Skip to the audio tools

Audio Studio Privacy Policy

How the Audio Studio local testing draft handles accounts, uploaded audio, processing providers, and result access.
Oct 4, 2026

Draft status and scope

Local testing draft — not finalized for public launch. Last draft update: October 4, 2026.

Audio Studio is the working name of an audio separation product. This notice describes the current local testing workflow. The operator's legal identity, contact details, retention schedule, and third-party data arrangements must be completed before public launch. This update date is not a public launch effective date.

  • Service operator: To be provided.
  • Privacy contact email: To be provided.

Information used by the service

The information used depends on the features you use and which integrations are enabled:

  • Account and sign-in information: Name, email address, verification status, avatar if supplied, and account timestamps. Authentication may also handle login credentials, session records, authentication cookies, IP addresses, and browser information to sign you in and protect your account.
  • Registration and technical information: The service may record an IP address, language, referral or campaign source, and technical logs needed to operate the service, diagnose failures, and address abuse.
  • Uploaded audio and results: Audio you explicitly submit for processing, including audio extracted locally from a video, its filename, size and file type, and the separated tracks produced from it. Audio can contain personal information about you or other people.
  • Task records: Your account association, file metadata, processing status, the processing provider's task identifier, result storage references, and relevant timestamps. These records support ownership checks, progress reporting, and access to results.

Only submit recordings you are entitled to share. Avoid uploading confidential recordings or sensitive personal information during local testing while the retention and provider arrangements are still being finalized.

Local preview and submitted processing

Selecting a file creates a preview in your browser; selection alone does not upload it. For video music removal, the browser extracts an MP3 audio file locally after you explicitly start processing. Only that extracted audio is uploaded for separation. The original video is never uploaded by this workflow.

When you sign in and explicitly start an available audio processing task, the audio is uploaded to storage configured as a private Cloudflare R2 bucket. The server sends a temporary signed link to Replicate to run the Demucs audio separation model. The resulting vocal, drum, bass, and other tracks are then copied to the service's R2 storage for playback and download.

Cloudflare and Replicate receive the data needed for their respective storage and processing roles. Their own systems may also handle service logs and related technical information. Their retention practices, any model-related data use, processing locations, and applicable contractual safeguards still require verification before public launch. This draft does not promise that those providers never retain data or use it for model improvement.

The optional instrumental download is mixed in your browser from the drum, bass, and other result tracks. It downloads those tracks but does not submit another model processing task.

For a video result, the browser downloads the separated vocal track and combines it with the original picture to create a local video file for download. The exported video is not uploaded or saved on the service. Local video processing loads a component of about 8 MB when first used. Server audio processing, including separation of audio extracted from videos, remains disabled by default and is available only when explicitly enabled for local development testing; it is not available in production.

Cookies and browser storage

Authentication cookies support sign-in and sessions. The workspace also uses browser session storage to keep an account-scoped task identifier so that you can resume checking a task. That identifier is not the audio file or a signed download link.

Local media previews, downloaded tracks, and video exports may occupy browser memory while you use the workspace. Within the same page, the workspace retains an account-scoped association between an original video, its extracted audio, and its task so that recovery uses the correct source. The video files and this association are not persisted in browser storage. A full page reload cannot recover the original video or a local export; a saved audio task can still be checked by its signed-in owner. Download local exports before leaving the page. Releasing a preview, selecting another file, or closing the page does not delete files already uploaded to the server or a processing provider.

This draft does not assume that optional advertising, analytics, or additional sign-in integrations are enabled. Any such integrations and required choices must be disclosed according to the actual launch configuration.

Access expiry and data retention

A completed audio result is available through the service for 24 hours. This is an access period, not a promise that files are physically deleted after 24 hours. Individual playback and download links last up to 15 minutes and may expire sooner near the end of the result access period. During that period, the signed-in owner can request fresh links.

The testing service now includes a media cleanup routine. Inputs, including uploads never submitted for processing, become eligible for cleanup 24 hours after upload. Completed result files become eligible when their 24-hour access period ends. Partial results from failed, cancelled, or timed-out tasks have a separate conservative waiting period of at least 24 hours after the last possible save window. Only the service's audio files in its dedicated R2 bucket are within this routine's scope.

The routine defaults to a preview that does not delete files. Actual deletion requires explicit activation and a running scheduler, which have not been enabled as part of this local change. Deletion occurs when a cleanup run succeeds; failed deletions remain eligible for retry. This does not delete Replicate-held copies, backups, or files you downloaded. Task records are retained to prevent duplicate submissions and enforce trial limits, and self-service account and audio deletion is not yet available.

The finalized retention and deletion arrangements, including task records, account data, logs, backups, and provider-held copies, are to be provided before public launch. Expiring a link does not establish that a stored copy has been deleted.

Access controls and disclosure

The audio workflow checks task ownership and uses private storage and temporary signed links to limit access. Anyone who receives a valid signed link may be able to open it until it expires, so treat those links as private. These controls do not guarantee absolute security.

Data is provided to the storage and processing services described above as needed to deliver the requested feature. Other disclosures may be necessary to comply with applicable law or respond to a legitimate security incident. Any additional recipients and contractual arrangements must be reflected in the finalized notice.

Payments and future features

The current local audio separation trial does not charge the user or deduct credits for a separation task. It does not require payment card details to submit that task. If commercial billing or other features are introduced, the payment providers, information handled, and relevant terms must be disclosed before use. This statement describes the audio trial, not every billing capability present in the project.

Your requests and contact details

Depending on applicable law, you may have rights to request access, correction, deletion, or other controls over your personal information. The operator, working privacy contact, and request procedure are to be provided. This local draft does not offer an active public privacy request channel or guarantee immediate deletion from all storage, backups, or third-party systems.

This notice must be updated as the service, enabled integrations, and data arrangements change. The finalized notice will identify its effective date and explain any required notifications or choices for material changes.

See the Terms of Service for the current service scope and use restrictions.