Legal
Privacy Policy
Last updated: October 1, 2026
1 - Controller and General Information
The controller responsible for data processing within ArcaLyra is:
Birk Roolf
Ahornstraße 1
75045 Walzbachtal
Germany
Email: hello@arcalyra.app
ArcaLyra can generally be used without creating a user account and without providing a name or email address.
The app processes data only where required for its functionality, license and access verification, access-system security, voluntarily submitted feedback, and a strictly limited aggregated usage statistic.
ArcaLyra does not use advertising, personalized advertising, cross-app tracking, or user profiling.
2 - Locally Stored Content
Imported sheet music, images, PDF files, edits, annotations, set lists, settings, tutorial progress, and other user-created content are generally stored locally on the device.
This content is not automatically transmitted to the developer or to the ArcaLyra server.
Only when the user deliberately uses an export, backup, or sharing function and selects an external destination or service will the selected files be transferred to the destination chosen by the user.
Processing by an external provider is governed by that provider's own privacy policy.
3 - Access to Device Features
ArcaLyra accesses external files or folders only when the user explicitly selects them through the operating system's file or folder picker.
This access may be used to import sheet music or other supported content, restore a backup, or, on supported platforms, save exports and backups to a user-selected destination.
Depending on the selected function, ArcaLyra may also request access to:
Camera: for photographing or scanning sheet music within the app
Microphone: for functions such as the tuner
Files and storage: for user-initiated imports, exports, and backup restoration
Camera images are captured only when the user actively initiates the capture. They are processed locally on the device and are stored only when the user accepts or imports them.
Microphone input is processed locally and in real time for the selected function. ArcaLyra does not transmit microphone audio to the ArcaLyra server and does not use microphone data for statistics or access verification.
Imported content is copied to ArcaLyra's local app storage and is displayed and edited there.
Sheet music, images, PDF files, annotations, and other editing content are not transmitted as part of aggregated usage statistics or license and access verification.
4 - Contact and Bug Reports
The “Bugs & feedback” form transmits a message through an encrypted connection to the ArcaLyra reporting service at Cloudflare only when the user deliberately sends it. No email application or user account is required.
Only the selected report type, subject, message, app version including build number, platform (iOS or Android), language and a random identifier for that individual message are transmitted. This identifier prevents duplicate tickets when sending again; it identifies neither a device nor a user and is never reused for other messages. The service adds a ticket number, receipt time, processing status and modification time. No sheet music, attachments, logs, account, installation or device identifiers are attached. IP addresses are not stored in tickets or the report database.
Please do not enter names, contact details or other personal information in the free-text fields. Any such information you enter would be transmitted as part of the message. Reports are collected in an access-protected internal overview and read by the developer. There is currently no automated AI analysis. Without contact details, a personal reply is not possible; you may quote your ticket number in a separate enquiry.
Until delivery is confirmed, the message and its identifier remain stored locally for manual retry. After confirmation, the local message text is removed; the ticket number and receipt time remain until the next confirmed message or removal of the app data. The app allows a new message no sooner than 24 hours later. No recurring user identifier is transmitted to the server for this purpose. Additional general volume and size limits restrict abuse. Cloudflare technically processes connection data for transmission and protection; see Section 9.
Tickets are stored only for as long as needed to handle them. Tickets marked as completed are automatically deleted no later than six months and one day after completion. The additional day accounts for the daily deletion run. Technical recovery copies of the reporting service may retain deleted data for up to 30 further days; they are used solely for recovery.
Voluntary contact by email remains available independently of this form, including from older app versions. Only the content and attachments selected by the user are transmitted. Contact details, messages and voluntary attachments are generally deleted no later than six months after completion, unless statutory retention obligations or necessary legal claims require otherwise.
The legal basis is Article 6(1)(b) GDPR for contract-related enquiries and otherwise Article 6(1)(f) GDPR based on the legitimate interest in support, troubleshooting, abuse prevention and continued development.
5 - Aggregated Usage Statistics
ArcaLyra transmits a strictly limited usage statistic to the ArcaLyra server.
Only counting events relating to the following actions are recorded:
Main menu or app opened
Paywall displayed
Monthly or yearly subscription selected
Purchase started
Purchase completed successfully
Purchase cancelled
Access-code section opened
Code redeemed successfully
Invalid code entered
Technical error during code verification
Only the following technical information is transmitted with an event:
Event type
Platform
App version
Build number
A random event identifier generated solely for that individual event
The event identifier is never reused and cannot be used to link different events to a user or device.
The server stores only a hash of this identifier to prevent duplicate counting.
This hash is deleted after no more than seven days.
The resulting statistics contain only aggregated daily counts grouped by event type, platform, app version, and build number.
No device identifier, installation identifier, daily user identifier, advertising identifier, store identifier, or other recurring identifier is used for these statistics.
It is therefore not possible to determine which events originated from the same user or device.
The statistics cannot recognize individual users or track their behavior across multiple events.
The following information is not transmitted:
Names or email addresses
Store accounts or payment information
Advertising or device identifiers
Precise location
Sheet music, images, or PDF files
Edits, annotations, or set lists
Microphone or camera content
The sole purpose of these statistics is to understand basic app and purchase-flow usage, identify technical problems, and improve the app functionally and economically.
The legal basis is Article 6(1)(f) GDPR.
The legitimate interest lies in privacy-preserving measurement of basic app usage, functional monitoring, and improvement of the purchase and access system.
No profiling takes place because no recurring identifier is used.
Aggregated counts may be retained for the long term because they cannot be assigned to a user or device.
6 - Storage Periods
Locally stored content remains on the device until it is deleted by the user, the app data is removed, or the app is uninstalled.
Technical hashes used to prevent duplicate event counting are deleted after no more than seven days.
Information relating to access codes and issued access grants is stored for as long as required to provide, verify, renew, or revoke access and to prevent abuse.
The storage and deletion periods described in Section 4 apply to tickets, local delivery data and support emails.
7 - Subscriptions and Payments
ArcaLyra uses the app marketplace through which the app was obtained to manage subscriptions and purchases.
Payment, billing, and account information is processed by the respective app marketplace operator.
ArcaLyra does not receive complete payment information.
The app only receives the technical status information required to recognize a purchase or active subscription and unlock access to the app.
This may include the product identifier, detected subscription status, validity status, and technical verification information.
For offline verification of a store subscription, ArcaLyra stores a technical verification status locally on the device.
This may include the detected subscription status, product identifier, app version and build number, and the time of the most recent successful verification.
This allows a confirmed subscription to be used offline for up to 14 days.
This local store verification status is not transmitted to the ArcaLyra server.
Further information about the processing of payment, billing, and account information can be found in the privacy information of the app marketplace through which ArcaLyra was obtained.
Separate subscription inventory statistics
Independently of the local verification status, a separate ArcaLyra service maintains an operational overview of active paid monthly and annual subscriptions and free trial and offer periods. For Google, it processes technical subscription notifications and checks known subscriptions against the store API. These statistics do not determine your access to the app.
For Apple, these statistics are limited to daily reports already aggregated by Apple. Only platform-wide counts by plan duration and status, together with report and retrieval timestamps, are stored. Individual Apple purchase or subscriber identifiers are not retrieved or stored for this purpose; regional and device breakdowns, prices, and revenue from the reports are not retained. The display states the report date because these figures become available with a delay.
For Google, the service processes the platform, subscription product identifier and plan duration, technical subscription and renewal status, validity and verification timestamps, and technical purchase and event identifiers. The stored record uses the plan duration instead of the full product identifier. Technical purchase identifiers are encrypted for subsequent store checks; matching and event identifiers are stored as cryptographically protected hashes. No names, email addresses, complete payment details, advertising identifiers, device or installation identifiers, sheet music, or editing content are stored for this purpose. The records are not linked to usage statistics, reports, or access codes.
The technical Google processing is pseudonymized, not completely anonymous. The operational display and its protected read API contain only aggregate counts and information about their freshness and completeness. Free trial and offer periods and sandbox and test purchases are not counted as active paid subscriptions. Unconfirmed or outdated figures are marked accordingly.
The service uses Cloudflare Workers and a Cloudflare D1 database restricted to the EU jurisdiction. The EU restriction covers database storage and execution, not all worldwide network and Worker processing. Google notifications are forwarded through Google Cloud Pub/Sub; undelivered notifications may be retained there for up to seven days for retries. Message storage is configured in an EU location. Infrastructure providers may process connection data for transmission and security; ArcaLyra does not store IP addresses or complete notification logs for these subscription statistics.
Individual technical Google records are retained during the subscription term and for up to 90 days after the later of the end of that term and the last confirmed status change. Event deduplication hashes are removed after 30 days. Links for replaced subscriptions are retained only as long as the corresponding individual records, with a minimum of 90 days. Aggregate daily counts are retained for up to 730 days. Cleanup runs during regular reconciliations. Technical recovery copies may retain deleted data for up to 30 further days and are used solely for recovery.
The legal basis for processing personal technical data is Article 6(1)(f) GDPR. The legitimate interest is accurate, data-minimizing inventory and business planning without personal usage profiles. The rights described below, including the right to object on grounds relating to your particular situation, also apply to this processing.
8 - Reviewer, Campaign, and Access Codes
ArcaLyra provides technical access codes, for example for app review or time-limited campaigns.
When a code is redeemed, the following data is transmitted in encrypted form to the ArcaLyra access service:
The entered and normalized access code
A randomly generated installation identifier
The platform
The app version and build number
The access code is not stored on the server in plain text, but only as a cryptographic hash.
The installation identifier is also stored in the database only in hashed form.
The service additionally stores the information required for the access grant, including the access type, platform, validity period, verification timestamps, redemption count, revocation status, app version, and build number.
The random installation identifier remains stored locally for as long as the app data exists.
It is used solely to bind an issued access grant to that installation, enable offline access, and prevent abusive multiple redemptions.
After successful verification, the app receives a digitally signed access entitlement.
It is stored locally and can be verified offline during its validity period.
No names, email addresses, payment information, store accounts, advertising identifiers, sheet music, files, or editing content are transmitted.
The legal basis is Article 6(1)(b) GDPR where processing is necessary to provide the requested access.
Protection against manipulation and abuse is additionally based on Article 6(1)(f) GDPR.
9 - Technical Service Provider Cloudflare
ArcaLyra uses Cloudflare Workers and Cloudflare D1 for the access service, aggregated usage statistics, subscription inventory statistics, the reporting service, and the publicly available development and WIP section.
When the WIP section is opened or refreshed, ArcaLyra only retrieves publicly available information about the app’s current development status.
No names, email addresses, installation identifiers, advertising identifiers, sheet music, files, or editing content are transmitted to the ArcaLyra server for this purpose.
The most recently loaded WIP status is cached locally on the device so that it can still be displayed when an internet connection is temporarily unavailable.
This local cache is deleted together with the app data.
The D1 database is restricted to the EU jurisdiction.
Data stored in that database is therefore run and stored within the European Union.
ArcaLyra does not store IP addresses in the D1 database.
Persistent Worker logs, traces, and log exports are disabled for this service.
Cloudflare may nevertheless process limited connection and network data for technical transmission, network security, and abuse prevention.
This may include the IP address.
Cloudflare is a company based in the United States.
Where processing takes place outside the European Economic Area, Cloudflare states that it uses appropriate safeguards, including the European Commission's Standard Contractual Clauses.
More information:
https://www.cloudflare.com/privacypolicy/
10 - Data Subject Rights
Where personal data is processed, data subjects may have the following rights, subject to the applicable legal requirements:
Access
Rectification
Erasure
Restriction of processing
Data portability
Objection to processing based on legitimate interests
Requests to exercise these rights, including erasure and objection, may be sent by email to hello@arcalyra.app.
Because the aggregated usage statistics contain no user or device identifier, individual statistical events cannot subsequently be assigned to a particular person or selectively removed from the aggregated counts.
Data subjects also have the right to lodge a complaint with a data protection supervisory authority.
11 - Changes to This Privacy Policy
This privacy policy may be updated when functions, technical processes, or legal requirements change.
The current version is available within the app and at:
https://arcalyra.com/app-privacy-policy
