Effective August 30, 2026
Soundfish privacy disclosure
A composition can remain in its self-contained URL fragment and in your browser. Hosted services receive additional data only when a feature needs them or when you send the composition elsewhere.
Composition data
Soundfish stores the complete canonical composition after the# in its URL. Browsers do not send that fragment in an ordinary HTTP request. The editor can also retain compositions in IndexedDB on your device. Clearing Soundfish site data removes that local browser library.
Anyone who receives a complete Soundfish URL can read the composition. If you paste the URL into ChatGPT, Claude, or another hosted agent, that provider receives the fragment and CLI output under its own data policy. Provider-opening links contain neither the prompt nor the fragment; you choose whether to paste it.
Optional account sync
Local editing does not require an account. If you sign in, Hraness Suite Accounts handles authentication and Soundfish associates cloud checkpoints with the resulting account identifier. Convex stores the canonical composition checkpoints needed for the synchronized library. Deleting a composition from My loops removes its account ownership and deletes canonical content after its final stored reference is gone.
Soundfish does not publish an automatic expiration period for cloud library checkpoints. Provider backups and security records can follow the hosting providers' own retention schedules.
Anonymous page analytics
The production site sends one cookieless, memory-only pageview for checked editor, documentation, and research routes to PostHog's US ingestion service. The event contains the canonical route and a fixed cookieless identifier. It creates no person profile and includes no URL query, fragment, referrer, composition content, account identity, automatic interaction event, replay, or advertising identifier.
Local development and preview deployments do not send these events. The application respects the browser's Do Not Track setting.
Soundfish mailing list
If you use the footer subscription form, your email address, the Soundfish list choice, the form source, and a short-lived Cloudflare Turnstile proof are sent to Hraness Accounts at account.hraness.com. Cloudflare verifies the anti-abuse proof. Hraness Accounts records dated consent, and Resend sends confirmation and subscribed messages from news.hraness.com. You are not subscribed until you confirm.
After confirmation, each newsletter message includes a Soundfish-specific unsubscribe link. Using it removes you from only the Soundfish list, without changing another product subscription or a separate general Hraness subscription.
Hosting and private-alpha processing
Vercel serves the website and can process ordinary request metadata needed to deliver and protect it. The optional synchronized library uses Hraness Suite Accounts and Convex as described above.
The separate audio-to-MIDI API remains a private alpha and is not the public composition editor. Authorized callers must acknowledge rights and third-party processing before uploading audio. Soundfish sends the audio to Klangio for transcription. The checked service caps input retention at 24 hours and MIDI artifact retention at 30 days; its capability document records Klangio's result-retention period as 14 days.
Control and contact
- Remove local compositions by deleting Soundfish browser data.
- Remove a synchronized composition from My loops.
- Keep a fragment out of hosted agents when the composition is sensitive.
For a privacy question or account-data request, use the support path. Start with a public mention that asks for a private channel. Do not include a composition URL, account identifier, or other sensitive data in the public message.