Clean Take
FeaturesHow it worksPricingFAQAbout
Join beta

Clean Take — Privacy Policy

Version: 1.0-draft Last updated: May 17, 2026

This Privacy Policy explains how Clean Take, a service operated by ASTROLABE CAE (ASTROLABE), a French simplified joint-stock company (SAS) registered under SIREN 851 726 588, with its registered office at 8 place du Colombier, 35000 Rennes, France, collects, uses, retains, shares and protects personal data in the context of the iOS mobile application, website, APIs, cloud services, collaborative workspaces and related features (collectively, the "Service").

For any privacy-related question: privacy@cleantake.app

Core privacy commitment — Clean Take is offline-first Most of the audio analysis of your rehearsal (take segmentation, transcription of conversations, tempo and chord detection, song clustering, insight extraction) runs directly on your device, with no network communication. No audio recording is transferred to our servers until you explicitly choose to publish the session. See Section 4.


1. Who is the data controller?

Unless otherwise stated, the data controller is:

ASTROLABE CAE (ASTROLABE) 8 place du Colombier 35000 Rennes, France SIREN: 851 726 588 EU VAT: FR53 851 726 588 Email: privacy@cleantake.app

In certain cases, particularly when a studio, music school, conservatory, label or other organization uses Clean Take on its own account, Clean Take may act as a data processor for content or data processed on behalf of that professional customer. In such cases, a Data Processing Addendum (DPA) supplements this policy.


2. What categories of data do we process?

2.1 Account and identification data

  • name, first name or pseudonym;
  • email address;
  • internal account identifier;
  • avatar (auto-generated colored avatar with initials, or uploaded profile photo);
  • delegated authentication elements (Apple ID, Google, Facebook) if you choose these providers;
  • favorite instruments selected at signup (vocals, guitar, bass, drums, keyboards, winds, strings, percussion, other);
  • language preferences (FR / EN / ES / DE), theme (Clean Take / Studio / Neon), app icon, timezone;
  • group identity color if you belong to a band.

2.2 Audio content and files you create

  • Session master file: a continuous audio recording for the entire rehearsal, captured locally on your device as WAV PCM lossless or AAC 256 kbps (mono or stereo per your settings);
  • Takes auto-segmented from the master via AI segmentation;
  • Manual markers placed during recording;
  • Interludes: discussions between songs, captured as distinct segments;
  • Instrument calibrations: sound samples of your instrument (timbre, dynamics) to improve later stem separation;
  • Audio imports: audio files you import from the Files app, Mail or other apps via the iOS share sheet;
  • Premium processing outputs (if enabled): cleaned audio, instrument-separated stems, chord charts, rehearsal reports;
  • Lineage: editing history of a take (split, merge, trim, extend, reanchor).

2.3 Audio metadata generated on-device

Our application analyzes recordings locally on your device to produce:

  • Harmonic fingerprint (12-dim chroma): musical signature of each take;
  • Temporal harmonic sequence: chord progression over time;
  • Rhythmic descriptor: onset and rhythmic pattern analysis;
  • Tempo estimation (BPM) with octave-error tolerance;
  • Energy analysis (RMS);
  • Vocal coverage detection (silence / minimal / moderate / dominant);
  • Voice Activity Detection (VAD) via the Silero model, to isolate speech from music;
  • Clustering: automatic grouping of takes by song;
  • Confidence levels associated with each suggested association.

This metadata is computed on your device, stored in a local SQLite database (GRDB), and does not leave your device until you explicitly publish the session.

2.4 Transcriptions and extracted insights

When you enable transcription:

  • Text transcription of interludes (spoken exchanges between takes), performed by Whisper.cpp directly on your device (tiny or base models, in FR / EN / ES / DE or multilingual), or as a fallback by Apple's SpeechAnalyzer framework;
  • Structured insights extracted from transcriptions: positive feedback, identified problems, decisions made, action items — these insights are computed on-device from the transcribed text;
  • Textual fingerprint of transcriptions, for deduplication;
  • Automatic summaries per take, based on insights from adjacent interludes.

⚠️ Important: transcription may capture sensitive conversations between musicians. You remain responsible for the use of transcriptions and for obtaining the consent of recorded persons (see Section 11).

2.5 Group metadata

If you create or join a group:

  • group name, avatar, identity color;
  • list of members and their roles (owner, admin, member);
  • instruments associated with each member;
  • permissions and entitlements (debug inspector, unlock, budget management, etc.).

2.6 Collaborative communications

  • Chat messages in group conversations (text, take shares, file shares);
  • Polls and votes: availability, song choice, yes/no votes — including guests responding via public link without an account (see specific case in Section 7);
  • Collaborative rating of takes (1-5 stars);
  • Text comments anchored to a precise moment of a take;
  • Song proposals and their discussions.

2.7 Repertoire and setlists

  • catalog of the group's songs (title, artist, key, BPM, notes);
  • ordered setlists (for rehearsal or concert);
  • mastery milestones (progression templates: structure, arrangement, stage, etc.);
  • progress per song and per milestone;
  • song proposals and group votes.

2.8 Planning and calendar

  • dates and times of rehearsals and concerts;
  • recurrence (weekly, biweekly, etc.);
  • concert venues: address, city, geocoding (latitude/longitude);
  • setlist associated with each session or concert;
  • synchronization with your native iOS calendar (via EventKit) if you enable it — in that case events are created/read in your device's calendar, without transiting our servers.

2.9 Budget and expenses

If you use the budget feature:

  • group expense records (amount, label, category, date);
  • splits between members (equal, weighted, individual);
  • balances per member.

2.10 Technical and logging data

  • IP addresses and timestamps;
  • device identifier, model, operating system (iOS), application version;
  • device language;
  • connection events, errors, technical logs;
  • performance metrics, latency, sync status;
  • session identifiers, technical authentication tokens.

2.11 Telemetry and product analytics

  • product usage events (screens visited, actions performed);
  • aggregated and de-identified metrics;
  • reliability signals, crashes, errors, diagnostics;
  • statistics useful for observability, security and support.

2.12 Payments and subscriptions (Apple In-App Purchase)

Paid purchases and subscriptions are managed exclusively through Apple In-App Purchase (StoreKit 2). Apple processes your payment; we do not have access to your credit card data. We process:

  • subscription status (active, expired, in trial);
  • subscribed offer type;
  • Apple transaction and receipt identifiers;
  • server notifications received from Apple (App Store Server Notifications V2).

2.13 Push notifications

If you enable notifications:

  • your device's push token;
  • notification preferences (chat, planning, sharing, processing, etc.);
  • delivery and interaction events;
  • notifications transit through Firebase Cloud Messaging (FCM) (see Section 8).

2.14 Spotify integration (optional)

If you connect your Spotify account (see Section 12.1).


3. For what purposes do we use your data?

3.1 Providing the Service

Account creation and management, authentication, recording, storage, synchronization, sharing, collaboration, workspace and permission management, requested audio and AI features.

Legal basis (EU/EEA): performance of the contract.

3.2 Security and defense of our systems

Prevention of unauthorized access, detection of abuse, infrastructure and account security, evidence retention for incidents.

Legal basis: legitimate interest, and where applicable legal obligation.

3.3 Support, maintenance and improvement

Bug diagnosis, stability improvement, error tracking, user assistance, prioritization of product evolutions.

Legal basis: legitimate interest; consent where required for certain non-essential analytics.

3.4 Service communications

Transactional and security emails, notifications of important changes, account or incident status.

Legal basis: performance of the contract, legitimate interest, or legal obligation.

3.5 Push notifications

Inform you of a message, share, invitation, completed processing, calendar event.

Legal basis: performance of the contract for service-related notifications; device setting.

3.6 Subscription management and accounting compliance

Purchase verification, paid feature activation/deactivation, compliance with accounting, tax or legal obligations.

Legal basis: performance of the contract and legal obligation.

3.7 Legal compliance and defense of our rights

Response to authority requests, defense in court, regulatory compliance.

Legal basis: legal obligation and legitimate interest.


4. On-device commitment and explicit publication

Clean Take is designed on the offline-first principle:

  • All audio recordings (master + takes) are first stored locally on your device;
  • All audio analysis (segmentation, transcription, chroma, tempo, chords, clustering, insights) runs on-device;
  • None of this content is transferred to our servers until you explicitly choose to publish the session.

Explicit publication is a conscious action on your part. Until it occurs, your session stays on your device and is not accessible to Clean Take / Astrolabe.

After publication, master audio files and takes are encrypted in transit (TLS) and at rest (S3 server-side encryption) on our Scaleway infrastructure in France.


5. Do we use your content to train AI models?

No. Unless expressly stated and with your explicit opt-in, Clean Take does not use your private content (audio, transcriptions, insights, messages, group metadata) to train or fine-tune general-purpose generative AI models.

Clean Take may, however, use technical telemetry data, operational logs, performance and reliability signals, and aggregated or de-identified product usage data to operate, supervise, secure, maintain and improve the Service.


6. Who receives your data?

On a need-to-know basis:

  • Authorized personnel of Clean Take / ASTROLABE CAE;
  • Administrators of your group or owners, for data shared in their space;
  • Sub-processors for infrastructure and services (see Section 7);
  • Apple for in-app purchases and App Store distribution;
  • Third-party services you have explicitly chosen to connect (see Section 12);
  • Competent authorities if required by law or for the defense of our rights.

7. Sub-processors and service providers

CategoryProviderData concernedLocationSafeguards
Hosting (compute, storage, database, processing queue)Scaleway SAS (Paris, France)Account, published audio, metadata, group communications, planning, budgetFrance (EU)Native GDPR, French hosting
Push messagingFirebase Cloud Messaging (Google LLC)Push token, delivery eventsUnited StatesStandard Contractual Clauses (SCCs), EU-US Data Privacy Framework
App Store distribution and in-app paymentsApple Inc.Transaction ID, receipt, subscription statusUnited StatesData Privacy Framework, Apple DPA
Authentication (if used)Apple, Google, FacebookUser ID, email, name — strictly the minimumUnited StatesSCCs / Data Privacy Framework
Music catalog (opt-in only)Spotify ABSpotify user ID, selected playlistsSweden (EU) + United StatesGDPR, see Section 12.1
Crash reporting and observabilitySentry or Firebase Crashlytics (selection in progress — see updates)Anonymized logs, device ID, app versionUnited StatesSCCs / Data Privacy Framework

The up-to-date list of sub-processors is maintained at cleantake.app/privacy/subprocessors (to be published).


8. Where is your data hosted?

Our primary hosting for V1 is Scaleway in Paris (France).

Published audio files, databases and the processing queue are hosted in France. Push notifications transit through Firebase Cloud Messaging (Google, United States) — see Section 9.

A multi-region strategy may be deployed later to reduce latency for non-European users; this policy will be updated accordingly.


9. Transfers outside the European Economic Area

Some of our sub-processors are located in the United States (Apple, Google/Firebase, Spotify in part). When personal data is transferred outside the EEA, we implement the appropriate safeguards required by applicable law:

  • Adequacy decision (EU-US Data Privacy Framework) where applicable;
  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • additional contractual, technical and organizational measures where necessary.

10. How long do we keep your data?

CategoryDuration
Account dataFor the lifetime of the account, then a 30-day grace period before definitive deletion
Published audio content and metadataFor the lifetime of the account / group, until deletion by user or admin
Chat messages and collaborationsWhile the group is active, unless previously deleted
Application and API logs90 days
Security logs (investigations)Up to 12 months when justified
Crash reports and diagnostics90 to 180 days
Product analytics (raw)13 months max, then aggregation / anonymization
Accounting data (IAP)As required by regulation (10 years in France for accounting records)
System backups30 days max
User data after account deletionDefinitive purge within 30 days, unless legal obligation (e.g. billing)

11. Microphone, recording and third-party consent

Clean Take uses your device's microphone to capture your rehearsals. You are responsible for how you use the microphone:

  • Obtain the consent of recorded persons (group members, guests, audience);
  • Comply with local laws on recording conversations (some jurisdictions require all-party consent);
  • Do not record in prohibited contexts (school premises without authorization, private spaces of others, communications protected by professional secrecy).

Clean Take provides a clear visual indication (Dynamic Island, Lock Screen widget, in-app animation) whenever a recording is active.


12. Third-party services and integrations

12.1 Spotify (optional integration)

If you choose to connect your Spotify account, Clean Take uses Spotify's official Web API to read the information you have explicitly authorized us to access. This integration is optional — you can fully use Clean Take without connecting Spotify.

Authorization flow. The connection uses Spotify's standard Authorization Code with PKCE flow. You consent to a list of scopes (read your basic profile, your private playlists, and the collaborative playlists you participate in) directly on Spotify's consent screen. We never see your Spotify password.

What we collect from Spotify:

  • your Spotify user ID and public display name (via /v1/me);
  • when you initiate a playlist import: metadata of the playlists you select — playlist name and, for each track, artist name(s), title, album, ISRC code, Spotify track ID, and cover URL (if available);
  • OAuth tokens (access token and refresh token) issued by Spotify.

What we never collect from Spotify:

  • your Spotify password or any payment information;
  • audio content streamed by Spotify;
  • your listening history, queue, library, recommendations or social graph;
  • data about other Spotify users you follow.

How we use it. Spotify data is used only as song metadata to populate your group's repertoire references in Clean Take. The audio that Clean Take analyzes is always your own microphone recordings — never Spotify content. We never use data from Spotify to train AI models and never share it with third parties beyond what is necessary for Service operation.

How we store it. Metadata from Spotify is stored with your account data in our primary European hosting region (Scaleway, Paris). OAuth tokens are encrypted at rest with AES-256-GCM via a key managed separately from the database, and never returned to clients or written to application logs.

Retention. Imported track references follow the retention policy applied to the rest of your account content (Section 10). When you disconnect Spotify or delete your account, stored OAuth tokens are permanently deleted.

How to disconnect. At any time via:

  • Settings → Integrations → Spotify → Disconnect in the Clean Take app;
  • or directly from your Spotify account at https://www.spotify.com/account/apps/.

Disconnection removes our ability to fetch new data but does not automatically delete song references already imported into your group's repertoire — you can remove them manually or delete your account to wipe everything (Section 13).

12.2 iOS Calendar (EventKit)

If you enable calendar synchronization, Clean Take uses Apple's EventKit framework to read/write events in your device's calendar. This integration is local to your device and does not transit our servers.

12.3 iOS Files (import and future backup)

Clean Take may access files you explicitly choose via the iOS Files picker (audio import, future backup to your cloud). See Section 14 on the upcoming user backup feature.

12.4 Other integrations

Any other third-party integration (music catalogs, collaboration tools) will be added in a later version of this policy, with your explicit consent if required.


13. Account deletion and deletion process

Deletion of your account results in the total and definitive removal of your account data and associated private content, subject only to:

  • the technical time necessary to execute deletion workflows;
  • temporary persistence of copies in secure backups (purged within 30 days);
  • retentions strictly required by law (e.g. billing, accounting).

Process

  1. Deletion request from the app (Settings → Account → Delete my account) or by email to privacy@cleantake.app;
  2. Logical deactivation of the account immediately;
  3. Confirmation email sent to your address;
  4. Active data purge within 30 days;
  5. Revocation of access to groups, tokens, sessions and shared links;
  6. Anonymization of content shared in group spaces you leave (your comments become anonymous rather than deleted, to preserve the integrity of the remaining group's discussions);
  7. Backup expiration within 30 days;
  8. Definitive non-reversible deletion.

For active IAP subscriptions at the time of deletion: cancel first via Apple settings (https://apps.apple.com/account/subscriptions), then delete your Clean Take account. Apple handles any refund per its policies.


14. User backup (upcoming, opt-in)

An upcoming backup feature will allow you to automatically export your audio takes and metadata to your cloud (iCloud Drive, Google Drive, OneDrive, Dropbox, Nextcloud, local NAS, etc.) via the iOS Files framework. This feature will be opt-in: no backup will be performed without your explicit activation. Content will be encrypted client-side before transfer to your cloud, and we do not have access to your cloud credentials.


15. Your rights

Subject to applicable law, you have the following rights:

  • Right of access: confirmation that data about you is processed and a copy of that data;
  • Right of rectification: correction of inaccurate data;
  • Right to erasure ("right to be forgotten");
  • Right to restriction of processing;
  • Right to object to processing;
  • Right to portability: receive your data in a structured, machine-readable format;
  • Right to withdraw consent at any time when processing is based on consent;
  • Right to lodge a complaint with the CNIL (https://www.cnil.fr) or any other competent supervisory authority.

To exercise your rights: privacy@cleantake.app

We may ask for reasonable information to verify your identity before processing your request.


16. Security

We implement appropriate technical and organizational measures:

  • TLS encryption for all network communications;
  • Encryption at rest for audio (Scaleway S3 server-side encryption) and OAuth tokens (AES-256-GCM);
  • Strong authentication: time-limited tokens, refresh tokens, iOS Keychain storage;
  • Strict access control: granular permissions per group, per role;
  • Logging and monitoring of access and security events;
  • Regular backups with restoration testing;
  • Environment separation (dev / staging / prod);
  • Regular audit of open source dependencies and licenses.

No system being completely risk-free, we cannot guarantee absolute security.


17. Cookies, SDK and similar technologies

In the mobile application

The Clean Take (iOS) app does not use cookies. It uses:

  • secure local storage (iOS Keychain) for authentication tokens;
  • a local encrypted database (GRDB / SQLite) for your content before publication;
  • App Groups for communication between the main app, widgets and the share extension.

App Tracking Transparency (ATT): we do not perform cross-app tracking and do not request ATT authorization.

On the website (cleantake.app)

The website uses strictly necessary cookies for operation and, where applicable, a privacy-friendly analytics tool (Plausible or Umami — selection in progress, no tracking cookies, IP anonymization). No third-party advertising or tracking cookies are used.


18. Children's data

The Service is not directed to users under 16 years of age.

Music schools, conservatories, MJC: in this supervised usage context, the Clean Take account must be that of the teacher or institution, acting as the responsible party. Recordings may include minors if their parents have given informed consent to the institution. A dedicated offering for these uses will be proposed later.

If we learn that an account has been created in violation of this rule, we may take appropriate measures, including suspension or deletion of the account concerned.


19. Policy updates

We may update this Privacy Policy to reflect product evolution, architectural changes, regulation or our practices.

In case of substantial modification, we will inform you:

  • via in-app notification;
  • via email to the address associated with your account;
  • via visible update of the "Last updated" date at the top of this document.

Your continued use of the Service after notification constitutes acceptance of the changes, unless applicable law requires otherwise (notably the right of withdrawal).


20. Contact

For any question, rights exercise request or complaint:

ASTROLABE CAE (ASTROLABE) 8 place du Colombier 35000 Rennes, France privacy@cleantake.app

For copyright / DMCA questions: copyright@cleantake.app — see dmca-policy.md.

French supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL) 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 https://www.cnil.fr

Clean Take

Made in France · By and For musicians.

Product
  • Features
  • Pricing
  • Changelog
Company
  • About
  • Press
  • Contact
Legal
  • Privacy
  • Terms
  • Legal notice
  • DMCA
© 2026 Clean Take · cleantake.app