We keep data collection to the minimum needed to run your account and validate your license. Here's exactly what we collect, why, and your rights over it.
1. Who we are
The data controller for Aura Mixer is Net Glow Studios – Dawid Mika, a sole proprietorship registered in Poland (NIP: 5482769338). Our registered business address is on record in Poland's CEIDG register and is available on request at support@aura-mixer.com. For any privacy question, contact support@aura-mixer.com.
2. What we collect
Account — your email address and a hashed password. Licenses — your purchases, license keys, and device activations. Device fingerprint — see below. Payments — handled by Stripe; we store only order metadata (e.g. amount, date, license issued), never card numbers. Download log — when you download the installer we record the build version and time, your browser's user-agent, a salted one-way hash of your IP address (never the raw address), and — if you're signed in — your account, for aggregate download statistics and abuse protection. Analytics — with your consent, Google Analytics 4 collects aggregate, anonymised usage (which pages are viewed, roughly from where); it loads only after you opt in via the cookie banner, and never if you decline. We run no ad tracking, remarketing, or cross-site behavioural profiling.
App diagnostics (opt-in) — if you enable "Share anonymous diagnostics" in the desktop app (off by default), the app sends engine-health events only: audio-glitch counts, engine restarts, crash signatures and session summaries, together with the app version, Windows version and audio-engine settings. They are tied to a random install id generated when you opt in — deliberately not your device fingerprint — so diagnostics cannot be linked to your account, license or purchases; the ingest endpoint stores no IP address, and device names, file paths and anything about what you play are never collected. Diagnostics are deleted after 90 days, and you can turn them off anytime in the app's settings (already-sent data ages out on the same schedule).
3. The device fingerprint
When you activate Premium, the app computes a SHA-256 hash of your Windows MachineGuid on your device and sends only that hash to us — never raw serial numbers or hardware identifiers. It's used solely to bind your license to your device(s) and to let you self-deactivate a seat. You can remove a device from your account at any time.
4. Payments
Card payments are processed by Stripe. We never see or store your full card number. Stripe processes your payment data under its own privacy policy; we receive only the confirmation and metadata needed to issue your license and a VAT invoice.
5. How we use your data
To validate and manage licenses, run your account, provide support, prevent fraud, meet our tax/accounting obligations, and send transactional emails (receipts, email verification, password resets). We do not send marketing email without your separate consent, and we never sell your data. The lawful bases are performance of our contract with you, our legitimate interests in securing and improving the service, and compliance with legal obligations.
6. Cookies & third-party scripts
Two kinds of cookies. Strictly-necessary (always on): a session cookie (aura.auth) that keeps you signed in, and an anti-forgery cookie that protects forms against CSRF. Analytics (optional, off until you agree): if you accept in the cookie banner, Google Analytics 4 sets its own cookies (e.g. _ga) to measure aggregate usage. You choose — Accept or Decline — and can change your mind any time via Cookies in the footer. Decline and no analytics cookies are set and Google Analytics is never loaded. We use no advertising or cross-site tracking cookies.
The sign-up page loads Google reCAPTCHA to block automated abuse. reCAPTCHA is provided by Google, may set its own cookies and process limited technical data under Google's privacy policy, and runs only on the registration form.
7. Who we share with
Only the processors needed to run the service: Stripe (payment processing), Google (reCAPTCHA anti-abuse on sign-up, and — with your consent — Google Analytics for aggregate usage statistics), and OVH (hosting our servers, including self-hosted outbound transactional email). Each acts under a data-processing agreement; where a processor is outside the EEA (e.g. Stripe, Google), transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses. We may also disclose data where required by law.
8. Your rights (GDPR / RODO)
You can access, correct, export, delete, or restrict processing of your personal data, and object to certain processing. You can delete your account — which releases your licenses and unbinds your devices — from your profile, or by contacting us. You also have the right to lodge a complaint with the Polish supervisory authority, the UODO (Urząd Ochrony Danych Osobowych), or your local one.
9. Data retention
We keep your data while your account is active. After you close it, we delete or anonymize your personal data, except records we're legally required to keep — in particular accounting and tax records, which Polish law requires us to retain for the statutory period (generally 5 years).
10. Security
Data is encrypted in transit (TLS). Passwords are hashed. License tokens are signed and device-bound, and on your machine are stored encrypted by the operating system. No method is perfectly secure, but we design to minimize what we hold.
11. International transfers
Some processors may be located outside the EEA. Where that happens, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses, so your data keeps an equivalent level of protection.
12. Children
Aura Mixer is not directed to children under 16, and we don't knowingly collect their data.
13. Changes & contact
We'll post updates here and update the date at the top; we'll announce material changes. For any privacy request, contact support@aura-mixer.com.