Privacy Policy for VOISEN
Last updated: 19.6.2026
This Privacy Policy explains how personal data is collected, used, and protected in connection with the VOISEN website, standalone application, and VST plugin available through voisenvst.com.
1. Controllers
The controllers of personal data processed under this Privacy Policy are:
Jan Galajda
Czech Republic
Lukáš Kečkéš
Slovak Republic
Contact Email: support@voisenvst.com
The controllers are responsible for deciding how and why personal data is processed. Under the GDPR, users have the right to know the identity and contact details of the controllers.
2. Scope of this Policy
This Privacy Policy applies to:
- the VOISEN website;
- the VOISEN standalone desktop application;
- the VOISEN VST plugin;
- account registration and login;
- subscription and access verification;
- audio file upload, processing, and output delivery;
- support communications and bug reports;
- locally generated diagnostic logs submitted by the user through a bug report feature;
- and optional marketing communications where consent is provided.
3. Age Restriction
VOISEN is intended only for individuals who are at least 18 years old. The service is not intended for children. If it is discovered that an account has been created in violation of this rule, the account may be suspended or deleted. GDPR contains additional safeguards for children using online services, which is why an 18+ restriction should also be stated clearly in onboarding and terms.
4. Personal Data Collected
Depending on how the service is used, the following categories of personal data may be processed:
- Account data, such as email address and authentication-related records.
- Subscription and access data, such as whether the user came from Patreon, whether the user has an active paid membership, whether Patreon verification was completed, whether the user authorized Patreon to provide membership-related information, and whether the account is eligible to access the service.
- Usage data, such as whether the app or plugin has been opened, certain service activity timestamps, and limited in-app event information relevant to troubleshooting or product reliability.
- Support and bug report communications, including emails, bug report titles, bug descriptions, attachments, screenshots, and any other information voluntarily provided in support requests or bug reports.
- Technical and security data, including provider logs, authentication logs, infrastructure events, limited crash/debugging information, app type information (for example, standalone application or VST plugin), and locally generated diagnostic logs submitted by the user to help investigate a reported issue. Depending on the circumstances, such logs may include technical identifiers, device or environment details, host application details, timestamps, file-related metadata, or other information associated with the reported problem. Providers may also process IP addresses and similar technical identifiers by default.
5. How Personal Data Is Collected
Personal data may be collected:
- directly from the user during registration, login, upload, support contact, bug report submission, or newsletter sign-up;
- automatically through use of the VOISEN app, plugin, and related systems;
- from locally generated diagnostic logs created on the user’s device and transmitted to the operator only if the user chooses to submit a bug report;
- from Patreon for subscription and access verification, including where the user chooses to start a Patreon verification flow on VOISEN, is redirected to Patreon, and authorizes Patreon to confirm membership-related information needed to determine eligibility for access;
- and from service providers used for authentication, storage, infrastructure, and email delivery.
6. Purposes and Legal Bases
Personal data is processed for the following purposes and legal bases under Article 6 GDPR:
- To create and manage user accounts, provide login functionality, and operate the service, based on performance of a contract.
- To verify Patreon membership status, determine whether a user is eligible to create an account or activate paid access, and control access to paid features, based on performance of a contract. This may include a Patreon verification flow initiated by the user through VOISEN, followed by Patreon authorization and confirmation of membership-related status. Membership status may also be checked periodically in the background, approximately once per hour.
- To receive, process, and return uploaded audio files and generated stems, based on performance of a contract.
- To provide transactional communications, such as login or access-related emails, based on performance of a contract or legitimate interests where appropriate.
- To maintain service security, detect abuse, diagnose failures, investigate bugs, debug issues, and improve reliability, based on legitimate interests. Legitimate interest may be used where the processing is necessary for secure and stable operation of the service.
- To receive and review bug reports, including submitted diagnostic logs, screenshots, app type information, and related technical details, and to respond to support requests, based on legitimate interests and, where necessary, steps taken at the user’s request before entering into a contract.
- To send optional marketing emails, only where the user has given consent through a separate opt-in mechanism. Marketing consent can be withdrawn at any time.
7. Audio Uploads and Processing
Users may upload audio files to the service for source separation and related processing. The uploaded source files and generated output stems are processed on infrastructure used to perform the requested separation task.
Uploaded source files are stored temporarily and are deleted within 24 hours after upload or earlier if replaced by a new processing job, whichever occurs first. Generated output stems are stored temporarily and are deleted within 24 hours after creation or earlier if replaced by a new processing job, whichever occurs first. Fixed and limited retention periods are generally more consistent with GDPR storage-limitation principles than indefinite retention.
Users may be able to re-download generated outputs during that temporary availability period.
8. File Names and Metadata
VOISEN may store limited file-related metadata, including a file name or altered file name associated with a processing job. Because file names may include personal or identifying information, users should avoid uploading files with unnecessary sensitive or personal naming where possible. Data minimisation under GDPR means only data necessary for the stated purpose should be stored.
9. Support Communications and Bug Reports
When contacting support or submitting a bug report, users may provide personal data contained in the message itself, the bug report title or description, attached files, screenshots, diagnostic logs, app type information, or other materials.
Diagnostic logs used for bug reporting are generated locally on the user’s device and are transmitted to the operator only if the user chooses to send a bug report. These materials are processed for the purpose of responding to the request, reproducing and troubleshooting issues, diagnosing failures, improving service reliability, and protecting the service from misuse.
Users should avoid including unnecessary sensitive or personal information in bug descriptions, screenshots, file names, or other materials submitted through support or bug report features.
10. Marketing Communications
If marketing communications are offered, they will only be sent to users who separately opt in. Marketing consent must not be bundled with account creation or required to use the paid service. Users can unsubscribe from marketing emails at any time, and unsubscribing from marketing does not affect account access or core service use.
Transactional or service-related emails, such as account and access emails, may still be sent where necessary to operate the service.
11. Recipients and Processors
Personal data may be processed by third-party service providers that help operate VOISEN, including providers for:
- authentication and database services, such as Supabase;
- email delivery, such as Resend;
- subscription verification and membership-related access checks, such as Patreon;
- infrastructure, hosting, storage, and compute services, including providers such as Render and Runpod/AWS-related infrastructure used for file processing and delivery.
These providers may process personal data on behalf of the controller in accordance with their own service roles and applicable data processing arrangements.
12. International Transfers
Some service providers may process personal data outside the European Economic Area. Where this happens, appropriate safeguards should be used as required under applicable data protection law, such as standard contractual clauses or another valid transfer mechanism where applicable.
13. Retention
Personal data is retained only for as long as necessary for the purposes described in this Privacy Policy, taking into account contractual necessity, security, support, dispute resolution, and legal obligations. GDPR requires that data be kept no longer than necessary for the purposes for which it is processed.
In particular:
- uploaded source files are retained for up to 24 hours or until earlier replacement by a new processing job;
- generated output files are retained for up to 24 hours or until earlier replacement by a new processing job;
- account and subscription records are retained while the account remains active and for a limited period afterward where necessary for legal, security, fraud-prevention, or dispute-related purposes;
- support communications are retained for as long as reasonably necessary to respond to the request and maintain service integrity;
- consent records for marketing preferences may be retained as necessary to demonstrate consent status or opt-out history.
Although files may be deleted from active systems according to the retention schedule above, limited copies may temporarily remain in provider-managed logs, caches, or backups where applicable. Public provider documentation indicates that default logging and retention may exist for services such as Supabase, Render, and Runpod, and exact retention may depend on account plan or configuration.
14. User Rights
Subject to applicable law, users may have the right to:
- request access to their personal data;
- request correction of inaccurate personal data;
- request deletion of personal data;
- request restriction of processing;
- object to certain processing;
- request data portability where applicable;
- withdraw consent at any time where consent is the legal basis; and
- lodge a complaint with a competent supervisory authority.
The right to deletion is not absolute and may be limited where retention is necessary for legal claims, compliance, or other lawful reasons.
15. How to Exercise Rights
Privacy-related requests, including account deletion requests, can be sent to support@voisenvst.com. A request may need to be verified before action is taken in order to protect the account and prevent unauthorized deletion or disclosure.
16. Security
Reasonable technical and organizational measures are used to protect personal data and reduce the risk of unauthorized access, loss, misuse, or disclosure. However, no method of internet transmission or electronic storage can be guaranteed to be completely secure.
17. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time. The latest version will be made available on the website and, where appropriate, through the app or plugin. Material changes may also be communicated by email or through the service interface.