Privacy Policy

Last updated: April 2, 2026

1. Data Controller

Name: Renma Matsumura (Sole Proprietor)

Address: Yamato Building 6F, 7-14-5 Roppongi, Minato-ku, Tokyo, Japan

Contact: support@deckready.app

DeckReady ("the Service") respects your privacy and is committed to protecting your personal information in accordance with Japan's Act on the Protection of Personal Information (APPI) and the EU General Data Protection Regulation (GDPR).

2. Information We Collect and Legal Basis

2.1 Account Information — Through Google OAuth, we collect your name, email address, and profile picture.
Legal basis: Performance of contract (GDPR Art. 6(1)(b))

2.2 Usage Data — We record preset names, LUFS values, processing duration, and track counts for quota management and service improvement.
Legal basis: Contract performance and legitimate interest (GDPR Art. 6(1)(b)(f))

2.3 Payment Information — Credit card information is managed by Stripe, Inc. We never store or access your card numbers. Stripe shares only subscription status and customer ID with us.
Legal basis: Contract performance (GDPR Art. 6(1)(b))

2.4 Audio Files (Privacy by Design) — All audio processing occurs entirely within your browser using the Web Audio API / OfflineAudioContext. Audio files are never transmitted to, stored on, or accessed by our servers. This architecture implements the Privacy by Design principle under GDPR Article 25.

2.5 Cookies — We use cookies for Google AdSense advertising and Google Analytics.
Legal basis: Consent (GDPR Art. 6(1)(a)). Cookies are activated only after consent is obtained.

3. How We Use Information

  • Service operation (account management, processing quota)
  • Billing management (subscription processing)
  • Usage analytics (feature improvement, preset usage trends)
  • Ad delivery optimization (Google AdSense, Free tier only)
  • Customer support

4. Third-Party Sharing and International Transfers

We share information with the following services.

  • Google LLC (United States) — Authentication (OAuth), analytics (Google Analytics, only after consent) and advertising (AdSense, only on the legacy mastering tool pages and only after consent). Google states in its own published materials that it participates in the EU-US Data Privacy Framework.
  • Stripe, Inc. (United States) — Payment processing. Stripe states in its own published materials that it is PCI DSS Level 1 compliant and participates in the EU-US Data Privacy Framework.
  • Servers we operate (Japan) — Application and database hosting. This runs on dedicated servers we manage rather than a third-party cloud platform.
  • Umami (on servers we operate) — Analytics. No data is shared with a third party; processing happens only on infrastructure we manage, and only after consent.

Your audio files are never shared with any of them. The Audio Safety Checker analyses everything inside your browser, and the audio never travels over the network at all.

5. Cookies and Advertising

We use the following cookies:

  • Essential cookies — Session management, authentication and language (no consent required, cannot be disabled)
  • Analytics cookies (Google Analytics 4 and Umami) — Understanding how the site is used (activated after consent)
  • Advertising cookies (Google AdSense) — Legacy mastering tool pages only (activated after consent)

Analytics and advertising are both off by default. Until you consent, the Google Analytics, Umami and Google AdSense scripts are not loaded at all — so no request is made to those providers, no IP address reaches them, and no cookie is set.

You can withdraw consent from “Cookie settings” in the footer, in the same number of actions it took to give it. After withdrawal the scripts are not loaded again unless you consent again. Declining changes nothing about the Audio Safety Checker: analysis runs entirely in your browser and needs no analytics cookies.

Analytics events carry only your locale, device class, browser family, bucketed file size, duration and bitrate, codec, verdict and issue codes. File names, track titles, artist and album names, file paths, audio data and audio hashes are never transmitted. What may be sent is restricted by an allow-list in the implementation and verified by automated tests.

6. Data Retention

Account data: Deleted within 30 days of deletion request.

Usage records: May be retained in anonymized form after account deletion.

Payment records: Retained per Stripe's policy (minimum 7 years for legal obligations).

Cookie consent records: Retained for 12 months as proof of consent.

7. Your Rights

Under Japan's APPI: Right to disclosure, correction, suspension of use, and deletion of retained personal data.

Under GDPR (EEA/UK residents): Right of access, rectification, erasure (right to be forgotten), restriction of processing, data portability, objection, and withdrawal of consent. We do not engage in automated decision-making or profiling (AdSense targeting is Google's processing). You also have the right to lodge a complaint with a supervisory authority.

How to exercise your rights: Email support@deckready.app from your registered email address for identity verification. We will respond within 30 days. No fees are charged.

8. Security Measures

Technical: HTTPS/TLS encryption, database access controls, parameterized queries via Prisma (SQL injection prevention).

Organizational: Minimum access privileges, regular security reviews.

Incident response: In case of a data breach, we will report to Japan's Personal Information Protection Commission (preliminary report: promptly / full report: within 30 days) and notify affected users. Under GDPR, we will notify the supervisory authority within 72 hours.

9. Children's Privacy

The Service is not intended for users under 16. If we become aware that a user under 16 has created an account, we will promptly delete the account and associated data.

10. Changes and Contact

This policy may be updated as needed. Significant changes will be notified via email or in-service notification at least 30 days in advance.

Contact: support@deckready.app