Last updated: January 2025. This policy applies to edmfeedback.com.
Short version: We collect your email address to manage your account. We never store your audio files — they are analyzed entirely in your browser. We use Supabase (EU-hosted) for data storage. You can delete your account and all data at any time.
EDMFeedback ("we", "us", "our") is operated as an individual/sole trader service. For data protection queries, contact us at: [email protected]
This service is operated from Norway and complies with the EU General Data Protection Regulation (GDPR) as implemented in Norwegian law through the Personal Data Act (Personopplysningsloven).
Your account data and analysis history is stored in Supabase, with the database hosted in the EU (Ireland or Frankfurt region). Supabase is GDPR-compliant and processes data under Standard Contractual Clauses. See Supabase's privacy policy.
When you run an analysis, anonymised technical data about your track (numbers only — no audio) is sent to Anthropic's Claude API, hosted in the US. Anthropic does not use API inputs to train its models. See Anthropic's privacy policy.
We believe in full transparency about every service that touches your data:
| Service | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase | Auth & database | Email, analysis history, plan | EU (Frankfurt) |
| Anthropic (Claude) | AI feedback generation | Track measurements only (no audio, no personal data) | US |
| Stripe | Payment processing | Email, payment details (we never see card numbers) | US/EU |
| Resend | Transactional email | Email address (confirmation emails only) | US |
| Hetzner | Audio analysis server | Audio file (analyzed and immediately deleted, never stored) | EU (Germany) |
| Google Analytics 4 | Usage analytics | Anonymised page views (IP anonymised, no advertising) | US |
| Audio analysis system | Technical & musicality analysis | Audio file processed on our EU server, immediately deleted | EU (Germany) |
US-based processors operate under Standard Contractual Clauses (SCCs) as required by GDPR Article 46.
As a user, you have the following rights:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
We use one functional cookie: a session token set by Supabase when you log in. This cookie is strictly necessary for the service to function and does not require consent under ePrivacy rules. We do not use advertising cookies, tracking cookies, or third-party analytics cookies.
This service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has registered, please contact us and we will delete the account.
If we make material changes to this policy, we will notify registered users by email at least 14 days before the changes take effect.
We use Google Analytics 4 to understand how people use EDMFeedback — which pages are visited, how long analyses take, and where users drop off. This helps us improve the service. We do not use advertising tracking, remarketing, or any third-party ad networks.
Google Analytics anonymises your IP address before storage. We have configured it with anonymize_ip: true and do not share data with advertisers.
You can change your analytics preference at any time:
For any privacy-related questions: [email protected]