and we will delete the account and its data.
13. Cookies and local storage
The website uses a small number of cookies: strictly necessary session cookies set by our authentication provider, and — only after you opt in — analytics and marketing technologies. Our web analytics are cookieless. Full details, including how to withdraw consent, are in the Cookie Policy (/legal/cookies). The plugin does not use cookies; it stores your session tokens and cached results in a settings folder on your computer (see the EULA at /legal/eula).
14. Security
We protect your data with measures appropriate to the risk, including:
- all traffic between the plugin, the website, the API and our providers is encrypted in transit (TLS); data is encrypted at rest by our storage and database providers;
- passwords are never stored by us; our authentication provider stores only salted hashes; API keys are stored only as SHA-256 hashes, and the full key is shown once;
- uploads and results live in private storage that is not publicly accessible; the plugin retrieves them through single-use, time-limited signed links, and an automatic rule deletes them after 24 hours;
- every database row is protected by row-level access controls so that one user cannot read another user's data, and privileged operations run only on our servers under secrets held in a secrets manager;
- rate limiting on sign-in and job submission, signature verification of every payment notification, and validation of every upload before it is processed;
- our logs never contain passwords, tokens, API keys, payment data or audio;
- access to production systems is limited to the people who need it.
No system is perfectly secure. Please use a strong, unique password and keep your API keys private. The plugin stores your session tokens in a settings file in your user profile protected by your operating system's file permissions; anyone with full access to your computer account could read it.
15. Data breaches
If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33 / UK GDPR), report serious security incidents to the Israeli Privacy Protection Authority as required by the Data Security Regulations, and, where the breach is likely to result in a high risk to you, tell you directly without undue delay, explaining what happened and what you can do.
16. Marketing communications
We send marketing email only if you have opted in (for example by ticking a box at sign-up or on the website). Every marketing email has an unsubscribe link, and you can also withdraw consent at support@tonamorph.com. We will still send service emails that are necessary to run your account (receipts, security notices, changes to these documents); you cannot opt out of those while you have an account.
17. Changes to this policy
We may update this policy. If the change is material, we will notify you by email or through a prominent notice in the plugin or on the website at least 14 days before it takes effect. The effective date at the top shows when it was last changed.
18. Contact
Tonamorph Audio
Registration number: Privacy requests: support@tonamorph.com General support: support@tonamorph.com Website: https://tonamorph.com