Privacy Policy for Audioexperiment.com
Last updated 23 August 2026.
At Audioexperiment.com, accessible from https://audioexperiment.com, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by Audioexperiment.com and how we use it.
If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us.
This Privacy Policy applies only to our online activities and is valid for visitors to our website with regards to the information that they shared and/or collect in Audioexperiment.com. This policy is not applicable to any information collected offline or via channels other than this website. Our Privacy Policy was created with the help of the Free Privacy Policy Generator.
Consent
Using the site is not consent to anything optional. Nothing that is not needed to show you the page is loaded before you have chosen it in the cookie banner, and if you choose nothing, nothing optional loads. The only thing reading this page commits you to is the description below of what happens either way.
Information we collect
The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information.
If you contact us directly, we may receive additional information about you such as your name, email address, the contents of the message, and any other information you may choose to provide.
If you create an account
An account is optional. Everything on this site that makes sound or calculates something works without one. If you do create an account, this is the whole list of what is stored:
- Your email address, and the times the account was created and last signed in. There is no password – signing in works by a one-time link sent to that address, and those links are stored only as a hash, so nobody reading the database can sign in as you.
- What you save to your library: rooms and speakers, with the settings and measurements they contain, under the names you give them.
- Your membership periods, if you buy Pro: when each year started and ended, where it came from and what was paid.
- The confirmation you tick when you buy Pro: the sentence you confirmed, the date of the terms you confirmed it under, and when you did it. It is kept because it is what decides whether the 14-day right of withdrawal applies, and the seller has to be able to show it.
- Feedback you send from the account pages: the text, which page you were on, and your browser's user agent string. Your IP address is not stored with it.
The account row is created the moment you ask for a sign-in link, before you open it – that is how the link can be checked when it arrives. So if you type an address and never continue, an account with that address exists and nothing else. An unused link stops working after 72 hours, and you can have the whole row removed by writing to us.
There is no profiling, no advertising and no sharing of any of this with anyone except the two processors named below.
If you share a link
The room reflection auralisation tool can turn the settings you are listening to into a link that anyone can open. Sharing is a deliberate act: nothing you save or listen to becomes public unless you press the share button. Making a link needs an account; opening one does not, and never will.
What is stored when you do, and nothing else:
- The settings themselves – the room, the loudspeaker placement and the listening position – as a copy taken at the moment you shared them. Changing your own settings afterwards does not change what you shared.
- A title, if you gave one.
- A message, a nickname and one link back, if you are a Pro member and filled them in. These are published: they are shown on the link page to everyone who opens it. A nickname is the only place on this site where a name you chose is shown publicly, so pick one you are happy to be seen – and it may not be an email address, which the form refuses. You can change or clear all three afterwards, and clearing them removes them from the page.
- The address of the link. It is a random string unless you are a Pro member and chose one yourself, in which case it is the words you picked.
- The loudspeaker measurement, but only if you ticked the box for it. If you did, the sentence you confirmed and the time you confirmed it are stored with the link, because that confirmation is the whole reason the measurement may be published.
- The times the link was created and last opened, and how many times it has been opened – one number per link, so that you can see whether a link is still in use before you take it down. Nothing is stored about who opened it, from where, or when each open happened.
- Your account, if you were signed in. If you were not, the link is not connected to any person at all.
A shared link is public. Anyone who has it can open it, which is the point of it – it is meant to be posted in a forum thread. It is not listed anywhere on this site and search engines are asked not to index it, but the address itself is not a secret. Your email address is never shown on it, and neither is your IP address, which is not stored with the link at all. Opening someone's shared link adds one to that link's counter and tells them nothing else – not who you are, not where you are, not when you opened it.
Getting rid of one. If you were signed in when you shared, deleting your account removes the link as well. Either way – with an account or without – a link disappears on its own once nobody has opened it for a while, and you can write to the address at the bottom of this page to have one removed by hand.
How long each thing is kept
- Your account and library: until you delete them. Nothing expires on its own, and there is no inactivity sweep – a room you saved two years ago is still there.
- Sign-in links: 72 hours, then they are deleted whether used or not.
- Payment records: kept as accounting records, which in Finland means six years from the end of the accounting year. This is the one thing deleting your account does not remove; it is detached from you instead.
- Feedback: kept until it has been acted on, and detached from your account if you delete it.
- Shared links: 90 days from the last time anyone opened them, so a link that is being used stays and a link that nobody opens goes. Deleting your account removes yours immediately.
- Server log lines, and the sign-in abuse log: 14 days.
- Analytics: Google's own retention, if you accepted it.
How we use your information
We use the information we collect in various ways, including to:
- Provide, operate, and maintain our website
- Improve, personalize, and expand our website
- Understand and analyze how you use our website
- Develop new products, services, features, and functionality
- Reply to you, if you have written to us
There is no mailing list and no marketing: we do not send you email unless you have written first.
Log Files
The web server writes a line for every request it serves. That line contains your IP address, the time, the page, the referring page and your browser's user agent string. This happens for everyone, with or without an account, and it cannot be switched off – a server that does not log cannot be operated or defended against abuse. An IP address is personal data, so we say so here rather than claiming the log is anonymous.
These lines are deleted after 14 days, by a rotation rule that does nothing else. They are read only when something is broken or being attacked, and they are never combined with your account or used to build a profile. The IP address is not hashed, and that is a deliberate choice rather than an omission: a bounded retention with a stated reason is what actually limits this, and hashing the live log would mean putting another moving part in the path of every request.
One more log records your IP address together with the time, and only when a sign-in link is requested for an address that has no account here. It exists to stop one specific abuse: without it, a script could ask for links to thousands of made-up addresses, and each request would create a record here and send mail to somebody who never asked for it. The line holds nothing else – not the address that was typed, not what you did afterwards – and it is read by an automatic rule that temporarily blocks an address that keeps doing it. The block lifts by itself, and it gets longer each time the same address comes back, up to three months. The firewall remembers a blocked address for that long and nothing else about it. It is kept for 14 days like the server log, on the same rotation.
The site's own application log is separate and normally holds no personal data: sign-in problems are recorded by account number, and a failed email is recorded as a one-way fingerprint plus the domain, never the address itself. There is one exception, and it exists so that nobody loses money they have paid: if a payment arrives that cannot be matched to any account, the payer's email address is written to that log so the purchase can be assigned by hand. Deleting your account does not reach either log.
Cookies and Web Beacons
This is the complete list. There are no web beacons, tracking pixels or fingerprinting scripts on this site.
| Cookie | Set when | Kept for | What it does |
|---|---|---|---|
cc_cookie | You answer the cookie banner | 182 days | Remembers your answer so you are not asked again. Without it the banner cannot know that you already said no. |
PHPSESSID | Only when you sign in | 1 year | Keeps you signed in. If you never sign in, this cookie is never set – reading the site does not give you one, and neither does opening a link somebody shared with you. |
_ga, _ga_* | Only if you accept analytics | up to 2 years | Google Analytics. Not set if you decline, and not set at all if your browser sends Global Privacy Control. |
The first two are needed for the site to work as you asked it to; only the third one is a choice, and it is off until you make it. You can also delete all of them from your browser's settings at any time.
Analytics
This site uses Google Analytics to count visits and see which pages are read. It is loaded only if you accept the "Performance and Analytics" category in the cookie banner, and it sets cookies beginning with _ga in your browser. If you decline, the script is never loaded. You can change your choice at any time from the cookie settings link, and Google's own policy is at policies.google.com/privacy.
Google is a US company, so accepting analytics means this one piece of data may be handled outside the EU, under the standard contractual clauses and the EU–US Data Privacy Framework. Nothing else on this site leaves Europe: the server, its database and the sign-in email provider are all in the EU. If that matters to you, decline analytics – everything on the site works exactly the same either way.
What the tools store in your browser
The calculators and listening tests on this site run entirely in your browser. Audio you play, including any file you choose yourself, is never uploaded – it is decoded locally and it never leaves your computer.
Some tools remember settings so that you do not have to set them up again. This is kept in your own browser, in localStorage and sessionStorage, and it is not sent anywhere and not readable by us:
- the player's volume and whether its panel is collapsed
- the room reflection auralisation tool's room, speaker and listener settings, and – if you ask it to precompute a sharper directivity model – the result of that computation, which is a few hundred kilobytes
- the vertical reflections calculator's saved setups
Clearing your browser's site data for audioexperiment.com removes all of it.
Who else processes this data
Two companies handle parts of this on our behalf. They are processors: they may use the data only to do the job described here.
- Resend (Plus Five Five, Inc.) sends the sign-in emails. It receives your email address and the message containing the link. The account is configured for Resend's EU region, and click and open tracking are turned off – so the link in your mail is the real address it appears to be, and no pixel reports back when you open it. Resend's policy: resend.com/legal/privacy-policy.
- Stripe (Stripe Payments Europe, Ltd.) handles payment if you buy Pro. Payment happens on Stripe's own pages: this site never sees your card details. Stripe tells us that a payment succeeded, for which account, and how much – that is what the payment history is made of. Stripe's policy: stripe.com/privacy.
The site itself runs on a server in Europe, and its database is on that server. Google Analytics, if you accept it, is the one processor outside this list – see the Analytics section above.
Your data: export and deletion, without asking us
If you have an account, both of these are buttons on your membership page, and they work immediately:
- Export gives you one JSON file containing everything listed above – account, library, membership periods, purchase confirmations and feedback.
- Delete removes your email address, your sign-in links, your whole library and any links you have shared – a shared link stops working the moment you delete the account, so a link you posted in a forum thread will be dead. It cannot be undone.
Three things are deliberately kept when you delete, and they are no longer connected to you. Your membership periods stay, because a payment that happened is bookkeeping we have to be able to account for; the purchase confirmations stay with them, because they are part of the terms that payment was made under; and feedback you sent stays, because it is information about the site rather than about you – note that this includes the text you wrote and the browser user agent string that came with it, so if you put something identifying in the message, say so and it will be removed by hand. The account row that remains holds no address – it is replaced with a placeholder at a domain that cannot exist, so no mail can reach it and it identifies nobody.
If you would rather have it done by hand, or you no longer have access to the address you signed up with, write to the address at the bottom of this page.
Advertising
Audioexperiment.com carries no advertising, and there are no advertising partners or ad networks. No third-party ad servers, ad cookies or web beacons are used on this site. If that ever changes, this section will say what changed before it happens.
Third Party Privacy Policies
This Privacy Policy does not apply to other websites you may reach from links here. If you follow a link away from Audioexperiment.com, the site you land on has its own policy and its own practices.
You can choose to disable cookies through your individual browser options. To know more detailed information about cookie management with specific web browsers, it can be found at the browsers' respective websites.
California and other US states (CPRA and similar laws)
We do not sell or share personal information, and we never have. There is no advertising here, no ad network and no data broker. The "Do Not Sell or Share My Personal Information" link in the footer opens the cookie settings, because that is where the only choice there is to make actually lives.
Global Privacy Control is honoured. If your browser sends the
Sec-GPC signal, analytics is not loaded at all – the script is not
even sent to your browser – and you do not have to touch the banner.
The same cookie banner is shown everywhere in the world, and it asks before anything optional is loaded. That is the strictest of the models this site would have to satisfy, and it was chosen deliberately: telling them apart would require locating you by IP address, which would mean collecting a new piece of personal data in order to protect your privacy.
California residents have the right to know what is collected, to have it deleted, to correct it, and not to be treated differently for asking. Export and deletion are the buttons described above; for anything else, write to us.
GDPR Data Protection Rights
We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:
The right to access โ You have the right to request copies of your personal data. This is free, and if you have an account you do not need to ask: the export button gives you the file straight away.
The right to rectification โ You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete.
The right to erasure โ You have the right to request that we erase your personal data, under certain conditions.
The right to restrict processing โ You have the right to request that we restrict the processing of your personal data, under certain conditions.
The right to object to processing โ You have the right to object to our processing of your personal data, under certain conditions.
The right to data portability โ You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us – and note that erasure and portability are already self-service for account holders, as described above.
The legal basis for keeping your account is the contract you have with us by using it; for the membership records and the purchase confirmations it is the legal obligation to keep accounting records and to be able to show the terms a sale was made under; and for analytics it is your consent, which you can withdraw at any time from the cookie settings. The controller is the operator of this site, reachable at the address below. If you believe your data is handled wrongly, you can complain to your national data protection authority – in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi).
Children's Information
Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.
Audioexperiment.com does not knowingly collect any Personal Identifiable Information from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.
Contact
Write to contact.audioexperiment@gmail.com. There is one person reading it, so plain language works better than legal language.