Privacy Policy
Last updated: August 2026. This notice explains how we process personal data under the EU General Data Protection Regulation (GDPR) and the German BDSG.
1. Controller
The controller responsible for data processing on ToneTwin (“the Service”) is the provider named in our Impressum. Privacy enquiries: [email protected]. We have not appointed a Data Protection Officer as we are not legally required to; if that changes, the contact will be listed here.
2. What we collect
- Account: your email address and a user ID, received from Sign in with Apple or Google. We never receive your Apple/Google password.
- Profile & app data: display name, gear you select, presets, saved tones, the songs/parts you research, upvotes, match ratings, optional feedback comments, and support requests you send.
- Subscription: your plan and status from our billing providers. We do not receive or store card or bank details.
- Technical: a session/authentication cookie set when you log in, plus standard server log data (IP address, timestamp, user-agent) processed by our hosting provider to deliver and secure the Service.
- Product analytics: page or screen paths, clicks, device/browser information, onboarding and subscription-funnel steps, song/rig interactions, and errors. In the iOS app, analytics starts only after sign-in, uses your pseudonymous internal user ID instead of your email address, and does not use session replay. On the website, optional privacy-masked session replay can be enabled after the required consent; input values and marked private account areas are masked.
3. Purposes & legal bases
- Provide the Service (accounts, tone matching, saving gear/tones) — performance of a contract, Art. 6(1)(b) GDPR.
- Billing & subscriptions — contract, Art. 6(1)(b) GDPR.
- Security, abuse prevention, and keeping the Service running — legitimate interests, Art. 6(1)(f) GDPR.
- Support, match feedback, and communication you initiate — contract / legitimate interests in responding to you and improving the Service, Art. 6(1)(b)/(f) GDPR.
- Product analytics — our legitimate interest in understanding and improving the signed-in Service, Art. 6(1)(f) GDPR, or consent where required, Art. 6(1)(a) GDPR. Optional website session replay uses consent. You may object to analytics based on legitimate interests or withdraw consent without affecting the Service.
- Legal obligations (e.g. tax/retention duties) — Art. 6(1)(c) GDPR.
4. Processors & recipients
We use vetted service providers (processors under Art. 28 GDPR) only to run the Service, and never sell your data:
- Supabase — database, authentication, and storage.
- OpenRouter and a web-search provider — the song/part you research is sent to generate the tone result.
- Apple — App Store subscriptions and payment processing in the iOS app.
- RevenueCat — App Store subscription status and entitlement management in the iOS app.
- Polar — website subscriptions and payment processing.
- PostHog — product analytics, error tracking, privacy-masked session replay, and a data warehouse used to analyze Service usage, match feedback, and subscription funnels.
- Google Tag Manager — loads consent-controlled analytics tags.
- Our hosting provider — runs the application servers.
5. International transfers
Some processors (including OpenRouter, Apple, and our current PostHog US-cloud project) process data outside the EU/EEA. Where data is transferred to such countries, we rely on an applicable adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism.
6. Retention
We keep account and app data for as long as you have an account. Analytics data is retained according to our configured vendor retention period and is then deleted or aggregated. If you delete your account, your profile, presets, and saved tones are deleted promptly; you may also ask us to erase analytics linked to your internal user ID. Data we must keep for legal reasons (e.g. invoices) is retained only for the statutory period and then deleted.
7. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time. You can delete your account and all associated data yourself from the Account screen, or contact us using the address above. You also have the right to lodge a complaint with a supervisory authority, for example the data-protection authority of your German federal state (Landesdatenschutzbehörde).
8. Cookies
We use strictly necessary cookies to keep you signed in. On the website, optional analytics storage and replay remain disabled in the EEA, UK, and Switzerland until you choose “Accept” in the consent banner. Choosing “Essential only” keeps them disabled. You can withdraw or revisit your choice through “Cookie settings” in the footer. In the iOS app, analytics starts only after sign-in and session replay is disabled. We do not sell personal data.
9. Children
The Service is not directed at children under 16. We do not knowingly collect their data.
10. Changes
We may update this policy; the “last updated” date above reflects the current version. Material changes will be communicated in the app.
See also our Terms of Use and Impressum.
