Privacy Policy - TandaBuilder
Last updated: September 2026 - version 26.9
TandaBuilder is designed around a simple principle: your audio files never leave your Mac, and your playlists, tandas and milongas only leave it if you choose to share or publish them (section 9). This page lists precisely the only data that is transmitted to our servers or those of third parties, and why.
1. Data that remains local
- Audio files from your library
- Metadata read from your files (title, orchestra, year, BPM, etc.)
- Playlists, saved tandas, milonga history, except what you choose to share or publish (section 9)
- Preferences, settings, theme, MIDI and audio configuration
- Album covers and Chromaprint fingerprints stored locally (
.externalStorage)
This data is stored in the app's sandbox container (App Store) or in ~/Library/Application Support/TandaBuilder Pro (Pro).
2. Network communications
| Service | Data sent | Purpose | Required? |
| api.tandabuilder.com (Catalog API) | Title, orchestra, duration, BPM, key | Automatic enrichment (Automatch) | Can be disabled via preferences |
| api.tandabuilder.com (AI Tanda) | Tanda criteria (style, orchestra, energy…) | Suggestion generation | Only if user clicks "Generate" |
| api.tandabuilder.com (AI Tanda tuning, Pro) | Metadata from locally composed tanda (title, orchestra, singer, year, genre, score) - a closed set of a few songs, never audio or full library | Reordering + tanda explanation | Pro, automatically after local generation |
| api.tandabuilder.com (Analytics) | Anonymous usage statistics (generator events, performance, library sizing) - no PII, no titles or files | Product improvement (see section 5) | Can be disabled via preferences |
| tandabuilder-license.jrth92.workers.dev (Pro only) | License ID + hashed hardware fingerprint (SHA-256 of machine UUID) | License validation, jailbreak detection | Required (license condition) |
| tandabuilder.com | No user data | Download updates (Sparkle) | Required (Pro) |
| Stripe | Payment data (Pro purchase) | Purchase and billing | If Pro purchase |
| Apple StoreKit (App Store only) | Apple ID, product ID | Subscription / in-app purchase | If in-app purchase |
| Apple ShazamKit | Audio fingerprint of song | Automatic recognition | Optional feature |
| Spotify Web API (User OAuth) | Search by title/artist | Enrichment from Spotify | If connected to Spotify |
| OpenAI / Anthropic | Indirect only: prompts transit through our API, never your files or full library | AI Tanda Suggester | If you click "Generate" |
| Resend.com | Purchase email address | Send license number after Pro payment | If Pro purchase |
| api.tandabuilder.com and tandabuilder.com (Sharing by link) | The metadata of the shared tanda or playlist, the same as in the exchange file (section 9) - never audio or file paths | Serve the link's page to anyone who holds it | Only if you share |
| api.tandabuilder.com and tandabuilder.com (Publishing, Pro) | Name of the milonga, date, venue and event if you entered them, your DJ name, five fields per track (title, orchestra, singer, year, genre), and the share image generated on your Mac | Your public DJ page (section 9) | Only if you publish |
None of these communications include your audio files themselves, nor your identifying information, except the email address provided for the Pro purchase and the DJ name under which you choose to publish.
3. What we do NOT do
- No ad tracking, no third-party analytics SDKs (no Firebase or Google Analytics)
- No Apple ad identifier (IDFA) used
- No personal data or individual profiling: the only statistics are anonymous, aggregated, and disableable (see section 5)
- No sale or sharing of user data
- No AI training on your personal data (see point 4 below)
4. Feedback 👍/👎 (optional)
When you click a thumbs up or down after an AI tanda suggestion, we record:
- The criteria you had selected
- The suggested tanda
- Your feedback (positive / negative)
This data contains no personal identifiers. It is used to improve the quality of suggestions via a fine-tuning dataset. You can disable this submission in AI preferences.
5. Anonymous usage statistics (optional)
To better understand which features are useful and where to focus our efforts, the app may send strictly anonymous usage statistics:
- usage events (tanda generation, playlist generation, library scan) with counters and execution times;
- the failure of an important operation, with its cause taken from a closed list (for example: import impossible for lack of access permission to the folder, or folder containing no recognized audio file). The path and the name of the folder concerned are never sent;
- a snapshot of your library sizing (number of songs, percentages of songs with BPM / tonality / metadata, average quality), at most once per day.
What is never sent: song titles, file names, paths, playlist content, email, license number. No IP addresses are retained on our server. The identifier attached to these statistics is an anonymous installation ID (random UUID), with no link to your hardware, license, or identity, and reset if you reinstall the app.
This data is hosted on our server in Europe (no third-party service, no Firebase or Google Analytics). Legal basis: legitimate interest (product improvement). You can disable this submission at any time in Preferences › General › Anonymous statistics.
6. Pro purchases - Stripe and license
When purchasing a Pro license:
- Stripe collects your payment information (secure PCI-DSS process, we never have access)
- Our Cloudflare Workers backend stores: email, license ID, activation history (max 3 by default)
- Resend.com sends your license key by email
Your payment data is managed by Stripe according to their policy. We do not store any credit card numbers.
7. Web account (tandabuilder.com)
The account is optional: ear training, orchestra pages and public search all work without one. If you create one:
- What we collect: your email address, the site language, a public nickname if you choose one, and what you produce while signed in (blind test progress, duels, favourites, saved tandas).
- Why: to open your session, keep your progress and your collections, and place you in the leaderboard if you have chosen a nickname. Legal basis: performance of the service you ask for by creating the account.
- Where: your identity (address, nickname, access right) is stored at Cloudflare, in a D1 database. Your usage data sits on our server in Europe, which never receives your email address: the two are linked only by an account identifier.
- Who else: Resend.com delivers the sign-in link. If you sign in with Google, Google passes us your identifier, your address and its verification status, nothing more.
- Your nickname is public as soon as you choose one: it appears in the leaderboard and to your opponents. Without a nickname, you play unnamed.
- How long: as long as the account exists. An unused session expires after 90 days, and an unused sign-in link is deleted the next day.
- Pro licence: if your account address is the one used for a Pro purchase, web access is granted on that basis. The comparison happens between our two services, without passing anything to a third party.
- Deletion: write to contact@tandabuilder.com. The account and the attached data are deleted.
8. Newsletter (optional)
Creating an account subscribes you to nothing.
- Consent: you tick a box in your member area, separate from account creation. It is the only basis on which we write to you anything other than a service message.
- Content and frequency: a few messages a year about what is new in TandaBuilder and on the site.
- Withdrawal: untick the box in the same place, or use the unsubscribe link in every message. It works without signing in, and the date of your consent is erased at the same time.
- Data used: your email address and the site language, so we can write in your language. No address is ever sold, passed on or rented.
- Who delivers: Resend.com.
9. Sharing and publishing sets
By default, your tandas, your playlists and the history of the milongas you played (your "sets") stay on your Mac (section 1). Nothing leaves it without an explicit action on your part. What you share by link or publish can be withdrawn in one action; a file you have handed to someone cannot be taken back. Three actions, which do not have the same reach.
- Sharing by file: the application writes an exchange file that you hand to whoever you want. It does not pass through any of our servers. It contains the name, notes and tags of the tanda or playlist, the date it was played, and for each track its metadata (title, orchestra, singer, year, genre, duration, tempo, key, community catalog identifier and acoustic fingerprint). Never the audio or the paths of your files. The author name you entered in the settings, if any, is included too.
- Sharing by link (web account): the same metadata is stored on our server in Europe, attached to your account, and served to anyone who has the link. The link is randomly generated and we ask search engines not to index the page, but this is not a promise of confidentiality: anyone who receives the link can pass it on. Regenerating the link invalidates the previous one, and deleting the share erases the data from our server. It is kept as long as the share exists, and at most as long as your account exists.
- Publishing on your DJ page (Pro license): the milonga is displayed publicly on tandabuilder.com, under your DJ name, on a page that search engines may index. What is published: the name of the milonga, its date, the venue and the event if you entered them (an event chosen from the agenda links to its public page, an event typed by hand is only your statement). For each track, five fields and five only: title, orchestra, singer or instrumental, year, genre. What is never published: the audio, the paths of your files, the exact take (catalog identifier and fingerprint), the duration, the tempo, the key and your playback settings. A share image is generated on your Mac at the time of publication and sent to the site as is. The pages are hosted by Cloudflare, a US company (see the legal notice, section 9 of the terms), the publication data on our server in Europe. It is kept as long as the milonga is published, and at most as long as your account exists. Unpublishing, from the application or by writing to us, erases this data from our server, and the site is rebuilt without it, usually within minutes and at the latest the next day; copies made in the meantime by third parties or by search engines do not depend on us.
Your DJ page and medialuna.org. Your DJ identity (name, bio, photo, upcoming dates) is managed on medialuna.org, our events platform, where your Pro license opens a DJ profile. Your page on tandabuilder.com displays it from its public feed, and it is the publication of that profile that makes your page visible: unpublishing it on medialuna.org also removes your page here. In return, medialuna.org may display the sets you publish here. Nothing flows between the two sites other than what you have already made public on one or the other.
The people you name. By entering a venue, an event or other people, you publish information that does not concern only you. Name a natural person only with their consent. Anyone named in published content may request its removal at contact@tandabuilder.com.
Legal basis: performance of the service you ask for by sharing or publishing. For the people you name, we rely on our legitimate interest in displaying the milonga as you describe it; they may object by requesting removal. You may at any time withdraw content, request a copy of what is published under your name, or request its deletion (section 10).
10. Your rights (GDPR)
You can at any time:
- Request deletion of your license and associated data (Pro backend)
- Request a copy of your data stored on our server
- Revoke Spotify authorization in your Spotify account preferences
- Request deletion of your web account and the attached data
- Withdraw a set shared by link or published, or request the removal of content that names you (section 9)
For any request: contact@tandabuilder.com. We reply within one month. You may also lodge a complaint with the CNIL (cnil.fr).
11. Publisher
Jan TUMPACH-LEGO - independent publisher.
Contact: contact@tandabuilder.com.