Privacy policy
Last updated: 2 September 2026
In short
- The player runs on your machine. Your rooms, layouts, mixes and audio never reach us, with or without an account.
- The player sends no telemetry. It is not a version of the service with analytics turned off; there is no code in it that reports anything.
- This website counts a few gestures, so the install instructions can be improved. Third-party services wait for your yes.
- An account is optional. It holds an email address and a password, plus a line per Surroundify installation you choose to bind — never anything from inside one. Deleting it takes two clicks and is immediate.
- One optional exchange leaves your network: claiming an HTTPS name orders a certificate, which carries the name you chose and nothing else.
1. Data controller
The data controller is Resourcepool, whose details appear in the legal notice. Any question about your data can be sent there by email.
2. The software: nothing reaches us
Surroundify is installed on a computer you own and runs there. The rooms, speaker layouts, mix profiles, your own presets and their audio are written to a folder on that machine — ~/Library/Application Support/Surroundify on macOS, ~/.local/share/surroundify on Linux, %APPDATA%\Surroundify on Windows. There is no account, no synchronisation and no reporting.
We therefore cannot read that data, correct it, or restore it: that is the trade-off of this design, and it has a downside worth knowing — a room lives on the machine it was made on. Surroundify has a backup feature that packs the lot into one file, and it is worth using.
The one exception, and it is yours to trigger. If you claim a name under apps.surroundify.co so your phone will install the player to its home screen, the player orders a certificate for that name and registers where it should point. What leaves your network is the name you typed and the private address it resolves to. No audio, no room, no listening history.
3. The account, if you create one
The site works without one, and so does the player. An account exists for one purpose: to bind a Surroundify installation you own to you, so that features needing to know whose machine it is can work. Creating one is a deliberate act and nothing on the rest of the site asks for it.
- What is held: an email address, a password, and the dates the account was created and last used. No name, no telephone number, no billing details, no profile. The password is stored hashed by our authentication provider and is never revealed to us — which is also why we can never tell you what it is, only help you set a new one.
- Legal basis: performance of the service you asked for by signing up (article 6.1.b of the GDPR).
- Retention: for as long as the account exists. Deleting it from the account page removes it immediately and completely — there is no grace period during which we keep a copy, and no backup we can restore it from.
- Email: the address is used to verify itself, to reset the password, and to confirm a change of address. It is not used for anything else and there is no mailing list.
- Staying signed in: one cookie, set only once you sign in, valid for 14 days and destroyed when you sign out. It cannot be read by scripts on the page. The cookie policy describes it.
An account still cannot reach your player. It holds no room, no mix, no audio and no listening history, because the player sends none of that anywhere. Binding an installation lets this site know a machine is yours; it does not let it look inside.
4. Bound servers
A Surroundify installation can be bound to an account. You start it from the account page, which gives you a short code; you type that code into the player, and the player introduces itself to us. The direction matters — we never connect to your machine, and could not: it is behind your router, which is the point of the product.
- What is held: a name for the machine (its hostname, which you can change), the operating system it runs and the version of the player, the dates it was bound and last checked in, a random identifier the installation generated for itself, and a hash of the token it authenticates with. Nothing else.
- What is never held: your rooms, speaker layouts, mixes, presets, audio files or anything you have played. The player does not send them, and there is no request we could make that would fetch them.
- The identifier is a random draw made by the installation, not taken from the hardware. It exists so re-binding the same machine replaces its entry rather than adding a second one, and it identifies nothing outside this.
- Legal basis: performance of the service you asked for by binding (article 6.1.b of the GDPR).
- Retention: until you unbind, from either end, or delete the account — all three remove the record immediately. Pairing codes expire after ten minutes and are deleted.
A bound player still works exactly as an unbound one. Nothing about playback depends on us, and if this site disappeared tomorrow your installation would not notice.
5. Technical logs
Like any website, Surroundify is served by a host that logs requests — IP address, date, page requested, browser type — for security and correct operation. Those logs belong to the host named in the legal notice; they are not mined to analyse your behaviour.
6. Usage measurement on this website
To find out which part of the install loses people, this site counts a few gestures. That measurement takes two forms, which do not follow the same rules.
Our own counting, first: the site being opened, sections read, tracked buttons clicked, the platform tab chosen, install commands copied, and whether the room diagram was dragged. It stays on our server, uses no cookie and retains no IP address. A randomly drawn identifier, particular to your browser and renewed every thirteen months, exists solely so you are not counted twice. Those are the conditions on which the CNIL exempts audience measurement from consent. Purpose: improving the documentation (legitimate interest, article 6.1.f). Retention: 25 months, as daily counters.
7. What we do not do
- No account is required for anything the player does. Where one exists it holds an email address and a password, and is never sold, shared or profiled.
- No advertising, no retargeting, no commercial profiling.
- No selling, renting or exchanging of data.
- No listening history, no library scanning, no record of what you played: the player reports none of it, and there is nowhere for it to go.
- No automated decisions producing legal effects concerning you.
8. Transfers outside the European Union
Usage counters are held on the infrastructure of the host named in the legal notice. Accounts are held by the processor named in section 3, in the European Union, with transfers to the United States possible under the standard contractual clauses and the EU–US Data Privacy Framework. No transfer to a third country is arranged for any other purpose than the third-party measurement described above, which happens only with your consent.
9. Security
Exchanges with this site are encrypted (HTTPS). Account passwords are never seen by this site: they go straight to the authentication provider, which stores them hashed. Staying signed in uses a cookie no script on the page can read, and changing an email address, changing a password or deleting an account all require the password to be entered again moments beforehand — a session alone is not enough. The measurement endpoint reads only the identifier and the event names it is sent, and refuses anything outside a fixed list.
10. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection provided by the GDPR. In practice:
- For everything the player holds, you exercise them yourself and immediately, on your own machine — we have no access to it.
- For an account, the same page that shows it is the one that changes it: your account page displays the address we hold, changes it, changes the password, lists and unbinds your servers, and deletes the account outright. Deletion is immediate, takes the bound servers with it, and we keep no copy.
- For what this site stored in your browser, the same applies from privacy settings.
- For the usage counters on our server, withdrawing consent takes one click in those same settings. To have the counters already recorded erased, send us the measurement identifier that the page displays.
You may also lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at cnil.fr.
11. Changes
This policy may change if the site or the software changes. The date of the last update appears at the top of the page; substantial changes will be flagged on the site.