Privacy policy
Last updated: 22 September 2026
1. Who we are
Voidscan Audio publishes and sells Parasite, a software synthesizer. We decide what personal data is collected through this site and why, which makes us the data controller for it under the General Data Protection Regulation. There is one decision we do not take alone, explained in section 4: for the Meta pixel, we and Meta decide together that the data is collected and sent, and are joint controllers for that step.
SIRET: 830 075 990 00036. Our postal address and the rest of our identity are on the legal notice.
For anything in this policy, write to hello@voidscan-audio.com. We are small enough that this reaches a person, not a queue.
2. What we collect and why
Only what the product needs to work, and, on the terms in section 4, what is needed to tell whether an advertisement for Parasite worked. Nothing here is sold.
Buying Parasite
When you buy, our payment provider sends us your email address, the order reference and the amount, so that a licence key can be created and sent to you. We never see your card details: they are entered on the payment provider's own page and never reach us.
If the advertising tags of section 4 are on in your browser, the order confirmation page also reports the purchase to the networks, with the amount and the order reference, so that one sale is counted as one.
Legal basis: performance of the contract. Order records are kept ten years, which French accounting law requires of us.
Your account, if you create one
An account is optional and exists to let you manage your licence, your machines and your presets. We store your email address, the username you choose, and your password in hashed form, meaning we cannot read it and neither can anyone who obtained the file.
If you are signed in while the advertising tags of section 4 are on, a SHA-256 digest of your email address is handed to the three networks so that a network which already holds your address can recognise you among its own users. The address itself never leaves your browser toward them. This is not part of the account contract: it rests on your consent, and the Cookies link at the foot of every page withdraws it.
Legal basis: performance of the contract, except for the digest just described, which rests on consent. Kept for as long as the account exists. Delete it and this goes with it, except what we must keep for accounting.
Licences and activations
A licence records which machines it has been activated on, so that the limit stated at purchase can be enforced and so that you can move your licence to a new computer yourself. The plug-in sends an identifier derived from the machine, not an inventory of it. It also checks periodically that the licence is still valid, and asks the site whether a newer version exists.
Legal basis: performance of the contract, and our legitimate interest in preventing a licence being shared without limit. Kept while the licence exists.
Presets you sync or share
If you use preset sync, the presets you save are stored on our server so that your machines and your account stay in step. A preset is a set of synthesizer parameters; it contains no audio and nothing about you beyond the name you gave it. Sending a preset to another user is something you do deliberately, one preset at a time.
Legal basis: performance of the contract. Kept until you delete the preset or the account.
Emails we send you
Your licence key, address verification, password resets. These are part of the service, not marketing. If we ever start a mailing list it will be a separate, opt-in choice with an unsubscribe link on every message.
Server logs
Our servers record the usual technical lines: IP address, time, page or endpoint requested, and the browser's user agent. They exist to keep the service running and to spot abuse.
Legal basis: our legitimate interest in the security and reliability of the service. Kept six months.
Advertising and measurement
Which pages you open, whether you start a checkout, buy, download the demo or create an account, and the cookies and identifiers that let three advertising networks join those events to the ads they showed you. This is the one thing on this site that the product does not need, so it has its own section and its own legal basis.
Legal basis: consent. Section 4 says what is sent, to whom, on what terms, and how to take the consent back.
3. Cookies and local storage
The site itself sets no cookies. The fonts are served from our own domain, so opening a page here calls no one on its own, with one exception: the press page carries the trailer, embedded from YouTube, so opening that page alone contacts Google. It is embedded through the host YouTube provides for the purpose, which does not set its tracking cookies until the video is actually played. What does call out is the set of advertising tags described in section 4, on the terms set out there; the cookies they set are listed at the end of this section.
Three values are kept in your browser's local storage, and only after you sign in:
- td-token keeps you signed in, so that every page does not ask for your password again.
- td-email and td-username let the dashboard show who is signed in without asking the server first.
All three are strictly necessary to a service you asked for, which is why nothing asks your permission for them. They stay in your browser, are never sent anywhere except to our own API to prove who you are, and signing out removes them. Clearing your browser data removes them too. The one qualification is in section 4: with the advertising tags on, a digest of td-email, and not the address, is given to the networks.
Three more values may appear, none of them needed for the site to work:
- vs-consent records your answer to the banner, when you gave it, which version of the banner it was, and the country code of your connection at the time. It exists so that you are not asked again on every page. It is kept six months, then the question comes back; it comes back sooner if the list of networks changes, because agreeing to three is not agreeing to four.
- vs-country is the two letter country code that decides whether the banner is shown, obtained as described in section 4. It is kept so that the question is not put to our hosting provider on every page. Clearing your browser data removes it.
- vs-success-query keeps whatever our payment provider put in the address of the page you land on after buying. It is kept so that we can see what that address contains, because we do not know and need to, in order to count one sale once rather than twice. It holds no name and no card detail, and it is overwritten by the next purchase.
- vs-checkout is written when you click the buy button. It holds the two Meta cookies described below, your browser's user agent and a number drawn at random, so that the sale our payment provider later tells us about can be matched to the visit that produced it. The same number is added to the payment link, travels to our payment provider and comes back to us with the order.
- vs-aid is a random identifier created when the tags are switched on and deleted when they are refused. It exists so that a visit and a later purchase can be connected in our own records. It is never given to an advertising network, and at present it goes nowhere at all: if we start recording events on our own server it will accompany them, and this page will say so first.
Once the tags are on, the networks set cookies on this domain. They are theirs, not ours: we do not read them, and each lifetime is chosen by the network that sets it.
- _fbp and _fbc, set by Meta. The first identifies your browser to Meta; the second records the identifier of the Facebook or Instagram ad that brought you here, if one did. Both last three months.
- _ga and _ga_ followed by our property id, set by Google Analytics. The first identifies your browser to Google; the second keeps track of the current session. Both are set to last two years.
- _gcl_au, set by Google Ads. It records that you arrived from a Google or YouTube ad, so that a later purchase can be attributed to it. Lasts three months.
- _ttp and _tt_enable_cookie, set by TikTok. The first identifies your browser to TikTok; the second only records that TikTok is allowed to set the first. Both last thirteen months.
Google and Meta can also read or set cookies on their own domains (google.com, doubleclick.net, facebook.com) when their scripts load, which is how they recognise a browser they already know. Those are governed by their policies, linked in section 4, not by this one.
Refuse in the banner, or later through the Cookies link at the foot of every page, and none of the above is set from the next page onwards. Cookies already set expire on their own schedule, or you can delete them from your browser now.
4. Advertising and measurement
We advertise Parasite on Instagram, Facebook, YouTube and TikTok. Two things make those ads cost less: knowing which of them brought people here, and showing them to people who have already looked at Parasite rather than to everyone. Both need the networks to be told who came here and what they did. This section says exactly what is told, to whom, and on what basis.
The three networks
- Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, for Instagram and Facebook. Its privacy policy is at facebook.com/privacy/policy.
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for YouTube, Google Ads and Google Analytics. Its privacy policy is at policies.google.com/privacy.
- TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, Ireland, for TikTok. If you are in the United Kingdom the responsible company is TikTok Information Technologies UK Limited instead. Its privacy policy is at tiktok.com/legal/page/eea/privacy-policy.
What they receive
Each network is sent a short list of events, and nothing outside it:
- that a page was opened, with its address and the page you came from;
- that a scene on the homepage came into view as you scrolled;
- that you clicked the Buy button;
- that you bought, with the price, 59 euros, and the order reference, so that one sale is counted once and not twice;
- that you downloaded the demo, and for which operating system;
- that you created an account.
Google Analytics alone is also told when you sign in. The randomizer and mutator pages are outside all of this: they carry no advertising tag at all.
Every event travels with what any request to a network's server carries: your IP address, your browser's user agent, the cookies that network has set on this domain, and an event identifier we generate.
The sale, which is sent from our server rather than your browser
A purchase is the one event this page does not report. The payment happens on our payment provider's own site, where none of these tags run, and the page you return to afterwards is told nothing about your order: we measured it, and the address it returns to is empty. So a purchase is sent to Meta by our server instead, when our payment provider tells it that an order completed.
That message carries more than the browser ever could, and you should know exactly what: your email address, your first and last name, and your country, each hashed with SHA-256 before it is sent, plus the IP address you paid from and your browser's user agent, which cannot be hashed and still work. It also carries the amount, the currency and the order reference. It does not carry your name or address in readable form, and it never carries anything about your card.
Legal basis: your consent, the same one. If you refused the banner, nothing about your purchase is sent to anyone, and refusing does not stop you buying.
What your browser hands us when you click buy
At that moment, and only then, the page sends our own server the two Meta cookies described in section 3, your browser's user agent, and a number drawn at random. It adds the same number to the payment link, so that our payment provider returns it to us with the order and we can tell which visit produced which sale. That row is kept fourteen days on our server and then deleted.
This goes to us, not to a network. What reaches Meta is the result: a purchase carrying the two cookies, which is what lets it tell you which advert produced a sale rather than merely that one happened. Without it we would be paying for advertising we could not measure.
Your browser stays silent about the sale rather than reporting it as well, so that one purchase is counted once.
If you are signed in, your email address is normalised, hashed with SHA-256 in your browser, and the digest is given to all three networks, so that a network which already holds your address can match it. The address itself is never sent to them. A digest cannot be turned back into the address, but a network can recognise the same digest again, which is the point. Meta's own script does the hashing, in the page, before anything leaves it; for Google and TikTok we do it ourselves and hand over the digest. Signed out, no digest exists to send.
What they do with it
The three networks are not processors working for us. Each uses what it receives for its own purposes as well, principally to build advertising profiles and to measure and improve its own advertising products, and each answers for that under its own policy. For the Meta pixel we and Meta are joint controllers for the collection and sending of the data, under Meta's Controller Addendum, which sets out who does what; Meta alone is controller once it has the data. You can exercise your rights against either of us, and we will pass on whatever is not ours to answer. How long each network keeps what it receives is set by its own policy, linked above.
Google Analytics is set to keep event data fourteen months, the longest its own settings allow, after which it deletes it. Meta and TikTok keep what they receive for as long as their own policies say, linked above.
Where the banner appears
Legal basis: consent, under article 6(1)(a) of the GDPR and article 82 of the French data protection act for the cookies. If you visit from the European Economic Area, the United Kingdom or Switzerland, the banner appears on your first page and nothing above loads until you answer it. Accepting is one click; refusing is one click of the same size, and the site works exactly the same afterwards. Scrolling, closing the tab or ignoring the banner are not answers and load nothing. If your browser sends the Global Privacy Control signal, we take that as your answer, treat it as a refusal, and do not ask.
Visitors from anywhere else are not asked: the tags load on arrival, and the Cookies link at the foot of every page opens the same banner so that they can be turned off in one click. To decide which of the two applies, the page asks our own hosting provider which country your connection comes from, a single request to our own domain that tells no one else anything, and falls back on your browser's timezone if that fails. If neither gives an answer, you are asked.
Your answer is kept six months, then the question comes back. Withdrawing is the same Cookies link: refuse there and nothing loads from the next page onwards.
What is not done
Nothing is sold. No list of customers or addresses is uploaded to any network. Nothing is sent from the plug-in itself: it talks to our API about licences and updates and to no one else. No event carries a preset, an audio file, or anything you typed into a form.
5. Who else sees it
Seven companies. The first four each do one job for us and are not free to use your data for their own purposes. The last three are the advertising networks of section 4, and they are: what they receive, they also use for themselves.
- Our hosting and content delivery provider, Cloudflare, Inc., which serves this site and the plug-in downloads, and which tells the page which country a connection comes from.
- Our server provider, which hosts the application and the database behind api.voidscan-audio.com.
- Our email provider, which delivers licence keys, verification and password resets.
- Our payment provider, PayKickstart, which runs the checkout and takes the payment. For the payment itself it decides on its own how it processes your data, so its own privacy policy applies to that part.
- Meta Platforms Ireland Limited, for the Instagram and Facebook pixel, on the terms in section 4.
- Google Ireland Limited, for Google Ads, YouTube remarketing and Google Analytics, on the terms in section 4.
- TikTok Technology Limited, for the TikTok pixel, on the terms in section 4.
We do not sell personal data. We do share the events listed in section 4 with the three networks named there, on the terms there, and nothing beyond that list.
6. Data outside the European Union
Some of those providers are established in the United States, so some of your data is processed there. Cloudflare, Google and Meta pass what they receive to their American parents, which are certified under the EU–US Data Privacy Framework. The European Commission has decided that the framework gives adequate protection, and that decision is what those transfers rest on.
TikTok is different, and you should know it before you accept. Its transfers rest on the standard contractual clauses adopted by the Commission, and they are not only to the United States: TikTok's own privacy policy says that staff in China, Singapore and Malaysia may access European users' data remotely. On 2 May 2025 the Irish Data Protection Commission found that TikTok's transfers to China had not met the requirements of the GDPR, and fined it; TikTok has appealed. Refusing, in the banner or through the Cookies link, keeps your data out of that entirely.
For the payment provider and the others, ask us and we will tell you which mechanism applies and, where the mechanism is a contract, how to obtain a copy of it.
7. Your rights
Over the data we hold about you, you can ask for: access to it, correction of it, erasure of it, restriction of how we use it, a copy of it in a portable format, and you can object to processing we base on our legitimate interest. Where we rely on your consent, you can withdraw it at any time, and withdrawing it is as easy as giving it was.
For the advertising cookies, withdrawing means the Cookies link at the foot of every page: it reopens the banner, and refusing there stops everything in section 4 from the next page onwards.
Write to hello@voidscan-audio.com. We answer within one month. We may need to check that the request comes from you before acting on it, which for an account holder usually means writing from the address on the account. For what the three networks hold on their own account, you can also write to them directly at the addresses in section 4.
Under French law you may also give directives about what happens to your data after your death.
If you think we have handled your data badly, tell us first and we will try to put it right. You can also complain to the French data protection authority, the CNIL, at cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
8. Changes to this policy
If this policy changes, the date at the top changes with it. A change that affects what we collect or why, rather than wording, is announced on the site before it takes effect, and if it needs your consent we ask for it rather than assume it.
The previous version of this page said that if advertising measurement were ever added, this page would say so before it happened, and that the banner would make refusing take exactly as many clicks as accepting. This version is that notice, published before the first tag was switched on, and section 4 is the banner.