ReelMusic

Privacy Policy

How the ReelMusic iOS application and the reelmusic.app website process your personal data.

Last updated: 7 September 2026

1. Controller and contact details

The controller responsible for the processing of your personal data within the meaning of Art. 4(7) GDPR is:

Roman Koch, sole proprietor (Einzelunternehmer) Martin-Opitz-Str. 14 13357 Berlin Germany

E-mail: apps@romankoch.online Websites: https://reelmusic.app, https://romankoch.online

Data protection officer. We have not appointed a data protection officer. We are not required to do so under Art. 37 GDPR or § 38 BDSG, because we do not employ the number of persons that triggers that obligation and our core activity does not consist of large-scale processing of special categories of data or of regular and systematic monitoring of data subjects on a large scale. You may address all data protection enquiries to the contact above.

EU representative. Not applicable — the controller is established in the European Union.


2. Scope and purpose of this policy

This policy explains what personal data we process when you use:

It explains why we process that data, on what legal basis, who receives it, how long we keep it and what rights you have.

Most of this policy describes the App, because that is where the substantial processing happens. Processing that is specific to the website is set out in section 18. Sections 1, 5, 8, 10, 11, 15 and 19 to 21 apply to both.

It does not apply to:

Capitalised terms not defined here have the meaning given to them in our Terms and Conditions.


3. How ReelMusic works — a short data-flow summary

We consider it good practice to explain the processing before listing it formally, because the App's core function involves sending your video content to third-party AI services.

  1. On first launch, the App generates a pseudonymous installation identifier (UUID) on your device. There is no registration and no sign-in — no Apple account login is required, and we do not collect your name or e-mail address.
  2. You select a video from your device. The App compresses it on your device.
  3. The compressed video is uploaded to our cloud storage (Google Firebase, EU region).
  4. Our server sends the video to Google's Gemini API, which analyses mood, pacing and content and returns a text description and a structured "music brief".
  5. Our server sends the resulting text prompt (not the video) to WaveSpeed AI, which routes it to the selected music-generation model (currently Mureka) and returns an audio track.
  6. The generated track is returned to the App. Combining ("muxing") the track with your video happens on your device; the finished video is never uploaded to us.
  7. Your uploaded video is deleted from our servers immediately after the generation job completes.

The remainder of this policy describes each step in the terms required by Arts. 13 and 14 GDPR.


4. Categories of personal data we process

4.1 Installation and identity data

The App works without registration or sign-in. We do not collect your name, e-mail address or other contact details. To provide the service we process:

This technical identity is mandatory — without it we cannot meter your credits, restore purchases or deliver generated tracks (see section 7). Once a generation job has been processed, all data relating to that job is removed from our systems; the only record that persists server-side is your credit balance, linked to this identifier.

4.2 Subscription, purchase and billing data

We never receive or store your payment card details, bank details or billing address. Payment is processed exclusively by Apple through the App Store. Apple acts as an independent controller for that payment relationship.

4.3 Content data (your video and everything derived from it)

⚠️ Your video may contain personal data of yourself and of other people — faces, voices, licence plates, house numbers, screen contents, location cues. Please read section 12 before uploading footage that shows other people.

4.4 Usage and quota data

4.5 Device, technical and security data

4.6 Analytics data

We do not use analytics to build advertising profiles, we do not use the Apple Advertising Identifier (IDFA), and we do not run third-party advertising SDKs.

4.7 Diagnostic and crash data

4.8 Support communications

4.9 Special categories of data

We do not intentionally process special categories of personal data within the meaning of Art. 9 GDPR. However, a video you upload may incidentally reveal such information (for example health-related, religious or political content, or biometric-quality images of faces). We do not analyse video for the purpose of identifying individuals, we do not run facial recognition, and we do not derive or store any biometric template. Where such content is present, it is processed only incidentally and transiently as part of the generation job and is deleted with the video (see section 11). Please do not upload footage whose content you would not want processed by our AI service providers.


# Purpose Data categories Legal basis
1 Creating and managing your pseudonymous installation identity; authenticating requests 4.1 Art. 6(1)(b) GDPR — performance of the contract
2 Providing the core service: analysing your video, generating a music track, delivering it to your device 4.1, 4.3, 4.4 Art. 6(1)(b) GDPR — performance of the contract
3 Managing subscriptions, trials, entitlements and restoring purchases 4.1, 4.2 Art. 6(1)(b) GDPR
4 Metering the number of generations you have used, so that your balance survives reinstalling the App 4.1, 4.4 Art. 6(1)(b) GDPR
5 Preventing abuse of the free trial, of our quota system and of our AI service budget; verifying that requests originate from a genuine copy of the App 4.1, 4.4, 4.5 Art. 6(1)(f) GDPR — legitimate interest in protecting the service against fraud and cost abuse
6 Ensuring the security, integrity and availability of our systems; investigating faults; server logging 4.5 Art. 6(1)(f) GDPR — legitimate interest in operating a secure service; Art. 32 GDPR
7 Enforcing the content restrictions in our Terms and the content policies of our AI providers 4.3, 4.4 Art. 6(1)(f) GDPR — legitimate interest in lawful operation; Art. 6(1)(c) GDPR where a legal obligation applies
8 Understanding how the App is used in order to improve it (analytics) 4.6 Art. 6(1)(a) GDPR — your consent, obtained in the App; § 25(1) TDDDG for the storage of, or access to, information on your device
9 Diagnosing crashes and performance problems 4.7 Art. 6(1)(a) GDPR — your consent, obtained in the App
11 Responding to your support requests 4.1, 4.8 Art. 6(1)(b) GDPR where the request concerns the contract; otherwise Art. 6(1)(f) GDPR
12 Complying with statutory retention, tax and accounting obligations 4.2 Art. 6(1)(c) GDPR — legal obligation (§ 147 AO, § 257 HGB)
14 Delivering our website, keeping it available and secure, and investigating faults and attacks (server log files) 18.1 Art. 6(1)(f) GDPR — legitimate interest in operating a secure website
15 Loading the optional external services on our website (web fonts, QR-code image) 18.3 Art. 6(1)(a) GDPR — your consent, given in the banner on the website; § 25(1) TDDDG for the access to information on your device
13 Establishing, exercising or defending legal claims any of the above Art. 6(1)(f) GDPR; Art. 9(2)(f) GDPR where special categories are involved

Balancing test (Art. 6(1)(f)). Where we rely on legitimate interests, we have weighed our interests against your rights and freedoms. The processing is limited to what is necessary, uses pseudonymous identifiers rather than directly identifying data wherever possible, and does not involve profiling for advertising. You may object at any time under Art. 21 GDPR (see section 15). A summary of the balancing test is available on request.

Withdrawing consent. Where processing is based on consent, you may withdraw it at any time with effect for the future, in the App's settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.


6. Where the data comes from

We receive personal data:


7. Is provision of data mandatory?

The technical identifiers in section 4.1 are required to perform the contract: without them we cannot provide the App, meter your credits or restore your purchases. They are generated automatically — you do not have to provide any contact details such as your name or e-mail address.

Providing content data (section 4.3) is voluntary in the sense that you decide which video, if any, to upload — but without a video no music can be generated.

Analytics and diagnostics (sections 4.6 and 4.7) are entirely optional. Declining or later withdrawing consent has no effect on your ability to use the App.


8. Recipients and processors

We use the following service providers. Those marked as processors act on our documented instructions under a data processing agreement pursuant to Art. 28 GDPR.

Provider Role What it receives Processing location Transfer safeguard
Google Ireland Limited / Google LLC — Firebase (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, App Check, Remote Config) Processor Account data, content data, usage and quota data, technical data Firestore, Cloud Storage and Cloud Functions are configured for the europe-west3 (Frankfurt, Germany) region. Some administrative and support processing may take place in the USA. Google's Cloud Data Processing Addendum incl. EU Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC
Google Ireland Limited / Google LLC — Gemini API (video analysis) Processor The uploaded video and the analysis prompt; the returned analysis Google infrastructure; processing may take place outside the EU/EEA, including in the USA Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC
Google Ireland Limited / Google LLC — Google Analytics for Firebase Processor Analytics events, App-instance identifier, coarse device and country data Google infrastructure incl. the USA Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC — used only with your consent
Google Ireland Limited / Google LLC — Firebase Crashlytics Processor Crash reports and stack traces, device model, OS and App version, App-instance identifier Google infrastructure incl. the USA Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC — used only with your consent
WaveSpeedAI PTE. LTD., 3 Phillip Street #10-04, Royal Group Building, Singapore 048693 Processor The generated text music prompt and model parameters; returns the audio track. No video and no account identifier of yours is transmitted. Singapore / USA [Art. 28 data processing agreement and EU Standard Contractual Clauses — to be concluded / confirmed]
Mureka (Kunlun Tech / Skywork AI) — music generation model, reached through WaveSpeedAI Sub-processor The text music prompt only Outside the EU/EEA Contractual chain through WaveSpeedAI — [to be confirmed]
RevenueCat, Inc., 633 Taraval St., Suite 101, San Francisco, CA 94116, USA Processor Your UID, subscription and entitlement events, country/storefront, device platform USA RevenueCat Data Processing Addendum incl. EU Standard Contractual Clauses
Apple Inc. / Apple Distribution International Ltd. Independent controller Purchase, payment and App Store account data; Sign-in-with-Apple data Ireland / USA Apple's own privacy policy applies to Apple's own processing
Alfahosting GmbH, Halle (Saale), Germany — hosting of our self-hosted analytics server Processor / our own infrastructure Aggregated, non-identifying usage counts (see section 9) Germany Not applicable — processing within the EU
[WEBSITE HOST — legal name, address, country] — hosting of reelmusic.app Processor Server log data for the website: IP address, timestamp, page requested, status code, referrer, browser and operating system [Country — to be confirmed] [Art. 28 data processing agreement — to be concluded / confirmed]
Google Ireland Limited / Google LLC — Google Fonts (web fonts on the website) Independent controller for its own processing Your IP address, browser and operating system, and the address of the page requesting the font Google infrastructure incl. the USA EU–US Data Privacy Framework certification of Google LLC; Standard Contractual Clauses — loaded only with your consent
Operator of api.qrserver.com — QR-code image in the "Scan QR" dialog [operator legal name and address — to be confirmed] Independent controller for its own processing Your IP address, browser and operating system, and the App Store address encoded in the QR code [To be confirmed] [To be confirmed] — requested only with your consent, and only if you open that dialog
Professional advisers (tax adviser, lawyer), where required Recipient Billing and contract data as necessary EU Statutory confidentiality obligations

We do not sell personal data, and we do not disclose it to third parties for their own marketing purposes.

We may disclose personal data to public authorities or courts where we are legally obliged to do so, or where disclosure is necessary to establish, exercise or defend legal claims.


9. Analytics in detail

This section concerns the App only. Our website carries no analytics at all — see section 18.4.

First-party (self-hosted) analytics. We operate our own analytics service on a server rented in [EU LOCATION]. It records anonymous, aggregated usage counts — for example how often a generation was started or how often an error screen was shown. These records contain no account identifier, no IP address in stored form and no device identifier, and cannot be linked back to you by us. Because the data is anonymous once stored, GDPR does not apply to the stored records; the transmission itself and any access to information on your device take place only after you have consented.

Google Analytics for Firebase. With your consent we additionally use Google Analytics for Firebase, which assigns your installation a randomly generated App-instance identifier and transmits event data to Google. This identifier is pseudonymous, is reset when you delete and reinstall the App, and can be reset by you at any time in the App's settings. We do not enable the advertising-identifier (IDFA) integration and we do not link analytics data to advertising networks. Analytics data retention in Google's systems is configured to 2 months.

Consent. Both components are switched off by default. They are activated only after you give consent in the App and can be switched off again at any time in the App's settings, with effect for the future.

App Tracking Transparency. We do not track you across apps or websites owned by other companies. Accordingly, the App does not present Apple's App Tracking Transparency prompt.


10. International data transfers

Some of our processors process data outside the European Economic Area, in particular in the United States and Singapore.

You can request a copy of the relevant safeguards from us at the address in section 1.

Transfers to a third country always carry a residual risk that the level of protection is not equivalent to that in the EU, in particular because of possible access by local authorities and because enforcing your rights may be more difficult.


11. Retention periods

Data Retention
Uploaded video file (4.3) Deleted automatically as soon as the analysis has completed or failed — typically within a minute of upload — and in any event no later than 24 hours after upload, by an automatic storage lifecycle rule. The working copy held by the Gemini API for the duration of the analysis is deleted in the same step, rather than being left to that service's own 48-hour expiry
Analysis text and generated prompts (4.3) Stored with the job record for 14 days, then deleted
Generated audio track on our servers (4.3) Deleted as soon as the App confirms the track has been saved to your device, and in any event no later than 14 days after generation, by an automatic storage lifecycle rule. The copy on your device remains under your control
Job records and error states (4.4) Deleted immediately after the job has been processed; error states no later than 14 days after the job
Usage ledger (4.4) Until the installation identity is deleted (see next row); anonymised aggregates may be retained longer
Installation identity, credit balance and all associated records (4.1, 4.4) Deleted after twelve (12) months of inactivity, together with all other data linked to the installation identity. Separately purchased credit packs expire twelve (12) months after purchase
Subscription and entitlement records (4.2) For the duration of the entitlement, then as required by statutory retention obligations
Invoicing and accounting records 10 years pursuant to § 147 AO and § 257 HGB. During this period processing is restricted to that purpose
Server and security logs (4.5) 14 days, unless a longer period is needed to investigate a specific security incident
Analytics data (4.6) Self-hosted: anonymous aggregates, no defined deletion point. Google Analytics for Firebase: 2 months
Crash and diagnostic data (4.7) 14 days
Website server log files (18.1) [X days — to be confirmed with the host], unless a longer period is needed to investigate a specific security incident
Support correspondence (4.8) 3 years from the end of the year in which the matter was concluded (statutory limitation period, § 195 BGB)

Where deletion is not possible because of a statutory retention obligation, we restrict processing instead (Art. 18 GDPR) and delete the data at the end of the retention period.


12. Videos containing other people

If the video you upload shows or is audible of other identifiable people, you are responsible for having a legal basis for their personal data being processed — normally their consent, or another basis under Art. 6 GDPR. In relation to that content you act as the controller and we act as your processor for the purposes of the generation job; the corresponding terms are set out in [Annex [X] of our Terms and Conditions / our separate Data Processing Agreement for business users].

We ask you not to upload footage of other people without their knowledge, and not to upload footage of children, of medical or other sensitive situations, or of documents containing personal data.

Because your video is passed to our AI providers, it leaves our systems. Please take this into account when deciding what to upload.


13. AI-specific disclosures

Your content is not used to train AI models. We do not train models on your videos, prompts or generated tracks, and we have contractually excluded such use by our providers to the extent they permit it:

Abuse monitoring. Our AI providers may inspect inputs and outputs to detect breaches of their content policies. This can include limited human review by the provider. We have no control over the timing of such review.

Automated decision-making. The AI analysis of your video and the resulting music are an automated process, but they do not produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22(1) GDPR. Automated checks may block a generation request that appears to breach content rules or exceeds your quota; you can always contact us to have such a decision reviewed by a human.

AI transparency. Tracks produced with the App are generated by artificial intelligence. Depending on the model used, outputs may carry a machine-readable watermark. Your obligations regarding the labelling of AI-generated content — including under Art. 50 of the EU AI Act (Regulation (EU) 2024/1689) and the rules of the platform you publish on — are set out in our Terms and Conditions.


14. Security

We apply technical and organisational measures appropriate to the risk in accordance with Art. 32 GDPR, including:

No system can be guaranteed to be completely secure. Please notify us immediately at the address in section 1 if you believe your account has been compromised.


15. Your rights

Under the GDPR you have the following rights in relation to your personal data:

Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59–61, 10555 Berlin, Germany https://www.datenschutz-berlin.de

How to exercise your rights. Write to apps@romankoch.online. We will respond without undue delay and in any event within one month of receipt, extendable by two further months where necessary (Art. 12(3) GDPR). We may ask you for information to verify your identity — normally proof of control over the e-mail address linked to your account. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive (Art. 12(5) GDPR).

Deletion. The App does not use user accounts. Your server-side data (installation identity, credit balance, job records) is deleted automatically after twelve (12) months of inactivity, and you can request earlier deletion at any time by writing to apps@romankoch.online. Deleting the App from your device removes all locally stored content, including the installation identifier itself; any remaining server-side credit balance then becomes unlinkable to you and is deleted after twelve (12) months of inactivity at the latest. Please note that this does not cancel an App Store subscription — you must cancel that in your Apple Account settings — and does not affect data we are legally required to retain (section 11).


16. Children

The App is not directed at children. You must be at least 18 years old to use it; if the law of your country of residence sets a higher age for the validity of consent or the conclusion of contracts, that higher age applies. We do not knowingly process the personal data of children below that age. If you believe a child has provided us with personal data, please contact us and we will delete it without undue delay.


17. Information stored on your device

The App stores information on your device that is strictly necessary to provide the service you have requested, and may therefore be stored without consent pursuant to § 25(2) no. 2 TDDDG:

Information stored or read for analytics and diagnostics purposes is not strictly necessary and is stored only with your consent under § 25(1) TDDDG (see section 9).

The App does not use browser cookies. It does not use the Apple Advertising Identifier and does not participate in cross-app tracking.

Information stored in your browser when you visit our website is described separately in section 18.2.


18. The ReelMusic website (reelmusic.app)

This section covers processing that happens when you visit our website at reelmusic.app, including the legal pages hosted there. The website is an information site: it has no user accounts, no sign-in, no shop and no contact form, and nothing you type is sent to us through it.

18.1 Server log files

Each time a page or file is requested, your browser automatically transmits technical data, which our hosting provider records in a log file:

Purpose: delivering the page you asked for, keeping the site stable and available, and detecting and investigating faults and attacks. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure and functioning website. Retention: see section 11. We do not merge log data with other data, and we do not use it to identify you or to build a profile.

18.2 No cookies; information stored in your browser

The website sets no cookies. It stores exactly one entry in your browser's local storage:

Entry Purpose Value Lifetime
rm-consent Records the choice you made in the consent banner, so that the banner does not ask you again and your decision is honoured on later visits all or essential Until you clear your browser data, or reset your choice on the cookie settings page

Storing this entry is strictly necessary to provide the function you asked for — namely to respect your own choice — and may therefore be stored without consent under § 25(2) no. 2 TDDDG. It contains no identifier, it is never transmitted to us, and it cannot be used to recognise you.

18.3 Optional external services

The following services are hosted by other companies. They are loaded only if you choose "Accept all" in the consent banner. When one of them is loaded, your IP address and browser details reach that company, which may be outside the EU/EEA, and that company decides for itself how it uses that data.

Service What it does What it receives
Google Fonts
fonts.googleapis.com, fonts.gstatic.com
Google Ireland Limited / Google LLC
Supplies the typefaces used on the site. If you decline, the site falls back to the typefaces already installed on your device. Your IP address, browser and operating system, and the address of the page requesting the font
QR-code service
api.qrserver.com
[operator — to be confirmed]
Draws the QR code shown in the "Scan QR" dialog. It is requested only if you actually open that dialog. Your IP address, browser and operating system, and the App Store address encoded in the code

Legal basis: Art. 6(1)(a) GDPR — your consent — together with § 25(1) TDDDG for the access to information on your device that loading these resources involves. Withdrawing consent: you can change or reset your choice at any time on our cookie settings page, with effect for the future. Withdrawal does not affect the lawfulness of what happened before.

We have no influence over what these providers do with the data once it reaches them, and we cannot rule out that it is processed outside the EU/EEA. Section 10 explains the safeguards that apply to transfers to Google. If you would rather avoid this entirely, choose "Only necessary" — the site works fully without these services.

18.4 No analytics and no advertising on the website

The website loads no analytics, no tracking pixels, no social-media plug-ins and no advertising services. We do not track you across sites, we build no profiles, and we share nothing with advertising networks. The analytics described in section 9 relates to the App only. If we ever add analytics to the website, we will update this policy and add it to the consent banner as a separate option that is off until you switch it on.

The website links to the Apple App Store, to our Terms and Conditions and this policy on their own subdomains, and to third-party news and legal-information sites cited as sources. Following such a link takes you to a service whose operator is responsible for its own processing; this policy stops at our door.

18.6 Contacting us from the website

The website has no contact form. The contact links open your own e-mail programme. If you write to us, we process your message as described in sections 4.8, 5 and 11.


19. Additional information for residents of the United States

This section supplements the above for residents of California and of other US states with comparable privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, Texas).

Categories of personal information collected in the last 12 months: identifiers (account ID, e-mail address, device identifiers); commercial information (subscription and purchase history); internet or other electronic network activity (usage and analytics events); audio, electronic or visual information (the videos you upload and the audio generated from them); inferences drawn for the purpose of generating music (mood and style attributes derived from your video). Sources, purposes and recipients are those described in sections 4, 5 and 8.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA/CPRA. We have not sold or shared personal information of consumers, including minors under 16 years of age, in the preceding 12 months.

Your rights include the right to know, to access, to delete, to correct and to opt out of sale or sharing (not applicable, as we do neither), and the right not to be discriminated against for exercising them. To exercise them, contact us at apps@romankoch.online. You may use an authorised agent; we will require proof of authorisation. We do not use or disclose sensitive personal information for purposes other than those permitted under the CCPA, so no right to limit its use applies.

Retention: as set out in section 11.


20. Apple App Store privacy information

Apple requires us to publish a summary of our data practices ("privacy nutrition labels") on the App's App Store product page. That summary is a simplified representation prepared according to Apple's categories; this privacy policy is the authoritative and complete description. If the two ever appear to conflict, this policy governs and we will correct the App Store entry.


21. Changes to this privacy policy

We may update this policy to reflect changes in the App, in our service providers or in the law. The current version is always available in the App under Settings → Privacy Policy and at https://privacy.reelmusic.app. If a change is material — for example a new category of data, a new purpose or a new third-country recipient — we will notify you in the App before it takes effect (we do not hold your e-mail address). Where the change requires your consent, we will ask for it.

Version history

Version Date Change
1.0 14.08.2026 Initial version
1.1 07.09.2026 Scope extended to the reelmusic.app website. New section 18 (server log files, browser storage, optional external services, no website analytics). Website host, Google Fonts and the QR-code service added to section 8; log retention added to section 11; two purposes added to section 5. Former sections 18–20 renumbered to 19–21.