Privacy Policy
1. Controller
Gerald Floßmann, Tatzendpromenade 2a, 07745 Jena, Germany. Email: support@songbookbuddy.com. Website: www.songbookbuddy.com
2. General information on data processing
We take the protection of your personal data seriously. Personal data is treated confidentially and in accordance with the statutory data protection regulations (GDPR).
3. Hosting and website operation
Our website is hosted by the following provider: Hostinger International Ltd. When you visit the website, the following data is collected automatically: IP address; date and time of the request; browser type and version; operating system; referrer URL. This data is technically required to provide the website and ensure system security. Legal basis: Art. 6(1)(f) GDPR.
4. Contact
If you contact us by email, Discord, or in-app support, your details including the contact data and information you provide are stored for the purpose of handling the enquiry. Legal basis: Art. 6(1)(b) and, where applicable, Art. 6(1)(f) GDPR.
5. Use of the Songbook Buddy app
To run the app we process, in particular: (a) Account data — email address and authentication data (and, where used, anonymous purchase sessions until you secure them with an email). (b) Licence / purchase data — subscription or one-time purchase status, platform (e.g. Apple, Google, PayPal), and related transaction identifiers needed to deliver entitlements. (c) User library content synced to the cloud — selected personal fields (e.g. song titles, ChordPro text, notes, layout settings) are encrypted on your device before upload (AES-GCM; key derived from your account password). We cannot read those encrypted fields. Limits: identifiers, timestamps, and some structural or shared metadata (e.g. band membership, setlist structure) are stored so sync and collaboration can work; shared band song payloads use separate per-band encryption. (d) Sharing with other people — when you send a song or a setlist to another Songbook Buddy account, its content (text, notes, settings, and any attached sheet) is transferred through our servers and kept there until the recipient accepts or declines it, or it expires. It is encrypted in transit, but not end-to-end encrypted: while it waits, it is readable on the server. (e) Wi-Fi sync — linked audio files and sheet attachments are copied directly between your own signed-in devices on the same local network. The transfer is encrypted, only devices of your account can take part, and none of it passes through our servers. (f) Fonts — some fonts are downloaded on first launch from our own website (songbookbuddy.com); no third party is involved. If you choose an additional font in the font browser, it is downloaded from Google Fonts (Google Ireland Limited), which receives your device's IP address for that request. (g) Diagnostics — you may send a report from Preferences → About. For signed-in users, a minimized technical report may be sent after unexpected errors (default on; can be turned off). Reports include technical data (version, device/platform, locale, recent logs, sync state; may include file paths). Song lyrics are not included automatically. Email addresses that appear in log lines are replaced by an anonymous code before a report is put together. A contact address is included only if you enter one in the report dialog; it is remembered for later reports, automatic ones included, until you clear it. Reports you choose to send, including attachments, are readable by support so we can help you. Legal basis: Art. 6(1)(f) GDPR. (h) Anonymous usage statistics (opt-in, default off) — with your consent the app sends aggregate counts only (launches, days used, songs added or opened, and which features were used) under a random identifier generated on your device. No account is required. No personal data, song content, titles, lyrics, file names, or precise timestamps are sent, and the identifier is separate from any synchronization identity. Turning the setting off stops further collection and deletes this device's statistics record. Legal basis: Art. 6(1)(a) GDPR.
6. Cloud services (Supabase)
We use Supabase (Supabase Inc.) as a processor for: account authentication; encrypted and non-encrypted sync data as described above; licence/entitlement records; support reports; optional usage statistics; and (on the website) certain forms and download-click counters. Processing is not limited to synchronisation. Legal basis: Art. 6(1)(b) and, where applicable, Art. 6(1)(f) or (a) GDPR.
7. Website download statistics
We count installer downloads of Songbook Buddy (DMG, ZIP, APK, Windows setup) from the Download page and from direct requests under /files/ for those installer files. For each event we may store: channel (stable/beta), platform, version, artifact type, link, timestamp, page path, referrer, site host, browser user-agent (and derived device/browser/OS labels), a one-way hash of the IP address (not the raw IP), country code when the CDN provides it, and a source label (website click, in-app update link, or other direct /files/ request). Help packs and other non-installer files under /files/ are not counted this way. No account is required. Legal basis: Art. 6(1)(f) GDPR.
8. Beta portal
The beta area uses Supabase Auth (email and password). Session data is stored in your browser (local storage). You may also submit beta-related emails (newsletter signup, TestFlight / Play tester addresses). Legal basis: Art. 6(1)(b) and/or (f) GDPR.
9. Payment and store providers
Purchases may be processed by Apple, Google, and/or PayPal. Those providers process payment data under their own policies; we receive entitlement and limited transaction metadata (and, for some PayPal flows, payer email for recovery). Recipients of app data are Supabase (cloud provider), the app store providers (Apple / Google), PayPal when you pay that way, and Google Fonts (Google Ireland Limited) — the last only when you download an additional font yourself.
10. Cookies and local storage
We do not use advertising or third-party analytics cookies. Where needed for the beta portal, the browser may store a session in local storage (not a marketing cookie). Hosting may set technically necessary cookies or use HTTP authentication for protected staging/production paths. Legal basis: Art. 6(1)(f) GDPR.
11. Your rights
You have the right at any time to: access your stored data; rectification of inaccurate data; erasure of your data; restriction of processing; data portability. You also have the right to lodge a complaint with a data protection supervisory authority.
12. Retention period
Personal data is stored only for as long as necessary for the respective purpose (for example account and entitlement data while your account is active; support reports while needed for triage; download-event counters for aggregate statistics; opt-in usage statistics until you withdraw consent). When you delete your account, it is removed for good 30 days after the request (until then you can undo it). The removal covers your library, your diagnostic reports and the files you stored with us — sheet attachments, report attachments and the content of shares you sent or received. Payment records are kept without a link to your account, as accounting law requires.
13. SSL / TLS encryption
This site uses SSL or TLS encryption for security reasons.
14. Changes to this privacy policy
We reserve the right to adapt this privacy policy to reflect current legal requirements or changes to our services.
Delete your account and the data stored for it
Last updated: 27 September 2026