Privacy
Mixar is open source under GPL-3.0 and you can read every line of it. This page describes the little data we do collect, in plain terms, so you can decide whether you want to share it.
This website
We use PostHog to understand which parts of this site are useful, hosted at https://eu.i.posthog.com. It runs in cookieless mode, which means:
- PostHog sets no cookie and writes nothing to local or session storage.
- There is no consent banner, because there is nothing to consent to.
- You are not given a persistent identifier. PostHog counts unique visitors with a salted hash computed on their servers and discarded daily.
During normal use we send two kinds of event: that a page was viewed, and which outbound link was clicked (for example the quick-start guide, or the repository). An error report is a third kind, sent only when a page throws — see below. Alongside each one, the page's own address, its title, and your screen dimensions travel with the event, because that is the minimum a web analytics tool needs to tell two pages apart.
Before anything is sent, we strip your timezone and your browser language from every event. There is no autocapture, so the text you read and the code samples on this site are never sent.
Your browser's user-agent string does travel with the event, because cookieless mode needs it: it is one of four inputs PostHog combines — with the day, your IP address and this site's domain — into a one-way hash that stands in for a cookie. That hash is rotated daily and the key for it is discarded once the day is processed, so the original string cannot be recovered from it. This is also why no location data is stored: your IP is used for the same one-way calculation and is discarded before any other processing runs.
The Mixar app
The desktop app does not collect usage data. Anonymous, opt-in analytics are planned but have not shipped: telemetry is currently an explicit non-goal for this milestone.
When it does arrive, it will be off by default with a one-time prompt and a Settings switch, and it will carry only a randomly generated identifier plus your app version, operating system, architecture, and whether it is a debug or release build. Track data is not part of that design: the component that sends analytics has no access to your library or your audio, so it cannot leak them.
When something breaks
If a page throws an error, we record it so we can fix it. That report contains the error message, the stack trace, and the address of the page it happened on — which is the same page address already described above. It is linked to the same anonymous, daily-rotating identifier as everything else, so it cannot be traced back to you over time.
We do not record what you typed, and we do not record errors from browser extensions or other scripts injected into the page.
What Mixar never collects
This is not a filter applied to your data. The component that sends analytics has no access to your library or your audio in the first place, so it cannot leak any of it. Mixar never collects:
- Track titles, artists, albums, genres, or any other metadata.
- File names, file paths, or anything about your folders and collections.
- Your name, your email, your username, or your account, because there is no account.
- Your MIDI controller's device identifiers.
- Your audio, ever.
Turning it off
If your browser sends Do Not Track orGlobal Privacy Control, we collect nothing: the analytics code is told to drop every event, so no page view or click reaches PostHog. A content blocker that blockshttps://eu.i.posthog.comhas the same effect. Because the mode is cookieless, blocking it costs nothing: there is no stored state to fall back to and nothing to clear afterwards.
Questions
The analytics code is small and readable, and so is the rest of Mixar. Open an issue on the repository if anything here is unclear or looks wrong.