PULSATRAX
FeedAboutDiscoverCreatorsMusicPULSATRAX VisualizerChartsSmart MatchCollaborateRemix ChallengesPreset LibraryEventsGamesForumLoginRegister
AboutCreatorsFAQRulesCreator GuidelinesSafetySupportTermsPrivacyDelete AccountCopyrightCookies
FeedDiscoverMusicVisualsStudioLogin
Privacy Policy

How PULSATRAX Handles Data

We collect and use data needed to operate accounts, music tools, safety systems, and the community. This policy explains what that includes.

Last updated: August 9, 2026

On this page Controller What we collect Purposes and legal bases Uploads and DAW Microphone Cookies Safety logs Third parties Current providers Retention AI content Your rights

Controller and contact details

PULSATRAX is operated by Mario Rämman, an individual based in Finland. Mario Rämman is the data controller for personal data processed through PULSATRAX.

  • Privacy requests: [email protected]
  • General support and public contact: [email protected]

Account and profile data

We may collect account details such as username, display name, email address, password hash, verification state, profile information, avatar or profile media, social links, settings, security preferences, and account status.

Some data comes directly from you. Device, browser, IP-related, session, and usage signals are generated when you use the service, and reports or collaboration activity may provide information from other users.

Public profile information, posts, events, comments, forum activity, charts, and selected uploads may be visible to other users or visitors depending on the feature.

Purposes and legal bases

  • Contract and requested service: creating and operating accounts, profiles, messages, uploads, collaboration tools, Studio projects, and optional tools you deliberately ask to run.
  • Legitimate interests: securing the platform, preventing fraud and abuse, moderating content, maintaining reliability, and understanding technical failures. These interests are balanced against user rights.
  • Consent: optional external media and advertising technologies where consent is required. Consent can be withdrawn at any time in Cookie settings.
  • Legal obligations and claims: responding to lawful requests, copyright matters, disputes, and preserving information where the law requires it.

Uploads and posts

We store content you upload or create, including tracks, images, posts, comments, messages, events, reports, profile intro tracks, stories, and forum content.

PULSATRAX Studio projects

Studio projects, loop metadata, user-uploaded loops, saved project JSON, names, timestamps, and related settings may be stored so the DAW can reopen and manage your work.

Recorded vocals and microphone permission

PULSATRAX Studio voice recording relies on a technical permission controlled by your browser or device. Granting that device permission is not treated as consent to unrelated personal-data processing.

Microphone audio stays in the recording workflow unless you deliberately save or upload the result. A saved recording may be stored as a user audio asset, included in a Studio project, and processed for playback as part of the service you requested. You can refuse or revoke the device permission in your browser, although recording will then be unavailable.

Cookies and sessions

PULSATRAX uses essential cookies or session storage for login, CSRF protection, account security, preferences, and keeping the app working. See the Cookie Policy.

Advertising services

Advertising is not currently active for visitors. If PULSATRAX enables Google AdSense or another advertising provider later, its optional scripts will remain blocked until you consent. Advertising services are separate from core account features.

Analytics

PULSATRAX does not currently use a separate visitor analytics service such as Google Analytics. Technical and security logs needed to operate and protect the service are not used as optional advertising analytics. If a separate analytics service is introduced, this policy and the consent controls will be updated before it is used where consent is required.

Moderation, security, and abuse logs

We may store reports, moderation decisions, rate-limit events, login/session signals, blocked words, admin actions, IP-related security records where available, device or browser signals, and other logs needed to detect spam, scams, abuse, copyright issues, or attacks.

Direct messages are intended to be private between users, but may be reviewed when reported or when needed to investigate abuse, safety, legal, or security issues.

Recipients, providers, and external services

Posts or profiles may include links or embeds from services such as YouTube. External media is blocked until you allow it in Cookie settings; the external service may then process device, browser, cookie, and interaction data under its own policy.

Hosting, email delivery, push notification, anti-abuse, and infrastructure providers may process limited data on behalf of PULSATRAX where needed to operate the service. Data is also shared when you choose to publish it, when collaboration or messaging requires another user to receive it, or when disclosure is legally required.

If a provider processes data outside Finland or the European Economic Area, PULSATRAX will use an available lawful transfer mechanism where required.

Current service providers

The following provider categories are currently used. A provider receives only the information needed for its role or information you deliberately send to it.

  • Cloudflare: DNS, content delivery, availability, and network security. Cloudflare can process request details such as IP address, browser and device headers, requested URL, timing, and security signals. See Cloudflare's Privacy Policy.
  • Zoho Mail: transactional email and support delivery. Email address, recipient name, message content, and delivery metadata may be processed. See Zoho's Privacy Policy.
  • Google: optional Google sign-in processes an account identifier, verified email, display name, and profile picture URL when you choose to link Google. Google may also provide Web Push delivery and optional YouTube media. See Google's Privacy Policy.
  • OpenAI: when you submit a Studio Coach question and GPT support is available, PULSATRAX sends the question and a compact project summary such as BPM, genre, arrangement observations, loop metadata, and preference signals to the OpenAI API. Audio and project files are not sent. API requests are marked not to store response application state, but OpenAI may retain limited abuse-monitoring data under its business service terms. See OpenAI's business data information.
  • LRCLIB and Hugging Face: if you deliberately search the Visualizer lyrics catalog, your title and artist query is sent directly to LRCLIB. If you start local vocal separation, your browser downloads the model from Hugging Face; the audio itself stays in your browser. Those providers receive ordinary network request details such as your IP address and browser headers. See the LRCLIB service and Hugging Face's Privacy Policy.
  • Browser push providers: when you enable notifications, the browser-selected provider may be Apple, Google, Microsoft, Mozilla, or another browser push service. PULSATRAX sends the push endpoint, encryption keys, and notification payload needed for delivery.
  • Server hosting and storage: the hosting environment stores the PULSATRAX database, uploaded files, private media, logs, and routine backups under access controls.

Apple and Google native push integrations exist in the application code but are not currently configured for production native-device delivery. PULSATRAX will update this section when that changes.

Data retention

  • Account, profile, Studio, upload, and communication data is generally kept while the account is active or until you delete it.
  • Account deletion removes account credentials and personal security data. Shared posts, conversations, collaboration history, and moderation context may remain in anonymized form where needed for other users, platform integrity, or legal claims.
  • Session and trusted-device data lasts until expiry, revocation, logout, or account deletion. An installed Android app session and a trusted-device cookie can each last up to 30 days; the security device identifier can last up to one year.
  • Short-lived rate-limit records are normally removed after a matter of hours. Stories are visible for 24 hours and may remain in cleanup processing for up to a further 48 hours.
  • Studio Coach daily quota counters are removed after no more than 90 days. PULSATRAX does not store the Coach question or answer in that quota table.
  • Security and moderation records are kept only as long as reasonably needed to investigate abuse, enforce rules, protect users, resolve disputes, or meet legal duties.
  • Routine backups are normally retained for up to 14 days. Deleted data may remain in an encrypted or access-controlled backup until that backup expires.
  • Your cookie-consent choice is stored for up to six months, after which PULSATRAX asks again.

AI-generated or assisted content

Users may create or upload AI-assisted music, artwork, text, or profile content. PULSATRAX may store and display that content like other user-generated content. Users are responsible for making sure AI-assisted content does not violate rights, impersonate people deceptively, or mislead collaborators and listeners.

Studio Coach is an optional advice tool. When GPT support is used, the submitted question and compact project metadata are sent to OpenAI as described above. Do not put personal, confidential, or special-category information in a Coach question. Coach does not make legal or similarly significant decisions about users.

How data is used

Data is used to operate accounts, show content, power PULSATRAX Studio, deliver notifications, support messages, handle reports, protect the platform, enforce rules, debug issues, and maintain reliability and performance.

An email address, username, and login credentials are needed to create and secure an account. Most profile details and public uploads are optional, but a feature cannot work if you do not provide the data it specifically needs. PULSATRAX does not currently make solely automated decisions that produce legal or similarly significant effects for users.

User rights and contact

Subject to applicable law, you may request access to your data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw consent without affecting earlier lawful processing.

You can delete your account from Profile settings. Step-by-step instructions and an email request path for people who cannot sign in are available on the Account Deletion page. To request a copy of your data or exercise another privacy right, contact [email protected]. Data copies are currently handled by verified email request rather than an automatic download tool. PULSATRAX may need to verify your identity before fulfilling a request.

Because the controller is based in Finland, you may also lodge a complaint with the Office of the Data Protection Ombudsman of Finland. For broader support or moderation issues, use Contact / Support.

AboutCreatorsFAQRulesCreator GuidelinesSafetySupportTermsPrivacyDelete AccountCopyrightCookies
Your privacy choices

Essential cookies keep PULSATRAX secure and working. External media and future advertising stay off unless you allow them.

Read the Cookie Policy
Privacy controlsCookie settings
Essential

Login, security, language, and your saved consent choice.

Always on

PULSATRAX does not currently use a separate analytics service.