Legal

Privacy Policy (Datenschutzerklärung)

Last updated: 2026-09-11 · Technical outline — replace with counsel-reviewed copy before public launch.

1. Controller

Operator details will appear on the Impressum page. Contact for privacy requests: the address listed there.

2. Data we process

  • Account data (email/username, password hash, plan).
  • Uploaded media (clips, songs) and generated videos.
  • Integration secrets you connect (e.g. Buffer API key, YouTube OAuth tokens) — stored encrypted at rest.
  • Billing identifiers via Stripe (customer / subscription IDs).
  • Usage and quota counters for plan limits.

3. Purposes & legal bases

Provide the Lyricly service (contract), secure the platform (legitimate interest / legal obligation), and process payments (contract / legal obligation). Exact Art. 6 bases: finalize with counsel.

4. Processors / transfers

  • Hosting: Contabo VPS (region documented in ops notes).
  • Object storage: Cloudflare R2 (prefer EU jurisdiction bucket).
  • Payments: Stripe.
  • Optional publish: Buffer / YouTube / TikTok when you connect them.

5. Retention

Account and media are kept while the account is active. After self-service deletion, live systems are wiped; encrypted backups may retain residual copies until rotation (see ops retention).

6. Your rights

Access, rectification, erasure, portability, and restriction. In the app: Profile → Download my data / Delete my account (members). Owner wipe is ops-assisted.

7. Security

Passwords use argon2id. Session cookies are HTTP-only HMAC tokens. BYO API keys and OAuth tokens are Fernet-encrypted at rest. Media on the app server is access-controlled; R2 uses provider encryption at rest and HTTPS in transit.

TermsImpressum← Register