Last updated: 27 September 2026 (cancellation and withdrawal requests described in 3.4c; checkout open; provenance certificate and its signature/time-stamp described in 3.4b)
Casa Santa Solutions UG (haftungsbeschränkt) (Amtsgericht Wuppertal, HRB 37143), represented by Kristina Julia Stüwe, Beethovenstraße 14a, 42579 Heiligenhaus, Germany · hello@melognite.app. No data protection officer has been appointed; the statutory appointment thresholds are not met. Data-protection enquiries: hello@melognite.app.
Covers melognite.com (informational website) and melognite.app (service). Where third parties act as independent controllers (e.g. the payment provider), their own notices apply additionally.
3.1 Server log files (both sites). IP address, date/time, requested resource, referrer, user-agent, to deliver and secure the service. Art. 6(1)(f) GDPR. Hosting processors: Hetzner Online GmbH (DE, .com) and IONOS SE (DE, .app + backend/data), each under an Art. 28 data-processing agreement.
3.2 Scripts, samples and fonts: served by us. All scripts, instrument samples and web fonts used by the Website and the App are hosted on our own servers (IONOS, Germany). No content-delivery network and no third-party font service is contacted when you load our pages. Our pages load no third-party payment script; the checkout described in 3.4a is a separate page hosted by our Merchant of Record and opens only when you actively start a purchase.
3.2a Web fonts. All typefaces are self-hosted under their respective font licences (SIL OFL 1.1; ITF Free Font License; see the Licenses page). Your IP address is not transmitted to Google, Fontshare or any other font provider.
3.3 Account & passwordless sign-in (App): a one-time code or sign-in link by email. Email address, authentication tokens/links, login timestamps, to provide the account. Art. 6(1)(b).
3.4 Subscriptions, payments, entitlements. Payments for paid plans are handled by our Merchant of Record, FastSpring (the FastSpring contracting entity named at checkout and on your receipt), an independent controller for payment data (we do not receive full payment data). We receive limited subscription/entitlement data (e.g. email, plan, status, subscription ID) via signed server notifications, stored on our backend (our server at IONOS, Germany, and our managed database at Supabase, hosted in the EU). Art. 6(1)(b). FastSpring is based in the USA; the payment transaction you request is processed there (Art. 49(1)(b) GDPR; FastSpring additionally relies on its own transfer safeguards). MoR privacy notice: fastspring.com/privacy.
3.4a Checkout page. Our sites load no payment script in normal use. When you actively start a purchase or open subscription management, you are taken to a checkout or portal page hosted by FastSpring; only then does FastSpring receive your IP address and may set strictly functional cookies for the checkout you requested. Legal basis: Art. 6(1)(b) GDPR and § 25(2) TDDDG (necessary for the service you explicitly request).
3.4b Usage records & file fingerprint. To run your plan we store, per account, the usage records it needs: the identifiers of songs you have counted (genre + seed number), the fingerprints (hashes) of exported musical versions, timestamps, your plan context, and usage events (e.g. limit contacts and re-bookings). These records contain no audio and no musical content beyond those identifiers; we treat them as pseudonymous personal data. Every export is accompanied by a provenance certificate (generation seed, recipe parameters, engine generation, export timestamp, SHA-256 digests of the exported files; see Terms 4.3b) that contains no name, email address or account identifier. If you are signed in when you export, the certificate text (which contains no audio and no personal data) is sent to our server to be signed with our key and forwarded as a SHA-256 hash to an independent time-stamping authority (freetsa.org, RFC 3161), which receives only that hash; the resulting signature and time-stamp are written into the certificate and not stored by us beyond the request log (Section 3.1). Legal basis Art. 6(1)(b) and (f) (proof of provenance you request; abuse prevention). Legal basis Art. 6(1)(b) (billing/allowances) and (f) (abuse prevention, product statistics); retention see Section 6.
3.4c Cancellation and withdrawal requests. When you use our Cancel or withdraw page, we process the details you enter (name, email address, plan, type of request, requested date, reason or message) and the time we received them. To carry out a cancellation, we look up the matching subscription at our Merchant of Record, FastSpring (subscription and account ID, plan, billing dates and the name on the FastSpring account, which we only compare with the name you entered), cancel it there with effect from the end of the current billing period where the case is clear, and send you a confirmation by email (via Resend, see 3.5) stating the date your subscription ends. The confirmation contains a personal link that lets the account holder keep the subscription if the request did not come from them. To run this, to recognise duplicate or abusive requests and to protect your subscription against cancellations by third parties, we keep a record of each request: a reference number, a keyed hash of your email address (never the address itself), a masked form of it (e.g. a***@example.com), the FastSpring subscription and account ID and the product (plan) concerned, the result of the name comparison, the outcome and the relevant dates; it contains no name and no free text. For abuse protection we also keep a keyed hash of your IP address that changes daily and is deleted after two days. Legal basis: Art. 6(1)(b) and (c) GDPR (performing the contract; § 312k BGB) and Art. 6(1)(f) GDPR (protection against cancellations by third parties and abuse). Retention: the record is deleted 400 days after the request or after the end of the cancelled subscription, whichever is later; the emails themselves are kept as business correspondence for the statutory retention periods.
3.5 Transactional email (Resend). Login (magic-link) and service emails are sent via Resend, Inc., 2261 Market Street, San Francisco, CA, USA, as our processor under an Art. 28 data-processing agreement, processing the recipient email address, the transactional message content (including one-time sign-in codes and links) and delivery/log metadata; Resend hosts and stores this data, including message content, in the United States. Even where an EU sending region is used, Resend stores account, log and delivery metadata in the United States; these transfers are safeguarded by the EU Standard Contractual Clauses and the EU-US Data Privacy Framework. Legal bases Art. 6(1)(b) and (f). Resend privacy notice: resend.com/legal/privacy-policy.
3.6 The generator itself. Melognite is deterministic and runs in your browser. Apart from the usage records described in 3.4b (song identifiers, export fingerprints, usage events), we do not store the music you generate — no audio, no MIDI files, no sketches — on our servers; your own browser keeps your working state, history and Takes locally on your device (see 3.8). No content profiling.
3.7 Launch-notification / newsletter (Brevo). If you submit your email for launch news, we process it for that purpose on your consent (Art. 6(1)(a)), using double opt-in; withdraw any time (unsubscribe link), without affecting past processing. This is operated through our email-marketing processor Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France) under an Art. 28 data-processing agreement, processing your email address, the double-opt-in confirmation and technical delivery metadata within the EU. Brevo privacy notice: brevo.com/legal/privacypolicy.
3.8 Cookies & local storage. We set no analytics or advertising cookies. The App stores the following data locally on your device (localStorage/sessionStorage); none of it is transmitted to us unless a row says so:
You can clear all of this at any time via your browser’s site-data settings. Any storage that is not necessary in the above sense (incl. embeds, 3.10) is set only with prior consent (§ 25(1) TDDDG).
3.9 Analytics / error tracking. Currently none. We do not use analytics or error-tracking services.
3.10 Embedded third-party content (planned). Embeds load only after your consent (§ 25(1) TDDDG, Art. 6(1)(a)); before consent, no data is sent. When loaded, the provider receives your IP and may set cookies and process usage data as its own controller, possibly in third countries (incl. USA) under SCCs/DPF:
3.11 Rights reports („report a seed“). If you use the report form to tell us that a generated result infringes your rights, we process the seed, the genre, any share link, your description of the work and your reasoning, your name and email address and the capacity in which you act, plus the time of receipt. Purposes: (a) blocking the reported seed, (b) assessing the report, (c) replying to you, (d) documenting who reported what and when; this is what protects both sides if a report is later disputed. Legal bases: Art. 6(1)(c) and (f) GDPR (handling notices of infringement; defending against claims; preventing misuse of a procedure that blocks before it checks). Providing the data is voluntary, but without the seed we cannot act at all. Recipients: no one beyond us, unless a legal claim makes disclosure necessary. Retention: see section 6. Blocked seeds are kept indefinitely as a bare number without any personal data attached; a block that expires would silently undo itself.
Seed reservation. When you reserve a seed we store, linked to your account: genre, seed number, date, guaranteed term, the FastSpring order reference and the digest of your reservation code (never the code itself). A public register lists genre, seed number, date and scope of active reservations, without any personal data. To keep our promise verifiable we also keep, without any link to a person, a counter per genre and seed of how many accounts have exported that seed („release marks“); this counter is not deleted with an account. Legal basis: Art. 6(1)(b) GDPR (performance of the contract). Retention: for the guaranteed term of the reservation and the statutory retention periods for invoicing data.
Rights notices. If you send us a rights notice concerning a seed, we process your name, contact details, the information in the notice and any files you attach, to review the notice, to answer it and to defend legal claims. Legal basis: Art. 6(1)(c) and (f) GDPR. Retention: the notice and our decision for three years from the end of the year of the decision; attached files for twelve months, longer while a dispute is pending.
Hosting Hetzner (DE, melognite.com) and IONOS (DE, melognite.app incl. all scripts, samples and self-hosted fonts); backend & managed database Supabase (hosted in the EU); transactional email Resend, Inc. (USA; SCC/DPF, see 3.5); newsletter Brevo / Sendinblue SAS (FR, EU, see 3.7); payments FastSpring (Merchant of Record) (independent controller, USA; no payment script on our pages, checkout is hosted by FastSpring and opens only on checkout intent); embeds after consent Google/Meta/TikTok/X/LinkedIn/Spotify/SoundCloud/Apple (planned, 3.10). Data-processing agreements are in place with our processors.
Transfers outside the EU/EEA (transactional email via Resend, USA; checkout SDK when you open it; consent-based embedded platforms) rely on EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework, or your explicit consent (Art. 49(1)(a)) for consent-based embeds.
Only as long as necessary: server logs 14 days; account data for the account's life then deleted/anonymised, subject to statutory tax/commercial retention (up to 6 to 10 years) for invoicing data; usage records (3.4b) for the life of the account plus the statutory retention periods that apply to billing records; newsletter data until withdrawal. Account deletion: email hello@melognite.app and we delete your account and its usage records within 30 days, except data we must retain under statutory duties; residual copies in our routine backups expire with the backup rotation. An active paid subscription must be cancelled first (Section 3.4).
Access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21), and withdrawal of consent (7(3)) any time. You may complain to a supervisory authority, in particular the competent Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Düsseldorf. Contact: hello@melognite.app.
We do not use automated decision-making with legal or similarly significant effects (Art. 22 GDPR).
Appropriate technical/organisational measures (incl. TLS). Not directed to children under 16; no knowing processing of their data without parental consent. We may update this notice; the current version applies.