Home Pricing Docs Compare SDK Blog Changelog Status Contact Get API Key →
This policy explains what data we collect across all FreqBlog products, why, and your rights under UK GDPR. We keep it short and plain — no legal fog.

1. Who We Are

The data controller is Steven Birring trading as Stackbase / FreqBlog. ICO registration number: CSN0293296.

This policy covers all products operated via freqblog.com and its subdomains: the freqblog.com website and the Music Metadata API (api.freqblog.com).

Contact us at [email protected] for any privacy-related queries.

2. What We Collect

Data Why we collect it Legal basis (UK GDPR) Retention
Email address & name Music API account creation; to contact you about your account or service changes; to deliver purchased products Contract performance (Art 6(1)(b)) Duration of account + 12 months
API keys & usage logs To issue and manage Music API keys; endpoint calls, timestamp, HTTP status — for rate limiting, abuse detection, and service monitoring Contract performance / Legitimate interests (Art 6(1)(b)/(f)) 60 days rolling for request logs; key data held for duration of subscription + 12 months
Origin IP address The IP address of the first authenticated call made with each API key is recorded against that key, to detect abuse and to identify a single person operating multiple free accounts. Individual requests are not logged with an IP address. Legitimate interests (Art 6(1)(f)) Held for the life of the key
Webhook destination URL If you configure a webhook, the destination URL you supply is stored against your key so we can notify it. The signing secret is derived per delivery and is never stored. Contract performance (Art 6(1)(b)) Until you change or remove it, or the key is deleted
Subscription records Subscription ID, billing email address, plan tier, status and billing-period dates — to run your subscription, apply the right quota, and handle renewals and cancellations Contract performance (Art 6(1)(b)) As required by UK tax law (7 years)
Uploaded audio files (API) To perform the requested audio analysis via /analyze Contract performance (Art 6(1)(b)) Deleted immediately after analysis completes
Billing information To process subscription and one-off payments. Card details are handled directly by Stripe — we never see or store card numbers. Contract performance (Art 6(1)(b)) As required by UK tax law (7 years)
Email enquiries To respond to messages you send to [email protected] Legitimate interests (Art 6(1)(f)) 12 months

We do not collect payment card details (handled by Stripe), phone numbers, or any other personal data beyond the above.

3. Cookies

The freqblog.com website uses a small number of cookies. We ask for your consent before any non-essential cookies are set, via the banner shown on your first visit.

CookiePurposeTypeRetention
__cf_bmCloudflare bot management / DDoS protectionStrictly necessary30 minutes
_ga, _ga_*Google Analytics 4 — aggregated page-view and traffic-source statistics. Set only after you click “Accept” on the cookie banner.Analytics (consent)Up to 2 years
Session cookieKeeps you signed in to your dashboard / account area (api.freqblog.com/dashboard). Set on the api.freqblog.com domain, not on freqblog.com.Strictly necessarySession

You can withdraw analytics consent at any time by clicking the “Cookie settings” link in the footer, or by clearing your browser cookies for this domain. Declining does not affect the service.

4. Who We Share Data With

We do not sell, rent, or share your personal data with third parties for marketing purposes. Data may be shared only in the following circumstances:

5. International Transfers

Your data is stored on servers located within the EU (Hetzner, Finland). Some of the processors listed above are US-based and may process data outside the UK/EEA under Standard Contractual Clauses: Google Analytics 4 (only where you have consented), Cloudflare (which routes and filters traffic through its global network), Stripe (payments), and Resend (transactional email). Our off-host backups are encrypted on our own server before upload, so the storage provider holds ciphertext only. We do not transfer personal data outside the UK or EEA for any other purpose.

6. Your Rights

Under UK GDPR you have the following rights regarding your personal data:

Access
Request a copy of the personal data we hold about you.
Rectification
Ask us to correct inaccurate or incomplete data.
Erasure
Request deletion of your data where there is no overriding legal reason to keep it.
Restriction
Ask us to limit how we use your data while a dispute is resolved.
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to processing based on legitimate interests, including profiling.
Withdraw Consent
Where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, email [email protected]. We will respond within 30 days at no charge.

7. Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK's data protection authority:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113

8. Changes to This Policy

We may update this policy from time to time. We will notify active API users by email before material changes take effect. The "last updated" date at the top of this page will always reflect the current version.

9. Contact

For any privacy-related questions, contact us at [email protected].