Privacy Policy

Last updated: July 26, 2026

1 - Controller and General Information

The controller responsible for data processing within ArcaLyra is:

Birk Roolf

Ahornstraße 1

75045 Walzbachtal

Germany

Email: hello@arcalyra.app

ArcaLyra can generally be used without creating a user account and without providing a name or email address.

The app processes data only where required for its functionality, license and access verification, access-system security, and a strictly limited aggregated usage statistic.

ArcaLyra does not use advertising, personalized advertising, cross-app tracking, or user profiling.

2 - Locally Stored Content

Imported sheet music, images, PDF files, edits, annotations, set lists, settings, tutorial progress, and other user-created content are generally stored locally on the device.

This content is not automatically transmitted to the developer or to the ArcaLyra server.

Only when the user deliberately uses an export, backup, or sharing function and selects an external destination or service will the selected files be transferred to the destination chosen by the user.

Processing by an external provider is governed by that provider's own privacy policy.

3 - Access to Device Features

ArcaLyra accesses external files or folders only when the user explicitly selects them through the operating system's file or folder picker.

This access may be used to import sheet music or other supported content, restore a backup, or, on supported platforms, save exports and backups to a user-selected destination.

Depending on the selected function, ArcaLyra may also request access to:

Camera: for photographing or scanning sheet music within the app

Microphone: for functions such as the tuner

Files and storage: for user-initiated imports, exports, and backup restoration

Camera images are captured only when the user actively initiates the capture. They are processed locally on the device and are stored only when the user accepts or imports them.

Microphone input is processed locally and in real time for the selected function. ArcaLyra does not transmit microphone audio to the ArcaLyra server and does not use microphone data for statistics or access verification.

Imported content is copied to ArcaLyra's local app storage and is displayed and edited there.

Sheet music, images, PDF files, annotations, and other editing content are not transmitted as part of aggregated usage statistics or license and access verification.

4 - Contact and Bug Reports

When users contact ArcaLyra, send feedback, or create a bug report, this is done through the email application configured on the device.

Only the content and attachments selected or entered by the user before sending are transmitted.

Contact details, messages, and voluntarily submitted attachments are stored only for as long as necessary to process the request.

They are generally deleted no later than six months after the matter has been completed.

Data may be retained for longer where statutory retention obligations apply or where retention is necessary for the establishment, exercise, or defence of legal claims.

The legal basis is Article 6(1)(b) GDPR for contract-related requests and otherwise Article 6(1)(f) GDPR based on the legitimate interest in support, troubleshooting, and continued development.

5 - Aggregated Usage Statistics

ArcaLyra transmits a strictly limited usage statistic to the ArcaLyra server.

Only counting events relating to the following actions are recorded:

Main menu or app opened

Paywall displayed

Monthly or yearly subscription selected

Purchase started

Purchase completed successfully

Purchase cancelled

Access-code section opened

Code redeemed successfully

Invalid code entered

Technical error during code verification

Only the following technical information is transmitted with an event:

Event type

Platform

App version

Build number

A random event identifier generated solely for that individual event

The event identifier is never reused and cannot be used to link different events to a user or device.

The server stores only a hash of this identifier to prevent duplicate counting.

This hash is deleted after no more than seven days.

The resulting statistics contain only aggregated daily counts grouped by event type, platform, app version, and build number.

No device identifier, installation identifier, daily user identifier, advertising identifier, store identifier, or other recurring identifier is used for these statistics.

It is therefore not possible to determine which events originated from the same user or device.

The statistics cannot recognize individual users or track their behavior across multiple events.

The following information is not transmitted:

Names or email addresses

Store accounts or payment information

Advertising or device identifiers

Precise location

Sheet music, images, or PDF files

Edits, annotations, or set lists

Microphone or camera content

The sole purpose of these statistics is to understand basic app and purchase-flow usage, identify technical problems, and improve the app functionally and economically.

The legal basis is Article 6(1)(f) GDPR.

The legitimate interest lies in privacy-preserving measurement of basic app usage, functional monitoring, and improvement of the purchase and access system.

No profiling takes place because no recurring identifier is used.

Aggregated counts may be retained for the long term because they cannot be assigned to a user or device.

6 - Storage Periods

Locally stored content remains on the device until it is deleted by the user, the app data is removed, or the app is uninstalled.

Technical hashes used to prevent duplicate event counting are deleted after no more than seven days.

Information relating to access codes and issued access grants is stored for as long as required to provide, verify, renew, or revoke access and to prevent abuse.

The deletion periods described in Section 4 apply to support emails and any personal data they contain.

7 - Subscriptions and Payments

ArcaLyra uses the app marketplace through which the app was obtained to manage subscriptions and purchases.

Payment, billing, and account information is processed by the respective app marketplace operator.

ArcaLyra does not receive complete payment information.

The app only receives the technical status information required to recognize a purchase or active subscription and unlock access to the app.

This may include the product identifier, detected subscription status, validity status, and technical verification information.

For offline verification of a store subscription, ArcaLyra stores a technical verification status locally on the device.

This may include the detected subscription status, product identifier, app version and build number, and the time of the most recent successful verification.

This allows a confirmed subscription to be used offline for up to 14 days.

This local store verification status is not transmitted to the ArcaLyra server.

Further information about the processing of payment, billing, and account information can be found in the privacy information of the app marketplace through which ArcaLyra was obtained.

8 - Reviewer, Campaign, and Access Codes

ArcaLyra provides technical access codes, for example for app review or time-limited campaigns.

When a code is redeemed, the following data is transmitted in encrypted form to the ArcaLyra access service:

The entered and normalized access code

A randomly generated installation identifier

The platform

The app version and build number

The access code is not stored on the server in plain text, but only as a cryptographic hash.

The installation identifier is also stored in the database only in hashed form.

The service additionally stores the information required for the access grant, including the access type, platform, validity period, verification timestamps, redemption count, revocation status, app version, and build number.

The random installation identifier remains stored locally for as long as the app data exists.

It is used solely to bind an issued access grant to that installation, enable offline access, and prevent abusive multiple redemptions.

After successful verification, the app receives a digitally signed access entitlement.

It is stored locally and can be verified offline during its validity period.

No names, email addresses, payment information, store accounts, advertising identifiers, sheet music, files, or editing content are transmitted.

The legal basis is Article 6(1)(b) GDPR where processing is necessary to provide the requested access.

Protection against manipulation and abuse is additionally based on Article 6(1)(f) GDPR.

9 - Technical Service Provider Cloudflare

ArcaLyra uses Cloudflare Workers and Cloudflare D1 for the access service, aggregated usage statistics, and the publicly available development and WIP section.

When the WIP section is opened or refreshed, ArcaLyra only retrieves publicly available information about the app’s current development status.

No names, email addresses, installation identifiers, advertising identifiers, sheet music, files, or editing content are transmitted to the ArcaLyra server for this purpose.

The most recently loaded WIP status is cached locally on the device so that it can still be displayed when an internet connection is temporarily unavailable.

This local cache is deleted together with the app data.

The D1 database is restricted to the EU jurisdiction.

Data stored in that database is therefore run and stored within the European Union.

ArcaLyra does not store IP addresses in the D1 database.

Persistent Worker logs, traces, and log exports are disabled for this service.

Cloudflare may nevertheless process limited connection and network data for technical transmission, network security, and abuse prevention.

This may include the IP address.

Cloudflare is a company based in the United States.

Where processing takes place outside the European Economic Area, Cloudflare states that it uses appropriate safeguards, including the European Commission's Standard Contractual Clauses.

More information:

https://www.cloudflare.com/privacypolicy/

10 - Data Subject Rights

Where personal data is processed, data subjects may have the following rights, subject to the applicable legal requirements:

Access

Rectification

Erasure

Restriction of processing

Data portability

Objection to processing based on legitimate interests

Objections may be sent by email to hello@arcalyra.app.

Because the aggregated usage statistics contain no user or device identifier, individual statistical events cannot subsequently be assigned to a particular person or selectively removed from the aggregated counts.

Data subjects also have the right to lodge a complaint with a data protection supervisory authority.

11 - Changes to This Privacy Policy

This privacy policy may be updated when functions, technical processes, or legal requirements change.

The current version is available within the app and at:

https://arcalyra.com/app-privacy-policy