Privacy & Legal
Last updated 18 August 2026
Who is responsible
- Service provider and data controller
- Sergio Muscat
- support@timbria.eu
Timbria is run by an individual, not a company. Write to the email address above about anything on this page, including any request about your own data — it reaches a person, and it is the fastest route to a reply.
What Timbria does
You upload an image. Timbria reads its colours, contrasts, edges and detail, and composes music from what it finds. The same image and the same settings always produce the same music: the composition is calculated from the picture, not improvised.
To choose a musical style for an image, Timbria asks an AI model to look at it. You can also sign in with Google to keep your work across visits. Both send something to Google, for different reasons — both are described in full below.
What is held, and why
| What | Why | Legal basis |
|---|---|---|
| The image you upload | It is the score. It is kept so a piece can be played back, re-composed and shown on a share page. | Art 6(1)(b) — to provide what you asked for |
| Your description of the image, if you write one | It guides which musical styles are proposed. It is private: it is never shown on a share page. | Art 6(1)(b) |
| Title and artist, if you enter them | They name the artwork. These ARE shown publicly on a share page, and only there. | Art 6(1)(b) |
| The music produced — the MIDI, the audio and the composition data | So a piece can be replayed and shared without being recomposed each time. | Art 6(1)(b) |
| A random device identifier | It holds your work for you before there is an account to hold it. It identifies a browser, not a person, and is not used to track you. | Art 6(1)(b); ePrivacy Art 5(3) — strictly necessary |
| Your IP address | Recorded with each request to enforce rate limits and to detect abuse. It is not used to identify you or to profile you. | Art 6(1)(f) — security and preventing abuse |
| Your email address, display name and Google account identifier — only if you sign in | To recognise you as the same person on your next visit and to show your name back to you. The identifier links your account to your Google sign-in; it is not shown to anyone else. | Art 6(1)(b) |
| Your sessions — only if you sign in | Each sign-in is recorded with when it started, when it expires and when it was last used, so a session can be kept alive while you are using Timbria and ended cleanly when it is not. It also records which browser identifier that sign-in claimed, because that is how work you made before signing in becomes yours. | Art 6(1)(b); ePrivacy Art 5(3) — strictly necessary, see below |
An account is optional. Everything above the sign-in rows works without one, tied instead to the device identifier below. Signing in gets you the same work back on a different device, and nothing else changes about how Timbria treats what you make. Timbria runs no analytics, no advertising and no third-party trackers, whether or not you sign in.
What leaves this service
Analysing your image
Your image, and your description of it if you wrote one, are sent to Google (Google Ireland Limited and its affiliates) to be analysed by the Gemini model. This is what produces the style proposals and the written note about the piece. It happens on the server, not in your browser.
Google acts as a processor for Timbria, and this involves a transfer outside the European Economic Area, safeguarded by the European Commission's Standard Contractual Clauses under Art 46 GDPR. Google's handling of the data is governed by its own terms for the Gemini API.
Signing in with Google
This is a separate transfer, for a separate reason. If you choose to sign in, you authenticate directly with Google and Timbria never sees your Google password — Google then sends Timbria your email address, your display name and an account identifier, so Timbria can recognise you on your next visit. No image or description is involved in this exchange, and analysing an image never requires signing in.
This also involves a transfer outside the European Economic Area, under the same Standard Contractual Clauses named above. Google's handling of your account information during sign-in is governed by Google's own privacy policy, not this one.
Nothing else leaves. Fonts, the audio engine and every other asset are served from this site rather than from a third party — deliberately, because loading a file from another company's server would disclose your IP address to them on every page view.
Cookies and local storage
Timbria sets two cookies, both used only to run the sign-in you asked for — neither is used for advertising, analytics or tracking, and neither is shared with anyone:
| Name | Purpose | Lifetime |
|---|---|---|
| timbria_oauth | Holds the anti-forgery state and the sign-in proof for a Google sign-in while it is in progress, plus whether you ticked "Keep me signed in". Deleted the moment sign-in completes. | Up to 10 minutes |
| timbria_session | Keeps you signed in. Read on every request to a page or feature that needs to know who you are. | Ends when you close your browser — unless you tick "Keep me signed in", which keeps it for 14 days, renewed while you keep using Timbria, up to a hard limit of 30 days from signing in |
It also writes two entries to your browser's local storage, both belonging to this site alone:
- A random device identifier — so that the pieces you make are still yours when you come back, before or without an account. It is a random value with no meaning: it is not derived from your device, your browser or anything about you.
- A note that you have read the introduction — so that the front page shows it in full the first time and shortened afterwards on a small screen.
Consent under ePrivacy Art 5(3) is required for storing anything on your device UNLESS it is strictly necessary for a service you explicitly requested. Every cookie and storage entry above meets that test, with one deliberate exception: keeping the session cookie alive for up to 30 days, instead of letting it end with your browser, is a convenience rather than a necessity, so it is not covered by that exemption. It does not need a banner either, because it is already consented to by the "Keep me signed in" checkbox — unticked by default, so persistence happens only if you affirmatively ask for it. That is the remedy WP29 Opinion 04/2012 itself names for this situation, not a claim that the checkbox is unnecessary; the distinction between the two is the entire basis for there being no banner on this page.
You can clear any of this at any time through your browser's "clear site data". Everything keeps working; the only effect is that you are signed out and unsaved pieces stop being recognised as yours. Your rate limit is not affected — it is not tied to these.
Deliberately not used: device fingerprinting. It would have identified a returning visitor without storing anything, and it is refused on both counts — it is treated as tracking under the same rules whether or not it writes to your device, and it is unreliable in a way that matters here, because two similar devices can look identical and be handed each other's work.
How long it is kept
- The current version of a piece is kept indefinitely, as is any version you have pinned or shared.
- A version you have replaced is deleted after 48 hours, unless it is pinned or shared. The delay exists so that recomposing something is undoable.
- No request log is kept by Timbria. Rate limiting counts requests in memory only, and those counters are discarded on a recurring timer and whenever the service restarts. The web server in front of Timbria keeps its own access log, as any web server does.
- A session is deleted once it expires or once you sign out, whichever comes first — swept from storage on the same recurring cycle that clears everything else here.
Deletion removes the image, the audio and the composition together.
Deleting your account removes it, its sign-in, its sessions, and everything it owns — every piece, image and audio render, and the share links to them. This cannot be undone.
When you share a piece
Sharing produces a link that anyone holding it can open, showing the image, the music, the title and artist if you entered them, and the note about the composition. It does not show your description of the image, and there is no listing or index — a piece is reachable only by its link.
Two consequences worth knowing before you share. A share follows the piece rather than a fixed recording, so if you recompose it, the link plays the new version. And a link that has been passed on cannot be recalled — you can stop the link working, but not what someone has already saved.
Your rights
Under the GDPR you may ask for a copy of your data, ask for it to be corrected or deleted, ask that its use be restricted, ask for it in a portable form, and object to processing that relies on legitimate interests. There is no automated decision-making with legal effects.
Write to support@timbria.eu. If you are signed in, say so — your account is the reliable way to prove which pieces are yours. If you are not, there is no such proof, so a request is easiest to act on if it names the share links or the device involved.
If you are not satisfied with the response, you may complain to the Office of the Information and Data Protection Commissioner in Malta, or to the supervisory authority where you live.
Changes
This notice will change as Timbria does — accounts and sign-in are the latest example, added in this update along with the cookies they need. The date at the top is when it last changed.
← Back to Timbria