Privacy
Privacy notice
MixReady is an invite-only alpha run by one person, and this page is written
the way the product is built: plainly, listing what is actually stored and
what actually happens to it. Effective 6 August 2026. Questions and
requests: support@mixready.art.
What MixReady stores about you
- Your account — email address, a salted password hash
(never the password), when the account was created.
- Provider connections — if you connect Beatport or
SoundCloud, the OAuth tokens for your own accounts, encrypted at
rest, plus a small health record (connected or not, last check, which
account). Disconnecting destroys the tokens.
- Your sets and choices — the prompts you type, the sets
MixReady builds, your edits, swaps, ratings, blacklist entries and
preferences. Set-building prompts you type are sent to the AI provider
with track titles and artist names — never your email, your identity, or
your listening history.
- Your library scan, if you run one — track metadata from
your rekordbox library (titles, artists, BPM, keys, measured audio
features) and the file paths of your audio files. Paths are needed to play
and analyse your files; on a hosted server this means those paths are
stored server-side. Audio files themselves are never uploaded.
- Play history, only if you opt in — reading your
rekordbox play history as a calibration source is off by default, and a
preview endpoint shows exactly what opting in would contribute before you
do.
- Server logs — the server keeps ordinary operational
logs, which include client IP addresses; they rotate with the system
journal's size limits.
What it deliberately does not do
No analytics, no tracking pixels, no advertising, no cookies beyond your own
sign-in session, and nothing is ever sold or shared for marketing. The app
works the same whether or not anyone is watching, because nobody is.
Who touches the data
- Anthropic — processes set-building prompts (your typed
request plus track titles and artists).
- Cloudflare — fronts the hosted app and this site
(tunnel, access control, static hosting).
- Beatport / SoundCloud — your own connected accounts;
MixReady talks to them as you, with the tokens you granted.
- Last.fm / Deezer — artist lookups (bios, similar
artists). Only artist names are sent, nothing about you.
- Backups — the server's data directory is copied
periodically to a second private machine we operate. Backup copies are
pruned manually; an erasure request covers them (below).
Export and deletion
Both are self-serve, in the app under Settings → Privacy &
data:
- Export downloads everything stored about your account
as one JSON file — account details, preferences, connections (never
tokens), devices, your sets with their tracklists, and your blacklist.
- Delete account asks for your password, then erases your
account record, preferences, connection tokens, paired devices, your sets,
your library's ownership records and file paths, and your play-history
contributions — immediately, from the live system. Anything you
contributed to shared pooled statistics is recomputed without you.
If you can't sign in (blocked, or the password is gone), email
support@mixready.art from your account
address and the same deletion runs operator-side. Backup copies containing
your data are purged within 30 days of an erasure request.
Retention
Account data lives until you delete it. Spent invite codes stop recording
who used them once that account is deleted. The shared reference corpus
(public tracklists, catalogue metadata) is not personal data and stays.
The formal bit
Processing your account and library data is necessary to provide the service
you signed up for (GDPR Art. 6(1)(b)); optional contributions like the
play-history pool run on consent (Art. 6(1)(a)), asked per switch, never
bundled. The data controller for the alpha is the operator reachable at
support@mixready.art. If this notice
changes in a way that matters, the change is announced in the app before it
takes effect.