Privacy Policy (Datenschutzerklärung)

Last updated: October 2025

Your privacy is important to us. This Privacy Policy explains how we collect, use, and protect your information when you use our platform. This service is operated by the entity stated in our Impressum.

1. Information We Collect

Account Data: We collect your name, email, and an encrypted password when you create an account.

Payment Data: Subscriptions are handled exclusively through Stripe. We never store full credit card information.

Uploaded Files: MusicXML and MXL files you upload are stored securely and can be shared via link if you choose. They remain private unless you explicitly share them.

Cookies: Only essential cookies are used for login and session management.

2. How We Use Your Information

Service Operation: To authenticate users and maintain core functionality.

Security: To detect and prevent unauthorized access or misuse.

3. Data Sharing & Third Parties

Stripe: Payment processing is handled by Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin, Ireland). Stripe processes your payment data in accordance with its Privacy Policy.

Hosting: Our servers are hosted in the EU. Server logs may temporarily store IP addresses for security purposes.

We do not sell or rent personal data to advertisers or other third parties.

4. Data Security

Passwords are encrypted using industry-standard algorithms, and all communications are transmitted over HTTPS.

We implement technical and organizational measures to protect data from loss, misuse, and unauthorized access.

5. Data Retention

We retain your account data until you request deletion. Subscription and transaction data may be retained for tax and legal obligations.

6. Your Rights (Ihre Rechte)

You have the right to access, correct, or delete your data, and to request data portability under GDPR.

You can delete your account and uploaded files at any time in your account settings.

For data-related requests, contact us at the email stated in our Impressum.

7. Legal Basis

Data processing is based on Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interests in operating a secure service).