Legal

Third-party notices

TrackClear Studio incorporates and redistributes third-party software. The notices below satisfy the attribution and notice requirements of those components' licenses.

This is the notice shipped with TrackClear Studio 0.5.0 and later. Last verified 10 September 2026 against the binaries in the installer's binary folder and the packages in package.json and the backend requirements file.

Verbatim copies of every license referred to here are installed with the app, in the licenses/ folder. Each entry names the file it relies on.

1. FFmpeg

Files shipped: resources/bin/ffmpeg.exe and resources/bin/ffprobe.exe in the install folder. Version: n8.1.2-44-g7c533d0f86-20260822, built with gcc 15.2.0 (crosstool-NG 1.28.0.23_185f348). Producer: BtbN/FFmpeg-Builds, win64-lgpl variant. Releases: https://github.com/BtbN/FFmpeg-Builds/releases (asset name ffmpeg-n8.1-latest-win64-lgpl-8.1.zip; the versioned asset for this build is ffmpeg-n8.1.2-44-g7c533d0f86-win64-lgpl-8.1.zip). Upstream: https://ffmpeg.org, source at https://git.ffmpeg.org/ffmpeg.git, commit 7c533d0f86 (full hash 7c533d0f86f13a06ec93968f6194349665b3536a): https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/7c533d0f86 License: GNU Lesser General Public License, version 3 or later. See licenses/LGPL-3.0.txt and licenses/GPL-3.0.txt (the LGPL v3 incorporates the GPL v3 by reference).

Checksums (SHA-256) of the shipped binaries:

FileSize (bytes)SHA-256
ffmpeg.exe113,981,440110a3f4171be1d010edb2ec4bf57838cd632082070cffb4f4b18b7fffc4a7e6b
ffprobe.exe113,775,1049d49ff93ca7c6086748e3b6551feb82ffb5cceeb2e785fa04ba64dce052524b0

The copies in the installer's binary folder (what the installer packages) and in backend/bin/ (what development runs) are byte-identical: same sizes, same hashes. ffprobe.exe reports the same version string and the same configuration as ffmpeg.exe.

TrackClear Studio redistributes these two files as unmodified, standalone executables. They are invoked as separate child processes over a command line and their output is read back over a pipe. No FFmpeg library is linked into TrackClear Studio, statically or dynamically, and no FFmpeg source code is included in or derived from in this product.

Build configuration, verbatim

Output of ffmpeg.exe -version on 10 September 2026:

ffmpeg version n8.1.2-44-g7c533d0f86-20260822 Copyright (c) 2000-2026 the FFmpeg developers
built with gcc 15.2.0 (crosstool-NG 1.28.0.23_185f348)
configuration: --prefix=/ffbuild/prefix --pkg-config-flags=--static --pkg-config=pkg-config --cross-prefix=x86_64-w64-mingw32- --arch=x86_64 --target-os=mingw32 --enable-version3 --disable-debug --disable-w32threads --enable-pthreads --enable-iconv --enable-zlib --enable-libxml2 --enable-libvmaf --enable-fontconfig --enable-libharfbuzz --enable-libfreetype --enable-libfribidi --enable-vulkan --enable-libshaderc --enable-libvorbis --disable-libxcb --disable-xlib --disable-libpulse --enable-gmp --enable-lzma --enable-liblcevc-dec --enable-opencl --enable-amf --enable-libaom --enable-libaribb24 --disable-avisynth --enable-chromaprint --enable-libdav1d --disable-libdavs2 --disable-libdvdread --disable-libdvdnav --disable-libfdk-aac --enable-ffnvcodec --enable-cuda-llvm --disable-frei0r --enable-libgme --enable-libkvazaar --enable-libaribcaption --enable-libass --enable-libbluray --enable-libjxl --enable-libmp3lame --enable-libopus --enable-libplacebo --enable-librist --enable-libssh --enable-libtheora --enable-libvpx --enable-libwebp --enable-libzmq --enable-lv2 --enable-libvpl --enable-openal --enable-liboapv --enable-libopencore-amrnb --enable-libopencore-amrwb --enable-libopenh264 --enable-libopenjpeg --enable-libopenmpt --enable-librav1e --disable-librubberband --enable-schannel --enable-sdl2 --enable-libsnappy --enable-libsoxr --enable-libsrt --enable-libsvtav1 --enable-libtwolame --enable-libuavs3d --disable-libdrm --enable-vaapi --disable-libvidstab --enable-libvvenc --disable-whisper --disable-libx264 --disable-libx265 --disable-libxavs2 --disable-libxvid --enable-libzimg --enable-libzvbi --extra-cflags=-DLIBTWOLAME_STATIC --extra-cxxflags= --extra-libs=-lgomp --extra-ldflags=-pthread --extra-ldexeflags= --cc=x86_64-w64-mingw32-gcc --cxx=x86_64-w64-mingw32-g++ --ar=x86_64-w64-mingw32-gcc-ar --ranlib=x86_64-w64-mingw32-gcc-ranlib --nm=x86_64-w64-mingw32-gcc-nm --extra-version=20260822
libavutil      60. 26.102 / 60. 26.102
libavcodec     62. 28.102 / 62. 28.102
libavformat    62. 12.102 / 62. 12.102
libavdevice    62.  3.102 / 62.  3.102
libavfilter    11. 14.102 / 11. 14.102
libswscale      9.  5.102 /  9.  5.102
libswresample   6.  3.102 /  6.  3.102

ffprobe.exe -version prints ffprobe version n8.1.2-44-g7c533d0f86-20260822 with the identical configuration: line and the same seven library versions.

What the configuration establishes:

Written offer for source code

TrackClear Studio ships FFmpeg in binary form only. The complete corresponding source code for the FFmpeg version above, and for the libraries statically linked into it, is available as follows:

Independently of those third-party sites, TrackClear Studio makes the following written offer, valid for three years from the date you purchased or obtained this copy of TrackClear Studio: any recipient of this software may request, and will receive, a complete machine-readable copy of the corresponding source code for the FFmpeg binaries described above, including the build scripts used to produce them, for no more than the cost of physically performing the distribution. Send the request, quoting the FFmpeg version string above, to trackclearsupport@gmail.com. This offer is transferable to anyone who receives the software from you.

TrackClear Studio keeps its own self-hosted copy of that source archive so that the offer can be honored even if the third-party repositories above move or disappear.

Libraries statically linked into the FFmpeg executables

The FFmpeg binaries above statically incorporate the following third-party libraries. Each carries its own license and its own notice requirement. Presence was confirmed by the configuration: line above and, for sub-dependencies that FFmpeg's configure does not see, by scanning the shipped ffmpeg.exe for the library's own identification strings. License identifiers were checked against each project's published license file.

LibraryLicenseLicense fileNotes
chromaprintLGPL-2.1 (own code MIT; includes LGPL-2.1 FFmpeg code, so LGPL-2.1 as a whole)LGPL-2.1.txt, MIT.txtAcoustID fingerprints. See FFTW3 below
FFTW3 (fftw-3.3.11, inside chromaprint)GPL-2.0-or-laterGPL-2.0.txtSub-dependency of chromaprint. See below
libmp3lame (LAME)LGPL-2.0-or-laterLGPL-2.1.txtMP3 encoding
libopenh264BSD-2-ClauseBSD-2-Clause.txtCisco. See patent note below
libvorbis, libtheora, libopusBSD-3-ClauseBSD-3-Clause.txtXiph.Org
libfreetypeFTL or GPL-2.0 (dual)FTL.txtTaken under the FTL
libharfbuzzMIT (Old MIT)MIT.txt
libfribidiLGPL-2.1-or-laterLGPL-2.1.txt
fontconfigMIT-style (fontconfig license)MIT.txt
libassISCISC.txt
libunibreak (inside libass)ZlibZlib.txtSub-dependency
libaomBSD-2-Clause + Alliance for Open Media Patent License 1.0BSD-2-Clause.txtPatent license: https://aomedia.org/license/patent-license/
libdav1dBSD-2-ClauseBSD-2-Clause.txtAV1
librav1eBSD-2-ClauseBSD-2-Clause.txtAV1
libsvtav1BSD-3-Clause-Clear + AOM Patent License 1.0BSD-3-Clause-Clear.txtAV1
libdoviMITMIT.txtSub-dependency of libplacebo
libvpxBSD-3-ClauseBSD-3-Clause.txtGoogle
libwebp, libsnappyBSD-3-ClauseBSD-3-Clause.txtGoogle
libjxlBSD-3-ClauseBSD-3-Clause.txtJPEG XL
highway (inside libjxl)Apache-2.0Apache-2.0.txtSub-dependency
brotli (inside libjxl)MITMIT.txtSub-dependency
libpng (1.8.0)PNG Reference Library License v2libpng-2.0.txtSub-dependency
libopenjpegBSD-2-ClauseBSD-2-Clause.txt
libkvazaarBSD-3-ClauseBSD-3-Clause.txtTampere University
libvvencBSD-3-Clause-ClearBSD-3-Clause-Clear.txtFraunhofer HHI
liboapvBSD-3-ClauseBSD-3-Clause.txtSamsung / Academy Software Foundation
libuavs3dBSD-3-ClauseBSD-3-Clause.txtPeking University et al.
libzimgWTFPLWTFPL.txt
libvmafBSD-2-Clause-PatentBSD-2-Clause-Patent.txtNetflix
libsoxr (0.1.3)LGPL-2.1-or-laterLGPL-2.1.txt
libtwolameLGPL-2.1-or-laterLGPL-2.1.txt
libblurayLGPL-2.1-or-laterLGPL-2.1.txt
libgmeLGPL-2.1-or-laterLGPL-2.1.txt
libopenmptBSD-3-ClauseBSD-3-Clause.txt
libplaceboLGPL-2.1-or-laterLGPL-2.1.txt
libsshLGPL-2.1LGPL-2.1.txt
libsrtMPL-2.0MPL-2.0.txtHaivision
libzmq (ZeroMQ 4.3.5)MPL-2.0MPL-2.0.txt
librist (0.2.x)BSD-2-ClauseBSD-2-Clause.txt
libaribb24LGPL-3.0-or-laterLGPL-3.0.txt
libaribcaptionMITMIT.txt
liblcevc-decBSD-3-Clause-ClearBSD-3-Clause-Clear.txtV-Nova
libopencore-amrnb / amrwbApache-2.0Apache-2.0.txt
libzvbi (0.2.45)LGPL-2.0-or-laterLGPL-2.1.txtLibrary half of ZVBI; the ZVBI command-line tools are GPL and are not included
libxml2MITMIT.txt
libiconvLGPL-2.1-or-laterLGPL-2.1.txt
zlibZlibZlib.txt
xz / liblzma0BSD0BSD.txt
gmpLGPL-3.0-or-later or GPL-2.0-or-later (dual)LGPL-3.0.txtTaken under LGPL-3.0
SDL2ZlibZlib.txt
OpenAL SoftLGPL-2.0-or-laterLGPL-2.1.txt
lv2, lilv, serd, sord, sratomISCISC.txt
oneVPL (libvpl)MITMIT.txtIntel
nv-codec-headers (ffnvcodec)MITMIT.txtNVIDIA headers only; no NVIDIA SDK code
AMD AMF headersMITMIT.txt
libva (VAAPI)MITMIT.txt
Vulkan headers and loaderApache-2.0Apache-2.0.txt
libshaderc, glslang, SPIRV-ToolsApache-2.0 (glslang also BSD-3-Clause and MIT for parts)Apache-2.0.txt, BSD-3-Clause.txt
OpenCL headersApache-2.0Apache-2.0.txt
winpthreadsMIT and BSD-3-ClauseMIT.txt, BSD-3-Clause.txtMinGW-w64
libgompGPL-3.0 with GCC Runtime Library Exception 3.1GPL-3.0.txt, GCC-exception-3.1.txtSee note below

The LGPL-2.0 text is the LGPL 2.1 text's predecessor; components marked LGPL-2.0-or-later are taken under LGPL 2.1, whose text ships as licenses/LGPL-2.1.txt.

chromaprint and FFTW3

The chromaprint inside these binaries is statically linked against FFTW3, which is licensed GPL-2.0-or-later. Evidence: the string fftw-3.3.11 and several hundred fftw_codelet_* symbols are present in ffmpeg.exe. FFmpeg's own configure has no visibility into this and therefore does not flag it; the BtbN download is labeled LGPL, and that label is accurate about FFmpeg's own code and silent about this.

The question of whether calling the executable as a separate process keeps the GPL from reaching the application is with counsel (see counsel). Until it is answered this file states the fact and ships the GPL-2.0 text as licenses/GPL-2.0.txt. If counsel's answer requires a change, the engineering options are to build chromaprint with -DFFT_LIB=kissfft or -DFFT_LIB=avfft, which removes FFTW entirely (see our build notes), or to ship AcoustID's fpcalc separately with an FFmpeg built without --enable-chromaprint.

Note on libgomp

libgomp is GPL-3.0, but carries the GCC Runtime Library Exception 3.1, which expressly permits distribution inside non-free programs when compiled with GCC in the ordinary way. It is listed because an automated license scan will flag it and it should not cause alarm. The exception text ships as licenses/GCC-exception-3.1.txt.

libopenh264 is BSD-licensed as to copyright. Cisco separately funds the H.264 patent pool, but that coverage applies to binary modules Cisco itself distributes. This build compiles OpenH264 from source, so it does not inherit that coverage. The FFmpeg-native AAC encoder used for the stitched snippet video sits in a comparable pool. Both are part of the same counsel conversation.

2. Genre classification model

LAION-CLAP, Apache License 2.0, https://github.com/LAION-AI/CLAP. See licenses/Apache-2.0.txt.

Model weights are redistributed in ONNX form as resources/models/genre/model.onnx with model.json beside it (copied at build time from the backend model folder). The export to ONNX is done offline by an offline export script; PyTorch and the laion_clap package are build-time tools and are not shipped. LAION-CLAP was chosen over the more accurate MTG-Jamendo/Essentia models specifically because those are CC BY-NC-SA and cannot be used in a product that is sold.

3. Python backend

The backend is a Windows executable (resources/backend/trackclear.exe plus _internal/) frozen by PyInstaller from CPython 3.14.5 and the packages below. The list was taken from the frozen build's own module table (the frozen module table and the _internal/ folder), which is what actually ships, and then compared with the backend requirements file. The bundled-library entries for numpy come from the numpy wheel's own LICENSE.txt, which names each DLL it carries.

ComponentVersionLicenseLicense file
CPython3.14.5Python Software Foundation License 2.0PSF-2.0.txt
PyInstaller (bootloader and runtime hooks)6.21.0GPL-2.0-or-later with the PyInstaller Bootloader Exception; the frozen program is unrestrictedPyInstaller-COPYING.txt
pytaglib (taglib.pyd)3.2.0GPL-3.0-or-later (see the TagLib note below)GPL-3.0.txt
TagLib (built into taglib.pyd)2.1.1 (bundled by the pytaglib wheel)MPL-1.1 or LGPL-2.1 (dual); taken under MPL-1.1MPL-1.1.txt
utfcpp (built into taglib.pyd)4.0.8 (bundled by the pytaglib wheel)Boost Software License 1.0BSL-1.0.txt
numpy2.4.6BSD-3-Clause AND 0BSD AND MIT AND Zlib AND CC0-1.0 (SPDX expression from the wheel)BSD-3-Clause.txt, 0BSD.txt, MIT.txt, Zlib.txt
OpenBLAS (inside numpy.libs/libscipy_openblas64_*.dll)as bundled by numpy 2.4.6BSD-3-ClauseBSD-3-Clause.txt
LAPACK (inside the same DLL)as bundled by numpy 2.4.6BSD-3-Clause-Open-MPIBSD-3-Clause-Open-MPI.txt
GCC runtime library (libgfortran, libgcc, inside the same DLL)as bundled by numpy 2.4.6GPL-3.0-or-later with GCC Runtime Library Exception 3.1GPL-3.0.txt, GCC-exception-3.1.txt
onnxruntime1.28.0MITMIT.txt
rapidfuzz3.9.3MITMIT.txt
requests2.34.2Apache-2.0Apache-2.0.txt
requests-oauthlib2.0.0ISCISC.txt
oauthlib3.3.1BSD-3-ClauseBSD-3-Clause.txt
google-auth2.53.0Apache-2.0Apache-2.0.txt
google-auth-httplib20.4.0Apache-2.0Apache-2.0.txt
google-auth-oauthlib1.4.0Apache-2.0Apache-2.0.txt
google-api-python-client2.197.0Apache-2.0Apache-2.0.txt
google-api-core2.31.0Apache-2.0Apache-2.0.txt
httplib20.31.2MITMIT.txt
uritemplate4.2.0BSD-3-Clause or Apache-2.0BSD-3-Clause.txt
pyasn1, pyasn1-modules0.6.3, 0.4.2BSD-2-ClauseBSD-2-Clause.txt
python-dotenv1.2.2BSD-3-ClauseBSD-3-Clause.txt
Send2Trash2.1.0BSD-3-ClauseBSD-3-Clause.txt
pywin32312Python Software Foundation LicensePSF-2.0.txt
cryptography48.0.0Apache-2.0 or BSD-3-ClauseApache-2.0.txt
cffi2.0.0MITMIT.txt
pycparser3.0BSD-3-ClauseBSD-3-Clause.txt
certifi2026.5.20MPL-2.0MPL-2.0.txt
charset-normalizer3.4.7MITMIT.txt
idna3.17BSD-3-ClauseBSD-3-Clause.txt
urllib32.7.0MITMIT.txt
Jinja23.1.6BSD-3-ClauseBSD-3-Clause.txt
MarkupSafe3.0.3BSD-3-ClauseBSD-3-Clause.txt
PyYAML6.0.3MITMIT.txt
packaging26.2Apache-2.0 or BSD-2-ClauseApache-2.0.txt
pyparsing3.3.2MITMIT.txt
typing_extensions4.15.0PSF-2.0PSF-2.0.txt
setuptools82.0.1MITMIT.txt
OpenSSL (libcrypto-3.dll, libssl-3.dll)3.0.20, as shipped with CPython 3.14.5Apache-2.0Apache-2.0.txt
libffi (libffi-8.dll)as shipped with CPython 3.14.5MITMIT.txt
SQLite (sqlite3.dll)3.50.4, as shipped with CPython 3.14.5Public domainnone required
Microsoft Visual C++ runtime (vcruntime140.dll, vcruntime140_1.dll, msvcp140.dll, MSVCP140_1.dll)14.xMicrosoft Visual C++ Redistributable license, which permits redistribution with applications built with Visual Studionone (proprietary, redistributable)

onnxruntime's own third-party notices (protobuf, Eigen, Abseil, and others compiled into onnxruntime.dll) are published in ThirdPartyNotices.txt in the onnxruntime wheel and at https://github.com/microsoft/onnxruntime/blob/main/ThirdPartyNotices.txt.

Packages in the backend requirements file that are not in the shipped executable

pandas 2.2.2 (BSD-3-Clause), tqdm 4.66.4 (MPL-2.0 and MIT), fastapi 0.111.0 (MIT) and uvicorn 0.30.1 (BSD-3-Clause) are pinned in the backend requirements file but no backend module imports them, so PyInstaller does not freeze them and they do not ship. They are listed here so the requirements file and this notice agree; their license texts (BSD-3-Clause.txt, MPL-2.0.txt, MIT.txt) are in licenses/ regardless.

TagLib and pytaglib

TagLib (https://github.com/taglib/taglib) is offered under either the Mozilla Public License 1.1 or the LGPL 2.1, at the recipient's choice. TrackClear Studio takes it under the MPL 1.1 (licenses/MPL-1.1.txt), which permits linking into a larger closed-source work provided the MPL-covered source itself stays available under the MPL. TagLib's source is available from the repository above; the copy compiled into taglib.pyd is TagLib v2.1.1 as bundled in the pytaglib 3.2.0 source distribution (https://pypi.org/project/pytaglib/3.2.0/#files).

pytaglib (https://github.com/supermihi/pytaglib) is the Python binding. Its 3.2.0 wheel declares License-Expression: GPL-3.0-or-later and ships the GNU GPL v3 as its LICENSE.txt; that text is licenses/GPL-3.0.txt. Earlier versions of this notice and the comment in the backend requirements file describe pytaglib as MIT; the wheel's own metadata and license file say otherwise, and this notice follows the wheel. Whether a GPL-licensed binding can remain inside a proprietary application is an open question alongside the FFTW3 one in section 1 and is part of the same counsel review.

Copyleft components removed from the product

aubio (GPL-3.0-or-later) was removed; tempo detection is numpy code in code written for this product. mutagen (GPL-2.0-or-later) was replaced by TagLib; nothing in the backend imports it, it is out of requirements.txt, and it is absent from the frozen module table. See our copyleft audit.

4. Frontend and desktop runtime

Production npm dependencies, as reported by npx license-checker --summary --production on 10 September 2026: MIT: 11, UNLICENSED: 1. The UNLICENSED entry is trackclear-frontend@0.5.0 itself, which is this proprietary application. The full production list:

PackageVersionLicenseLicense file
react19.2.7MITMIT.txt
react-dom19.2.7MITMIT.txt
scheduler0.27.0MITMIT.txt
react-router7.16.0MITMIT.txt
react-router-dom7.16.0MITMIT.txt
cookie1.1.1MITMIT.txt
set-cookie-parser2.7.2MITMIT.txt
zustand5.0.14MITMIT.txt
papaparse5.5.3MITMIT.txt
@types/react19.2.16MITMIT.txt
csstype3.2.3MITMIT.txt

Electron, Chromium and Node.js

The desktop shell is Electron 36.9.5 (MIT), which bundles Chromium (BSD-3-Clause plus the licenses of Chromium's own third-party components) and Node.js (MIT). Their notices are not reproduced here. electron-builder places the complete texts in the install folder, next to the application executable:

Both files are copied verbatim from the Electron distribution (node_modules/electron/dist/LICENSE and node_modules/electron/dist/LICENSES.chromium.html).

Build tools that do not ship

Vite, Vitest, ESLint, electron-builder, Testing Library, jsdom and the other devDependencies in package.json are used to build and test the application. None of their code is in the installer.

5. Fonts

The interface is styled for Inter and DM Mono, both published under the SIL Open Font License 1.1. No font file is embedded in the application or the installer. src/index.css loads both families from Google Fonts at run time (@import url('https://fonts.googleapis.com/css2?family=Inter...&family=DM+Mono...')), and when the machine is offline the CSS falls back to the system sans-serif and monospace faces. Because no font file is redistributed, the OFL imposes no notice obligation on TrackClear Studio. The license text is nonetheless included as licenses/OFL-1.1.txt for reference, so that if font files are ever bundled the required text is already in place.

6. Where to find these files in the installed app

This notice is an engineering record of what ships and under which license. Nothing in it is legal advice.

Looking for the license texts themselves? Verbatim copies of every license named above are installed with the app, in the licenses/ folder next to TrackClear Studio.exe. In the app they are under Settings, then About, then Third-party notices.