Privacy Policy
Last updated: July 26, 2026
1 - Controller and General Information
The controller responsible for data processing within ArcaLyra is:
Birk Roolf
Ahornstraße 1
75045 Walzbachtal
Germany
Email: hello@arcalyra.app
ArcaLyra can generally be used without creating a user account and without providing a name or email address.
The app processes data only where required for its functionality, license and access verification, access-system security, and a strictly limited aggregated usage statistic.
ArcaLyra does not use advertising, personalized advertising, cross-app tracking, or user profiling.
2 - Locally Stored Content
Imported sheet music, images, PDF files, edits, annotations, set lists, settings, tutorial progress, and other user-created content are generally stored locally on the device.
This content is not automatically transmitted to the developer or to the ArcaLyra server.
Only when the user deliberately uses an export, backup, or sharing function and selects an external destination or service will the selected files be transferred to the destination chosen by the user.
Processing by an external provider is governed by that provider's own privacy policy.
3 - Access to Device Features
ArcaLyra accesses external files or folders only when the user explicitly selects them through the operating system's file or folder picker.
This access may be used to import sheet music or other supported content, restore a backup, or, on supported platforms, save exports and backups to a user-selected destination.
Depending on the selected function, ArcaLyra may also request access to:
Camera: for photographing or scanning sheet music within the app
Microphone: for functions such as the tuner
Files and storage: for user-initiated imports, exports, and backup restoration
Camera images are captured only when the user actively initiates the capture. They are processed locally on the device and are stored only when the user accepts or imports them.
Microphone input is processed locally and in real time for the selected function. ArcaLyra does not transmit microphone audio to the ArcaLyra server and does not use microphone data for statistics or access verification.
Imported content is copied to ArcaLyra's local app storage and is displayed and edited there.
Sheet music, images, PDF files, annotations, and other editing content are not transmitted as part of aggregated usage statistics or license and access verification.
4 - Contact and Bug Reports
When users contact ArcaLyra, send feedback, or create a bug report, this is done through the email application configured on the device.
Only the content and attachments selected or entered by the user before sending are transmitted.
Contact details, messages, and voluntarily submitted attachments are stored only for as long as necessary to process the request.
They are generally deleted no later than six months after the matter has been completed.
Data may be retained for longer where statutory retention obligations apply or where retention is necessary for the establishment, exercise, or defence of legal claims.
The legal basis is Article 6(1)(b) GDPR for contract-related requests and otherwise Article 6(1)(f) GDPR based on the legitimate interest in support, troubleshooting, and continued development.
5 - Aggregated Usage Statistics
ArcaLyra transmits a strictly limited usage statistic to the ArcaLyra server.
Only counting events relating to the following actions are recorded:
Main menu or app opened
Paywall displayed
Monthly or yearly subscription selected
Purchase started
Purchase completed successfully
Purchase cancelled
Access-code section opened
Code redeemed successfully
Invalid code entered
Technical error during code verification
Only the following technical information is transmitted with an event:
Event type
Platform
App version
Build number
A random event identifier generated solely for that individual event
The event identifier is never reused and cannot be used to link different events to a user or device.
The server stores only a hash of this identifier to prevent duplicate counting.
This hash is deleted after no more than seven days.
The resulting statistics contain only aggregated daily counts grouped by event type, platform, app version, and build number.
No device identifier, installation identifier, daily user identifier, advertising identifier, store identifier, or other recurring identifier is used for these statistics.
It is therefore not possible to determine which events originated from the same user or device.
The statistics cannot recognize individual users or track their behavior across multiple events.
The following information is not transmitted:
Names or email addresses
Store accounts or payment information
Advertising or device identifiers
Precise location
Sheet music, images, or PDF files
Edits, annotations, or set lists
Microphone or camera content
The sole purpose of these statistics is to understand basic app and purchase-flow usage, identify technical problems, and improve the app functionally and economically.
The legal basis is Article 6(1)(f) GDPR.
The legitimate interest lies in privacy-preserving measurement of basic app usage, functional monitoring, and improvement of the purchase and access system.
No profiling takes place because no recurring identifier is used.
Aggregated counts may be retained for the long term because they cannot be assigned to a user or device.
6 - Storage Periods
Locally stored content remains on the device until it is deleted by the user, the app data is removed, or the app is uninstalled.
Technical hashes used to prevent duplicate event counting are deleted after no more than seven days.
Information relating to access codes and issued access grants is stored for as long as required to provide, verify, renew, or revoke access and to prevent abuse.
The deletion periods described in Section 4 apply to support emails and any personal data they contain.
7 - Subscriptions and Payments
ArcaLyra uses the app marketplace through which the app was obtained to manage subscriptions and purchases.
Payment, billing, and account information is processed by the respective app marketplace operator.
ArcaLyra does not receive complete payment information.
The app only receives the technical status information required to recognize a purchase or active subscription and unlock access to the app.
This may include the product identifier, detected subscription status, validity status, and technical verification information.
For offline verification of a store subscription, ArcaLyra stores a technical verification status locally on the device.
This may include the detected subscription status, product identifier, app version and build number, and the time of the most recent successful verification.
This allows a confirmed subscription to be used offline for up to 14 days.
This local store verification status is not transmitted to the ArcaLyra server.
Further information about the processing of payment, billing, and account information can be found in the privacy information of the app marketplace through which ArcaLyra was obtained.
8 - Reviewer, Campaign, and Access Codes
ArcaLyra provides technical access codes, for example for app review or time-limited campaigns.
When a code is redeemed, the following data is transmitted in encrypted form to the ArcaLyra access service:
The entered and normalized access code
A randomly generated installation identifier
The platform
The app version and build number
The access code is not stored on the server in plain text, but only as a cryptographic hash.
The installation identifier is also stored in the database only in hashed form.
The service additionally stores the information required for the access grant, including the access type, platform, validity period, verification timestamps, redemption count, revocation status, app version, and build number.
The random installation identifier remains stored locally for as long as the app data exists.
It is used solely to bind an issued access grant to that installation, enable offline access, and prevent abusive multiple redemptions.
After successful verification, the app receives a digitally signed access entitlement.
It is stored locally and can be verified offline during its validity period.
No names, email addresses, payment information, store accounts, advertising identifiers, sheet music, files, or editing content are transmitted.
The legal basis is Article 6(1)(b) GDPR where processing is necessary to provide the requested access.
Protection against manipulation and abuse is additionally based on Article 6(1)(f) GDPR.
9 - Technical Service Provider Cloudflare
ArcaLyra uses Cloudflare Workers and Cloudflare D1 for the access service, aggregated usage statistics, and the publicly available development and WIP section.
When the WIP section is opened or refreshed, ArcaLyra only retrieves publicly available information about the app’s current development status.
No names, email addresses, installation identifiers, advertising identifiers, sheet music, files, or editing content are transmitted to the ArcaLyra server for this purpose.
The most recently loaded WIP status is cached locally on the device so that it can still be displayed when an internet connection is temporarily unavailable.
This local cache is deleted together with the app data.
The D1 database is restricted to the EU jurisdiction.
Data stored in that database is therefore run and stored within the European Union.
ArcaLyra does not store IP addresses in the D1 database.
Persistent Worker logs, traces, and log exports are disabled for this service.
Cloudflare may nevertheless process limited connection and network data for technical transmission, network security, and abuse prevention.
This may include the IP address.
Cloudflare is a company based in the United States.
Where processing takes place outside the European Economic Area, Cloudflare states that it uses appropriate safeguards, including the European Commission's Standard Contractual Clauses.
More information:
https://www.cloudflare.com/privacypolicy/
10 - Data Subject Rights
Where personal data is processed, data subjects may have the following rights, subject to the applicable legal requirements:
Access
Rectification
Erasure
Restriction of processing
Data portability
Objection to processing based on legitimate interests
Objections may be sent by email to hello@arcalyra.app.
Because the aggregated usage statistics contain no user or device identifier, individual statistical events cannot subsequently be assigned to a particular person or selectively removed from the aggregated counts.
Data subjects also have the right to lodge a complaint with a data protection supervisory authority.
11 - Changes to This Privacy Policy
This privacy policy may be updated when functions, technical processes, or legal requirements change.
The current version is available within the app and at:
https://arcalyra.com/app-privacy-policy