Privacy Policy

Effective date: 2026-04-22

This Privacy Policy describes how Intrect ("we") collects, uses, and protects your personal information when you use ArtifactNet. We comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA / CPRA), and the Korean Personal Information Protection Act (PIPA).

The short version.

1. Data Controller

Intrect, contact: [email protected]

2. Information We Collect

2.1 Account information

2.2 Audio submissions

2.3 Usage logs

3. How We Use Your Information

PurposeLegal basis (GDPR Art. 6)
Provide the inference ServiceContract performance
Authenticate users and enforce quotasContract performance
Bill paid subscribersContract performance
Improve detection accuracy (non-reconstructable spectral residual and numeric features only — never raw audio, never for generative AI)Legitimate interest
Detect abuse, fraud, or security incidentsLegitimate interest
Send service notifications and security alertsLegitimate interest
Comply with legal obligations (court orders, etc.)Legal obligation

4. What we store (and don't)

We never store the original audio you submit by default — not from the demo, not from the dashboard, not from YouTube URLs. The uploaded waveform is processed in memory and discarded immediately after analysis completes. The single exception is the optional "include original audio" box on the free-demo Report form (§ 4.1), which requires an explicit click to take effect.

ArtifactNet is a detection classifier, not a generative model. Nothing you send to us is used to train music-generating AI. We do not build, license, or sell generative audio models.

4.1 Free demo (demo.intrect.io) — zero-retention

Effective 2026-04-22 the free demo operates under a zero-retention policy. What this means in practice:

DataRetentionPurpose
Original audio / YouTube streamNever stored. Processed in memory, discarded after analysis.
Analysis result in server-side cache (spectral scores + feature vectors, no IP, no filename, no URL)1 hour. Automatically discarded after that — nothing is transferred to long-term storage.Lets you press "Report" if you believe the verdict is wrong.
Reported submissions (only when you press Report)Indefinite on object storage; retained so we can investigate the reported verdict and improve the detector.False-positive / false-negative investigation, classifier improvement.
Original audio attached to a Report (only if you tick the optional box)Indefinite, same as above.Only used to reproduce and debug the reported analysis.
Client IPTransient (rate-limiter cache, minutes), then discarded. Not included in reports.Rate limiting, abuse prevention.

If you close the browser without pressing Report within 1 hour, every server-side trace of your demo submission is gone.

4.2 Paid tiers (Creator / Pro / Enterprise)

Paid subscribers are processed under stricter retention:

DataRetention
Uploaded audioNever stored.
Spectral residualDeleted within 24 hours after analysis.
Analysis results and forensic features30 days, then deleted — not retained for model improvement.
Submission metadata (filename, URL, format, duration)30 days.
Account recordUntil you delete your account.

4.3 Usage / security logs (all tiers)

DataRetention
Usage logs (quota, billing)12 months
Security and audit logs12 months

5. We Do NOT

5a. Requesting deletion of your submissions

You may email [email protected] at any time with a request to delete specific submissions (identify by filename, timestamp, or approximate time of use). We will remove them from active storage and any offline improvement set within 30 days. GDPR / CCPA / PIPA deletion requests are handled under the same process.

6. Third-Party Processors

ProviderPurposeRegion
Google (OAuth)AuthenticationUSA / global
RunPodGPU inference fallback (audio processed in-memory, not stored)USA
Cloudflare R2 (object storage)Stores reported demo submissions and paid-tier forensic artefacts under the retention rules in § 4.USA / global edge
Stripe (planned)Payment processing (no card data stored on our servers)USA / global

7. International Transfers

Your data may be processed in the United States or the European Union. We rely on Standard Contractual Clauses (SCC) for transfers outside the EU/EEA where applicable.

8. Your Rights

GDPR (EU/EEA users)

CCPA / CPRA (California users)

PIPA (Korean users)

To exercise any rights, email [email protected] with the subject "Data Subject Request". We respond within 30 days.

9. Security

Despite our safeguards, no system is 100% secure. If you discover a vulnerability, please report it to [email protected].

10. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, contact us and we will delete it promptly.

11. Changes

We may update this Policy. Material changes will be announced via email and on the dashboard at least 14 days in advance.