1. Controller and contact details
The controller responsible for the processing of your personal data within the meaning of Art. 4(7) GDPR is:
Roman Koch, sole proprietor (Einzelunternehmer) Martin-Opitz-Str. 14 13357 Berlin Germany
E-mail: apps@romankoch.online Website: https://romankoch.online
Data protection officer. We have not appointed a data protection officer. We are not required to do so under Art. 37 GDPR or § 38 BDSG, because we do not employ the number of persons that triggers that obligation and our core activity does not consist of large-scale processing of special categories of data or of regular and systematic monitoring of data subjects on a large scale. You may address all data protection enquiries to the contact above.
EU representative. Not applicable — the controller is established in the European Union.
2. Scope and purpose of this policy
This policy explains what personal data we process when you use the App, why we process it, on what legal basis, who receives it, how long we keep it and what rights you have.
It does not apply to:
- the App Store and your Apple Account, which are operated by Apple and governed by Apple's privacy policy;
- third-party platforms (e.g. Instagram, TikTok, YouTube) to which you may later upload a video you created with the App;
- any website or service we link to.
Capitalised terms not defined here have the meaning given to them in our Terms and Conditions.
3. How ReelMusic works — a short data-flow summary
We consider it good practice to explain the processing before listing it formally, because the App's core function involves sending your video content to third-party AI services.
- On first launch, the App generates a pseudonymous installation identifier (UUID) on your device. There is no registration and no sign-in — no Apple account login is required, and we do not collect your name or e-mail address.
- You select a video from your device. The App compresses it on your device.
- The compressed video is uploaded to our cloud storage (Google Firebase, EU region).
- Our server sends the video to Google's Gemini API, which analyses mood, pacing and content and returns a text description and a structured "music brief".
- Our server sends the resulting text prompt (not the video) to WaveSpeed AI, which routes it to the selected music-generation model (currently Mureka) and returns an audio track.
- The generated track is returned to the App. Combining ("muxing") the track with your video happens on your device; the finished video is never uploaded to us.
- Your uploaded video is deleted from our servers immediately after the generation job completes.
The remainder of this policy describes each step in the terms required by Arts. 13 and 14 GDPR.
4. Categories of personal data we process
4.1 Installation and identity data
The App works without registration or sign-in. We do not collect your name, e-mail address or other contact details. To provide the service we process:
- the installation identifier (UUID) — a random identifier generated on your device at first launch, used as the key for your credit balance and, transiently, for your generation jobs;
- the corresponding pseudonymous app user ID used by our subscription-management provider.
This technical identity is mandatory — without it we cannot meter your credits, restore purchases or deliver generated tracks (see section 7). Once a generation job has been processed, all data relating to that job is removed from our systems; the only record that persists server-side is your credit balance, linked to this identifier.
4.2 Subscription, purchase and billing data
- entitlement status (active / trial / expired / grace period), product identifier, purchase and renewal dates, cancellation and refund events;
- a pseudonymous customer record that links your UID to your subscription state;
- your country/storefront and currency as reported by the App Store.
We never receive or store your payment card details, bank details or billing address. Payment is processed exclusively by Apple through the App Store. Apple acts as an independent controller for that payment relationship.
4.3 Content data (your video and everything derived from it)
- the video file you select, in compressed form, including its audio track and any technical metadata that survives compression;
- the text analysis the AI produces from that video (a visual description and a structured music brief: mood, genre, tempo, instrumentation, narrative and similar attributes);
- the text prompts generated from that analysis and any prompt text or style settings you enter or adjust yourself;
- the generated audio track.
⚠️ Your video may contain personal data of yourself and of other people — faces, voices, licence plates, house numbers, screen contents, location cues. Please read section 12 before uploading footage that shows other people.
4.4 Usage and quota data
- number of generations used and remaining in the current billing period;
- a usage ledger: one entry per generation with job ID, model used, track length in seconds, timestamp and billing period;
- job records describing the state of each generation (queued, analysing, generating, ready, failed) and any error codes.
4.5 Device, technical and security data
- device model, operating system version, App version, language and region settings;
- a device attestation token generated by Apple's App Attest framework, which proves that requests come from a genuine, unmodified copy of our App;
- IP address and server log data associated with your requests, including timestamps and the endpoint called;
- an App-instance identifier used by our analytics components.
4.6 Analytics data
- product analytics events — for example: app opened, video selected, analysis started, generation started, generation succeeded or failed, paywall shown, subscription started, error displayed — together with coarse technical attributes (App version, OS version, device class, country) and aggregate timing data.
We do not use analytics to build advertising profiles, we do not use the Apple Advertising Identifier (IDFA), and we do not run third-party advertising SDKs.
4.7 Diagnostic and crash data
- crash reports and performance traces containing a stack trace, App and OS version, device model and the App-instance identifier. (Processed by Google's Firebase Crashlytics, only after you have given consent — see sections 5 and 9.)
4.8 Support communications
- your e-mail address and the content of any message you send us, including attachments, and our correspondence with you.
4.9 Special categories of data
We do not intentionally process special categories of personal data within the meaning of Art. 9 GDPR. However, a video you upload may incidentally reveal such information (for example health-related, religious or political content, or biometric-quality images of faces). We do not analyse video for the purpose of identifying individuals, we do not run facial recognition, and we do not derive or store any biometric template. Where such content is present, it is processed only incidentally and transiently as part of the generation job and is deleted with the video (see section 11). Please do not upload footage whose content you would not want processed by our AI service providers.
5. Purposes of processing and legal bases
| # | Purpose | Data categories | Legal basis |
|---|---|---|---|
| 1 | Creating and managing your pseudonymous installation identity; authenticating requests | 4.1 | Art. 6(1)(b) GDPR — performance of the contract |
| 2 | Providing the core service: analysing your video, generating a music track, delivering it to your device | 4.1, 4.3, 4.4 | Art. 6(1)(b) GDPR — performance of the contract |
| 3 | Managing subscriptions, trials, entitlements and restoring purchases | 4.1, 4.2 | Art. 6(1)(b) GDPR |
| 4 | Metering the number of generations you have used, so that your balance survives reinstalling the App | 4.1, 4.4 | Art. 6(1)(b) GDPR |
| 5 | Preventing abuse of the free trial, of our quota system and of our AI service budget; verifying that requests originate from a genuine copy of the App | 4.1, 4.4, 4.5 | Art. 6(1)(f) GDPR — legitimate interest in protecting the service against fraud and cost abuse |
| 6 | Ensuring the security, integrity and availability of our systems; investigating faults; server logging | 4.5 | Art. 6(1)(f) GDPR — legitimate interest in operating a secure service; Art. 32 GDPR |
| 7 | Enforcing the content restrictions in our Terms and the content policies of our AI providers | 4.3, 4.4 | Art. 6(1)(f) GDPR — legitimate interest in lawful operation; Art. 6(1)(c) GDPR where a legal obligation applies |
| 8 | Understanding how the App is used in order to improve it (analytics) | 4.6 | Art. 6(1)(a) GDPR — your consent, obtained in the App; § 25(1) TDDDG for the storage of, or access to, information on your device |
| 9 | Diagnosing crashes and performance problems | 4.7 | Art. 6(1)(a) GDPR — your consent, obtained in the App |
| 11 | Responding to your support requests | 4.1, 4.8 | Art. 6(1)(b) GDPR where the request concerns the contract; otherwise Art. 6(1)(f) GDPR |
| 12 | Complying with statutory retention, tax and accounting obligations | 4.2 | Art. 6(1)(c) GDPR — legal obligation (§ 147 AO, § 257 HGB) |
| 13 | Establishing, exercising or defending legal claims | any of the above | Art. 6(1)(f) GDPR; Art. 9(2)(f) GDPR where special categories are involved |
Balancing test (Art. 6(1)(f)). Where we rely on legitimate interests, we have weighed our interests against your rights and freedoms. The processing is limited to what is necessary, uses pseudonymous identifiers rather than directly identifying data wherever possible, and does not involve profiling for advertising. You may object at any time under Art. 21 GDPR (see section 15). A summary of the balancing test is available on request.
Withdrawing consent. Where processing is based on consent, you may withdraw it at any time with effect for the future, in the App's settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6. Where the data comes from
We receive personal data:
- directly from you — when you sign in, upload a video, adjust settings or contact us;
- from your device — technical and diagnostic data generated by the App and by iOS;
- from Apple — subscription lifecycle events reported through the App Store;
- from our service providers — subscription status from RevenueCat, job results from our AI providers.
7. Is provision of data mandatory?
The technical identifiers in section 4.1 are required to perform the contract: without them we cannot provide the App, meter your credits or restore your purchases. They are generated automatically — you do not have to provide any contact details such as your name or e-mail address.
Providing content data (section 4.3) is voluntary in the sense that you decide which video, if any, to upload — but without a video no music can be generated.
Analytics and diagnostics (sections 4.6 and 4.7) are entirely optional. Declining or later withdrawing consent has no effect on your ability to use the App.
8. Recipients and processors
We use the following service providers. Those marked as processors act on our documented instructions under a data processing agreement pursuant to Art. 28 GDPR.
| Provider | Role | What it receives | Processing location | Transfer safeguard |
|---|---|---|---|---|
| Google Ireland Limited / Google LLC — Firebase (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, App Check, Remote Config) | Processor | Account data, content data, usage and quota data, technical data | Firestore, Cloud Storage and Cloud Functions are configured for the europe-west3 (Frankfurt, Germany) region. Some administrative and support processing may take place in the USA. |
Google's Cloud Data Processing Addendum incl. EU Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC |
| Google Ireland Limited / Google LLC — Gemini API (video analysis) | Processor | The uploaded video and the analysis prompt; the returned analysis | Google infrastructure; processing may take place outside the EU/EEA, including in the USA | Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC |
| Google Ireland Limited / Google LLC — Google Analytics for Firebase | Processor | Analytics events, App-instance identifier, coarse device and country data | Google infrastructure incl. the USA | Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC — used only with your consent |
| Google Ireland Limited / Google LLC — Firebase Crashlytics | Processor | Crash reports and stack traces, device model, OS and App version, App-instance identifier | Google infrastructure incl. the USA | Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC — used only with your consent |
| WaveSpeedAI PTE. LTD., 3 Phillip Street #10-04, Royal Group Building, Singapore 048693 | Processor | The generated text music prompt and model parameters; returns the audio track. No video and no account identifier of yours is transmitted. | Singapore / USA | [Art. 28 data processing agreement and EU Standard Contractual Clauses — to be concluded / confirmed] |
| Mureka (Kunlun Tech / Skywork AI) — music generation model, reached through WaveSpeedAI | Sub-processor | The text music prompt only | Outside the EU/EEA | Contractual chain through WaveSpeedAI — [to be confirmed] |
| RevenueCat, Inc., 633 Taraval St., Suite 101, San Francisco, CA 94116, USA | Processor | Your UID, subscription and entitlement events, country/storefront, device platform | USA | RevenueCat Data Processing Addendum incl. EU Standard Contractual Clauses |
| Apple Inc. / Apple Distribution International Ltd. | Independent controller | Purchase, payment and App Store account data; Sign-in-with-Apple data | Ireland / USA | Apple's own privacy policy applies to Apple's own processing |
| Alfahosting GmbH, Halle (Saale), Germany — hosting of our self-hosted analytics server | Processor / our own infrastructure | Aggregated, non-identifying usage counts (see section 9) | Germany | Not applicable — processing within the EU |
| Professional advisers (tax adviser, lawyer), where required | Recipient | Billing and contract data as necessary | EU | Statutory confidentiality obligations |
We do not sell personal data, and we do not disclose it to third parties for their own marketing purposes.
We may disclose personal data to public authorities or courts where we are legally obliged to do so, or where disclosure is necessary to establish, exercise or defend legal claims.
9. Analytics in detail
First-party (self-hosted) analytics. We operate our own analytics service on a server rented in [EU LOCATION]. It records anonymous, aggregated usage counts — for example how often a generation was started or how often an error screen was shown. These records contain no account identifier, no IP address in stored form and no device identifier, and cannot be linked back to you by us. Because the data is anonymous once stored, GDPR does not apply to the stored records; the transmission itself and any access to information on your device take place only after you have consented.
Google Analytics for Firebase. With your consent we additionally use Google Analytics for Firebase, which assigns your installation a randomly generated App-instance identifier and transmits event data to Google. This identifier is pseudonymous, is reset when you delete and reinstall the App, and can be reset by you at any time in the App's settings. We do not enable the advertising-identifier (IDFA) integration and we do not link analytics data to advertising networks. Analytics data retention in Google's systems is configured to 2 months.
Consent. Both components are switched off by default. They are activated only after you give consent in the App and can be switched off again at any time in the App's settings, with effect for the future.
App Tracking Transparency. We do not track you across apps or websites owned by other companies. Accordingly, the App does not present Apple's App Tracking Transparency prompt.
10. International data transfers
Some of our processors process data outside the European Economic Area, in particular in the United States and Singapore.
- For transfers to Google LLC we rely on Google's participation in the EU–US Data Privacy Framework and, in addition, on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), supplemented by the technical and organisational measures described in Google's Cloud Data Processing Addendum.
- For transfers to RevenueCat, Inc. we rely on the Standard Contractual Clauses contained in RevenueCat's Data Processing Addendum [and, where applicable, on its Data Privacy Framework certification].
- Singapore is not covered by an EU adequacy decision. Transfers to WaveSpeedAI PTE. LTD. are therefore made on the basis of the Standard Contractual Clauses together with a transfer impact assessment [status: to be confirmed]. Only the generated text prompt is transmitted — no video, no account identifier and no contact details.
You can request a copy of the relevant safeguards from us at the address in section 1.
Transfers to a third country always carry a residual risk that the level of protection is not equivalent to that in the EU, in particular because of possible access by local authorities and because enforcing your rights may be more difficult.
11. Retention periods
| Data | Retention |
|---|---|
| Uploaded video file (4.3) | Deleted automatically as soon as the analysis has completed or failed — typically within a minute of upload — and in any event no later than 24 hours after upload, by an automatic storage lifecycle rule. The working copy held by the Gemini API for the duration of the analysis is deleted in the same step, rather than being left to that service's own 48-hour expiry |
| Analysis text and generated prompts (4.3) | Stored with the job record for 14 days, then deleted |
| Generated audio track on our servers (4.3) | Deleted as soon as the App confirms the track has been saved to your device, and in any event no later than 14 days after generation, by an automatic storage lifecycle rule. The copy on your device remains under your control |
| Job records and error states (4.4) | Deleted immediately after the job has been processed; error states no later than 14 days after the job |
| Usage ledger (4.4) | Until the installation identity is deleted (see next row); anonymised aggregates may be retained longer |
| Installation identity, credit balance and all associated records (4.1, 4.4) | Deleted after twelve (12) months of inactivity, together with all other data linked to the installation identity. Separately purchased credit packs expire twelve (12) months after purchase |
| Subscription and entitlement records (4.2) | For the duration of the entitlement, then as required by statutory retention obligations |
| Invoicing and accounting records | 10 years pursuant to § 147 AO and § 257 HGB. During this period processing is restricted to that purpose |
| Server and security logs (4.5) | 14 days, unless a longer period is needed to investigate a specific security incident |
| Analytics data (4.6) | Self-hosted: anonymous aggregates, no defined deletion point. Google Analytics for Firebase: 2 months |
| Crash and diagnostic data (4.7) | 14 days |
| Support correspondence (4.8) | 3 years from the end of the year in which the matter was concluded (statutory limitation period, § 195 BGB) |
Where deletion is not possible because of a statutory retention obligation, we restrict processing instead (Art. 18 GDPR) and delete the data at the end of the retention period.
12. Videos containing other people
If the video you upload shows or is audible of other identifiable people, you are responsible for having a legal basis for their personal data being processed — normally their consent, or another basis under Art. 6 GDPR. In relation to that content you act as the controller and we act as your processor for the purposes of the generation job; the corresponding terms are set out in [Annex [X] of our Terms and Conditions / our separate Data Processing Agreement for business users].
We ask you not to upload footage of other people without their knowledge, and not to upload footage of children, of medical or other sensitive situations, or of documents containing personal data.
Because your video is passed to our AI providers, it leaves our systems. Please take this into account when deciding what to upload.
13. AI-specific disclosures
Your content is not used to train AI models. We do not train models on your videos, prompts or generated tracks, and we have contractually excluded such use by our providers to the extent they permit it:
- Our Google Gemini API usage runs on a billing-enabled (paid) project. Under Google's Gemini API logging policy, prompts and responses on paid projects are not used to develop or improve Google's products or models by default; we have not opted into any data-sharing programme. Google retains limited logs for a defined period for abuse detection.
- Our agreement with the music-generation provider prohibits the use of our inputs and outputs for model training.
Abuse monitoring. Our AI providers may inspect inputs and outputs to detect breaches of their content policies. This can include limited human review by the provider. We have no control over the timing of such review.
Automated decision-making. The AI analysis of your video and the resulting music are an automated process, but they do not produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22(1) GDPR. Automated checks may block a generation request that appears to breach content rules or exceeds your quota; you can always contact us to have such a decision reviewed by a human.
AI transparency. Tracks produced with the App are generated by artificial intelligence. Depending on the model used, outputs may carry a machine-readable watermark. Your obligations regarding the labelling of AI-generated content — including under Art. 50 of the EU AI Act (Regulation (EU) 2024/1689) and the rules of the platform you publish on — are set out in our Terms and Conditions.
14. Security
We apply technical and organisational measures appropriate to the risk in accordance with Art. 32 GDPR, including:
- transport encryption (TLS) for all connections between the App, our backend and our providers;
- encryption at rest for stored files and database contents on our cloud infrastructure;
- authentication of requests via pseudonymous identifiers and short-lived tokens; app attestation via Apple App Attest to reject requests from tampered or emulated clients;
- database access rules that allow each account to read only its own records, and that prohibit clients from writing quota or billing data entirely;
- API credentials held in a managed secret store, never in the App itself;
- data minimisation in the generation pipeline — the video is sent only to the analysis provider, never to the music provider, and is deleted immediately after processing;
- least-privilege administrative access and logging of administrative actions.
No system can be guaranteed to be completely secure. Please notify us immediately at the address in section 1 if you believe your account has been compromised.
15. Your rights
Under the GDPR you have the following rights in relation to your personal data:
- Right of access (Art. 15) — to obtain confirmation whether we process your data and a copy of it, together with the information set out in Art. 15(1) and (2).
- Right to rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
- Right to erasure (Art. 17) — to have your data deleted where one of the grounds in Art. 17(1) applies. See "Deletion" below.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — to receive the data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to object (Art. 21) — to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) or (f) GDPR. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
- Right to withdraw consent (Art. 7(3)) — at any time, with effect for the future.
- Right to lodge a complaint (Art. 77) — with a supervisory authority, in particular in the Member State of your habitual residence, place of work or of the alleged infringement. The authority competent for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59–61, 10555 Berlin, Germany https://www.datenschutz-berlin.de
How to exercise your rights. Write to apps@romankoch.online. We will respond without undue delay and in any event within one month of receipt, extendable by two further months where necessary (Art. 12(3) GDPR). We may ask you for information to verify your identity — normally proof of control over the e-mail address linked to your account. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive (Art. 12(5) GDPR).
Deletion. The App does not use user accounts. Your server-side data (installation identity, credit balance, job records) is deleted automatically after twelve (12) months of inactivity, and you can request earlier deletion at any time by writing to apps@romankoch.online. Deleting the App from your device removes all locally stored content, including the installation identifier itself; any remaining server-side credit balance then becomes unlinkable to you and is deleted after twelve (12) months of inactivity at the latest. Please note that this does not cancel an App Store subscription — you must cancel that in your Apple Account settings — and does not affect data we are legally required to retain (section 11).
16. Children
The App is not directed at children. You must be at least 18 years old to use it; if the law of your country of residence sets a higher age for the validity of consent or the conclusion of contracts, that higher age applies. We do not knowingly process the personal data of children below that age. If you believe a child has provided us with personal data, please contact us and we will delete it without undue delay.
17. Information stored on your device
The App stores information on your device that is strictly necessary to provide the service you have requested, and may therefore be stored without consent pursuant to § 25(2) no. 2 TDDDG:
- your pseudonymous installation identifier and authentication token;
- your local settings and your local history of previous generations;
- temporary working copies of your video and of the generated audio.
Information stored or read for analytics and diagnostics purposes is not strictly necessary and is stored only with your consent under § 25(1) TDDDG (see section 9).
The App does not use browser cookies. It does not use the Apple Advertising Identifier and does not participate in cross-app tracking.
18. Additional information for residents of the United States
This section supplements the above for residents of California and of other US states with comparable privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, Texas).
Categories of personal information collected in the last 12 months: identifiers (account ID, e-mail address, device identifiers); commercial information (subscription and purchase history); internet or other electronic network activity (usage and analytics events); audio, electronic or visual information (the videos you upload and the audio generated from them); inferences drawn for the purpose of generating music (mood and style attributes derived from your video). Sources, purposes and recipients are those described in sections 4, 5 and 8.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA/CPRA. We have not sold or shared personal information of consumers, including minors under 16 years of age, in the preceding 12 months.
Your rights include the right to know, to access, to delete, to correct and to opt out of sale or sharing (not applicable, as we do neither), and the right not to be discriminated against for exercising them. To exercise them, contact us at apps@romankoch.online. You may use an authorised agent; we will require proof of authorisation. We do not use or disclose sensitive personal information for purposes other than those permitted under the CCPA, so no right to limit its use applies.
Retention: as set out in section 11.
19. Apple App Store privacy information
Apple requires us to publish a summary of our data practices ("privacy nutrition labels") on the App's App Store product page. That summary is a simplified representation prepared according to Apple's categories; this privacy policy is the authoritative and complete description. If the two ever appear to conflict, this policy governs and we will correct the App Store entry.
20. Changes to this privacy policy
We may update this policy to reflect changes in the App, in our service providers or in the law. The current version is always available in the App under Settings → Privacy Policy and at https://privacy.reelmusic.app. If a change is material — for example a new category of data, a new purpose or a new third-country recipient — we will notify you in the App before it takes effect (we do not hold your e-mail address). Where the change requires your consent, we will ask for it.
Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 14.08.2026 | Initial version |