Privacy Policy
The short version: Takebase holds your recordings and the names you give them, plus the email address you signed in with. It does not carry advertising, it does not track you across other apps or websites, and nothing in it is sold to anybody.
Who is responsible
The data controller is Tanel Teemusk (trading as Massruum), Estonia. For anything on this page - a question, a copy of your data, a deletion - write to hello@teemusk.com and a person will answer.
What Takebase holds
- Account details
- Your email address, and the display name and picture you choose. If you sign in with Google or Apple, we receive from them only what is needed to identify the account - an email address and a name. Apple's Hide My Email works normally; we never see your real address if you use it.
- What you put in
- The audio files you upload, together with the album, song and take names, artwork, comment text and the timecodes those comments sit at.
- How much room you are using
- The recorded length of each take, so the allowance can be counted.
- Sharing records
- Which albums you are a member of, the invitations you have sent or accepted, and the share links you have created, including whether each one has a password and whether it has been revoked.
- Crash and error reports
- When the app fails, Firebase Crashlytics sends a report: the device model, the OS version, the app version and the stack trace of what went wrong. No audio and no comment text is in it.
Takebase has no advertising SDK, no analytics profile of you, and no third-party tracker. It does not ask for your contacts, your location, your microphone or your photo library except at the moment you pick a picture to use as artwork.
Why
We use all of it to run the app: to sign you in, to store and play your recordings, to show the band who said what and where, to count your allowance against your plan, and to fix crashes. In GDPR terms the lawful basis is performance of the contract between us for everything the app needs to function, and legitimate interest for keeping it secure and working - which is what the crash reports are for.
Where it lives, and who else touches it
Nothing about you is sold, rented, or handed to a data broker. The only companies that hold any of it are the ones the app is built on, each acting only on our instructions:
| Provider | What it holds | Where |
|---|---|---|
| Google (Firebase Authentication) | Your sign-in identity | EU / global Google infrastructure |
| Google (Cloud Firestore, Cloud Functions) | All metadata: albums, songs, takes, comments, memberships, share links | europe-north1 - Finland |
| Google (Crashlytics) | Crash reports | Google infrastructure |
| Cloudflare (R2 object storage) | The audio files and artwork themselves | European Union |
| Apple / Google Play | Subscription billing, if you buy a plan | Their own terms apply; we never see your card |
Your audio is stored in the EU and is never public: the app fetches it through short-lived signed addresses that expire, and no page on the web serves it.
Who can hear your recordings
Only the members of the album a recording sits in. A share link plays nothing: it is an invitation, and whoever opens it is asked to install Takebase and sign in, which joins them to the album. So a forwarded link is a forwarded invitation to everything in that album - which is why a link stops working 24 hours after it is created, and why you can remove a member from an album at any time, which cuts their access off immediately.
How long it is kept
Your content stays until you delete it. Deleting an album deletes its songs, takes, comments, artwork and share links along with it. Deleting your account removes your account and the albums you own.
Deleting is final and it is quick: the recording leaves the app for everyone the moment you confirm, the room it took comes back to your allowance the same second, and the audio file itself is erased from storage within 48 hours. There is no undo, and nothing in the app can bring a deleted take, song or album back.
There is one exception, and it applies to free accounts only: an account nobody has opened for six months is deleted, with everything the account owns. We email the address on the account after five months of inactivity to warn you, and opening the app resets the clock. An account with an active subscription is never deleted this way, and if we cannot reach you by email nothing is deleted. This is set out in the Terms. Metadata backups are kept for 7 days and then expire. Crash reports are kept for the period Firebase Crashlytics retains them, which is currently 90 days.
Your rights
Under the GDPR you can ask us for a copy of your data, ask for it to be corrected, ask for it to be deleted, ask us to restrict how we use it, or object to our using it. Write to hello@teemusk.com - you do not need a reason and there is no charge. You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority where you live.
Children
Takebase is not aimed at children and is not for anyone under 13. If you believe a child has an account, write to us and it will be removed.
Changes
If this policy changes in a way that matters, the app will say so before the change takes effect. The date at the top says when this version was written.