Privacy Policy
Effective date: 2026-04-22
This Privacy Policy describes how Intrect ("we") collects, uses, and protects your
personal information when you use ArtifactNet. We comply with the EU General Data
Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA / CPRA),
and the Korean Personal Information Protection Act (PIPA).
The short version.
- We never store the original audio you submit, on any plan.
- ArtifactNet is a detector, not a generative model. Your submissions
are not used to train music or voice synthesis systems — ours or anyone else's.
- Free demo (demo.intrect.io): zero-retention by default.
Your analysis result is held in a 1-hour server-side cache so you can use the
Report button if you think the verdict is wrong; if you do not report
within that hour, the result is automatically discarded and nothing is kept.
- When you press Report, a non-reconstructable spectral analysis
(segment scores + forensic feature vectors) is archived under a random ID
— no IP, filename, URL, or session is included. You may optionally also
include the original audio with your report; this is only saved if you tick
that box explicitly.
- Paid subscribers (Creator / Pro / Enterprise) have their own retention rules
described below — these are separate from the demo.
- You can request deletion of any submission by emailing [email protected].
1. Data Controller
Intrect, contact: [email protected]
2. Information We Collect
2.1 Account information
- Email address (from Google OAuth or signup form)
- Display name and profile picture (Google OAuth only, optional)
- Subscription tier and billing status
- API keys (stored as bcrypt hashes)
2.2 Audio submissions
- Original audio is never stored by default. On every plan it is
decoded into memory, analysed, and discarded within the request lifetime. The
only exception is when a free-demo user presses the optional "include original
audio" box on the Report form (see § 4.1).
- For the free demo, the analysis result is held in a short-lived
(1 hour) server-side cache so the user can press "Report"; after that it is
deleted and nothing is stored. Only if the user submits a Report do we archive
the spectral analysis (no IP, no filename, no URL) under a random ID.
- For paid tiers (Creator / Pro / Enterprise), we retain the
spectral residual and analysis numbers as described in § 4.2 to deliver
forensic reports, accuracy review, and support.
- Spectral residual (STFT magnitude, no phase — cannot be converted back
into listenable audio)
- Submission metadata (filename, format, duration, file size, submitted URL):
paid tiers only. Not retained for the free demo.
- Inference results (verdict, probability, generator predictions, audio format)
and forensic features (segment-level scores, internal feature vectors): kept
under the retention rules in § 4.
2.3 Usage logs
- Per-day track count for quota enforcement (paid tiers)
- API request timestamps, endpoints accessed, response codes
- IP address: transient only — used by the rate-limiter cache (minutes) and
discarded. IP is not included in demo reports and not retained
long-term for authenticated users.
- Browser user-agent (anonymized aggregates only)
3. How We Use Your Information
| Purpose | Legal basis (GDPR Art. 6) |
| Provide the inference Service | Contract performance |
| Authenticate users and enforce quotas | Contract performance |
| Bill paid subscribers | Contract performance |
| Improve detection accuracy (non-reconstructable spectral residual and numeric features only — never raw audio, never for generative AI) | Legitimate interest |
| Detect abuse, fraud, or security incidents | Legitimate interest |
| Send service notifications and security alerts | Legitimate interest |
| Comply with legal obligations (court orders, etc.) | Legal obligation |
4. What we store (and don't)
We never store the original audio you submit by default —
not from the demo, not from the dashboard, not from YouTube URLs. The uploaded
waveform is processed in memory and discarded immediately after analysis
completes. The single exception is the optional "include original audio" box on
the free-demo Report form (§ 4.1), which requires an explicit click to take effect.
ArtifactNet is a detection classifier, not a generative model.
Nothing you send to us is used to train music-generating AI. We do not build,
license, or sell generative audio models.
4.1 Free demo (demo.intrect.io) — zero-retention
Effective 2026-04-22 the free demo operates under a zero-retention
policy. What this means in practice:
| Data | Retention | Purpose |
| Original audio / YouTube stream | Never stored. Processed in memory, discarded after analysis. | — |
| Analysis result in server-side cache (spectral scores + feature vectors, no IP, no filename, no URL) | 1 hour. Automatically discarded after that — nothing is transferred to long-term storage. | Lets you press "Report" if you believe the verdict is wrong. |
| Reported submissions (only when you press Report) | Indefinite on object storage; retained so we can investigate the reported verdict and improve the detector. | False-positive / false-negative investigation, classifier improvement. |
| Original audio attached to a Report (only if you tick the optional box) | Indefinite, same as above. | Only used to reproduce and debug the reported analysis. |
| Client IP | Transient (rate-limiter cache, minutes), then discarded. Not included in reports. | Rate limiting, abuse prevention. |
If you close the browser without pressing Report within 1 hour, every
server-side trace of your demo submission is gone.
4.2 Paid tiers (Creator / Pro / Enterprise)
Paid subscribers are processed under stricter retention:
| Data | Retention |
| Uploaded audio | Never stored. |
| Spectral residual | Deleted within 24 hours after analysis. |
| Analysis results and forensic features | 30 days, then deleted — not retained for model improvement. |
| Submission metadata (filename, URL, format, duration) | 30 days. |
| Account record | Until you delete your account. |
4.3 Usage / security logs (all tiers)
| Data | Retention |
| Usage logs (quota, billing) | 12 months |
| Security and audit logs | 12 months |
5. We Do NOT
- Store the original audio you submit by default. The only exception is the
optional "include original audio" box on the free-demo Report form, which
requires an explicit click and is not enabled unless you tick it.
- Train generative music or voice models. ArtifactNet is a detector; your
submissions never feed a synthesis system, ours or anyone else's.
- Sell, rent, or otherwise monetize your submissions or personal information.
- Share your data with advertisers or marketing platforms.
- Publish, redistribute, or make your audio publicly accessible.
- Use identifying metadata (filename, URL) when improving the classifier —
only the numeric residual / feature vectors are used.
5a. Requesting deletion of your submissions
You may email [email protected]
at any time with a request to delete specific submissions (identify by filename,
timestamp, or approximate time of use). We will remove them from active storage
and any offline improvement set within 30 days. GDPR / CCPA / PIPA deletion
requests are handled under the same process.
6. Third-Party Processors
| Provider | Purpose | Region |
| Google (OAuth) | Authentication | USA / global |
| RunPod | GPU inference fallback (audio processed in-memory, not stored) | USA |
| Cloudflare R2 (object storage) | Stores reported demo submissions and paid-tier forensic artefacts under the retention rules in § 4. | USA / global edge |
| Stripe (planned) | Payment processing (no card data stored on our servers) | USA / global |
7. International Transfers
Your data may be processed in the United States or the European Union. We rely
on Standard Contractual Clauses (SCC) for transfers outside the EU/EEA where applicable.
8. Your Rights
GDPR (EU/EEA users)
- Right of access: request a copy of your personal data
- Right to rectification: correct inaccurate data
- Right to erasure ("right to be forgotten"): delete your account and data
- Right to restrict processing
- Right to data portability: export your data in JSON format
- Right to object to processing based on legitimate interest
- Right to lodge a complaint with your local supervisory authority
CCPA / CPRA (California users)
- Right to know what personal information is collected
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt-out of sale (we do not sell personal information)
- Right to non-discrimination for exercising these rights
PIPA (Korean users)
- 개인정보 열람권, 정정·삭제 요구권, 처리정지 요구권
- 가명처리·익명처리 요구권
To exercise any rights, email [email protected]
with the subject "Data Subject Request". We respond within 30 days.
9. Security
- All API traffic is served over HTTPS / TLS 1.3
- Passwords are hashed with bcrypt (cost factor 12)
- API keys are stored as bcrypt hashes; only the prefix is recoverable for display
- JWT tokens use HS256 with rotating secrets in production environments
- Audio files are processed in sandboxed ffmpeg subprocesses with strict timeouts
- Database backups are encrypted at rest
Despite our safeguards, no system is 100% secure. If you discover a vulnerability,
please report it to [email protected].
10. Children
The Service is not directed to children under 16. We do not knowingly collect
personal information from children. If you believe we have collected data from a
child, contact us and we will delete it promptly.
11. Changes
We may update this Policy. Material changes will be announced via email and
on the dashboard at least 14 days in advance.