Skip to content
Mix Directive

Your information

Privacy notice

Last updated: 7 September 2026

This notice explains how Mix Directive collects and uses personal information when you visitmixdirective.com, create or use an account, join the private beta, use the Mix Directive desktop app, or contact us about the beta.

Who is responsible for your information

Mix Directive is responsible for the personal information described in this notice. Questions, privacy requests, and requests to withdraw from beta communications can be sent tohello@mixdirective.com.

Information we collect

Previous early-access applications

If you previously submitted the early-access form, we collected your name, email address, main operating-system platform, the music tool you used (if provided), what you wanted to test, and your agreement to be contacted about early access. The current account-first flow does not ask for those details again.

Accounts and sign-in

When you create or use an account, we process your email address, a Supabase user identifier, authentication status, session tokens, profile display name, connected sign-in provider names, and the stable plan status, billing interval, and renewal or end date shown on the account page. If you use email and password, Supabase Auth stores a salted password hash rather than a readable copy of your password. If you choose social sign-in, the selected provider sends Supabase the identity information needed to create or locate your account, which commonly includes your provider account identifier and email address.

Creating an account during the private beta also places the account on the beta-access list so we can show whether access is pending or accepted and contact the account address about access. This does not subscribe you to unrelated marketing.

The account page displays only your display name and connected sign-in provider names as social presentation details. We do not request your friends, posts, contacts, birthdays, or unrelated profile data. We do not request additional Google or Facebook scopes beyond the standard sign-in identity scopes.

When browser sign-in returns to the desktop app, the browser receives only an opaque, one-time code bound to a verifier held by the app. That code can be used for only two minutes, is deleted when the app redeems it, and is automatically purged after it expires. The app then stores its session in the operating system credential vault rather than in its ordinary settings files.

Desktop account and device access

To validate access and enforce the active-computer limit, the desktop app sends your account identifier, a device hash derived from a locally generated installation identifier, a bounded computer name, operating-system platform, app version and build channel, and session activity times. The device hash is not a hardware serial number. These details let the account show and revoke active installations and do not identify your songs or projects.

Payments and subscriptions

When you choose Pro, Stripe receives the account email, selected plan and billing interval, local checkout currency, billing and contact information, and payment details needed to process the subscription. Payment-card details are entered directly into Stripe’s secure checkout and are handled by Stripe; Mix Directive does not receive your full card number or security code.

Stripe returns payment and subscription status to our server so we can provide paid access and show your plan, billing interval, and renewal or end date. Stripe customer, subscription, and checkout identifiers remain server-side and are not displayed on your account page.

Messages and beta support

If you contact us, we collect your contact details and the contents of your message, including any diagnostic information or attachments you choose to send. Please do not send credentials, payment details, or unpublished creative material unless we have specifically requested it through a trusted channel.

Optional aggregate usage telemetry and issue reports

Usage telemetry is disabled by default. If you enable it, the app sends one privacy-minimised summary for the session: a random session identifier, app version, broad operating-system platform, bounded session duration, and counts of approved feature actions such as launching the app, starting playback, or opening the mixer. It does not send account or device identifiers, song titles, filenames, paths, prompts, lyrics, audio, or the properties attached to individual actions. We treat each raw summary as personal information while it is retained, even though it is not tied to your account or device.

If you choose Help → Report an Issue, we receive the summary and description you type, category, severity, optional contact email, app version and release channel, and—if you leave diagnostics enabled—your platform description, Python version, and report time. Reports do not automatically attach music, filenames, paths, lyrics, or prompts, but information you type into the description is included. The ingestion service uses a keyed hash of the request IP address to rate-limit abuse; it does not store the raw IP address in the report or telemetry row.

Technical and security information

When you use the site, Cloudflare and our server functions may process information such as your IP address, request time, requested page, browser and device information, approximate country or region, referring page, and security or bot-detection signals.

Information you need to provide

You do not have to provide personal information simply to read the public website. An email address and authentication details are required to create and maintain an account; without them, we cannot create or maintain an account, provide beta or Pro access, or recover access for you. Device and build details are required when the desktop app validates access, so the signed-in features cannot work without them. If you buy Pro, Stripe requires the billing and payment details needed to process the purchase; without those details, the subscription cannot be completed. Support messages, issue reports, and usage telemetry are optional.

How and why we use information

Manage beta access and send requested access updates

Maintain pending and accepted access status, contact account holders, issue invitations, and administer the beta.

Legal basis: your consent and steps taken at your request before providing beta access.

Create accounts, process Pro subscriptions, and provide secure access

Authenticate you, maintain sessions, confirm email addresses, show your minimal account identity and stable plan, process secure checkout, and open billing management when it applies.

Legal basis: performing our agreement with you or taking steps at your request.

Operate and secure the service

Validate desktop access, manage active computers, prevent abuse, troubleshoot faults, process issue reports, understand service reliability, and protect accounts and infrastructure.

Legal basis: our legitimate interests in running a secure and reliable service.

Optional usage telemetry

Receive the privacy-minimised session summaries described above and use anonymous daily totals to understand which features are used and how reliably the app runs.

Legal basis: your consent. You can disable it at any time in the app’s settings, which withdraws consent for future sessions. Disabling it does not affect processing that took place while it was enabled.

Respond to requests and meet legal obligations

Provide support, handle privacy requests, keep necessary records, and respond to lawful demands.

Legal basis: our legitimate interests and compliance with legal obligations.

You can ask us to stop beta-access communications at any time by emailing us. This does not affect processing that took place before your request. We do not make decisions about you that have legal or similarly significant effects using solely automated processing.

Who receives information

We use a small number of providers to operate the current site:

  • Cloudflare provides website hosting, content delivery, network security, and request logging. Read theCloudflare privacy policy.
  • Supabase stores early-access applications, account and active-device records, optional aggregate telemetry, issue reports, and two-minute desktop authorization codes, and provides the database, account authentication, session management, and account-confirmation email service used by the site and app. Read theSupabase privacy policy.
  • Social sign-in providers are used only if you choose one of the options currently enabled on the sign-in page. Google and Facebook are currently available. Their handling of information is also governed by theGoogle privacy policyandMeta privacy policy.
  • Stripe provides secure checkout, subscription payment processing, and the customer portal for Stripe-managed billing. Payment-card details are entered directly with Stripe. The site creates a short-lived checkout or portal link for the signed-in account and receives signed payment-status updates; it does not display Stripe customer, checkout, or subscription identifiers. Read theStripe privacy policy.

We may also disclose information if required by law, to protect people or the service, or as part of a business reorganisation where appropriate safeguards apply. We do not sell personal information, rent application lists, or disclose personal information for cross-context behavioural advertising.

Cookies and browser storage

The site currently uses storage that is necessary for the features you request:

  • Account cookies: secure, HTTP-only cookies hold an access token for up to one hour and a refresh token for up to 30 days. They are restricted to the site’s authentication endpoints and are cleared when you sign out.
  • Social sign-in cookie: a secure, HTTP-only verification cookie is used for up to 10 minutes to complete a social sign-in safely, then cleared.
  • Cloudflare Web Analytics: we use aggregate page visits, page views, referring sites, broad country, device, and browser categories, and page-performance measurements to understand how the website is used and performs. It does not use cookies or fingerprinting and does not give us visitor-level profiles or identifiers.

The current site does not use advertising cookies or third-party behavioural analytics. Blocking necessary storage may prevent sign-in from working.

How long we keep information

We keep personal information only while it is reasonably needed for the purpose for which it was collected, including operating the beta, providing account access, resolving support requests, securing the service, and meeting legal obligations.

  • • Previous early-access applications are kept while the beta programme is active and deleted or anonymised within 12 months after the private beta ends, unless you create an account or ask us to delete the application sooner.
  • • Account and active-device records under our direct control are kept while the account is active and deleted when you close it. Copies may remain in restricted provider backups until those backups are overwritten through the provider’s normal backup cycle.
  • • Desktop authorization codes expire after two minutes and are deleted when redeemed. Supabase access and refresh tokens held by the app follow the account-session lifetime and are removed from the device when you sign out.
  • • Raw optional usage telemetry is kept for 30 days, then deleted after its feature counts are added to daily rollups that contain no session, account, device, or request identifiers. Those anonymous totals may be kept indefinitely. Rate-limit hashes are used only for abuse control and are deleted after seven days.
  • • Issue reports and support messages are normally deleted or anonymised within 24 months after the last activity on the report or conversation. We may keep a specific record longer when it is needed for an active security investigation, dispute, or legal claim. Closing your account deletes the issue reports sent from the app under that account straight away, without waiting for that period; support messages you sent us by email are not deleted by closing your account.
  • • Operational logs under our direct control are normally kept for no more than 30 days. Logs isolated for an active security incident may be kept for up to 12 months after the incident is closed. Cloudflare and Supabase keep infrastructure and backup records according to their own limited operational schedules.
  • • Billing, transaction, tax, and accounting records may be kept for up to seven years after the relevant transaction or subscription ends where needed for tax, accounting, fraud prevention, disputes, or legal compliance. Stripe may also retain records for the periods described in its own privacy policy.

You can close your account yourself at any time from your account page. Closing an account deletes it, its sign-in methods, and its early-access record, and cancels any active subscription. It does not erase billing, security, dispute, or legal records that we or Stripe must retain for the periods described above. You may also ask us to delete an application or account information sooner. We will do so unless we need to retain specific information for a lawful reason.

International processing

Cloudflare, Supabase, Stripe, and social sign-in providers operate internationally, so personal information may be processed outside your country. Where data-protection law requires safeguards for an international transfer, we use the provider’s contractual and organisational safeguards or another legally recognised transfer mechanism. The providers’ notices linked above describe their processing locations and transfer arrangements in more detail.

Security and creative files

We use measures designed to protect information, including encrypted HTTPS connections, restrictive browser security headers, bot protection, row-level database controls, and secure HTTP-only account cookies. No online service can guarantee absolute security.

The current website has no feature for uploading songs, stems, lyrics, prompts, mixes, release masters, or project files. The desktop app processes those creative files locally unless you deliberately use a separate service or put information into an issue-report description. Your use of the website or app does not transfer ownership of creative work to Mix Directive.

Your choices and rights

Depending on where you live and the circumstances, you may have rights to ask for access to your personal information, correct it, delete it, restrict or object to its use, or receive a portable copy. You may also withdraw consent at any time and complain to your local data-protection authority. These rights can have legal limits.

To make a request, emailhello@mixdirective.com. We may need to verify that the request relates to you. If you are in the United Kingdom, you may also contact theInformation Commissioner’s Office.

Changes to this notice

We will update this page when the site’s data practices change, for example when production downloads or additional account features are introduced. Material changes will be highlighted where appropriate, and the date at the top will show when this notice was last revised.