Privacy
last updated · 22 May 2026
Tunr is a desktop audio mastering app for macOS and Windows, operated by A. O. Signtech (company registration no. 513915652, an Israeli company with its registered office at Harakefet 9, Zikhron Yaakov, Israel), operating under the brand "Tunr". A. O. Signtech is the data controller for personal information processed through tunr.studio and the Tunr app.
Tunr runs locally on your machine and processes audio on your CPU. Your audio files never leave your computer. This page explains every other piece of data that does: what it is, why we need it, and how to remove it.
What the desktop app collects
Practically nothing. Specifically:
- License-key validation: on first launch after you enter a paid license, Tunr makes a single HTTPS request to
tunr.studio/api/activatewith your key and a hash of your hardware UUID. The server confirms the key is valid and returns a signed activation token, which Tunr then verifies locally on every launch, with no further network calls. - Periodic revocation check: roughly once a month, Tunr re-pings
tunr.studio/api/statusto confirm the token hasn't been revoked (e.g. after a refund). Offline, it skips silently. - Update check: Tunr asks GitLab for the latest release number once per launch, the same request anyone makes visiting that page in a browser, with no Tunr-specific telemetry attached.
What the desktop app explicitly does not do
- No upload of your audio files, ever.
- No usage telemetry. We don't know which buttons you press, how often you master, or what genres you choose.
- No crash reports unless you opt in (a future version will offer this as a toggle, defaulting to off).
- No third-party trackers, ad SDKs, analytics, or fingerprinting.
What this website collects
tunr.studio uses privacy-respecting, cookieless analytics (Vercel Analytics) to count visits per page. No cross-site tracking, no advertising cookies, no consent banner required. The site sets no third-party tracking cookies. The Paddle checkout opens in an overlay managed by Paddle on their own domain; their privacy practices apply there (see below).
Getting a licence key
Tunr is free and the key arrives by email, so the form asks for an email address. When you submit it, we store:
- Your email address, and the licence key issued to it.
- Whether you ticked “email me about Tunr updates”, and when you ticked it.
- Which page you signed up from.
- A one-way hash of your IP address. Not the address itself: the hash lets us see that one machine has requested hundreds of keys, and nothing else.
The form is checked by Cloudflare Turnstile, which confirms a person and not a script is submitting it. Cloudflare runs that check on their own infrastructure.
If you ticked the updates box, your address joins our list at Resend and you can leave it from the unsubscribe link in any of those emails. If you did not tick it, you get the key itself and nothing else.
Payments & Paddle
Tunr is sold via Paddle, which acts as the Merchant of Record. Paddle, not A. O. Signtech, is the data controller for your billing data (name, billing address, payment method, invoice history) and is responsible for collecting and remitting tax. After you pay, Paddle passes us only:
- Your email address (to send the license key)
- The order ID and product purchased
- The country your card was issued in (for tax reporting)
- Whether the order was later refunded
We never see, store, or have access to your card number, CVV, full billing address, or bank details. Those remain with Paddle under PCI-DSS Level 1. Paddle's privacy policy: paddle.com/legal/privacy.
What we store
The minimum needed to run your license:
- Your email address, from the key form or from Paddle for purchases made before Tunr was free.
- Your license key and the hardware-UUID hashes of the machines you activated on (max 2).
- The signed activation tokens we've issued, plus any revocation status.
This data is held on Vercel infrastructure (EU region) and accessed only by A. O. Signtech for the purpose of issuing, validating, and revoking licenses and answering support email.
We send transactional email via Resend: the licence-delivery message, plus rare follow-ups such as security advisories. Product-update emails go only to people who asked for them on the key form, and every one of those carries an unsubscribe link. We never sell your email address or use it for third-party marketing.
Your rights
If you're in the EU, UK, or any jurisdiction with similar rules, you have the right to access, correct, delete, export, or restrict processing of your personal data. To exercise any of these, email allexp@gmail.com with the subject "Privacy request." We respond within 30 days, usually within 48 hours. Deleting your account invalidates your license; we'll process a pro-rated refund where applicable.
How long we keep things
- License + activation data: while your license is valid, plus 7 years (tax / audit).
- Email correspondence: 3 years from last reply.
- Anonymised analytics: 90 days, then aggregated.
Changes
We update the "last updated" date above whenever this policy changes. Material changes trigger an email to active license holders 14 days before they take effect.
Contact
A. O. Signtech, Harakefet 9, Zikhron Yaakov, Israel. Privacy questions: allexp@gmail.com.