Privacy Policy
Last updated: August 10, 2026
Karafy ("we", "us") turns YouTube links into karaoke files. This page explains what data the desktop app and its server collect, why, and what rights you have over it. Most of what Karafy does happens entirely on your own computer and never reaches us at all — the sections below spell out exactly which parts do.
1. Who we are
The data controller is GemuStudio Krzysztof Owsiany. For any privacy question or request, contact krzysztof@mrdev.pl.
2. What we collect, and why
Local mode (default)
Karafy downloads the YouTube audio, transcribes it, and separates vocals entirely on your own machine. Your audio, generated files, and job history never leave your computer — nothing is uploaded anywhere in local mode.
License activation
Activating a Pro license or credit pack sends your license key and your Windows computer name to Lemon Squeezy (our payment provider) to verify the license, and your license key and an instance identifier (no computer name) to our server to issue a short-lived access token. We never see or store your name, email, or payment details — Lemon Squeezy handles checkout, billing, and invoicing as the Merchant of Record.
Cloud processing (opt-in)
If you choose cloud-accelerated processing (spending cloud credits), your audio file is uploaded to our server and forwarded to OpenAI (transcription and lyrics correction) or RunPod (vocal separation). Uploaded audio is deleted as soon as processing finishes. For vocal separation, the resulting instrumental track is deleted as soon as your app downloads it. The resulting transcript text is kept on our server for up to 30 days to support retries and troubleshooting, then automatically deleted.
Lyrics lookup
To fetch lyrics, we send the song title and artist name (only) to Genius and LRCLIB, two public lyrics databases. No other data is sent.
Diagnostic error reports
To help us fix crashes and failures faster, Karafy automatically sends a diagnostic report — a random device identifier, your app version, OS info, the error itself, and that session's log file — when it hits an unhandled crash, a failed job, or a failed cloud request. Your Windows username is removed from this report, and your license key is masked (only the last few characters are visible) before it's sent. This is on by default; you can turn it off anytime in the app's About window, or send one manually with the "Send log now" button. Reports are kept for 90 days, then automatically deleted.
Usage analytics
Karafy sends basic usage events — the app launching, a karaoke job being created, a license being activated — to PostHog (hosted in the EU), tagged with the same random device identifier used for diagnostic reports, along with coarse properties like your plan, app version, and language. This helps us understand how many people use Karafy and what they use it for. It's tied to the same toggle as diagnostic error reports in the About window — turning that off stops both.
Automatic updates
Karafy checks GitHub for new releases and downloads updates automatically. This is a plain version check — no personal data is sent beyond what GitHub itself logs as standard web server access, which is outside our control.
3. Who we share data with
- Lemon Squeezy — payment processing and license validation (Merchant of Record)
- OpenAI — cloud transcription and lyrics correction, only for jobs you choose to run in the cloud
- RunPod — cloud vocal separation, only for jobs you choose to run in the cloud
- GitHub — hosts app updates and this website
- Seq — internal log viewer used by us to operate the service; not user-facing, receives operational logs (not raw audio or lyrics)
- PostHog (EU) — basic usage analytics (app launched, job created, license activated), tagged with a random device identifier, not your name or email
We don't sell your data, and we don't use any advertising trackers on this site or in the app.
4. Legal basis
We process license and payment data to perform the contract when you buy Pro or credits. We process diagnostic error reports, usage analytics, and cloud processing data based on our legitimate interest in keeping Karafy working reliably and understanding how it's used — you can object to diagnostic reporting and usage analytics at any time by turning off the shared toggle in the About window.
5. How long we keep data
- Local job history, generated files, settings: kept on your machine until you delete them — we never see this data
- Uploaded audio for cloud processing: deleted immediately after processing
- Separated instrumental audio: deleted as soon as your app downloads it
- Cloud transcription results (text): 30 days, then automatically deleted
- Diagnostic error reports: 90 days, then automatically deleted
- Usage analytics events: kept in PostHog under their standard retention policy
- Credit balance and license key: kept for the life of your license, to track your entitlements
6. International transfers
If you use cloud processing, your audio is processed by OpenAI and RunPod, which may process data outside the European Economic Area. Both providers offer standard contractual safeguards for international transfers.
7. Your rights
Under GDPR, you have the right to access, correct, delete, restrict, or export the data we hold about you, and to object to processing based on our legitimate interest. Since most Karafy data lives only on your own computer, most of these rights are already entirely in your hands — for anything held on our server (license/credits, cloud job history, diagnostic reports), email krzysztof@mrdev.pl and we'll act on your request.
8. Changes to this policy
If this policy changes materially, we'll update the "last updated" date above. We encourage you to check back occasionally.