Amadeo · Legal
Privacy Policy
Version: 8 October 2026 · App and website
Contents
1. Which information applies to you
This notice covers our website and the Amadeo app. If you only visit this website, the sections about website delivery, any contact you make and your privacy rights apply to you. Visiting does not create an Amadeo account or record learning progress. Information about piano input, accounts, purchases and error reports applies when you use the relevant app feature.
Amadeo is not yet publicly available in the App Store. This website introduces the planned product; it offers no ordering, reservations or waiting-list registration.
2. Controller and contact
The controller is Brandenburger Digital Systems UG (haftungsbeschränkt), Ströherstraße 20, 35683 Dillenburg, Germany, represented by managing director Dennis Brandenburger. For privacy questions and requests concerning your rights, contact info@amadeo-piano.com. Further company information is in our legal notice.
3. Piano input and local data
Microphone analysis for recognising piano notes runs on your device. Amadeo does not transmit the microphone recording to us, a cloud AI service or another provider. Musical events received through MIDI are also processed locally. These signals are not used to identify you.
To replay a practice run, the app may create a temporary local audio file. It is removed when you close the report; following an unexpected interruption, cleanup takes place on the next app launch. The recording is not synced with your account.
Without an account, progress, practice records and settings are stored locally. Support, voice downloads or configured error diagnostics can still involve the transmissions described below. Using the app without an account does not mean that no connection to a service provider ever takes place.
The requested learning functionality and necessary local storage serve the contract (GDPR Article 6(1)(b); section 25(2)(2) TDDDG). You grant and withdraw microphone permission in your device settings. That system permission is not consent to unrelated analytics.
4. Optional account and synchronisation
You can use an Amadeo account through Sign in with Apple. We process the identifier Apple provides, any shared name and email address, including an Apple relay address, and an internal account ID. We do not receive your Apple password.
For the backup and synchronisation you request, Supabase stores progress in pieces and Gym exercises, practice and review records, added pieces, XP and streaks, and syncable settings such as language and theme. Local device selections and system permissions are not transferred to other devices. The basis is GDPR Article 6(1)(b).
The configured backend region is Frankfurt am Main. Apple also processes sign-in data as an independent controller under its privacy policy. An account is not required for basic local use; account-dependent features are unavailable without one.
5. Support and administration
When you contact us, we process your message and supplied contact details to respond. In-app support also involves the category, app version, platform, language, timestamps, handling status and, where signed in, your account association. Conversation history, replies and read status support follow-up. An optional reply address is not automatically taken from your Apple sign-in.
Your account-bound conversation is available to you and explicitly authorised staff; internal status records support case handling. Administration also uses aggregate account, support and purchase figures. It does not provide a public user directory or personal advertising profiles. Please do not include passwords or payment details in support messages.
The basis is GDPR Article 6(1)(b) for contract-related requests, otherwise Article 6(1)(f) for responding to enquiries and operating the service securely and traceably. Email enquiries involve the mail providers concerned; our domain routes incoming email through IONOS SE.
6. Purchases and access rights
For App Store purchases, Apple processes payment. We do not receive card or bank details. To provide purchased access, we process product and transaction identifiers, store, purchase, expiry, renewal and refund information, trial or paid status, and the association with your Amadeo account. Apple, RevenueCat and our Supabase backend are involved.
The basis is performance of the contract (GDPR Article 6(1)(b)) and, where necessary to prevent abuse, our legitimate interest in correct ownership assignment (Article 6(1)(f)). Authorised administrators also see aggregate account, purchase and subscription figures, such as changes in active subscriptions. These use existing contract records; they do not create additional activity or advertising profiles. Apple is independently responsible for its Store and payment processing.
7. Technical error diagnostics
Technical error reporting is optional and off by default. If you enable it in Settings, collection starts at the next app launch. Sentry then receives error type, technical stack trace, app version, operating-system and device information. Free-form error messages are removed before transmission. Reports include neither microphone recordings nor your Amadeo account ID. Automatic session counting, interaction logs, screenshots and session replay are disabled.
We use Sentry to fix faults on the basis of your consent (GDPR Article 6(1)(a) and, where applicable, section 25(1) TDDDG). You can practise without consenting and withdraw consent in Settings at any time for the future. Switching off stops further collection; reports already sent may remain until their retention period expires. Under the current plan, Sentry retains error events for 30 days. Permission applies only to this device. The app stores the notice version, decision and time locally outside device backups. Before consenting, you confirm that you are at least 18.
8. Analytics and advertising
Amadeo has no advertising and uses no advertising identifier. PostHog usage analytics is disabled in the release described here. No usage events are sent to PostHog. Operational statistics derived from existing account and contract records are described in the purchases section.
If we introduce optional usage analytics later, we will first explain its purpose, data, provider and retention, and obtain separate consent. Consent to error reports or acknowledgement of this notice does not enable usage analytics.
9. Voice clips, reminders and widget
Musical content is bundled with the app. Some coach voice clips are downloaded from versioned Supabase storage and cached locally. Delivery infrastructure necessarily processes connection data such as IP address, time and requested file. No recording of your playing is uploaded. The purpose is the requested delivery, based on GDPR Article 6(1)(b), with Article 6(1)(f) for necessary security logs.
The coach character, text and synthetic voice are prepared learning content, not an open-ended AI chat. Your learning or support data is not sent to a speech generator to create the voice.
Practice reminders are scheduled locally and controlled in app and device settings. The widget reads a local progress summary from shared app storage; it does not send it to a widget service. Storage supports the features you choose.
10. Website and external links
Our website provides information about Amadeo. It offers a contact form, but no user account or direct checkout. Fonts, images, videos and the Amadeus animation are served with the website. We embed no advertising pixels, social feeds or external analytics scripts. Data from your Amadeo account is not transferred to the website.
To provide the website through ChatGPT Sites, OpenAI Ireland Ltd processes connection data, including IP address, time, requested address and technical browser information, to deliver and secure the website. The basis for our operation is GDPR Article 6(1)(f): providing accessible, secure product and legal information. Strictly necessary device access, where required, falls under section 25(2) TDDDG. Non-essential analytics or advertising technologies require separate prior consent.
ChatGPT Sites currently does not promise exclusively European processing. The Sites data processing addendum and subprocessor list explain processing and international transfers. The Sites agreement also covers technical usage and log data. For transfers from the European Economic Area, it provides for standard contractual clauses or an applicable adequacy decision. You can request a copy of the relevant safeguards from us. The website does not require a ChatGPT account.
External links, for example to the App Store or a supervisory authority, connect to the destination when opened. The destination provider’s notice applies there. Email links open your mail app; you send the message yourself. Social networks operate their own in-app browsers.
The hosting infrastructure uses Cloudflare to protect against automated attacks. It may set the technical __cf_bm cookie. This contains encrypted information used to distinguish legitimate requests from harmful bots and expires after 30 minutes of inactivity. It is not used for our advertising or cross-site usage analytics. We use this protection to deliver the website securely (GDPR Article 6(1)(f); section 25(2)(2) TDDDG for necessary device access). See Cloudflare’s cookie documentation. We do not set optional analytics or advertising cookies of our own.
11. Website contact form
When you submit the contact form, we store your email address, message, selected language, receipt time and handling status in our Supabase project in Frankfurt. No account is needed and your request is not linked to an app account. Only explicitly authorised administration can read it. We reply from our business mailbox; your address and our reply are also processed by our mail provider IONOS.
The basis is GDPR Article 6(1)(b) for contract-related requests and otherwise Article 6(1)(f) for responding to enquiries. To prevent abuse, we limit submissions using daily changing, secret-key-protected email digests and bounded counters, without storing an additional IP address list. These protection records are deleted within three days. This does not affect the hosting providers’ technical connection logs.
Completed website requests are removed by daily cleanup 30 days after closure; all website requests are removed by daily cleanup after 180 days. You may request access or earlier deletion through our contact address. Since they are not linked to an app account, these requests are not automatically erased when an app account is deleted. The retention criteria below apply to separate email correspondence and records subject to legal retention duties.
12. Recipients and international processing
Depending on the feature used, recipients include Supabase Pte. Ltd (Singapore) for account, sync, support and voice files; Functional Software, Inc. (Sentry) when error reporting is enabled; RevenueCat, Inc. for purchase management; Apple for sign-in and Store transactions; and OpenAI Ireland Ltd for website hosting. Email enquiries also involve the mail providers concerned; incoming mail for our domain is routed through IONOS SE. Website delivery is technically separate from account and learning data.
The app uses EU endpoints for Supabase (Frankfurt) and Sentry. An EU location does not exclude access from other countries, particularly the US and Singapore. Processing on our behalf is subject to agreements under GDPR Article 28. International transfers require the conditions of Articles 44 onwards, including an applicable adequacy decision or standard contractual clauses with necessary supplementary safeguards. You can request details and a copy of the safeguards applicable to your data through the contact above. Apple’s processing for sign-in, the Store and TestFlight is additionally explained in Apple’s privacy policy.
13. Retention and deletion
- Local progress: until you reset it in the app or remove app data. Device or operating-system backups are managed separately with the relevant provider.
- Account and synced data: for the account’s lifetime. You can request deletion in the app. The request may remain pending while involved services process it; the app confirms completion only after successful processing.
- In-app support: closed cases, replies and status records are removed by the daily cleanup process 180 days after their last update. Account deletion removes associated cases earlier. Open cases remain necessary while being handled.
- Technical evidence: acknowledged deletion-completion receipts expire after 30 days; unacknowledged recovery capabilities remain until acknowledgement. Residual Apple notification verification digests have a 181-day period. Ownerless refund markers become eligible for removal after 35 days if no matching transaction remains. These limited recovery and replay-protection records are distinct from the deleted learning profile.
- Error reports: Sentry error events are retained for 30 days.
- Email, infrastructure logs and backups: retention depends on handling the request, service security and the provider’s deletion cycle. Where a particular record is needed to comply with a statutory retention duty or establish, exercise or defend a legal claim, processing is restricted to that purpose. We do not use such retention to keep an active learning profile.
Objection or withdrawal does not automatically remove statutory retention duties. Data still needed for a specific legal claim is restricted to that purpose. Deletion from active systems and expiration of protected backup copies are separate processes. A recovered backup must not restore a deleted account to ordinary use.
14. Your rights
Subject to the legal conditions, you have rights of access, rectification, erasure, restriction and portability (GDPR Articles 15–20). You can withdraw consent for the future without affecting the lawfulness of earlier processing.
For processing based on legitimate interests, you may object on grounds relating to your particular situation (Article 21). We stop the relevant processing unless compelling legitimate grounds or necessary legal claims prevail.
Contact the address above. We verify identity only as necessary and normally respond within one month; any legally permitted extension is explained within that period. Export and account deletion are also available in the app. A local export while signed out is not a complete copy of the server account. Deleting an account does not cancel a Store subscription; cancel it separately through the Store.
You may complain to a supervisory authority, particularly where you live or work. Our competent authority is the Hessian Commissioner for Data Protection and Freedom of Information.
15. Minors and automated assessment
At launch, Amadeo is intended for adult learners. We do not offer child accounts or parent–child account management. An app store age rating is different: it assesses content and does not replace legal capacity or any required consent. If you believe a child has provided personal data to us without authorisation, please contact us so we can investigate.
Practice feedback is generated automatically from played pitches and timing. It supports learning and does not make decisions with legal or similarly significant effects under GDPR Article 22. No biometric identification takes place.
16. Changes to this notice
We update this notice when processing changes and inform you in good time of material changes. A revised notice does not replace consent where a new purpose requires it. The date at the beginning identifies the version.