Privacy
What we keep, and why
The short version: your recordings never leave your device, the site does not track you, and what we keep is what you type into the forms here plus what the beta build reports about itself.
Updated 29 September 2026 · English edition, revision 1
All of it, in five lines
- Your recordings stay with you. Audio, video, projects, stems and transcripts are made and kept on your device. None of it reaches us.
- No cookies, no analytics on this site. Nothing written to your browser.
- Three forms where you leave us data on purpose: the invite request, the contact form and the erasure request.
- The beta build reports about itself: that it is installed and in use, and when it crashed. Never what you recorded.
- One third party on this site, and only once you start filling in a form: the Cloudflare anti-spam check.
1 · The Multitake app
Multitake records, aligns and edits on your device. We receive none of what you record. Stem separation and transcription run on the device too, once their models are downloaded.
The app goes online for these things, and these only:
- The state of the beta — which versions are still active and which invite
codes are valid — read from our server,
api.multitake.studio, with a copy on GitHub if ours does not answer. The invite code itself is checked on your Mac against a list that holds only fingerprints of the codes. - Updates, downloaded from GitHub.
- Models, downloaded once when you first use the feature that needs them: stem separation from GitHub, transcription from Hugging Face.
- Song search: when you look a song up to fetch its details and cover, what you type goes to Apple's public iTunes catalogue.
Whoever answers each of those requests sees your IP address, as with any request. Apart from the beta reporting below, none of them carries data of yours.
2 · What the beta build reports
Taking part in the beta means testing the app, and a test we cannot see is no test. The beta build therefore sends our server three kinds of record, described here before you ask for an invite.
- Install record. A random number the app makes up at first launch (not a hardware identifier), the fingerprint of the invite code it was opened with, the app and macOS versions, and how many times the app was opened and for how many seconds it was in use since the last record. At most once an hour.
- Crash reports. If the app ended badly, at the next launch it sends that random number, the versions, the language, and — when there is one — the technical trace of the error. Nothing you recorded or named.
- Bug reports, only when you send one from Report a problem: what you write, what you choose to attach, and a technical summary shown in the form before you send it (app version, macOS version, Mac model, processor cores, memory, language, appearance, stem model).
These records are linked to your invite code, and so to you. They are used to know whether the build works and is used, to fix what breaks, and to answer your reports. The lawful basis is the beta you signed up for (GDPR Art. 6(1)(b)) and our legitimate interest in software that works (Art. 6(1)(f)). They are kept until six months after the beta ends. If you erase your data, the code goes and these records no longer lead back to your name.
3 · The invite request
You ask for a code with the request form: what you type there reaches our server.
- What we ask. Name and email, both required. If you like, your Mac and audio interface, the macOS version and a couple of lines about what you would record.
- What is recorded with it. The IP address the form was sent from, the moment it arrived, the version of this notice you consented to and the version of the Beta terms you accepted. The IP address makes abuse of a form open to everyone traceable; the two versions show which text you had in front of you (GDPR Art. 7(1)).
- What it is for. To decide on the request and to answer you. If it is accepted, to issue an invite code in your name, so that it can be revoked.
- Lawful basis. Your consent (GDPR Art. 6(1)(a)), given by ticking the box on the form. The box is never ticked for you, and the form does not send without it. Accepting the Beta terms is a separate box: it is a contract, not a consent, and it is kept to perform and evidence that contract (Art. 6(1)(b)).
- Where it goes. To the server that runs Multitake's backend, under the developer's control. It is not sold or shared, and it goes through no advertising, analytics or newsletter service: there are none here.
- How long. Until six months after the private beta ends. Sooner, if you ask.
- What you get. The invite with instructions and, if needed, a notice about important updates. No marketing. The reply goes out through an ordinary mail provider, which handles your address the way it handles that of anyone who receives an email.
Sending the form twice does not create a second request: the address is the key, and a later submission updates what is already there. The form gives the same answer in both cases, or it would be a way of finding out which addresses have asked. When a request arrives, a notification tells the developer there is something to read — without your name, your address or anything you wrote.
4 · Erasing your data
Withdrawing consent is as easy as giving it: there is a page for it, Erase my data. Replying to any email from Multitake and asking works just the same.
- What is deleted. The access request — name, email, the Mac, what you wrote, the IP address it came from — every invite code issued to you, and the messages you sent through the contact form with our replies. Whole rows, not a flag on them. An erased code stops working.
- It waits for you to confirm. An email goes to the address you gave, with a button to confirm and one to cancel, and nothing is deleted until you press the first. It is the identity check the GDPR asks for where there is reasonable doubt about who is asking (Art. 12(6)).
- If you never answer. Two reminders, after 7 and 15 days. At 30 days the request lapses without deleting anything, and a final email says so.
- If it wasn't you. Press “cancel” in that email: nothing is touched.
- How long it takes. A month at the outside from your confirmation (GDPR Art. 12(3)), normally a few days.
Asking to be erased creates a record of its own — the address, what you wrote, the IP address and a trace of the emails sent — kept to carry the erasure out and to show it was done in time. The basis is the legal obligation to answer you (GDPR Art. 6(1)(c)), not consent: that is why that form has no box to tick. When nothing of yours is left, that record goes too.
5 · The contact form
- What we ask. Name, email, a topic and your message.
- What is recorded with it. The IP address it was sent from, the moment it arrived and the version of this notice shown next to the form.
- What it is for. To read your message and answer you. The answer goes by email, and a copy is kept with your message.
- Lawful basis. The legitimate interest in answering whoever writes to us (GDPR Art. 6(1)(f)) and, when you write to exercise a right, the legal obligation to answer (Art. 6(1)(c)). There is no box to tick: writing is your own initiative.
- How long. As long as the conversation needs. It is deleted when you ask.
Please do not send recordings or sensitive data through the form: describe the setup instead.
6 · The anti-spam check on the forms
The forms are protected by Cloudflare Turnstile. It sets no cookies, does not
profile you and is not used to follow you from site to site. It does make a request to
challenges.cloudflare.com, which discloses your IP address and your browser's user
agent to Cloudflare, Inc., acting as a processor under the European Commission's Standard
Contractual Clauses. The lawful basis is the legitimate interest in keeping a form open to
everyone usable (GDPR Art. 6(1)(f)).
It loads when you start filling in a form, not when the page opens. Read the page and leave, and no request to Cloudflare is made at all.
7 · This website
This site does not use cookies and writes nothing to your browser's storage. There is no analytics, no tag manager, no pixel and no advertising. The typeface and the images are served from this domain: apart from the anti-spam check above, no page makes a request to anyone else. That is why there is no cookie banner: nothing here needs one.
The server keeps an ordinary access log — the IP address of each request, the time, the file requested, the response code and the browser's user agent — to keep the site running and to notice abuse, on the basis of legitimate interest (GDPR Art. 6(1)(f)). It is not combined with anything else, and it is discarded when that purpose no longer needs it.
The site and the backend run on Oracle Cloud Infrastructure, acting as processor solely for hosting them.
The builds are published on GitHub. Pressing “Download” takes you there, under GitHub's own privacy statement.
8 · Your rights
Over what we hold about you, you can ask at any time for access, a copy, correction, erasure, restriction, or object to its processing. We answer within thirty days. You also have the right to complain to your data protection authority; in Italy that is the Garante per la protezione dei dati personali.
For erasure there is a form. For everything else, use the contact below.
9 · Controller and changes
- Controller
- Fabio Della Selva — developer of Multitake
- Contact
- the contact form
- Scope
- The Multitake app, its private beta and this website, multitake.studio
If this notice changes, the date at the top changes with it. If the change concerns the beta data, we also write to those who have sent a request.