Privacy draft

Draft for owner review — not approved for publication

This describes data handling implemented in Chuck's current code for owner and legal review. It is not an approved privacy notice or legal advice and has no effective date. Configuration determines which integrations are active.

Account and session data

The app records your email, account identifiers, credit balance, account timestamps, verification and password-reset state, sessions and any per-user API key. Passwords are stored as salted PBKDF2-SHA-256 hashes, not plaintext. The browser uses a gt_session cookie for sign-in. Email verification is required before uploading, buying credits or downloading artifacts.

Track and editor data

Processing uses your uploaded audio, filename, artist and title, selected options and generated results. Retained studio data includes separated audio stems, lyrics and word timings, saved edits and appearance settings, revisions, export files, job progress and errors, and any uploaded logo or artwork.

The implementation uses Cloudflare Workers, R2 object storage for files, and D1 for account, job, editor and credit/payment metadata. Uploaded branding images are validated and re-encoded using Cloudflare Images when configured.

Configured integrations

When email delivery is configured, Resend receives the recipient email address and verification or reset message, including its link. When payment checkout is configured, Stripe receives your email, account reference and selected credit-package details and handles card entry. The app does not store card numbers or security codes; it records payment identifiers and credit-fulfillment records.

Modal integration code can dispatch job identifiers, processing options and lyric/editor state, and provide access to job audio and branding assets for processing. Remote Modal processing is not active for Chuck at this draft stage. Lyric lookup is optional and configuration-dependent; its provider and data handling must be confirmed before enablement. No processor-retention or training-use promise is made here.

File deadlines are not account deadlines

Track files have an original maximum retention window of 7 days from job creation, or 24 hours after the first actual ZIP or video download, whichever comes first. Instrumental preview does not start the download clock. Edits and exports do not extend it. Expired files are unavailable; cleanup deletes retained source, stem, output and studio objects and removes studio metadata, with retries if storage deletion fails.

Account records, job records and financial credit-charge, refund and fulfillment records are separate from temporary track files. Do not assume they are deleted within 7 days. Their retention periods, infrastructure logs and processor-held copies require owner review. Download and keep your own local backup before the track deadline.

Owner and legal review still needed

The published contact address is hello@ghost-trax.com. The request process remains subject to owner review.