Privacy Policy
Version 2026-07-31 — effective 31 July 2026
This policy explains what personal data BananaBoat Academy collects, why we collect it, who we share it with, and the rights you have over it. We keep data collection to what the service needs, we never sell your personal data, and we do not use your uploads or conversations to train public AI models.
Who we are
BananaBoat Academy ("we", "us", "our") is operated by BananenBoot, registered in the Netherlands at *, * *, the Netherlands (Chamber of Commerce **, VAT **).
For the purposes of the EU and UK General Data Protection Regulation (GDPR), we are the data controller for the personal data described in this policy. You can reach us about anything in this document at [email protected].
This policy applies to the BananaBoat Academy website, the Academy workspace, the mix analyzer, and the BananenBoot VST plugin when it connects to our services. It does not apply to third-party sites we link to.
Personal data we collect
We collect only the categories below. We do not buy personal data from data brokers, and we do not run advertising networks on the service.
Account data. Your email address, your password (stored only as a salted hash by our authentication provider — we never see or store the plaintext), your email verification status, your account identifier, and the date you created the account.
Consent records. The date, time, and version of the Terms of Service and this Privacy Policy that you accepted when you signed up. We keep this to demonstrate a valid basis for processing under GDPR art. 7(1).
Profile and learning preferences. Optional details you give during onboarding or in your account settings: your digital audio workstation, your self-reported skill level, the genres you produce, and your tutor preferences (answer depth, guidance style, terminology level).
Content you submit. Messages you send to the AI tutor, saved conversations and their titles, learning-insight summaries generated from your lessons, audio clips and MIDI files you choose to send for analysis, images you attach to a chat, and anything you write in the contact, feedback, or bug-report forms.
Subscription and usage data. Your plan tier, your token usage count and billing-period start, and the customer and subscription identifiers issued by our payment provider. We never receive or store your full card number, CVC, or bank credentials — those go directly to the payment provider.
Technical data. IP address, browser and device type, operating system, referring page, timestamps, and error or security logs generated when you use the service.
Sensitive data. We do not ask for special-category data (GDPR art. 9) such as health, biometric, religious, or political information, and we do not use voice in uploaded audio to identify anyone. Please do not upload recordings or files containing sensitive personal information about yourself or others.
How we use your data, and our legal basis
Under the GDPR we must have a lawful basis for every use of your data. Ours are:
| What we do | Why | Legal basis (GDPR art. 6) |
|---|---|---|
| Create and maintain your account, authenticate you, verify your email | To give you the service you signed up for | Performance of a contract, art. 6(1)(b) |
| Run the AI tutor, mix analysis, and theory tools on the content you submit | Core functionality you requested | Performance of a contract, art. 6(1)(b) |
| Save your conversations, learning insights, and preferences | To keep your progress between sessions | Performance of a contract, art. 6(1)(b) |
| Meter token usage and enforce plan limits | To operate plans fairly | Performance of a contract, art. 6(1)(b) |
| Take payment, manage subscriptions, issue invoices | To complete your purchase | Contract, art. 6(1)(b), and legal obligation, art. 6(1)(c) |
| Keep tax and accounting records | Required by law | Legal obligation, art. 6(1)(c) |
| Send service emails (verification, password reset, billing, material changes) | You need these to use and keep your account | Contract, art. 6(1)(b) |
| Detect abuse and fraud, keep the service secure and reliable | Protecting users and infrastructure | Legitimate interests, art. 6(1)(f) |
| Diagnose faults and improve features using aggregated or de-identified metrics | Making the product work better | Legitimate interests, art. 6(1)(f) |
| Answer support and feedback requests | Responding to you | Legitimate interests, art. 6(1)(f) |
| Establish, exercise, or defend legal claims | Protecting our rights | Legitimate interests, art. 6(1)(f) |
| Optional marketing emails, if we ever introduce them | Only with your prior opt-in | Consent, art. 6(1)(a) |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded the processing is limited, expected, and not overriding. You can object at any time — see Your rights.
Where we rely on consent, you can withdraw it at any time without affecting processing that already happened.
The AI tutor and your content
The tutor is powered by large language models operated by Anthropic and Google. When you send a message, we transmit the content needed for a useful answer — your message, relevant conversation history, your tutor preferences, and any mix metrics, audio clip, MIDI summary, or image you chose to attach.
What this means in practice:
- We do not use your prompts, uploads, or conversations to train public AI models, and our agreements with our AI providers prohibit them from doing so with data sent through our business accounts.
- Providers may retain inputs briefly for abuse monitoring under their own terms before deletion.
- Attachments you add for a single turn are sent for that request and are not necessarily kept in your saved chat history.
- AI output can be wrong. Treat tutor answers as educational suggestions, not authoritative advice. See the Terms of Service.
You control what you send. If you would rather not have a file processed by a third-party model, do not attach it to a chat.
Processing that stays on your device
Most mix analysis runs locally in your browser. Waveform rendering, loudness measurement, spectrum views, and beat detection are computed on your own machine, so the full audio file is not uploaded to us for basic analyzer work.
Audio leaves your device only when you deliberately send a region clip or mix metrics to the tutor for feedback.
International data transfers
Some of our providers process data in the United States or other countries outside the European Economic Area. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on at least one of the following safeguards:
- the European Commission's Standard Contractual Clauses (2021/914), with the UK International Data Transfer Addendum and the Swiss adaptations where applicable;
- an adequacy decision for the destination country;
- the EU-US Data Privacy Framework, and its UK Extension and Swiss-US framework, where the recipient is certified.
We assess each transfer for risk and apply extra technical measures such as encryption in transit and at rest. You may request a copy of the relevant safeguards by emailing us.
How long we keep data
We keep personal data only as long as we need it:
| Data | Retention |
|---|---|
| Account, profile, and preference data | For as long as your account is open |
| Saved conversations and learning insights | Until you delete them, or until your account is deleted |
| Audio, MIDI, and images sent to the tutor | Processed for the request; not retained on our servers as standalone files |
| Consent records | Life of the account plus 5 years, as proof of lawful processing |
| Invoices and accounting records | 7 years, as required by Dutch and EU tax law |
| Support and feedback correspondence | 24 months after the matter is closed |
| Security and error logs | Up to 12 months |
| Backups | Rolling backups overwritten within 90 days |
When you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except for records we must keep by law (mainly billing records) and data needed to defend an active legal claim.
How we protect your data
We apply technical and organisational measures appropriate to the risk, including:
- encryption in transit (TLS) and encryption at rest for our databases;
- passwords stored only as salted hashes, handled by a specialist authentication provider;
- access to production data limited to people who need it, protected by strong authentication;
- audio analysis performed in your browser wherever possible, so less data travels at all;
- logging and monitoring for unusual activity.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by GDPR art. 33, and notify you directly where the risk is high.
Keep your own account safe: use a unique password, keep your email verified, and tell us immediately if you suspect unauthorised access.
Your rights in the EEA, UK, and Switzerland
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data ("right to be forgotten") where we no longer have a valid reason to keep it;
- restrict processing while a dispute about accuracy or legitimate interests is resolved;
- data portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible;
- object to processing based on legitimate interests, and to direct marketing at any time and unconditionally;
- withdraw consent at any time where processing is based on consent;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — we do not make such decisions;
- lodge a complaint with a supervisory authority.
To exercise any of these rights, email [email protected]. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. Exercising your rights is free unless a request is manifestly unfounded or excessive. We may ask you to confirm your identity before we act.
Your rights in the United States
If you live in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or another state with a comprehensive privacy law, you have the right to:
- know what personal information we collect, use, and disclose, and to obtain a copy;
- delete the personal information we hold about you;
- correct inaccurate personal information;
- opt out of the sale of personal information, of sharing for cross-context behavioural advertising, and of profiling with legal or similarly significant effects;
- limit the use of sensitive personal information;
- appeal a refusal of any request, where your state provides an appeal right;
- be free from discrimination for exercising any of these rights — we will not deny service, charge different prices, or degrade quality.
We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months, including for consumers we know to be under 16. Because we run no advertising trackers, an opt-out preference signal such as Global Privacy Control has nothing to switch off, but we honour it as a valid opt-out request.
The categories of personal information in CCPA/CPRA terms that we collect are identifiers, customer records, commercial information, internet activity information, audio and electronic information you upload, and inferences drawn from your learning activity. We collect them for the business purposes listed in How we use your data and disclose them only to the service providers listed in Who we share data with.
Submit a request by emailing [email protected]. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days. An authorised agent may act for you with written permission that we can verify.
Other regions
We aim to apply the standards in this policy globally, regardless of where you live.
- Brazil (LGPD): you have rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and to revoke consent. Contact us at the address above.
- Canada (PIPEDA): you may access and correct your personal information and complain to the Office of the Privacy Commissioner of Canada.
- Australia (Privacy Act): you may access and correct your personal information and complain to the Office of the Australian Information Commissioner.
- Japan (APPI), South Korea (PIPA), and comparable regimes: you may exercise equivalent access, correction, suspension, and deletion rights by contacting us.
If your local law grants you a right not listed here, tell us and we will honour it where it applies.
Children
The service is not intended for children. You must be at least 14 years old to create an account, and we do not knowingly collect personal data from anyone below that age. We do not knowingly collect personal information from children under 13 within the meaning of the US Children's Online Privacy Protection Act.
If you believe a child has given us personal data, email [email protected] and we will delete the account and its data promptly.
Changes to this policy
We may update this policy as the service evolves or the law changes. The version number and effective date at the top of this page always reflect the current text.
For material changes — a new purpose for processing, a new category of recipient, or a change that reduces your rights — we will notify you by email or an in-product notice at least 30 days before the change takes effect, and where the law requires it we will ask for your consent. Continuing to use the service after the effective date means you accept the updated policy.
Contact and complaints
Questions, requests, or complaints about privacy: [email protected], or write to BananenBoot, *, * *, the Netherlands.
We are not required to appoint a Data Protection Officer, but the address above reaches the person responsible for privacy.
If you are unhappy with our response, you can complain to your local data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). In the UK it is the Information Commissioner's Office. You may also complain to the authority where you live or work, or where the alleged infringement took place. We would appreciate the chance to address your concern first.
See also our Terms of Service.