Privacy Policy

This English version is provided for convenience only. In case of discrepancies, the German version (Datenschutzerklärung) is legally binding.

Privacy Policy – Website modseven.net

Last updated: September 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws as well as other data protection regulations is: ModSeven Engineering Owner: Philipp Hanzik Gogolstraße 8b 90475 Nuremberg Germany Email: info@modseven.net

2. General information on data processing

As a matter of principle, we process personal data of our users only insofar as this is necessary to provide a functional website as well as our content and services. Personal data of our users is regularly processed only with the user’s consent. An exception applies in cases where prior consent cannot be obtained for factual reasons and the processing of the data is permitted by law.

3. Hosting (Vercel)

This website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When this website is accessed, technically necessary data (in particular server log files) is processed by Vercel. Vercel may process data in the USA. A data processing agreement (DPA) exists between us and Vercel for transfers to the USA. Insofar as data is transferred to third countries, this is done on the basis of the EU standard contractual clauses (Art. 46(2)(c) GDPR) and, where applicable, on the basis of the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a reliable, secure and high-performance provision of the online offer).

Further information: https://vercel.com/legal/privacy-policy

4. Server log files

When you visit our website, our hosting provider (Vercel) automatically collects and stores the following data transmitted by your browser or device in so-called server log files:

  • IP addressof the requesting device (truncated/anonymised where technically possible)
  • Date and timeof the request
  • URL and methodof the requested resource
  • HTTP status codeand amount of data transferred
  • User agentbrowser type, version and operating system
  • Referrerthe previously visited page, if transmitted

This data is stored for a limited time to ensure operation, security (defence against attacks) and error analysis, and is not merged with other data sources. Legal basis: Art. 6(1)(f) GDPR.

5. Cookies, language selection and cookie consent

Our website uses cookies. Cookies are small text files stored in your browser. We use both technically necessary cookies (e.g. to store your cookie decision, your language selection and, for logged-in users, a session cookie for authentication) and – after your consent – cookies for analytics purposes. The website is available in German and English. On your first visit the language is preselected automatically: for this we evaluate the country of origin derived from your IP address by our hosting provider (only the country code, e.g. “DE”) and, as a fallback, your browser’s language setting. This information is used solely to redirect you to the appropriate language version and is not stored by us. You can change your language at any time using the “DE / EN” switch in the page header.

  • cookieConsentStores your decision regarding the cookie banner. Duration: 365 days. Legal basis: Art. 6(1)(f) GDPR and § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act).
  • NEXT_LOCALEStores the most recently selected language (de/en) so that you see the appropriate language version directly on your next visit. Duration: 365 days. Legal basis: Art. 6(1)(f) GDPR and § 25(2) no. 2 TDDDG.
  • Authentication cookieOnly set when you sign in to the internal area. Contains a signed JSON Web Token (JWT). HTTP-only, secure. Legal basis: Art. 6(1)(b) GDPR.
  • Google Analytics (_ga, _ga_*)Only set if you explicitly consent to their use in the cookie banner. Legal basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG.

You can withdraw your consent at any time by deleting the cookies in your browser or by contacting us by email.

6. Google Analytics

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. It is used exclusively if you have explicitly consented in the cookie banner. The data stream is named “mdsvn”, the measurement ID is G-RT96KR6VJN. Google Analytics uses cookies and similar technologies to analyse your use of the website. The information generated about your use of this website is usually transmitted to a Google server in the USA and stored there. IP anonymisation is active; your IP address is therefore truncated by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide the website operator with further services related to website and internet usage.

  • Purposestatistical evaluation of website usage in order to improve the content and structure of the site
  • Legal basisArt. 6(1)(a) GDPR (consent) and § 25(1) TDDDG
  • RecipientsGoogle Ireland Ltd. / Google LLC (USA)
  • Third-country transfertransfer to the USA on the basis of the EU-US Data Privacy Framework and EU standard contractual clauses
  • Retention periodData transmitted from your device in the context of Google Analytics is automatically deleted after 14 months. The cookies _ga and _ga_* have a lifetime of up to 24 months.
  • WithdrawalYou can withdraw your consent at any time with effect for the future – by deleting the cookies in your browser, by declining in the cookie banner or by installing the browser add-on at https://tools.google.com/dlpage/gaoptout
Which data is processed

After consent has been given, the following data in particular is processed:

  • truncated IP address and the approximate location derived from it (country/region, no precise positioning)
  • pages visited, time and duration of the visit and the order of pages visited
  • referrer – the previously visited page or the source through which you reached the website
  • device and browser data: device type, operating system, browser, screen resolution, language setting
  • pseudonymous identifiers – the client ID in the cookies _ga and _ga_*, which links returning visits
  • interactions such as scroll depth, clicks on outbound links and standard GA4 events
No tracking without consent

Before you give your consent, no Google Analytics script is loaded and no analytics cookies are set. If you decline in the cookie banner or make no selection, no data is transmitted to Google at all. This data is not merged with other data we collect (e.g. from the contact form), and there is no automated decision-making or profiling for advertising purposes.

A data processing agreement pursuant to Art. 28 GDPR is in place with Google. Further information on how Google Analytics handles user data can be found in Google’s privacy policy: https://policies.google.com/privacy

7. Contact form

If you send us enquiries via the contact form or by email, your details from the enquiry form, including the contact details you provide there, are stored by us for the purpose of processing the enquiry and in case of follow-up questions. The following data is processed:

  • Nameto address you personally
  • Email addressto answer your enquiry
  • Subject & messagecontent of your enquiry
  • IP addressfor protection against misuse (spam prevention, security)
  • Timestampof the submission

The data is stored in a database operated by us (PostgreSQL via Prisma ORM) and additionally forwarded by email to our mailbox. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in efficient processing). The data is not passed on to third parties. Retention period: until your enquiry has been fully processed, but no longer than 24 months, unless statutory retention obligations require otherwise.

8. Email delivery (Strato)

For sending and receiving emails – in particular for contact form enquiries – we use the mail servers of Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with Strato. The servers are located in Germany. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable email delivery).

Privacy policy: https://www.strato.de/datenschutz/

9. Registration and login (internal area)

If you create a user account in the internal area, we process the data you provide (e.g. name, email address, password) in order to provide the customer account. Passwords are stored exclusively as hash values using bcrypt; they are never stored in plain text. After a successful login, a signed JSON Web Token (JWT) is set as an HTTP-only cookie in your browser to authenticate you for further requests. Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Retention period: until the account is deleted by you or by us; the session cookie has a limited validity.

10. Recipients / processors

We use the following service providers, each of which is bound by a data processing agreement pursuant to Art. 28 GDPR:

  • Vercel Inc. (USA)hosting of the website
  • Google Ireland Ltd. / Google LLCweb analytics via Google Analytics (only with consent)
  • Strato AG (Germany)sending and receiving emails

11. Your rights

You have the following rights vis-à-vis us with regard to the personal data concerning you:

  • Right of accessArt. 15 GDPR
  • Right to rectificationArt. 16 GDPR
  • Right to erasureArt. 17 GDPR
  • Right to restriction of processingArt. 18 GDPR
  • Right to data portabilityArt. 20 GDPR
  • Right to objectArt. 21 GDPR
  • Withdrawal of consentArt. 7(3) GDPR – the lawfulness of processing carried out before the withdrawal remains unaffected

To exercise your rights, an informal email to info@modseven.net is sufficient.

12. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The authority responsible for us is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18 91522 Ansbach Germany https://www.lda.bayern.de

13. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser bar.

14. Currency and amendment of this privacy policy

This privacy policy is currently valid and was last updated in September 2026. Due to the further development of our website or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The current privacy policy can be accessed on this page at any time.

App Privacy Policies

Privacy Policy – Choreo

Last updated: 6 May 2026

This privacy policy describes which personal data is processed when using the Choreo app (Android) and the associated backend services (website, MagicMirror integration), for what purpose and on what legal basis.

1. Controller

The controller within the meaning of the GDPR and other national data protection laws as well as other data protection regulations is: ModSeven Engineering – Philipp Hanzik Gogolstraße 8b, 90475 Nuremberg, Germany Email: info@modseven.net Please direct all enquiries regarding data protection, access, rectification and erasure exclusively to the email address above.

2. Scope

This policy applies to:

  • the mobile Choreo app for Android (package net.modseven.choreo)
  • the backend at https://choreo-mu.vercel.app (web pages for email confirmation, invitation acceptance, password reset)
  • the optional MagicMirror module “MMM-Choreo”, which authenticates against the backend

3. Which personal data is processed?

3.1 Registration & account
  • Email address (required, serves as login)
  • Display name (required, freely selectable)
  • Passwordnever stored in plain text, but hashed using bcrypt (12 rounds)
  • Profile picture / avatar (optional, uploaded by the user)
  • Role (ADMIN or MEMBER) and family membership
  • Timestamps for creation and email verification
  • Teasing pings: boolean setting for push reminders
3.2 Tasks and time tracking
  • Task definitions (title, optional description, type, interval, assignments, effort factor) — created by family members
  • Time entries: start time, end time, duration, source (TIMER/AUTO/MANUAL), optional note, assignment to user and task
  • Task instances per period with time of completion
3.3 Family / household
  • Family name and type (FAMILY or SHARED_FLAT)
  • Member list of the family
  • Optional MagicMirror token (random string granting read-only access to family data; can be generated and revoked by the family admin)
  • Invitations: recipient email, token, expiry date, acceptance status
3.4 Authentication & security
  • Refresh tokens (hashed in the database)
  • Email verification tokens (time-limited, single use)
  • Password reset tokens (time-limited — 60 minutes —, single use)
  • JWT access tokens (short-lived, not persisted server-side; stored exclusively on the user’s device in encrypted app storage)
3.5 Push notifications
  • FCM push token (issued by Firebase Cloud Messaging), per device
  • Platform identifier (android)
  • Used to send optional reminders (“teasing pings”, see 3.1)
3.6 Technical logs

On the server side, short-term access logs (IP address, user agent, time, requested URL) are generated by the hosting platform Vercel for routine operation. These are processed exclusively by Vercel for security and operational purposes (see processors below) and are not used by us for profiling.

3.7 We do not process:
  • Location data
  • Device contacts
  • Browser history
  • Advertising IDs
  • Third-party data without their consent
  • Special categories of personal data (health, biometric, political data — Art. 9 GDPR)

4. Purposes and legal bases

PurposeLegal basis
Provision of the service (account, tasks, time, family)Art. 6(1)(b) GDPR — performance of a contract
Sending email verificationArt. 6(1)(b) GDPR — performance of a contract
Sending invitation emailsArt. 6(1)(b) GDPR — performance of a contract; the address originates from the family context
Sending password reset emailsArt. 6(1)(b) GDPR — performance of a contract
Teasing pings (push reminders)Art. 6(1)(a) GDPR — consent (toggle in the settings, can be withdrawn at any time)
Security, abuse detection, logsArt. 6(1)(f) GDPR — legitimate interests
Use of MagicMirror tokenArt. 6(1)(a) GDPR — explicit action by the admin

5. Recipients / processors

We use processors within the meaning of Art. 28 GDPR with whom data processing agreements exist or for whom we rely on the respective data processing addendum:

5.1 Hosting of the web application

Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA

5.2 Database (Postgres)

Neon Inc. (or the Postgres platform currently used for the database; as of today: Neon, region Frankfurt/EU)

5.3 Push notifications

Google Ireland Limited (Firebase Cloud Messaging), Gordon House, Barrow Street, Dublin 4, Ireland

5.4 Sending emails (SMTP)

Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany

5.5 App distribution

The Choreo app is available in two ways:

  • Google Play Store (Google LLC) — installation, device and account data is processed in accordance with Google’s privacy policy
  • Direct APK download via https://choreo-mu.vercel.app/choreo.apk — delivered exclusively via Vercel (see 5.1); no additional data processing takes place beyond the server logs described in 3.6

6. Data transfer to third countries

Vercel and Google are corporations based in the USA. A transfer of personal data to the USA is possible. The transfer takes place on the basis of:

  • the EU-US Data Privacy Framework (for the respectively certified recipients)
  • additionally the standard contractual clauses (SCCs) of the EU Commission where no certification applies
  • as well as supplementary technical and organisational measures

The database (Neon) is operated in the Frankfurt (EU) region; the application data stored there is therefore not transferred to third countries.

7. Retention period and deletion

  • Account and family data remains stored as long as the account exists.
  • Time entries and tasks are generally stored permanently so that statistics and histories remain available. The user can delete individual entries in the app at any time.
  • Verification and reset tokens become unusable after redemption or expiry and are discarded during the next processing run (maximum lifetime of 60 minutes for reset, 24 hours for email verification).
  • Refresh tokens are invalidated on logout, password change or reset.
  • Invitations: 14-day lifetime, automatically invalid thereafter.
  • Push tokens are deleted when the user signs out or revokes push on the device.
  • Upon request by the user (email to info@modseven.net), the entire account including all tasks, times and avatars is deleted. In special cases (e.g. if the user is the admin of the only family administration) we will consult beforehand about handing over to another member.

8. App permissions (Android)

  • Push notifications (Android 13+): only if the user agrees; without consent the app continues to work but does not receive teasing pings.
  • Photo picker (PickVisualMedia): requested when the user wants to select an avatar image. Only the image selected by the user is read, never the entire photo library.
  • Internet and foreground service (for running timers): technically necessary.

9. Cookies and tracking

  • The app itself does not set cookies and uses no tracking (no Google Analytics, no Facebook pixel, no advertising IDs).
  • The website uses only technically necessary storage mechanisms (session storage during the email verification / reset flow), no tracking cookies.
  • No data is sold or passed on to advertising networks.

10. Avatar URLs

Profile pictures are delivered via a unique, hash-based URL of the form /api/users/<userId>/avatar?v=<sha1> so that browsers and the app can cache the image. The URL cannot be guessed (user ID and hash are both randomly generated), but the endpoints are technically publicly accessible. Anyone who knows the link can retrieve the image — comparable to an “unlisted” URL.

11. MagicMirror token

Family admins can generate a read-only token that allows a MagicMirror module to access basic family data (members, current time accounts, upcoming tasks). The token can be revoked at any time; a new token invalidates the old one.

12. Security measures

  • Transport encryption: TLS 1.2/1.3 for all connections between app, website and backend
  • Password hashing: bcrypt with 12 rounds
  • JWT signature: HS256 with a secret held server-side
  • Token rotation: refresh tokens are revoked on security events (password change, reset, logout)
  • Data minimisation: each endpoint only returns the fields required; in particular, the password hash is never transmitted to the client

13. Rights of data subjects

As a data subject within the meaning of the GDPR, you have the following rights:

  • Access (Art. 15) to the data stored about you
  • Rectification of inaccurate data (Art. 16)
  • Erasure of your data (Art. 17), insofar as no statutory retention obligations apply
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20) — on request we provide a machine-readable export of your data
  • Objection (Art. 21) to processing based on legitimate interests
  • Withdrawal of consent given, with effect for the future

To exercise these rights, an informal email to info@modseven.net stating the email address associated with your account is sufficient.

14. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). As a rule, the authority of your habitual residence is responsible. In Germany, the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, https://www.lda.bayern.de is responsible for us. Users from Austria can contact the Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, https://www.dsb.gv.at, dsb@dsb.gv.at.

15. Children

Choreo is primarily aimed at adults or families with parents as family admins. Accounts for minors may only be created with the consent of a parent or guardian. We do not collect data directly from children under 16 without such consent.

16. Changes to this privacy policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to implement changes to our services. The current version then applies to your next visit. Users will be notified by email of significant changes.

Privacy Policy – YAMA

Last updated: 8 July 2026

YAMA is a companion app for MeshCore radios. This privacy policy describes which data the app processes – the principle is local and offline: your content stays on your device, and an internet connection is only required for map tiles.

1. Controller

The controller for data processing in connection with this app is: ModSeven Engineering – Philipp Hanzik Gogolstraße 8b 90475 Nuremberg Germany Email: info@modseven.net Web: modseven.net

2. Basic principle: local and offline

YAMA is a companion app for MeshCore radios. The app is built to process as little data as possible:

  • It uses no user accounts, no advertising and no analytics or tracking services (no Google Analytics, Firebase Analytics, advertising IDs or similar).
  • Your messages, contacts, channels, settings and measurement points are stored exclusively locally on your device and are not transmitted to us or third parties.
  • An internet connection is only required for map tiles (see section 5).

3. Data stored locally on the device

The following data is stored locally in the app and does not leave your device towards our servers:

DataPurpose
Chat messages (sent/received)display and history of your conversations
Contacts / nodes (incl. public key, name, last known position)address book and map display
Channels and channel keysparticipation in channels
Saved room passwordsautomatic re-login to room servers
GPS measurement points of the direction-finding featurelocating / direction-finding a node
App settingsconfiguration of the app

This data remains stored until you delete it in the app or uninstall the app. If Android system backup is enabled on your device, app data may be included in this device-/account-bound backup. Legal basis: Art. 6(1)(b) GDPR (provision of the functions you requested).

4. Support / contact form

If you use the support / contact form in the app, the details you enter – name, email address and your message – are transmitted to our server at https://modseven.net so that we can process your request. Without active use of this form, no such transmission takes place.

Purpose: processing your request. Legal basis: Art. 6(1)(b) or (f) GDPR (responding to enquiries). Retention period: as long as necessary to process the request, or until statutory retention periods expire.

5. Map tiles (third-party providers)

For the map view, the app loads map tiles from external map services. In doing so, the respective provider necessarily receives your IP address and the requested tile coordinates (which reflect the approximate map section viewed). Depending on the selected map style, the following are used:

  • CARTO (tiles from basemaps.cartocdn.com) – map data © OpenStreetMap contributors, style © CARTO
  • Esri (satellite, server.arcgisonline.com)

Please note the privacy policies of these providers. The map is only loaded when you open the map view. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in displaying the map).

6. Bluetooth and mesh network

The app connects to your MeshCore device via Bluetooth. Only data between the app and the device is exchanged over this connection; there is no transmission to us. Please be aware of the nature of a radio mesh network: messages you send over the network, as well as any position of your node you may have configured, are transmitted by radio and relayed by other participants/repeaters. What you send over the mesh is therefore not private vis-à-vis other network participants. This is the responsibility of the user and is not processing by us.

7. Permissions and their purpose

PermissionPurpose
Bluetooth (scan/connect)searching for and connecting to the MeshCore device
Location (coarse/fine)your own position on the map, distance measurement, direction-finding points (local only; no tracking, no sharing)
Notificationsalerts about new messages
Foreground servicekeeping the connection to the device active in the background
Internet / network stateloading map tiles

On Android 12+, Bluetooth scanning is requested with the flag “not used to derive location” (neverForLocation). Location is only used for the map functions mentioned above.

8. Disclosure to third parties

Apart from the cases mentioned in section 4 (support server) and section 5 (map providers), no personal data is passed on to third parties. No data is sold.

9. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Since most data resides exclusively on your device, you can remove it yourself at any time by deleting it in the app or uninstalling the app. For matters concerning the support server, please contact the address given in section 1. You also have the right to lodge a complaint with a data protection supervisory authority.

10. Changes to this privacy policy

We amend this privacy policy when the app or the legal situation changes. The current version published here applies.

11. Contact

If you have any questions about data protection, you can reach us at: info@modseven.net

Privacy Policy – Tummo Breath App

Effective date: March 2026

1. Data Controller

Responsible for data processing within the Tummo Breath App: ModSeven Engineering – Philipp Hanzik Gogolstraße 8b, 90475 Nürnberg, Germany Contact: support@modseven.net

2. Health Data

The Tummo Breath App is a guided breathing exercise application. It does not collect, store, transmit, or share any health data or biometric information.

  • Local storage onlyAll breathing session data (e.g. session duration, round counts) is stored locally on your device only and is never transmitted to any server.
  • No health APIsThe app does not use any health or fitness APIs (e.g. Google Fit, HealthConnect).
  • No sharingNo health data is shared with third parties, advertisers, or analytics services.

3. What Data We Collect

The Tummo Breath App only collects data that you voluntarily submit through the in-app support form:

  • Nameto address you personally when responding
  • Email addressto reply to your inquiry
  • Message (free text)the content of your request
  • Date & timefor tracking and follow-up purposes

Through the support form we do not collect IP addresses, location data, health data, or any other tracking information. Aside from the anonymous usage statistics described in section 4, no analytics or advertising SDKs are used.

4. Anonymous Usage Statistics

To improve the app and understand which features and settings are used, we collect anonymous usage statistics. No personal data is collected in this process.

What is collected

Each time you start a breathing session, the app transmits the following information to our server:

  • a random identifier generated once on your device (a random UUID). It is not linked to your name, your device, an account, or any other identifiers, and cannot be traced back to you;
  • the country derived from the region set on your device (e.g. “DE”); no GPS or location access;
  • the settings the session was started with (e.g. number of rounds, breaths per round, hold times, music/voice guidance on/off, custom mode);
  • the app version as well as the date and time of the session start.
What is NOT collected

We do not collect or store any name, email address, precise location, or other personal data. Your IP address is not stored and is not evaluated for statistical purposes (as is technically unavoidable with any internet connection, it is only processed briefly to deliver the request by our hosting provider and is not logged).

Purpose and legal basis

Processing serves exclusively the statistical evaluation and improvement of the app. To the extent that this anonymous data has any personal reference at all, the legal basis is our legitimate interest in improving and further developing the app pursuant to Art. 6(1)(f) GDPR.

Recipients / Hosting

The data is saved in a PostgreSQL database hosted by Neon Inc. in the Frankfurt (EU) region. It is therefore stored exclusively within the European Union; no transfer to a third country takes place.

Retention period

The anonymous statistics data is stored for as long as it is needed for statistical evaluation, but no longer than 24 months.

Your control

Since the data is anonymous, it cannot be attributed to you. You can prevent the transmission at any time by using the app offline / in airplane mode or by uninstalling the app.

5. Legal Basis

Data processing is based on Art. 6(1)(b) GDPR (contract performance or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in responding to support inquiries).

6. Data Retention

Data submitted through the support form is stored for the duration of processing your inquiry and deleted within 90 days thereafter, unless legal retention obligations apply.

7. Data Deletion

You have the right to request deletion of your personal data at any time. To do so, send an informal email to support@modseven.net. We will completely remove your data within 30 days of receiving your request and confirm the deletion by email.

8. Your Rights

Under the GDPR, you have the following rights: access to your stored data (Art. 15), rectification of inaccurate data (Art. 16), erasure of your data (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing (Art. 21). You also have the right to lodge a complaint with a data protection supervisory authority.

9. Third-Party Sharing

Your data is not shared with, sold to, or otherwise transferred to any third parties. All processing is carried out exclusively by the data controller.

10. Changes

This privacy policy may be updated from time to time. The current version is always available at this URL.

NoteStrike – Privacy Policy

App Privacy Policy

NoteStrike uses the microphone (RECORD_AUDIO) solely to detect the pitch of notes played on your instrument.

  • Audio is processed locally on your device in real-time.
  • No audio is recorded, stored, or transmitted.
  • No personal data is collected or shared with third parties.

Cookies

We use cookies to improve your experience. Without your consent, only functional cookies are set.