MelogniteMelognite
Data protection

PRIVACY POLICY — Melognite (melognite.com & melognite.app)

Last updated: 22 August 2026

1. Controller

Casa Santa Solutions UG (haftungsbeschränkt) (Amtsgericht Wuppertal, HRB 37143), represented by Kristina Julia Stüwe, Beethovenstraße 14a, 42579 Heiligenhaus, Germany · hello@melognite.app. A data protection officer is not required and has not been appointed (fewer than 20 persons regularly process personal data).

2. Scope

Covers melognite.com (informational website) and melognite.app (service). Where third parties act as independent controllers (e.g. the payment provider), their own notices apply additionally.

3. Processing activities, purposes and legal bases

3.1 Server log files (both sites). IP address, date/time, requested resource, referrer, user-agent — to deliver and secure the service. Art. 6(1)(f) GDPR. Hosting processors: Hetzner Online GmbH (DE, .com) and IONOS SE (DE, .app + backend/data), each under an Art. 28 data-processing agreement.

3.2 Content-delivery network. Scripts and instrument samples may be served via jsDelivr (Fastly/Cloudflare); your IP is transmitted to the CDN to deliver files, possibly outside the EU. Art. 6(1)(f). We plan to self-host these assets to avoid this transfer.

3.2a Web fonts (Google Fonts). Certain pages currently load the typefaces Cinzel, Inter and JetBrains Mono from Google Fonts (fonts.googleapis.com / fonts.gstatic.com, Google Ireland Ltd / Google LLC). When a page loads, your IP address is transmitted to Google, possibly to servers in the USA. Legal basis Art. 6(1)(f) (uniform presentation); transfers safeguarded by EU Standard Contractual Clauses / EU-US Data Privacy Framework. We plan to self-host these fonts (all are SIL Open Font License) so that no data is sent to Google. Until then, this loading occurs as an essential part of page delivery.

3.3 Account & magic-link authentication (App). Email address, authentication tokens/links, login timestamps — to provide the account. Art. 6(1)(b).

3.4 Subscriptions, payments, entitlements. Payments are handled by our Merchant of Record, Paddle.com Market Limited ("Paddle"), an independent controller for payment data (we do not receive full card data). We receive limited subscription/entitlement data (e.g. email, plan, status), stored on our backend (our server at IONOS, Germany, and our managed database at Supabase, hosted in the EU). Art. 6(1)(b). MoR privacy notice: paddle.com/legal/privacy.

3.5 Transactional email. Login (magic-link) and service emails via Resend (Resend, Inc., USA), transfers safeguarded by EU Standard Contractual Clauses,, processing recipient email and delivery metadata. Art. 6(1)(b) and (f). Processing within the EU under an Art. 28 DPA ; third-country transfers are safeguarded by EU Standard Contractual Clauses. If a US provider is used instead, transfers are safeguarded by SCCs / EU-US DPF.

3.6 The generator itself. Melognite is deterministic and runs in your browser; we do not store the songs, seeds or sketches you generate. No content profiling.

3.7 Launch-notification / newsletter (Website). If you submit your email, we process it for that purpose on your consent (Art. 6(1)(a)), using double-opt-in; withdraw any time (unsubscribe), without affecting past processing. This is operated through our email-service processor Resend (Resend, Inc., 2261 Market Street, San Francisco, CA, USA) under an Art. 28 data-processing agreement; Resend processes your email address, the double-opt-in confirmation, and technical delivery/interaction metadata (e.g. send, bounce, open) on our behalf within the EU. Resend notice: https://www.brevo.com/legal/privacypolicy/.

3.8 Cookies & local storage. Only strictly necessary cookies/local storage (session/auth, consent state) — § 25(2) TDDDG and Art. 6(1)(f). No analytics/tracking cookies currently. Any non-essential storage (incl. embeds, 3.10) is set only with prior consent.

3.9 Analytics / error tracking. Currently none. We do not use analytics or error-tracking services.

3.10 Embedded third-party content (planned). Embeds load only after your consent (§ 25(1) TDDDG, Art. 6(1)(a)); before consent, no data is sent. When loaded, the provider receives your IP and may set cookies and process usage data as its own controller, possibly in third countries (incl. USA) under SCCs/DPF:

3.11 Rights reports („report a seed“). If you use the report form to tell us that a generated result infringes your rights, we process the seed, the genre, any share link, your description of the work and your reasoning, your name and email address and the capacity in which you act, plus the time of receipt. Purposes: (a) blocking the reported seed, (b) assessing the report, (c) replying to you, (d) documenting who reported what and when — this is what protects both sides if a report is later disputed. Legal bases: Art. 6(1)(c) and (f) GDPR (handling notices of infringement; defending against claims; preventing misuse of a procedure that blocks before it checks). Providing the data is voluntary, but without the seed we cannot act at all. Recipients: no one beyond us, unless a legal claim makes disclosure necessary. Retention: see section 6. Blocked seeds are kept indefinitely as a bare number without any personal data attached — a block that expires would silently undo itself.

4. Recipients / processors (summary)

Hosting Hetzner (DE), IONOS (DE); CDN jsDelivr/Fastly/Cloudflare; web fonts Google Fonts (until self-hosted); email + newsletter Resend (FR, EU); payments Paddle (MoR) (independent controller); embeds after consent Google/Meta/TikTok/X/LinkedIn/Spotify/SoundCloud/Apple. Data-processing agreements are in place with our processors.

5. International transfers

Transfers outside the EU/EEA (email, CDN, embedded platforms) rely on EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework, or your explicit consent (Art. 49(1)(a)) for consent-based embeds.

6. Retention

Only as long as necessary: server logs 14 days; account data for the account's life then deleted/anonymised, subject to statutory tax/commercial retention (up to 6–10 years) for invoicing data; newsletter data until withdrawal.

7. Your rights

Access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21), and withdrawal of consent (7(3)) any time. You may complain to a supervisory authority, in particular the competent Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Düsseldorf. Contact: hello@melognite.app.

8. Automated decision-making

We do not use automated decision-making with legal or similarly significant effects (Art. 22 GDPR).

9. Security; children; changes

Appropriate technical/organisational measures (incl. TLS). Not directed to children under 16; no knowing processing of their data without parental consent. We may update this notice; the current version applies.