Plain-language data policy
Privacy
Effective August 15, 2026
The short version
Your dub is private evidence. We use it only to provide the verification you requested. It is not placed in a public library, sold, used as entertainment content, or added to a generalized model-training corpus. During upload, you choose whether the audio stays in your private vault until you delete it or is permanently deleted when DubScan publishes the result. You can also delete it manually at any time.
Who may access or receive the audio
Access is limited to:
- DubScan’s internal analysis systems;
- authorized DubScan personnel performing or supporting the review; and
- the claimed artist or that artist’s official engineer, only when source confirmation is needed and you authorized that outreach before submission.
We share only the minimum audio and context reasonably necessary for source confirmation.
What we keep
Whether or not you retain the audio, we keep your account, transaction record, original filename, file size, upload date, check identifier, submitted metadata, workflow timestamps, the final finding, confidence factor, dance-floor verdict, reviewer explanation, and audit history. These records let you identify prior uploads, access results, and let us operate and secure the service.
Private incident reports
You may privately tell DubScan where a disputed dub came from. These reports are not published automatically. We use them to identify repeat patterns, investigate abuse, and contact a marketplace or payment provider when appropriate. We do not provide an open “scammer list.”
Engineering orders and riddims
Mix/master and remix orders are separate from authentication. The selected engineer and authorized DubScan operations personnel may access the source audio, creative direction, and uploaded riddim needed to deliver that order. A linked riddim URL is stored with the order. Engineering assets are never silently reused for authentication, a public library, or a record pool. Order, commission, selected-engineer, and settlement records may be retained for billing, disputes, tax, fraud prevention, and legal obligations after an audio asset is deleted.
Engineer marketplace and payout details
Public engineer cards contain the working name, studio, location, biography, portfolio, services, rates, and turnaround supplied by the engineer. Stripe Connect account state and manual PayPal, Zelle, or Cash App payout destinations are private and available only to authorized DubScan operations and relevant payment processors. Manual settlement references are retained in the private order audit trail.
Community content
Your community alias, posts, replies, submitted links, votes, reports, moderation history, and timestamps are stored separately from uploaded dub audio. Published community content is visible to other signed-in members. Items under review may be limited to you and authorized moderators. Private membership is an access control, not a promise that other members will keep a post confidential. Verification-audio retention choices do not delete community text; you may request removal subject to safety, dispute, and legal retention needs.
Profiles and badges
Your alias, selected roles, profile details, visibility setting, and earned badge identifiers are stored with your account. A members-visible profile appears in the signed-in member directory; a private profile is excluded from new-member discovery. Badge progress is calculated from relevant service and community activity. Public badge rules do not expose your private audio or private message contents.
End-to-end encrypted messages
Private-message bodies are encrypted in your browser before upload. DubScan stores ciphertext, participant identifiers, timestamps, delivery state, public message keys, and a private-key backup encrypted by your recovery phrase. DubScan does not receive that phrase and cannot ordinarily read message bodies. A participant may explicitly decrypt and share one selected message with moderators when filing a safety report; the rest of the conversation remains encrypted. The shared excerpt is retained with the report subject to safety, dispute, and legal needs.
Optional WhatsApp processing
WhatsApp integration is off by default. Alert-only mode sends a notification and app link, not the message body. Managed-bridge mode requires separate consent and allows Meta, DubScan, the connected WhatsApp Business account, and any disclosed automation provider to process bridged content. That content is therefore not participant-only even when an encrypted copy is preserved in DubScan. We retain the bridge mode, connection status, consent timestamp, automation setting, and limited account identifiers so the channel can be disconnected and later replaced by DubScan’s native app.
Events, tickets, and event archives
Event listings contain promoter-supplied dates, venue details, lineup, entry policy, pricing, and contact-facing profile information. Ticketing records include the buyer account, order, tier, payment state, single-use signed ticket identifier, and check-in timestamp. A promoter can see operational ticket and check-in information for that event, but not your full payment-card number. Stripe processes card details under its own privacy terms.
Promoter-published posters, galleries, and set replays are visible with the event archive. Uploaders must attest that they have publication rights and, where appropriate, permission from recognizable people. We keep order, payout, refund, fraud, and check-in records as required for accounting, dispute handling, security, and law even if an event page or media item is later removed.
Culture catalog, record pool, and contributor media
Published music, artwork, artist listings, stories, podcasts, shows, videos, contributor aliases, external links, prices, and release metadata are public culture content. Items awaiting moderation are available to the uploader and authorized DubScan operations. A track intentionally submitted to the record pool, plus its embargo and campaign note, is available to identity-verified DJ / selecta accounts; it becomes public only after publication. We store each verified DJ's save, rotation, or pass response and optional note for the DJ, the submitting artist, and service operations.
Public and record-pool media are separate from private verification uploads. Removing a culture item may stop future display while limited rights attestations, moderation decisions, file metadata, and dispute evidence remain available for safety, accounting, rights complaints, and legal obligations.
Artist marketplace, reviews, and referrals
Artist-order records include the buyer and artist accounts, sound name, creative brief, reference link, gross price, commission, artist net, payment state, delivery state, payout reference, and any referral code. The buyer, artist, authorized DubScan operations, Stripe, and relevant payout providers receive only the information needed for their part of the transaction. Published verified-order reviews display the reviewer alias, rating, text, and relationship to the listing; account and order identifiers remain in the private audit trail.
Referral records associate a code with a member account and record qualifying order, reward, reversal, and payout state. They are retained for fraud prevention, accounting, disputes, and tax or legal duties.
Infrastructure and processors
DubScan uses Google Cloud and Firebase for hosting, identity, private storage, and database services; Stripe and Stripe Connect for billing and automated marketplace settlement; Slack for internal workflow notifications; and, only after a member opts in, Meta for WhatsApp Business delivery. Slack notices contain case metadata and a private admin link, not the uploaded audio itself.
Your choices
Source-contact permission is optional. If you decline it, we complete the review using the evidence available and reflect any limitation in the confidence factor. You may choose your audio retention setting, manually delete retained audio, choose whether your profile is discoverable, block another member, turn WhatsApp off, and request access to or deletion of retained account and result records, subject to billing, security, fraud-prevention, moderation, and legal retention obligations.
Contact
Privacy requests can be sent to privacy@dubscan.com.