This Privacy Policy explains how Tunefork collects, uses, stores, shares, and protects personal data when people visit or use the Tunefork website, web application, audio comparison tools, Listener voting pages, public profiles, Team Workspaces, subscriptions, and related services.
Tunefork is operated under the trading name Tunefork by:
Francis Apalenis Brylowska 6 01-216 Warszawa Poland
Email: info@tunefork.co
The service is currently operated as a Polish non-registered activity (działalność nierejestrowana).
Francis Apalenis, operating under the Tunefork trading name, is the controller of the personal data processed for Tunefork’s core platform purposes, including Account administration, billing administration, service operation, security, fraud prevention, support, and compliance.
Tunefork has not appointed a Data Protection Officer. Privacy questions and requests should be sent to info@tunefork.co.
This Privacy Policy applies to personal data processed through:
It may apply to producers, DJs, artists, studios, labels, schools, organisations, Team owners, Team members, collaborators, Listeners, website visitors, subscribers, support contacts, and other people who interact with Tunefork.
For this Privacy Policy:
Tunefork acts as controller where it determines why and how personal data is processed for the operation of the service. This includes:
A Fork Creator decides matters such as:
A Fork Creator or Team Customer may therefore act as a separate controller for its own use of personal data received through Tunefork. It is responsible for:
Tunefork and a Fork Creator do not intend to act as joint controllers unless that relationship is expressly agreed or follows from the actual facts of the processing.
Tunefork’s standard Team plan is not intended as a general-purpose outsourced data-processing service.
Where a Team Customer proposes to use Tunefork in a way that would make Tunefork a processor acting solely on the Team Customer’s documented instructions, that processing must not begin until legally required data-processing terms under Article 28 GDPR have been agreed.
A Team Customer requiring such processing must contact info@tunefork.co before uploading or collecting personal data on behalf of employees, clients, students, or other third parties beyond the ordinary Tunefork product flow.
The information collected depends on how a person uses Tunefork.
For registration using email and password, Tunefork currently requests:
These fields are required to create an email-based Account. A person who does not provide them cannot create or use that type of Account.
Alternatively, a User may register or sign in through an available social-login provider, such as Google. In that case, Tunefork may receive:
Tunefork does not receive the User’s Google password.
Tunefork may also process:
When a person uses the contact form or communicates with Tunefork, we may process:
Name, email address, and message content are required where needed for Tunefork to receive and respond to the communication. Without sufficient contact details and information, Tunefork may be unable to investigate or respond.
Tunefork may request additional information where reasonably necessary to verify identity, investigate a matter, prevent unauthorised disclosure, or respond to a request.
Tunefork may process:
Tunefork currently supports MP3, FLAC, AIFF, and WAV files. The current maximum size of a single uploaded audio file is 50 MB.
Some project information may not identify a person on its own but may become personal data when connected with an identifiable User, artist, Listener, Account, organisation, or Team Workspace.
A paid Producer User may choose to create a public Producer Profile containing:
The User decides whether to activate the Producer Profile and what information to publish.
Listeners may listen, vote, and interact with a Fork without creating an Account.
When a Listener accesses or interacts with a Fork, Tunefork may process:
A Listener may provide a name or remain unnamed to the Fork Creator. An unnamed response is not necessarily anonymous to Tunefork because Tunefork may still process technical identifiers such as an IP address and session identifier for operation, security, analytics, and abuse prevention.
The Fork Creator may see:
IP addresses, session identifiers, and detailed device or browser data are not ordinarily displayed to the Fork Creator.
Optional Listener name and email fields are not required to submit an unnamed response unless a future Fork configuration clearly states otherwise.
When a person joins or uses a Team Workspace, Tunefork may process:
Joining a Team Workspace does not automatically make unrelated private Account information available to the Team owner.
Tunefork offers paid Producer and Team subscriptions. Payments are processed through Stripe.
Before a User continues to Stripe, Tunefork may request:
Tunefork may receive or process:
Tunefork does not receive or store complete payment-card details.
Stripe may act as an independent controller for certain payment, regulatory, compliance, and fraud-prevention activities and applies its own privacy documentation.
Tunefork may process:
Tunefork does not disclose internal security thresholds, abuse-detection methods, infrastructure limits, or detection logic where doing so could facilitate circumvention, manipulation, fraud, or harm.
Tunefork may obtain personal data:
Users retain ownership of their User Content and any intellectual-property rights they lawfully hold.
Tunefork receives only the limited permission reasonably necessary to:
Tunefork does not:
Uploaded audio is treated as private unless the User intentionally shares or publishes it through a Fork Link, Producer Profile, Team Workspace, or another Tunefork feature.
Users are responsible for ensuring that they have the rights, licences, permissions, and consents needed to upload and process User Content through Tunefork.
Where the EU GDPR or another applicable law requires a legal basis, Tunefork relies on the bases below.
| Processing activity | Purpose | Legal basis |
|---|---|---|
| Email-based Account registration and mandatory registration fields | Create and administer the Account | Performance of a contract, Article 6(1)(b) GDPR |
| Authentication, password reset, and Account recovery | Provide secure Account access | Performance of a contract, Article 6(1)(b), and legitimate interests in Account security, Article 6(1)(f) |
| Google or other social login | Provide the User’s selected authentication method | Performance of a contract, Article 6(1)(b) |
| Audio uploads, waveform generation, playback, Fork creation, results, and service-generated analytics | Provide the requested Tunefork service | Performance of a contract, Article 6(1)(b) |
| Producer Profiles and deliberate publication settings | Provide the selected public-profile feature | Performance of a contract, Article 6(1)(b) |
| Basic Listener voting, comments, playback, and engagement processing | Provide feedback functionality requested by the Fork Creator and expected by the Listener | Legitimate interests of Tunefork and the Fork Creator in operating the feedback service, Article 6(1)(f) |
| Optional Listener name or email disclosed to the Fork Creator | Allow the Listener to identify themselves or permit follow-up | Consent, Article 6(1)(a), where the interface requests the information as optional |
| Listener IP address, session, device, duplicate-vote, and anti-abuse data | Operate the page, maintain integrity of results, prevent duplicate or manipulated voting, diagnose faults, and secure the service | Legitimate interests in service operation, reliability, fraud prevention, and security, Article 6(1)(f) |
| Team Workspace administration | Provide Team membership, collaboration, seats, roles, and administration | Performance of a contract, Article 6(1)(b), and legitimate interests in Team administration, Article 6(1)(f) |
| Subscription and billing administration | Form and perform the paid-service contract | Performance of a contract, Article 6(1)(b) |
| Payment, invoice, tax, and accounting records | Meet financial, tax, and accounting requirements | Legal obligation, Article 6(1)(c) |
| Failed-payment handling, chargebacks, and payment fraud | Protect payment systems and resolve disputes | Performance of a contract, Article 6(1)(b), and legitimate interests in fraud prevention and claims management, Article 6(1)(f) |
| Support and ordinary service correspondence | Respond to Users and operate the service | Performance of a contract, Article 6(1)(b), or legitimate interests in responding to enquiries, Article 6(1)(f) |
| Privacy requests, consumer complaints, and legally required notices | Comply with legal duties | Legal obligation, Article 6(1)(c) |
| Security logs, diagnostics, and abuse investigations | Protect Tunefork, Users, Content, and service availability | Legitimate interests in security, fraud prevention, and enforcement, Article 6(1)(f) |
| Technically necessary cookies and browser storage | Authentication, session management, security, and requested functionality | Performance of a contract, Article 6(1)(b), and legitimate interests, Article 6(1)(f); these technologies are used only where technically necessary |
| Marketing emails | Send optional promotional communications | Consent, Article 6(1)(a), unless another lawful basis is clearly available under applicable law |
| Policy-acceptance and consent records | Demonstrate compliance and manage the contractual relationship | Legal obligation, Article 6(1)(c), and legitimate interests in evidencing compliance, Article 6(1)(f) |
| Legal claims and disputes | Establish, exercise, or defend legal claims | Legitimate interests, Article 6(1)(f), and legal obligation where applicable |
Where processing relies on legitimate interests, Tunefork considers the necessity of the processing, the reasonable expectations of the affected person, the nature of the information, and safeguards such as limited access and retention.
Where processing relies on consent, consent may be withdrawn at any time by contacting info@tunefork.co or using an available interface control. Withdrawal does not affect processing carried out lawfully before withdrawal.
Information deliberately published through a Producer Profile or public Fork Link may:
Search-engine indexing is possible but is not guaranteed.
A User who does not want a public Producer Profile or public Fork Link to remain available or indexed may contact info@tunefork.co. Tunefork will remove or restrict the page within its control and may take reasonable steps to request de-indexing.
Tunefork cannot guarantee that search engines, archives, recipients, or other third parties will immediately remove cached, copied, downloaded, or republished versions.
Fork Links do not currently have dedicated password protection.
Depending on the available settings, the Fork Creator may:
If the Fork Creator enables file downloading, a Listener with access to the Fork Link may download the relevant audio file.
Unless a specific access-control feature is expressly enabled, any person who obtains a Fork Link may be able to access the relevant Fork. Recipients may forward, copy, record, publish, download, or otherwise disclose the link or its Content.
Users should not upload or share unreleased, confidential, commercially sensitive, or embargoed Content unless they understand and accept these risks.
Each Team member retains ownership of the Content that the member uploads or creates.
Joining a Team Workspace does not transfer ownership of a member’s Content or unrelated private Account data to the Team owner.
A Team owner or administrator may access:
A Team owner or administrator may:
Administrative deletion rights do not transfer intellectual-property ownership.
A Team member should retain or request copies of important Content before leaving a Team, being removed, deleting an Account, or allowing a Team Workspace to be closed.
Tunefork uses Stripe for subscription payments, renewals, upgrades, prorated charges, failed-payment retries, refunds, invoices, billing communications, chargebacks, and payment fraud prevention.
Tunefork’s Stripe account is maintained as an individual account in Poland.
Stripe may collect payment-card and billing information directly from Users. Stripe’s processing is governed by its own terms and privacy documentation.
Tunefork does not receive or store complete payment-card details.
When a User selects Google or another social login, the provider authenticates the User and supplies Tunefork with the information needed to establish or access the Account.
The provider may independently process login, device, security, and Account data under its own privacy documentation. Tunefork does not control the provider’s independent processing.
Tunefork currently uses only cookies and browser-storage technologies that are technically necessary for:
Blocking or deleting these technologies may prevent parts of Tunefork from working correctly.
Tunefork does not currently use:
Tunefork may generate first-party service analytics from server-side and application events that are necessary for the requested functionality, including voting, playback completion, skip rate, engagement, security, and service reliability. This does not mean that non-essential analytics cookies are used.
If Tunefork introduces non-essential cookies or similar tracking technologies in the future, this Privacy Policy and any legally required consent mechanism will be updated before or when those technologies are activated.
Tunefork maintains an internal inventory of technically necessary cookies, tokens, and browser-storage items, including their purposes and durations.
Tunefork may disclose personal data to providers of:
These providers may process data only to the extent necessary to provide their services, subject to applicable agreements and data-protection requirements.
Apart from providers expressly named in this Privacy Policy, Tunefork does not publish a complete technical-vendor list where doing so could create security, confidentiality, or commercial risks.
Any data subject, User, Listener, or Team member may submit a reasonable request for information about relevant recipients or transfer safeguards to info@tunefork.co. Tunefork will provide information required by applicable law, subject to legitimate security, confidentiality, and third-party rights.
Tunefork may also disclose personal data:
Tunefork does not sell personal data in exchange for money and does not sell uploaded audio.
Tunefork’s primary application servers and primary storage are located in Germany, within the European Economic Area.
This does not mean that every category of personal data is processed only in Germany. Providers such as Stripe, Google, email providers, security providers, or their subprocessors may process limited data in other countries as part of their global infrastructure.
Where personal data is transferred outside the European Economic Area and applicable law requires safeguards, Tunefork or the relevant provider will rely on an appropriate legal mechanism, such as:
Information about relevant transfer safeguards and how to obtain a copy may be requested through info@tunefork.co. Any copy may be redacted where necessary to protect confidential or security-sensitive information.
Within Tunefork, Francis Apalenis is currently the only person authorised for routine human access to production data.
Developers, contractors, and support personnel do not currently have routine production-data access.
Technical service providers may process data to the extent necessary to provide hosting, storage, authentication, payment, email, backup, security, or other contracted services. Provider personnel may have restricted access where required for security, maintenance, incident response, or legal compliance under the provider’s own access controls.
Access arrangements may change as Tunefork develops. Material changes will be reflected in this Privacy Policy where required.
Tunefork applies the following current retention periods and criteria.
| Data category | Retention period or criterion |
|---|---|
| Active Account data | Retained while the Account remains active and then handled under the deletion or inactivity rules below |
| Active paid Account and User Content | Retained while the paid Account remains active and Tunefork continues providing the service |
| Free Account with no meaningful Account activity | May be deleted after 365 consecutive days without activity |
| Former paid Account | May be deleted 365 days after paid access ends, unless the Account is reactivated or continues to be used under an available plan |
| Meaningful Account activity | Includes a successful sign-in or an Account action such as uploading, creating, editing, sharing, administering a Team, or managing a subscription |
| Inactivity warning | Where reasonably practicable and a valid email remains available, Tunefork will send advance notice before inactivity-based Account deletion |
| Forks, audio, project settings, votes, comments, and engagement results | Retained while the related Fork and Account remain active; deleted when the Fork or Account is deleted under the applicable deletion process |
| Listener IP addresses, session identifiers, and ordinary technical event data | Normally retained for up to 90 days after collection |
| Error and diagnostic logs | Normally retained for up to 90 days, unless needed for an unresolved incident |
| Security, duplicate-vote, fraud, and anti-abuse logs | Normally retained for up to 12 months; relevant records may be kept longer where an incident, investigation, dispute, or recurring abuse pattern remains active |
| Contact and ordinary support correspondence | Normally retained for 24 months after the matter is closed |
| Privacy requests, formal complaints, withdrawal requests, and evidence of how the request was handled | Normally retained for 3 years after closure, or longer where required for an active dispute or legal obligation |
| Consent and marketing-preference records | Retained while the consent or preference is active and normally for 3 years afterwards as evidence; a minimal suppression record may be retained to respect an unsubscribe request |
| Failed-payment, chargeback, and payment-fraud records | Normally retained for 24 months after resolution, or longer where required for an active dispute, provider rule, or legal claim |
| Payment, invoice, tax, and accounting records | Retained for the period required by applicable Polish accounting and tax law, generally at least 5 years calculated under the applicable statutory rules, and longer where another mandatory period applies |
| Policy-acceptance records | Retained while the Account remains active and normally for 3 years afterwards where needed to evidence the applicable contractual version |
| Irreversibly anonymised or aggregated information | May be retained because it no longer identifies an individual |
If a User does not accept a policy or contractual change that legally requires express acceptance, access to affected functionality may end. The Account and associated User Content may then be retained for up to 365 days to allow export, reactivation where available, dispute handling, or orderly deletion, subject to shorter User-requested deletion and longer mandatory legal retention.
Tunefork may retain limited records longer where reasonably necessary or legally required for accounting, tax, fraud prevention, security, complaints, disputes, or the establishment, exercise, or defence of legal claims.
A User may request Account deletion through the Account interface, where available, or by emailing info@tunefork.co.
The request should be sent from the Account email address or include enough information to verify identity and authority.
After a confirmed deletion request:
The planned deletion period is therefore up to 40 days after confirmation, except for limited records that must or may lawfully be retained longer.
Backups are maintained for resilience and are not intended as a customer archive. Tunefork does not guarantee restoration from backup after deletion has been requested.
Cancelling a Paid Plan does not automatically delete the Account or its Content.
Deleting an Account does not automatically cancel payment obligations already validly incurred. A User should cancel an active Paid Plan before or together with an Account-deletion request.
A User may request a product export or copy of eligible Account data and User Content by emailing info@tunefork.co.
The request should be sent from the Account email address or include enough information to verify identity and entitlement.
A product export may exclude information that:
Users should request an export before deleting their Account. Once information has been permanently deleted, Tunefork cannot restore or export it.
The limitations applying to a voluntary product export do not reduce mandatory rights under applicable data-protection law.
A GDPR access request is handled under Article 15 GDPR. A portability request is handled under Article 20 GDPR and applies only where the legal requirements for portability are met.
Tunefork uses reasonable technical and organisational measures designed to protect personal data and User Content against unauthorised access, unlawful processing, accidental loss, misuse, alteration, destruction, and unauthorised disclosure.
Measures may include, to the extent actually implemented:
Tunefork does not receive a User’s Google password. Complete payment-card details are entered through Stripe and are not stored by Tunefork.
No online service can guarantee absolute security.
Users are responsible for protecting their registered email account, password, social-login access, authentication links, and private or unlisted Fork Links and for notifying Tunefork promptly of suspected unauthorised access.
Subject to applicable law, a person may have the right to:
Requests should be sent to info@tunefork.co.
Tunefork may request reasonable information to verify identity, Account ownership, authority to act for another person, and entitlement to receive the requested data. Verification information will not be used for unrelated purposes.
Tunefork will respond without undue delay and normally within one month after receiving a valid request. Where permitted by law, this period may be extended by up to two further months because of the complexity or number of requests. Tunefork will inform the requester of an extension and the reasons for it.
Certain rights may be limited where processing is necessary to comply with law, protect another person’s rights, maintain security, prevent fraud, preserve evidence, or establish, exercise, or defend legal claims.
A person may complain to the supervisory authority in the EU Member State of their habitual residence, place of work, or place of the alleged infringement.
The principal Polish supervisory authority is:
President of the Personal Data Protection Office Prezes Urzędu Ochrony Danych Osobowych (UODO) ul. Stanisława Moniuszki 1A 00-014 Warszawa Poland
A person may contact Tunefork first at info@tunefork.co, but doing so is not a condition for submitting a complaint to a supervisory authority.
Tunefork may send marketing emails only where the recipient has consented or where another specific lawful basis is available under applicable law.
Marketing emails will include an unsubscribe method where required.
A person who unsubscribes from marketing may still receive necessary operational communications, including:
Tunefork may retain a minimal suppression record to ensure that a person who has unsubscribed is not added back to the same marketing list unintentionally.
Tunefork is not intended for independent use by children under 16.
A person under 16 may use Tunefork only where the use is lawfully authorised and supervised by a parent, legal guardian, school, or other responsible organisation.
If you believe that a child has provided personal data without appropriate authorisation, contact info@tunefork.co.
Tunefork may generate:
These outputs may be subjective, incomplete, inaccurate, inconsistent, biased, manipulated, or statistically unrepresentative. They are informational and are not guaranteed predictions, professional advice, or final decisions about music, business, or release strategy.
Tunefork does not currently use personal data to make decisions that produce legal or similarly significant effects solely through automated processing.
Tunefork may contain links to:
Those third parties may collect and process personal data independently under their own terms and privacy policies.
Tunefork is not responsible for the privacy practices, content, or security of independent third-party services outside its reasonable control.
This does not limit Tunefork’s legal responsibilities concerning service providers that process personal data on Tunefork’s behalf.
Tunefork may update this Privacy Policy for legal, regulatory, security, technical, operational, payment, vendor, or product-development reasons.
The updated version will be published with a revised “Last updated” date.
Non-material changes may take effect when published.
Material changes will normally be announced by email at least 10 days before taking effect. A shorter period may be used where reasonably necessary because of law, security, fraud prevention, abuse prevention, or an urgent service change.
Where applicable law requires express consent or acceptance, continued use alone will not replace that consent or acceptance.
Users are responsible for keeping their Account email address current.
Privacy questions, rights requests, complaints, Account-deletion requests, data-export requests, and legal notices should be sent to:
info@tunefork.co
Controller and service provider:
Francis Apalenis Trading as Tunefork Brylowska 6 01-216 Warszawa Poland
Tunefork aims to respond to ordinary service complaints within five business days. Privacy-rights requests are handled under the statutory periods described in Section 19.