Overview
Jinxter Labs is the trading name of Rowena Simon Ruiter, a sole proprietor. Jinxter Labs ("we", "us") builds desktop applications, including SFX Showtime Pro, KaraYou and KaraHome, and their companion services. This policy describes what data these apps and services collect, why, and how it's handled. We keep data collection to the minimum needed to run license activation, free trials, and (for KaraYou) live song requests. We don't run advertising, analytics tracking, or sell data to third parties.
Accounts
Buying a license requires a JinxterLabs account. Creating one collects your email address and a hashed password (we never store your password itself). One account works across every Jinxter Labs app.
License Purchase & Activation
When you buy or activate a license for SFX Showtime Pro, KaraYou or KaraHome, we send your email address to Paddle.com Market Limited, our payment processor and merchant of record, to run checkout. Paddle handles the checkout itself, including your payment details - we never see or store your card information. The app also sends your license key and your device's name (e.g. "DESKTOP-ABC123") to our own license server to bind the license to your device. KaraHome sends the one-way hardware hash described under Free Trials instead of the device's name, and only falls back to the device's name if the hardware can't be read. See Paddle's Privacy Policy for how they handle checkout and billing data.
Free Trials
Each app offers a 14-day free trial. To enforce the trial period and prevent the same device from repeatedly re-starting a trial, the app computes a one-way SHA-256 hash of a hardware identifier (your motherboard or processor serial number) and stores that hash, along with a trial expiry date, in our Google Firestore database. This hash cannot be reversed back into your original hardware serial, and it is not linked to your name, email, or any other identifying information. Trial records are automatically deleted 180 days after they're created. (KaraHome uses Windows' own machine ID when neither serial number is available, and your device's name only if none of these can be read.)
KaraYou Live Requests
KaraYou includes an optional feature that lets audience members at a live event submit song requests from their own phone, via a companion web app (no install required). If you use this feature, either as the venue operator or as a guest submitting a request, the following data is collected:
| Data | Why we collect it |
|---|---|
| The name you type into the request form | Shown to the venue operator so they know who requested the song |
| Song title and artist | The request itself |
| A browser-generated device fingerprint | Lets you see your own request's queue status and enforces a per-device cooldown between requests, without requiring an account or login |
| Venue/room code | Routes your request to the correct venue's queue |
| A push-notification token | Only collected if you tap "Enable Notifications", used solely to alert you when your song is coming up next |
This data is stored in Google Firestore and is visible in real time to the venue operator running KaraYou, so they can manage their show's request queue. It is not used for advertising, profiling, or shared with any third party beyond Google (our cloud storage provider). At this time, request records are not automatically deleted. If you'd like a request record removed, contact us using the details below.
KaraHome Guest Connections
KaraHome lets guests add songs to the queue from their own phone by scanning a QR code (no install required). The guest page is served by the host's own computer, not by us. The name a guest types, the songs they search for and request, their favorites, and a random device ID kept in their browser go directly from the guest's phone to the host's KaraHome app and are stored only on the host's computer. None of it is sent to Jinxter Labs.
- Internet access (optional, off by default): if the host turns this on, guests who aren't on the host's Wi-Fi connect to the host's computer over the internet through a private link. These connections use plain HTTP, which is not encrypted. To create the link, KaraHome looks up the home's public internet address using ipify.org (or icanhazip.com as a fallback); like any website, those services see the host's IP address when it asks.
- QR scanner page: if a guest's link stops working, the guest page can open a scanner page on this website so the guest can scan the host's new QR code. The camera picture is processed entirely inside the guest's browser; no images or scanned codes are sent to us, and the page has no analytics. The scanned link opens directly on the host's computer.
Third Parties We Use
- Paddle.com Market Limited: payment processing and merchant-of-record services.
- Google Firebase / Cloud Firestore: cloud database used for trial tracking and KaraYou's live request queue.
- Google Cloud Messaging: opt-in push notifications for the KaraYou Live Requests queue.
- YouTube (Google): KaraHome searches for and plays karaoke videos from YouTube; YouTube's own privacy policy applies to that.
- ipify.org and icanhazip.com: public internet address lookup, only when KaraHome's optional internet access is turned on.
- Cloudflare: hosts and delivers this website, including the KaraHome QR scanner page; like any web host, it receives standard request information such as your IP address.
Data Security
We use reasonable technical measures (hashing device identifiers, restricting database access with security rules) to protect the data described above. No method of storage or transmission is 100% secure, and we can't guarantee absolute security.
Children's Privacy
Our apps and services are not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has submitted data through KaraYou Live Requests, contact us and we'll remove it.
Your Rights
You can ask us to tell you what data we hold about you, or to delete it, at any time by contacting us using the details below. For trial records, this happens automatically after 180 days; for anything else described on this page, we'll handle deletion requests manually.
Changes to This Policy
We may update this policy as our apps and services change. Material changes will update the "Last updated" date at the top of this page.
Contact
Questions about this policy or a data request? Email [email protected], or reach out via our Discord.