Privacy Policy
Last updated: August 27, 2026
Bass Remover — Play Along ("the App") is published by Bulpara Inc ("we", "us", "our"). This policy describes how we collect, use, and protect information when you use the App.
1. Your Audio Leaves Your Device
Separating a song is not done on your iPhone. Unlike some of our other apps, Bass Remover uploads the audio file you choose to our servers so it can be processed by a machine-learning model on GPU hardware. We want that stated plainly at the top of this policy rather than buried in it.
- What we upload: the audio file you pick — typically a commercially released song you already own.
- Where it goes: your file is uploaded directly to Cloudflare R2 object storage, then handed to Replicate, Inc., which runs the Demucs v4 source-separation model on it. The bass-removed mix that comes back is stored on R2 and downloaded by the App.
- What we do not do: we do not listen to, review, catalogue, index, fingerprint, share, sell, or train any model on your uploads. They are processed and deleted.
2. How Long We Keep It
- Your original upload: deleted within 24 hours. A storage lifecycle rule hard-deletes every uploaded file one day after it arrives. It is kept that long only so the Practice screen can A/B your bassless mix against the real recording during the session.
- The bass-removed result: deleted after 7 days. This is what History reopens when you return to a track. After 7 days the file is hard-deleted from storage; the entry may remain in your on-device History until you delete it.
- Delete on demand: "Delete my uploads" in the App's Settings immediately removes every stored object — originals and results — associated with your device.
The App shows this retention notice in Settings as well, so it is visible where the delete control is.
3. Data We Store Locally
- Practice history: track title, job status, the result URL, and your saved loop points and tempo for each track. Stored locally via SwiftData so practice resumes where you left it.
- Cached audio: downloaded mixes are cached in the App's sandbox on your iPhone and removed when you delete the track or the App.
- Preferences: theme and app settings.
- Usage counter: a local count of tracks processed this month and today, used to enforce the free-tier limit. It resets on the 1st.
- Purchase status: subscription state is managed by Apple's StoreKit and cached locally for feature gating.
4. Device Identifier
The App sends a random, app-generated device identifier with each job. It is not your Apple ID, your advertising identifier, or any hardware serial number, and it cannot be used to identify you personally. We use it for exactly three things: enforcing the free-tier quota, applying your subscription entitlement, and letting "Delete my uploads" find the files belonging to your device. Deleting and reinstalling the App generates a new identifier.
5. Permissions We Request
- Files / iCloud Drive: only the audio file you explicitly pick is imported into the App's sandbox. We do not browse or enumerate your storage.
- Share sheet: when you share a song into Bass Remover from another app, only that file is received.
- Notifications (optional): used only to tell you a track has finished processing while the App is in the background. You can disable this in iOS Settings.
The App does not request microphone access, does not access your Photo Library, and does not connect to any streaming service or music catalogue.
6. Third-Party Services
The App relies on the following third parties:
- Replicate, Inc. — runs the Demucs v4 separation model on your uploaded audio. Your file is transmitted to Replicate for the duration of the job. See Replicate's privacy policy.
- Cloudflare, Inc. (R2) — object storage for uploads and results, subject to the retention rules in section 2. See Cloudflare's privacy policy.
- Apple App Store / StoreKit — manages subscriptions and purchases, and validates them via the App Store Server API. Governed by Apple's privacy policy.
The App contains no advertising SDK, no analytics SDK, and no third-party tracking. There are no ads on any tier.
7. Data Storage and Security
- All transfers between the App, our backend, and our storage are over HTTPS.
- Uploads use short-lived, single-purpose pre-signed URLs; the storage bucket is not publicly browsable.
- Purchase verification uses Apple's signed transaction format, checked server-side against the App Store Server API.
- We hold no user accounts, no passwords, no email addresses, and no payment details. Payment is handled entirely by Apple.
8. Data Sharing
We do not sell your personal data. We do not share your audio with anyone other than the processors named in section 6, and only for the purpose of completing the job you asked for. We do not disclose what songs you process.
9. Your Rights
You can:
- Tap "Delete my uploads" in Settings to erase every file we hold for your device, at any time
- Delete individual tracks from History inside the App
- Delete the App to remove all local cached audio, history, and preferences
- Disable Notifications from iOS Settings at any time
- Request information about data handling, or ask us to delete anything associated with your device, by contacting hello@bulpara.com
10. Children's Privacy
The App is rated 4+ and is not intended for children under 13. The App processes only files you choose and includes no social feed, no messaging, and no user-generated content sharing.
11. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date.
12. Contact Us
If you have questions about this privacy policy, contact us at: