Spectra
Download
Legal

Privacy Policy

Spectra is a small independent product. This page explains what data the site and the app collect, why it exists, and how to have it removed.

Effective August 18, 2026.

The short version

You need an account to buy Spectra and hold a license key. That means an email address, a record of what you bought, and a license record. Payments are handled by Polar, so card numbers never reach this site. Product analytics are collected to see which parts of the site work. Nothing is sold to anyone.

Who is responsible

Spectra is built and operated by Cole Stanfield, an independent developer in Arizona. The site is spectraaudio.tech. For any privacy question, write to general@spectraaudio.tech.

What is collected

  • Account details. Your email address, and a name if you give one, when you sign in or sign up. Accounts are handled by Clerk.
  • Purchase records. What you bought, when, and whether it was a one-time purchase or a monthly subscription. Payments run through Polar as Merchant of Record. Card numbers and billing details go to Polar directly and are never stored on this site.
  • License records. Your license key and the Macs it is activated on, so the 3-Mac activation limit and device revoke can work.
  • Analytics events. Page views and product events such as starting a checkout, collected with PostHog. The analytics script is proxied first-party through /ingest on this domain, so it is not a third-party request. Vercel additionally collects aggregate, cookie-free page-view counts and performance timings (Vercel Analytics and Speed Insights).
  • Email records. A log of the transactional emails sent to you, so the same message is not sent twice. Delivery is by Resend, sending from general@spectraaudio.tech.
  • Ad attribution.If you arrive from an ad, the campaign identifiers in that link (such as the source, campaign name, and the ad network’s click identifier) are kept in a first-party cookie. If you then start a checkout, those identifiers are stored alongside your IP address and your browser’s user agent string, so a purchase can be matched back to the ad that produced it. Nothing here is collected for visits that did not come from a campaign link.
  • Download and install. Every download of Spectra is recorded: a random download id, the campaign that brought you here if there was one, your browser’s user agent string, the anonymous id our website analytics already uses, and a salted hash of your network address. The user agent and that hash are deleted after 7 days, and your network address itself is never stored. The app then uses this at its first launch to work out which download it came from, so we can tell which channels lead to installs and not only to clicks. That match is what links your anonymous website activity to your anonymous app activity, and it also creates a person record for you in our analytics tool. Turning off analytics in the app stops the match; the download record itself is still written, because it is made by the website before the app exists.
  • Community presets. If you publish an EQ preset, the preset itself and the display name you choose are public by design.

Why it is collected

  • To sign you in and keep your account working.
  • To deliver your license key and enforce the activation limit.
  • To take payment, issue receipts, and handle refunds.
  • To send transactional email such as purchase confirmations and account notices.
  • To understand which parts of the site and funnel work, so the product improves.
  • To publish community presets you chose to share.
  • To measure which ads bring people to Spectra, when an ad is what brought you here.
  • To match a download to the app's first launch, so installs can be counted per channel.

No advertising network runs code on this site. Your data is not sold, rented, or traded.

Who processes it

Spectra uses a small set of service providers. Each one only sees the data it needs to do its job.

  • Clerk, for authentication and account identity.
  • Polar, as Merchant of Record for payments, subscriptions, receipts, tax, and license keys.
  • PostHog, for product analytics, served first-party through /ingest.
  • Resend, for transactional email.
  • Neon, for the database that stores account, purchase, license, and preset records.
  • Vercel, for hosting the site, running its server code, and aggregate page analytics and performance metrics.
  • Meta, Reddit, and Google Ads, for measuring ads when advertising is running. They receive a purchase report only, sent from this site's server, and only for people who bought.

Each provider has its own privacy policy, and each acts on Spectra’s behalf for the purposes described above. The ad networks are the exception worth naming plainly: what they receive is described under Cookies below, and they use it to measure and improve their own advertising as well.

The macOS app

Spectra is a system-wide equalizer, so macOS asks you to grant audio capture permission. You grant it in System Settings, under Privacy & Security, and you can revoke it there at any time. This site never receives audio from the app.

The app talks to this site for two things: checking your license, and reading or publishing community presets. App updates are delivered by Sparkle, and the app download at /download is a redirect to GitHub Releases. If you have a specific question about what the app does on your Mac, email general@spectraaudio.tech and you will get a real answer.

Cookies

The site uses a session cookie from Clerk. Without it you cannot stay signed in, so it is required for the account area to function.

PostHog sets a first-party analytics cookie to recognize a returning browser and stitch a visit together. It is served from this domain through /ingest rather than a third-party host. No ad network sets a cookie here, and there are no cross-site ad trackers.

If you arrive from an ad, the campaign identifiers in that link are kept in a first-party cookie on this domain for up to 90 days. If you then buy Spectra, that purchase is reported to the ad networks Spectra is advertising on, so the ad can be measured. The report contains a hashed version of your email address, the click identifier from the link if there was one, and the amount. It never contains your name, your raw email address, your Spectra account identifier, your IP address, or your browser’s user agent string. Because the hashed email is a match key on its own, a purchase can be reported to a network that did not refer you. The report is sent by this site’s own server. No ad network script runs in your browser here.

Starting a download sets one more first-party cookie, holding that download’s random id for an hour. It exists so the page can offer you an “Open Spectra” link that tells the app which download it came from. It expires on its own and is safe to block.

You can block or clear cookies in your browser. Analytics cookies are safe to block. Blocking the Clerk session cookie will sign you out.

How long it is kept

  • Account details: for as long as your account exists.
  • Purchase and license records: for as long as your license is valid, and after that for as long as tax and accounting rules require. Polar keeps its own copy as Merchant of Record.
  • Analytics events: kept on a rolling basis for product analysis, and not used to build a profile of you beyond that.
  • Email log: kept so the same message is not sent to you twice.
  • Ad attribution: the IP address and browser user agent recorded at checkout are deleted after 90 days. The record of which campaign led to which purchase is kept, because that is what makes advertising measurable.
  • Download records: the salted hash of your network address, your browser user agent, and the ad network's click identifier are all deleted after 7 days. A download that no install ever claimed is deleted after 30 days. A claimed one keeps only the campaign and the match, because that is what makes install counts per channel possible.
  • Community presets: for as long as they are published. Delete a preset and it comes down.

Your rights

You can ask for a copy of the data held about you, ask for it to be corrected, or ask for it to be deleted. Email general@spectraaudio.tech and say what you want. Requests are handled by a person, usually within a few days.

Deleting your account removes your account and license records here. Polar may keep a record of the transaction itself, because a Merchant of Record has legal and tax obligations that survive account deletion. You can reach your Polar billing portal from /account/billing.

Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA. Those rights apply, and the same email address is the way to use them.

Children

Spectra is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child has given personal data here, email general@spectraaudio.tech and it will be deleted.

Changes to this policy

This policy will change as the product grows. When it does, the effective date at the top of this page changes. If a change is significant, it will be announced on the site or by email to account holders. Continuing to use Spectra after a change means the updated policy applies.

Questions about this page? Email general@spectraaudio.tech. You can also read the Terms of Service.