Privacy Policy

Effective date: 2026-09-11

This Privacy Policy describes how Intrect ("we") collects, uses, and protects your personal information when you use ArtifactNet. We comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA / CPRA), and the Korean Personal Information Protection Act (PIPA).

The short version.

1. Data Controller

Intrect, contact: privacy@intrect.io

2. Information We Collect

2.1 Account information

2.2 Audio submissions

2.3 Usage logs

3. How We Use Your Information

PurposeLegal basis (GDPR Art. 6)
Provide the inference ServiceContract performance
Authenticate users and enforce quotasContract performance
Bill paid subscribersContract performance
Improve detection accuracy (non-reconstructable spectral residual and numeric features only — never raw audio, never for generative AI)Legitimate interest
Detect abuse, fraud, or security incidentsLegitimate interest
Send service notifications and security alertsLegitimate interest
Comply with legal obligations (court orders, etc.)Legal obligation

4. What we store (and don't)

We never store the original audio you submit by default — not from the demo, not from the dashboard. The uploaded waveform is processed in memory and discarded immediately after analysis completes. The single exception is a free-demo Report (§ 4.1): sending one attaches the original audio, which that form requires. Nothing is kept unless you press Report.

ArtifactNet is a detection classifier, not a generative model. Nothing you send to us is used to train music-generating AI. We do not build, license, or sell generative audio models.

4.1 Free demo (demo.intrect.io) — zero-retention

Effective 2026-04-22 the free demo operates under a zero-retention policy. What this means in practice:

DataRetentionPurpose
Original audioNever stored. Processed in memory, discarded after analysis.
Analysis result in server-side cache (spectral scores + feature vectors, no IP, no filename, no URL)1 hour. Automatically discarded after that — nothing is transferred to long-term storage.Lets you press "Report" if you believe the verdict is wrong.
Reported submissions (only when you press Report)Indefinite on object storage; retained so we can investigate the reported verdict and improve the detector.False-positive / false-negative investigation, classifier improvement.
Original audio attached to a Report (every demo Report includes it)Indefinite, same as above.Only used to reproduce and debug the reported analysis.
Shared result page (only when you press Share)Until you revoke it. Stores the verdict, its probability, the segment scores, the analysed length, and the model version — plus any track name you type in yourself. Not the audio, not your uploaded filename, not your IP.Publishes that one result at a link you can send to other people.
Client IPTransient (rate-limiter cache, minutes), then discarded. Not included in reports.Rate limiting, abuse prevention.

If you close the browser without pressing Report or Share within 1 hour, every server-side trace of your demo submission is gone.

A shared page is unlisted by default: search engines are told not to index it, and only someone who has the link can open it. You can opt a page into search indexing when you create it. When you create the link we also hand you a management token — keep it, because without an account that token is the only way to take the page down again.

4.2 Paid tiers (Creator / Pro / Enterprise)

Paid subscribers are processed under stricter retention:

DataRetention
Uploaded audioNever stored.
Spectral residualDeleted within 24 hours after analysis.
Analysis results and forensic features30 days, then deleted — not retained for model improvement.
Submission metadata (filename, URL, format, duration)30 days.
Account record, including its signup acquisition snapshotUntil you delete your account.

4.3 Usage / security logs (all tiers)

DataRetention
Usage logs (quota, billing)12 months
Security and audit logs12 months
Signed-in API request log (timestamp, endpoint, response code, account ID, IP address, browser identifier)30 days, then deleted. Free-demo requests are not written to it at all.

5. We Do NOT

5a. Requesting deletion of your submissions

You may email privacy@intrect.io at any time with a request to delete specific submissions (identify by filename, timestamp, or approximate time of use). We will remove them from active storage and any offline improvement set within 30 days. GDPR / CCPA / PIPA deletion requests are handled under the same process.

6. Third-Party Processors

ProviderPurposeRegion
Google (OAuth)AuthenticationUSA / global
Google Analytics 4Usage measurement on the website, dashboard and demo pages: page and event data, linked across intrect.io, app.intrect.io, demo.intrect.io and try.intrect.io. Analytics storage is on by default; advertising storage, ad user data and ad personalisation are denied.USA / global
GitHub (OAuth)AuthenticationUSA / global
Paddle.com Market LimitedPayment processing as our Merchant of Record. Paddle collects your billing details directly; we receive order metadata by webhook (order ID, billing email, country, Paddle customer ID), and query Paddle's API for your billing email when a webhook omits it. Your card number never reaches us.USA / EU / global
Neon (managed PostgreSQL)Hosts the application database: your account record, usage history, and credit ledger.USA (us-east-1)
Cloudflare (R2, Workers, Pages, DNS, Web Analytics)Object storage for reported demo submissions and paid-tier forensic artefacts under the retention rules in § 4; edge delivery, DNS, and bot protection for every request to this service; and cookieless page-view and performance measurement.USA / global edge
ResendOutbound transactional email: address verification, report notifications, and operational alerts.USA / global

7. International Transfers

Your data may be processed in the United States, the European Union, and the Republic of Korea. Audio you submit for analysis is processed on hardware we operate in South Korea; it is not sent to a third-party inference provider. We rely on Standard Contractual Clauses (SCC) for transfers outside the EU/EEA where applicable.

8. Your Rights

GDPR (EU/EEA users)

CCPA / CPRA (California users)

PIPA (Korean users)

To exercise any rights, email privacy@intrect.io with the subject "Data Subject Request". We respond within 30 days.

9. Security

Despite our safeguards, no system is 100% secure. If you discover a vulnerability, please report it to security@intrect.io.

10. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, contact us and we will delete it promptly.

11. Changes

We may update this Policy. Material changes will be announced via email and on the dashboard at least 14 days in advance.