Privacy Policy
Last updated: 2 September 2026
The controller and contact address are stated in the legal notice (Impressum). This notice describes the data processing implemented by Annotune.
1. Data we process
We process account data (name, email, one-way password hash, your chosen avatar, the profile photo supplied by an OAuth provider if you sign in with one, and security settings including the secret behind two-factor authentication), authentication and security events, subscription identifiers and status, the withdrawal declaration you give at checkout (with its date, the wording version and the language shown), support messages, uploaded MusicXML/MXL content, score settings, share-link state and technical request data such as IP address and user agent.
2. Purposes and legal bases
We use the data to provide accounts, render and store scores, fulfill subscriptions, answer support requests and secure the service (Art. 6(1)(b) and (f) GDPR). Optional analytics runs only after consent (Art. 6(1)(a) GDPR). Required tax or accounting processing, and the record of your withdrawal declaration, are based on legal obligations (Art. 6(1)(c) GDPR).
3. Service providers
The application uses Neon (PostgreSQL database), Stripe (payments and billing portal), Resend (transactional email), Upstash Redis (security rate limits), and Google services where enabled (OAuth sign-in, reCAPTCHA and consent-based Analytics). Hosting, network and operational-log providers also process technical data as needed to run the service. Some providers may process data outside the EU/EEA under their applicable transfer safeguards. There is no image-upload processor: avatars are a colour and an icon stored in our own database, and the only photo we display is one an OAuth provider serves.
4. Cookies and local storage
Essential cookies are used for authentication, security and your consent choice. The public upload demo temporarily stores MusicXML and its file name in your browser's local storage. Optional Google Analytics is blocked until you consent. With your consent, Google Analytics also receives page speed measurements (Core Web Vitals: loading time, responsiveness and layout stability) together with the type of page they were measured on, so that we can find and fix slow pages. You can change your analytics choice at any time using “Cookie settings” in the footer.
5. Payments and email
Stripe receives the data necessary to process payments; Annotune does not store full card details. Resend processes email addresses and message content for verification, password reset, email changes and support replies. Two-factor codes are never emailed: they are generated by an authenticator app on your own device.
6. Storage and deletion
Account data and uploaded scores are kept while your account is active. Account deletion removes account-linked scores and authentication records from the application database. Security, support, payment and transaction records may be retained where required to establish claims, prevent abuse, or meet legal and tax duties. Provider-side retention may also apply.
7. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing. You may withdraw consent at any time without affecting earlier lawful processing. You may also complain to a competent data-protection authority. Contact the address in the Impressum to exercise these rights.
8. Security
Passwords are stored as one-way hashes. Transport encryption, access controls, rate limits and other technical and organizational safeguards are used. No internet service can promise absolute security.