Privacy

Privacy notice

MixReady is early-access software: accounts are created by invitation, or by approval from the waitlist. This page is written the way the product is built: plainly, listing what is actually stored and what actually happens to it. Effective 30 September 2026 — what changed from the previous version. Questions and requests: support@mixready.art.

In one screen

Who is responsible

MixReady is run by its operator reachable at support@mixready.art.

What MixReady stores about you

What it deliberately does not do

Inside the app: no analytics, no tracking pixels, no advertising, and nothing is ever sold or shared for marketing. Your sign-in is a token kept in your browser’s local storage (in the desktop app, in your operating system’s keychain), not a cookie. The server sets exactly two cookies, both unreadable by scripts: one that binds a Google, Apple, SoundCloud or DJ ID sign-in to the browser that started it, deleted when the sign-in completes, and one that only the operator receives during a maintenance window.

Four exceptions worth naming rather than burying. Errors are reported to Sentry and, from the desktop app, log lines are streamed to our log store — below, in full. The app loads its typefaces from Google Fonts, so opening it fetches those font files from Google — no cookie is set and nothing about you is measured, but like any web request it arrives carrying your IP address. The marketing site, unlike the app, counts visits: site analytics, below. And the landing page and every shared set’s page embed Apple’s and SoundCloud’s own music players, which they serve and can measure.

Crash reports, failure reports and the desktop log stream

Alpha testers do not send stack traces, so the software sends them. Three channels, each with a different reach:

Publishing a mix

MixReady can render a set as one continuous mix and publish it to your SoundCloud or Mixcloud account. The rendering happens entirely in your browser, from files on your computer or the streaming previews the set uses, and the audio never touches our server: your browser uploads it straight to SoundCloud or Mixcloud. To do that, our server hands the page a short-lived copy of the access token you granted for that account — enough to upload as you for about an hour, never the longer-lived token that could renew itself. The tracklist that becomes the mix’s description is composed on our server from the set. Both routes are new and lightly exercised; the privacy shape above is the part that is fixed.

Sharing a set

Every set is private until you share it. Share offers three choices: Private; Anyone with the link, which is unlisted, so nobody finds it unless you send it to them; and Community, which also lists it for other DJs in the app. A shared set gets a page at app.mixready.art/s/… that anyone holding the link can open, without an account.

Site analytics, in consent mode

The public site — the landing page, the get-started guide and the free tools on this domain — counts visits with Google Analytics running in its consent mode, and asks once whether it may do so with a cookie. Answering once covers all of them. The guides, the research articles, the download page and this notice carry no measurement script at all. The honest version of both halves:

The free tools

The tools under /tools talk only to our own server, without any sign-in. A search box sends what you typed; Rate my set sends the tracklist you pasted. Those requests are answered and not stored — nothing you type into a free tool is kept, and none of it is sent to an AI model. Your IP address is used to rate-limit the tools and for nothing else. Two of them (genres and hot tracks) read Beatport’s catalogue through MixReady’s own credentials, so Beatport learns nothing about you.

The music players on the landing page and on shared sets

The landing page shows a few real DJ sets, and a shared set’s page shows that set; both let you play any track on them. Those players are not ours: each one is Apple Music’s or SoundCloud’s own widget, embedded in the page and served by them from embed.music.apple.com or w.soundcloud.com. Which of the two a track uses depends on where that record is available. Nothing plays until you press play on a track.

Saving a set to your Apple Music library

Each of those sets, and every shared set’s page, has a Save to Apple Music button. It runs Apple’s own MusicKit library, loaded from js-cdn.music.apple.com the first time you press it and never before — if you do not press it, none of this happens and Apple is not told you were here.

Signing in with another account

You can sign in with an email address and password, with a one-time link emailed to you, or through Google, Apple, SoundCloud or DJ ID. With a provider, you sign in on their page; they tell us an opaque id for you, your email address and, where they offer it, a name and picture, and they learn that you signed in to MixReady. MixReady never sees your password for that provider. You can link and unlink these methods, and set or remove a password, under Settings → Account. The emailed link, email confirmations, password resets and the link that connects a provider from another device are all sent through Resend (below).

The desktop app

The browser extension

The MixReady extension for Chrome saves a DJ set you are reading on 1001tracklists.com into your own MixReady library. It is covered by this notice, and its data handling is deliberately narrow.

Sets you capture are yours, and nobody else’s — see Captured tracklists above.

Who touches the data

WhoWhat reaches themWhere
OpenAI Used only to read your set request and work out what you asked for, and to write the short notes MixReady shows about a set and its transitions. It receives only what that needs: the words you typed, and the titles, artists, BPM and keys of the tracks involved. MixReady sends it over an encrypted connection with no name, email, account or other identifier, so OpenAI cannot tell which of our users it came from. OpenAI’s terms for API customers say this data is not used to train its models. United States
Anthropic Used only for the same two jobs: it writes MixReady’s explanation of a set, and does OpenAI’s part whenever OpenAI cannot answer. It receives the same minimum, sent the same way: the words you typed and the details of the tracks involved, over an encrypted connection, with no name, email, account or other identifier, so Anthropic cannot tell which of our users it came from. Anthropic’s terms for API customers say this data is not used to train its models. United States
Our hosting provider Rents us the servers MixReady runs on, where everything above is stored. It provides the machines and does not process the data. European Union
Cloudflare Fronts the app, the admin console and this site, so every request — and its IP address — passes through Cloudflare; hosts the installers on dl.mixready.art; and stores the nightly backup archive, which is encrypted before it is uploaded. Global network; United States
Sentry Crash reports from the web app, the desktop app and the server: the error, the release, the component stack and your account id. Never your email or request contents. United States
Grafana Labs Operational logs, metrics and request traces from the server, and the redacted desktop log stream, tagged with account ids. Kept 14 days. Canada
Resend Delivers the transactional email: invites, welcome, email confirmation, password reset, sign-in links and provider-connect links. They receive the address and the message. United States
Google Three separate things. Sign-in with Google, if you use it. Google Fonts, which the app loads its typefaces from: a plain request carrying your IP address, no cookie, no measurement. And Google Analytics on the marketing pages only, cookieless until you allow a cookie (above). United States
Apple Sign in with Apple, if you use it. Apple Music catalogue lookups, made by our server on our own developer credentials, carry nothing about you; if you connect Apple Music, the token Apple issues for your library is stored encrypted and used to write playlists as you. The landing page and shared set pages also embed Apple’s own player (above). United States
Beatport, SoundCloud, TIDAL, Mixcloud Your own connected accounts: MixReady talks to them as you, with the tokens you granted, and refreshes those tokens on a timer. When you publish a mix, your browser uploads it directly to SoundCloud or Mixcloud. SoundCloud additionally serves the embedded player some tracks on the landing page and on shared set pages use, which needs no account of yours. United States and Europe
DJ ID (djid.me) A sign-in provider, if you use it: it tells us your id and email and learns that you signed in to MixReady. —

Backups. One archive of the server’s data is made each night, encrypted on the machine (GPG, AES-256) before it leaves it, and stored in Cloudflare’s R2 object storage. Seven are kept off the server and three on it; older ones are deleted automatically. An erasure request covers them (below). The archive contains everything under What MixReady stores; it does not contain your audio, which was never there.

Where your data lives

Your account and everything listed under What MixReady stores sits on our servers in the European Union. The operator is in Canada, and the other companies in the table above are mostly in the United States.

So wherever you are, some of your data crosses a border. If you are in the European Economic Area, the United Kingdom or Switzerland, the service’s own copy stays in the region, but the operator reaches it from Canada and each processor in the table receives its share under that company’s standard data-transfer terms. If you are anywhere else, your data is stored in the European Union. Canada’s federal privacy law (PIPEDA) applies to the operator regardless of where you are.

How it is protected

Honest limits: MixReady runs on a small number of servers and is run by its operators. That is the alpha’s shape, and it is why the terms ask you to keep your own copy of anything you depend on.

Export and deletion

Both are self-serve, in the app under Settings → Privacy & data:

If you can’t sign in (blocked, or the password is gone), email support@mixready.art from your account address and the same deletion runs operator-side. Backup copies containing your data age out within seven nights and are purged no later than 30 days after an erasure request; log lines naming your account id expire from the log store after 14 days; crash reports expire on Sentry’s own schedule. The shared reference corpus (public tracklists, catalogue metadata) is not personal data and stays.

Your rights

Wherever you are, you can ask what MixReady holds about you, have it corrected (email, username, name and picture are yours to change under Settings → Account), have it deleted, receive a copy, and withdraw any consent you gave — the play-history switch is in Settings, the site-analytics choice is above. Requests go to support@mixready.art and are answered within 30 days. You can also complain to the Office of the Privacy Commissioner of Canada or, in the EEA or the UK, to your local data-protection authority. None of this costs anything.

Children

MixReady is not for children. You must be at least 16 to hold an account (or older where the law where you live says so), and MixReady does not knowingly collect data from anyone younger. If you believe a child has an account, email and it will be removed.

Retention

The formal bit

Processing your account, library and set data — publishing a set you chose to share included — is necessary to provide the service you signed up for (GDPR Art. 6(1)(b)). Optional things — the play-history pool, the site-analytics cookie on the marketing pages — run on consent (Art. 6(1)(a)), asked per switch, never bundled, withdrawable in the same place. Crash reports, the desktop log stream, automatic failure reports, rate limiting, reports about shared pages and the cookieless consent-mode pings rest on legitimate interest (Art. 6(1)(f)): keeping early software working, secure and lawful, and counting visits without identifying visitors. The waitlist rests on your request to be admitted. The data controller is the operator reachable at support@mixready.art. If this notice changes in a way that matters, the change is announced in the app or by email before it takes effect, and the effective date at the top always says which version you are reading.

What changed in this version

Against the version effective 31 August 2026, this one: