Privacy Policy
Last updated: 2026-07-31
This policy explains what personal data Audio Audit collects, why we collect it, who else gets to see it, how long we keep it and what you can do about it. We have tried to write it in plain English rather than legal boilerplate.
Who we are
Audio Audit (audioaudit.io) is a trading name of Epix Studios Limited, a company registered in England and Wales (company number 8933101). We are the data controller for the personal data described here.
For anything to do with privacy or your data, email us at info@audioaudit.io.
What we collect
Account information
When you register we collect your first name, last name and email address, together with the password you choose (which is stored only as a salted hash — we never see or store it in readable form). Registration is protected by hCaptcha, which performs a bot check on the sign-up form.
If you tell us how you heard about us — an optional question we ask once after sign-up — we store that answer against your account so we know which channels are working.
Content you give us to analyse
When you use the service we handle the podcast feed URLs you submit, the episode audio we fetch from those public feeds or that you upload directly, and everything we generate from that audio: reports, measurements, waveform and spectrogram artifacts, and transcripts.
Usage information
We record how the site and the service are used — pages visited, reports run, features used, plus the technical details every web server receives (IP address, browser and device type, referring page, date and time). Usage events are tied to a first-party device identifier and, once you are signed in, to your account, so that we can see how anonymous visits turn into registered use.
Payment information
Paddle.com Market Ltd is the merchant of record for all purchases. Payment card details are entered on Paddle’s own checkout and never reach our servers — we never see or store card numbers. Paddle sends us transaction and subscription metadata (what was bought, when, the amount, the billing country and your billing email) so that we can enable the right plan on your account.
Cookies and similar technologies
Cookies
deviceid— a first-party cookie set by our own server, kept for 1 year. It is a random identifier used to join up usage events from the same browser.attribution— a first-party cookie, kept for 90 days. It records where you first arrived from and where you most recently arrived from: campaign tags in the URL (utm_source,utm_medium,utm_campaign,utm_term,utm_content), advertising click identifiers (such asgclid,gbraid,wbraid,fbclid,msclkid,ttclid,li_fat_id,twclid), the page you landed on, the external site that referred you, and the time. If you go on to create an account, this is stored against it so we know which marketing brought you here.- Matomo analytics cookies — used by our self-hosted analytics (see below) to count visits and sessions.
- Advertising cookies (
_fbp,_fbcand equivalents) — set only while we are running paid advertising campaigns, by the measurement tags described in the next section. When no campaigns are running these tags are switched off and the cookies are not set. csrftoken— a security cookie set by our backend when your browser talks to our API, kept for 1 year. It protects forms and API calls against cross-site request forgery. (Staff signing in to our Django admin also get a session cookie; ordinary users never do.)- Paddle — our checkout provider’s script loads on every page and may set its own cookies for fraud prevention and to keep a checkout session together.
- Crisp — the support chat widget loads on every page and sets its own cookies and browser storage so a chat conversation survives a page reload. This is independent of whether any ad campaign is running.
Browser storage
Some things are kept in your browser’s local storage rather than in a cookie, which means they stay on your device and are not sent to us with every request:
authToken— the signed token that keeps you logged in. Signing out removes it.userState— a cached copy of your own profile so pages render without waiting for the server.showOnboardingandaskAttribution— flags recording whether you have already seen the onboarding step and the “how did you hear about us?” question.preferredCurrencyandenhancementOptions— display and tool preferences you have chosen.
You can block or delete cookies in your browser settings, and clear local storage the same way. Blocking our own cookies and storage will sign you out and stop some preferences from sticking.
Advertising and conversion measurement
From time to time we advertise Audio Audit on Google and Meta (Facebook and Instagram). While a campaign is running we need to know which adverts actually led to sign-ups and purchases, so we measure conversions. This section describes exactly what that involves. When no campaigns are running, none of it happens — the tags and the data sharing below are switched off.
What we share, and with whom
- Google Ads, operated by Google LLC — so Google can report which of our adverts led to a sign-up or a purchase.
- Meta Pixel and Conversions API, operated by Meta Platforms — for the same purpose on Facebook and Instagram.
We send those companies a conversion event at two moments: when you register an account directly on our site (registering by accepting a team invitation does not generate one), and when you make your first successful payment of any kind — a subscription or a credit purchase. That purchase event fires once per account only; renewals, upgrades and repeat purchases do not generate further events. Each event contains:
- Your email address, hashed with SHA-256 before it leaves our servers — the platforms receive the hash, not your address. A hash still lets them recognise you if you are already one of their users, which is the point of sending it, but it is not readable as an email address.
- The advertising click identifier from the
attributioncookie (for examplegclidorfbclid) and, for Meta, the_fbp/_fbccookie values plus anexternal_id— a SHA-256 hash of your internal account number, which lets Meta recognise the sign-up and the purchase as the same account without us sending anything that identifies you directly. - What happened (a sign-up or a purchase), when, and for purchases the amount and currency.
- Your IP address and browser user-agent — but only where the measurement tags run in your browser, since they receive these as part of any web request. The events we send server-to-server do not include your IP address.
We do not send them your name, your podcast feeds, your audio, your reports or your transcripts, and we do not sell personal data to anyone.
Onward sharing by the ad platforms
We share this information with Google and Meta so that they can perform advertising measurement services on our behalf. Those companies may in turn share the data with their own third-party partners, vendors and service providers to deliver those measurement services, and each of them handles the data under its own privacy policy as well as ours. We have no control over what they do once it reaches them, which is why we name them and link their policies here.
Third-party ad serving on our site
We do not display third-party adverts on audioaudit.io, and no ad network serves banners, ad tags or web beacons to you here.
Opting out
- Google: privacy policy · Google Ads Settings
- Meta: privacy policy · Facebook Ad Preferences
- Industry-wide opt-out tools: youronlinechoices.com (Europe) and aboutads.info (US).
- Blocking cookies in your browser, or using a tracker-blocking extension, prevents the pixels from running at all.
- You can also object to this processing directly by emailing info@audioaudit.io. We will consider your objection and act on it for future events. Note that we cannot retrieve an event already sent — for that, use the platform opt-outs above, which are under your control rather than ours.
How we use your data, and our lawful basis
- Providing the service — running audits, storing your reports, managing your account and taking payment. Lawful basis: performance of our contract with you.
- Service emails — verification, password resets, report notifications, billing notices. Lawful basis: contract.
- Product announcements and promotional email — new accounts are set to receive product announcements and occasional promotional email by default. Every message carries an unsubscribe link, and you can switch these off at any time from the notification toggles in your account settings. Lawful basis: legitimate interests (telling our own customers about the product they signed up for), with the right to opt out at any time.
- Product analytics and site statistics — understanding which features are used so we can improve them. Lawful basis: legitimate interests (running and improving our business).
- Advertising measurement — as described above. Lawful basis: legitimate interests (measuring whether our marketing spend works). We do not use a consent banner for this; instead we disclose it here and you can object at any time by emailing us.
- Security, abuse prevention and debugging — server logs, rate limiting and bot checks. Lawful basis: legitimate interests (keeping the service available and secure).
Companies that process data for us
We keep this list short on purpose. Each of these companies only receives what it needs to do its job, and each processes it under its own data-processing terms.
- Google Cloud Platform (Google LLC / Google Ireland Limited) — hosting, databases, and storage of uploaded audio, reports and artifacts. Privacy notice
- Modal (Modal Labs, Inc.) — cloud compute that processes episode audio when analysis jobs run there. Privacy policy
- Paddle (Paddle.com Market Ltd) — merchant of record for payments, subscriptions, invoices and VAT. Privacy policy
- Amazon Web Services (Amazon Web Services EMEA SARL, SES in eu-west-1) — delivery of transactional and newsletter email. Receives your email address and the message contents. Privacy notice
- Crisp (Crisp IM SAS, France) — the support chat widget. Receives what you type into chat, plus your name and email if you are signed in. Privacy policy
- hCaptcha (Intuition Machines, Inc.) — bot check on the registration form. Privacy policy
- Google LLC and Meta Platforms — advertising measurement, only while campaigns are running, as described above.
Analytics stays with us
Our site analytics run on Matomo, self-hosted by us at stats.epixstudios.co.uk. Your browsing data goes to our own server and no third-party analytics company receives it. We do not use Google Analytics.
Your audio is not sent to an AI company
Transcription runs on our own infrastructure using a locally hosted speech-recognition model (faster-whisper). Your episode audio is not sent to OpenAI, Google, AWS or any other external AI or speech-to-text API, and it is never used to train anyone’s models.
Where your data is held
Our servers and storage are in Google Cloud, and our email is sent through AWS SES in the EU (Ireland). Our chat provider Crisp is a French company operating in the EU. Some of our other providers — Google, Meta, Modal and hCaptcha — are US-owned and may process data in or from the United States. Where data leaves the UK or the EEA, we rely on the transfer mechanisms available under UK and EU data protection law, as applicable: the UK International Data Transfer Agreement or Addendum, the European Commission’s Standard Contractual Clauses, and, where the provider is certified, the EU–US and UK–US Data Privacy Framework.
How long we keep things
- Account data — for as long as your account exists. Email us and we will delete it.
- Reports you have removed — the underlying content is purged 30 days after removal.
- Failed report content — error payloads and associated content are purged after 90 days.
- Podcast feed check history — 35 days, except where a check is the record of when we first saw a particular episode, which we keep for as long as we hold that episode.
- Processing job records — up to 28 days; stale in-progress rows are cleared after 7 days.
- Usage events — the analytics event log is kept for trend analysis, but when an account is deleted the link to that person is removed, leaving the events unattributed.
- Server and request logs — short-lived, typically no more than 30 days.
- Billing records — retained by us and by Paddle for as long as tax and accounting law requires (normally 6 years in the UK).
Security
Traffic to the site is encrypted with HTTPS, passwords are stored only as salted hashes, and access to production systems is limited to the people who need it. No system is perfectly secure, but we take this seriously. If a personal data breach ever occurs we will report it to the ICO where the law requires us to, and we will tell affected users directly where the breach is likely to put their rights and freedoms at high risk.
Your rights
Under UK GDPR (and the EU GDPR where it applies to you) you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted — email us and we will delete your account and its data;
- object to processing we carry out on the basis of legitimate interests, including the advertising measurement described above;
- ask us to restrict how we use your data;
- receive your data in a portable, machine-readable format;
- withdraw consent where we rely on it (for example, marketing emails), at any time.
Email info@audioaudit.io to exercise any of these. We will respond within one month. If you are not happy with how we have handled it, you can complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
Children
Audio Audit is a business tool and is not intended for children. We do not knowingly collect personal data from children under 13. If you believe a child has given us their information, contact us and we will delete it promptly.
Changes to this policy
We update this policy when what we do changes — for example when we add or remove a processor. The date at the top always reflects the current version, and we will highlight anything significant to account holders by email.
Contact
Epix Studios Limited, United Kingdom — info@audioaudit.io. You can also reach us through the chat bubble in the bottom-right corner of the site.