Privacy Policy — ClipMusic
How the ClipMusic iOS application and the clipmusic.app website process your personal data.
Last updated: 25 September 2026 · Version 1.1
1. Controller and contact details
The controller responsible for the processing of your personal data within the meaning of Art. 4(7) GDPR is:
Mapionix UG (haftungsbeschränkt)
Lisa-Weinert-Straße 9
31079 Sibbesse
Germany
Represented by the managing director: Peter Helmut Baumann
Commercial register: Amtsgericht Hildesheim, HRB 210361
E-mail: contact@clipmusic.app
Website: https://clipmusic.app
Data protection officer. We have not appointed a data protection officer. We are not required to do so under Art. 37 GDPR or § 38 BDSG, because we do not employ the number of persons that triggers that obligation and our core activity does not consist of large-scale processing of special categories of data or of regular and systematic monitoring of data subjects on a large scale. You may address all data protection enquiries to the contact above.
EU representative. Not applicable — the controller is established in the European Union.
2. Scope and purpose of this policy
This policy explains what personal data we process when you use:
- the ClipMusic iOS application (the "App"); and
- our website at clipmusic.app, including the legal pages hosted there.
It explains why we process that data, on what legal basis, who receives it, how long we keep it and what rights you have.
Most of this policy describes the App, because that is where the substantial processing happens. Processing that is specific to the website is set out in section 18. Sections 1, 5, 8, 10, 11, 15 and 19 to 21 apply to both.
It does not apply to:
- the App Store and your Apple Account, which are operated by Apple and governed by Apple's privacy policy;
- third-party platforms (e.g. Instagram, TikTok, YouTube) to which you may later upload a video you created with the App;
- third-party websites we link to. Once you follow such a link, the operator of that site is responsible for its processing.
Capitalised terms not defined here have the meaning given to them in our Terms and Conditions.
3. How ClipMusic works — a short data-flow summary
We explain the processing before listing it formally, because the App's core function involves sending content derived from your video to third-party AI services.
- On first launch, the App creates a pseudonymous installation identifier for your installation. There is no registration and no sign-in — we do not ask for your name, e-mail address or any other contact details.
- You select a video from your photo library. The App extracts a small number of still frames on your device and scales them down to at most 768 pixels on the longest side. The full video file and its audio track are not uploaded.
- The extracted frames, together with the genre you selected and any style text you entered, are sent to our backend (Google Firebase, EU region).
- Our backend sends the frames and your style input to Google's Gemini API, which analyses mood, scene and pacing and returns a set of music suggestions (genre, tempo, instrumentation, mood and similar attributes).
- After you choose a suggestion, our backend sends the resulting text prompt — not the frames and not the video — together with the desired track length and your vocals setting to ElevenLabs, which returns a generated audio track.
- The generated track is delivered to the App. Previewing and combining ("muxing") the track with your video happens on your device. The finished video is saved to your photo library and is never uploaded to us.
- Frames, analysis results and the generated track are not stored on our servers. They are only passed through for the duration of the request (see section 11).
The remainder of this policy describes each step in the terms required by Arts. 13 and 14 GDPR.
4. Categories of personal data we process
4.1 Installation and identity data
The App works without registration or sign-in. We do not collect your name, e-mail address or other contact details. To provide the service we process:
- the pseudonymous installation identifier created on first launch, used as the key for your music-minute balance and, transiently, for your analysis and generation jobs;
- the corresponding pseudonymous app user ID used by our subscription-management provider;
- the App Store app-transaction identifier, used to link your music-minute balance to your purchase so that it survives reinstalling the App.
This technical identity is mandatory — without it we cannot meter your music minutes, restore purchases or deliver generated tracks (see section 7).
4.2 Subscription, purchase and billing data
- entitlement status (active / trial / expired / grace period), product identifier (Basic, Pro, Musikminuten top-up), purchase and renewal dates, cancellation and refund events;
- a pseudonymous customer record that links your installation identifier to your subscription state;
- your country/storefront and currency as reported by the App Store.
We never receive or store your payment card details, bank details or billing address. Payment is processed exclusively by Apple through the App Store. Apple acts as an independent controller for that payment relationship.
4.3 Content data (frames from your video and everything derived from them)
- the still frames extracted on your device from the video you select, and the video's duration;
- the genre you select, any custom genre or style text you enter, and your vocals setting (no vocals / female / male);
- the music suggestions and analysis the AI produces from the frames (for example genre, subgenre, tempo, mood, energy level, instrumentation, tags and a short scene description);
- the text prompt sent to the music-generation service;
- the generated audio track.
The full video file, its original audio track and the finished video are not transmitted to us or to our AI providers.
Frames from your video may contain personal data of yourself and of other people — faces, bodies, licence plates, house numbers, on-screen text, screen contents, location cues. Please read section 12 before selecting footage that shows other people.
4.4 Usage and quota data
- your music-minute balance and the minutes used and remaining in the current billing period;
- the track length of each generation, used to deduct minutes from your balance.
4.5 Device, technical and security data
- device model, operating system version, App version and build, language and region settings;
- a device attestation token generated via Firebase App Check (using Apple's App Attest), which proves that requests come from a genuine, unmodified copy of our App;
- IP address and server log data associated with your requests, including timestamps and the endpoint called;
- rate-limiting counters used to protect the service against abuse.
4.6 Diagnostic data
The App keeps a technical diagnostic log on your device ("Protokoll"), for example error messages and the status of analysis, generation and export steps. This log stays on your device. It only reaches us if you choose to export it and send it to us, for example together with feedback.
4.7 Support communications and feedback
- your e-mail address and the content of any message or feedback you send us, including any attachments such as an exported diagnostic log, and our correspondence with you;
- if you use the contact form on our website: your name, your e-mail address, your message and the language version of the page you used (see section 18.6).
4.8 Special categories of data
We do not intentionally process special categories of personal data within the meaning of Art. 9 GDPR. However, frames from your video may incidentally reveal such information (for example health-related, religious or political content, or images of faces). We do not analyse frames for the purpose of identifying individuals, we do not run facial recognition, and we do not derive or store any biometric template. Where such content is present, it is processed only incidentally and transiently as part of the analysis and is not stored by us (see section 11). Please do not select footage whose content you would not want processed by our AI service providers.
5. Purposes of processing and legal bases
| # | Purpose | Data categories | Legal basis |
|---|---|---|---|
| 1 | Creating and managing your pseudonymous installation identity; authenticating requests | 4.1 | Art. 6(1)(b) GDPR — performance of the contract |
| 2 | Providing the core service: analysing frames from your video, suggesting music, generating a track and delivering it to your device | 4.1, 4.3, 4.4 | Art. 6(1)(b) GDPR — performance of the contract |
| 3 | Managing subscriptions, trials, top-up purchases, entitlements and restoring purchases | 4.1, 4.2 | Art. 6(1)(b) GDPR |
| 4 | Metering your music minutes | 4.1, 4.4 | Art. 6(1)(b) GDPR |
| 5 | Preventing abuse of the free trial, of our quota system and of our AI service budget (rate limiting, verifying that requests come from a genuine copy of the App) | 4.1, 4.4, 4.5 | Art. 6(1)(f) GDPR — legitimate interest in protecting the service against fraud and cost abuse |
| 6 | Ensuring the security, integrity and availability of our systems; investigating faults; server logging | 4.5 | Art. 6(1)(f) GDPR — legitimate interest in operating a secure service; Art. 32 GDPR |
| 7 | Enforcing the content restrictions in our Terms and the content policies of our AI providers | 4.3, 4.4 | Art. 6(1)(f) GDPR — legitimate interest in lawful operation; Art. 6(1)(c) GDPR where a legal obligation applies |
| 8 | Responding to your support requests and feedback, including a diagnostic log you choose to send and messages sent through the website contact form | 4.1, 4.6, 4.7 | Art. 6(1)(b) GDPR where the request concerns the contract; otherwise Art. 6(1)(f) GDPR |
| 9 | Complying with statutory retention, tax and accounting obligations | 4.2 | Art. 6(1)(c) GDPR — legal obligation (§ 147 AO, § 257 HGB) |
| 10 | Delivering our website, keeping it available and secure, and investigating faults and attacks (server log files); protecting the contact form against spam and abuse | 18.1, 18.6 | Art. 6(1)(f) GDPR — legitimate interest in operating a secure website |
| 11 | Loading web fonts from Google Fonts on our website | 18.3 | Art. 6(1)(a) GDPR — your consent; § 25(1) TDDDG |
| 12 | Establishing, exercising or defending legal claims | any of the above | Art. 6(1)(f) GDPR; Art. 9(2)(f) GDPR where special categories are involved |
Balancing test (Art. 6(1)(f)). Where we rely on legitimate interests, we have weighed our interests against your rights and freedoms. The processing is limited to what is necessary, uses pseudonymous identifiers rather than directly identifying data wherever possible, and does not involve profiling for advertising. You may object at any time under Art. 21 GDPR (see section 15). A summary of the balancing test is available on request.
6. Where the data comes from
We receive personal data:
- directly from you — when you select a video, choose a genre or enter style text, choose a suggestion or contact us;
- from your device — technical data generated by the App and by iOS;
- from Apple — subscription lifecycle events reported through the App Store;
- from our service providers — subscription status from RevenueCat, analysis results from Google and generated tracks from ElevenLabs.
7. Is provision of data mandatory?
The technical identifiers in section 4.1 are required to perform the contract: without them we cannot provide the App, meter your music minutes or restore your purchases. They are generated automatically — you do not have to provide any contact details.
Providing content data (section 4.3) is voluntary in the sense that you decide which video, if any, to use — but without frames from a video no music can be suggested or generated.
Sending us your diagnostic log (section 4.6) is entirely optional.
8. Recipients and processors
We use the following service providers. Those marked as processors act on our documented instructions under a data processing agreement pursuant to Art. 28 GDPR.
| Provider | Role | What it receives | Processing location | Transfer safeguard |
|---|---|---|---|---|
| Google Ireland Limited / Google LLC — Firebase (backend: authentication, database, cloud functions, App Check) | Processor | Installation identity, content data (frames, prompts, generated track in transit), usage and quota data, technical data | Configured for an EU region. Some administrative and support processing may take place in the USA. | Google's Cloud Data Processing Addendum incl. EU Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC |
| Google Ireland Limited / Google LLC — Gemini API (analysis of video frames) | Processor | The extracted frames, your genre and style input and the analysis prompt; returns the music suggestions | Google infrastructure; processing may take place outside the EU/EEA, including in the USA | Standard Contractual Clauses; EU–US Data Privacy Framework certification of Google LLC |
| Eleven Labs Poland sp. z o.o., Lipska 27/22, 03-908 Warsaw, Poland, and Eleven Labs Inc., 169 Madison Ave #2484, New York, NY 10016, USA — ElevenLabs Music API (music generation) | Processor | The text music prompt, track length and vocals setting; returns the audio track. No frames, no video and no identifier of yours are transmitted. | USA (storage); processing also in the Netherlands and Singapore | ElevenLabs Data Processing Addendum incl. EU Standard Contractual Clauses; EU–US Data Privacy Framework certification of Eleven Labs Inc. |
| RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA | Processor | Your pseudonymous app user ID, subscription and purchase events, country/storefront, device platform | USA | RevenueCat Data Processing Addendum incl. EU Standard Contractual Clauses |
| Apple Inc. / Apple Distribution International Ltd. | Independent controller | Purchase, payment and App Store account data | Ireland / USA | Apple's own privacy policy applies to Apple's own processing |
| ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany — hosting of clipmusic.app and of our e-mail | Processor | Server log data for the website: IP address, timestamp, page requested, status code, referrer, browser and operating system. Messages from the contact form and e-mails you send us, which are stored in our mailbox. The temporary spam-protection counter (section 18.6) | Germany | Not applicable — processing within the EU. Art. 28 GDPR data processing agreement concluded |
| Google Ireland Limited / Google LLC — Google Fonts (web fonts on the website) | Independent controller for its own processing | Your IP address, browser and operating system, and the address of the page requesting the font | Google infrastructure incl. the USA | EU–US Data Privacy Framework certification of Google LLC; Standard Contractual Clauses — loaded only with your consent |
| Professional advisers (tax adviser, lawyer), where required | Recipient | Billing and contract data as necessary | EU | Statutory confidentiality obligations |
We do not sell personal data, and we do not disclose it to third parties for their own marketing purposes.
We may disclose personal data to public authorities or courts where we are legally obliged to do so, or where disclosure is necessary to establish, exercise or defend legal claims.
9. Analytics and diagnostics
This section concerns the App only. For the website, see section 18.4.
No analytics, no crash reporting. The App currently uses no analytics service and no crash-reporting service. No usage statistics or crash reports are transmitted from your device to us or to third parties.
Diagnostic log. The App keeps a technical log on your device to help investigate errors. It is not sent to us automatically. You can export it from the App and attach it to an e-mail to us; in that case we process it as part of your support request (section 4.7).
If we introduce analytics or crash reporting in the future, we will update this policy beforehand and activate such features only after you have given your consent in the App, where consent is required.
App Tracking Transparency. We do not track you across apps or websites owned by other companies. Accordingly, the App does not present Apple's App Tracking Transparency prompt.
10. International data transfers
Some of our processors process data outside the European Economic Area, in particular in the United States and Singapore.
- For transfers to Google LLC we rely on Google's participation in the EU–US Data Privacy Framework and, in addition, on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), supplemented by the technical and organisational measures described in Google's Cloud Data Processing Addendum.
- For transfers to RevenueCat, Inc. we rely on the Standard Contractual Clauses contained in RevenueCat's Data Processing Addendum.
- For transfers to ElevenLabs we rely on the EU–US Data Privacy Framework certification of Eleven Labs Inc. and, in addition, on the Standard Contractual Clauses contained in the ElevenLabs Data Processing Addendum. Transfers to Singapore, which is not covered by an EU adequacy decision, are covered by those Standard Contractual Clauses. Only the generated text prompt, the track length and your vocals setting are transmitted — no frames, no video, no identifier and no contact details.
You can request a copy of the relevant safeguards from us at the address in section 1.
Transfers to a third country always carry a residual risk that the level of protection is not equivalent to that in the EU, in particular because of possible access by local authorities and because enforcing your rights may be more difficult.
11. Retention periods
| Data | Retention |
|---|---|
| Extracted frames (4.3) | Not stored. Frames are passed through our backend to the analysis service in memory and discarded as soon as the request has completed. Temporary frames on your device are deleted when the workflow ends. Google may keep limited logs for abuse monitoring under its Gemini API terms |
| Analysis results and prompts (4.3) | Not stored on our servers; returned directly to the App |
| Generated audio track (4.3) | Not stored on our servers; forwarded directly to the App. The copy on your device remains under your control |
| Music-minute balance and usage data (4.1, 4.4) | As long as needed to provide the minutes and entitlements you purchased; deleted earlier on request (section 15), unless statutory retention applies |
| Subscription and entitlement records (4.2) | For the duration of the entitlement, then as required by statutory retention obligations |
| Invoicing and accounting records | 10 years pursuant to § 147 AO and § 257 HGB. During this period processing is restricted to that purpose |
| Server and security logs (4.5) | Standard Firebase / Google Cloud logs, retained for 30 days under Google Cloud Logging's default setting |
| Diagnostic log (4.6) | Stays on your device until you delete it or the App. A copy you send us is kept as support correspondence |
| Website server log files (18.1) | Stored by our hosting provider in line with its standard settings and our data processing agreement. We have no access to IP addresses in these logs |
| Contact form spam protection (18.6) | The one-way hash of your IP address and the message counter are deleted automatically after one hour |
| Support correspondence and feedback, including contact form messages (4.7) | 3 years from the end of the year in which the matter was concluded (statutory limitation period, § 195 BGB) |
Where deletion is not possible because of a statutory retention obligation, we restrict processing instead (Art. 18 GDPR) and delete the data at the end of the retention period.
12. Videos containing other people
You are solely responsible for the videos you select. If a video shows other identifiable people, you must have the right to use it — normally their consent.
We ask you not to use footage of other people without their knowledge, and not to use footage of children, of medical or other sensitive situations, or of documents containing personal data.
Because frames from your video are passed to our AI provider, they leave your device and our systems. Please take this into account when deciding which video to use.
13. AI-specific disclosures
We use two AI services: Google Gemini to analyse frames from your video and ElevenLabs to generate the music.
Your content is not used to train AI models. We do not train models on your frames, prompts or generated tracks, and we have excluded such use by our providers to the extent they permit it:
- Our Google Gemini API usage runs on a billing-enabled (paid) project. Under Google's Gemini API terms, prompts and responses on paid projects are not used to develop or improve Google's products or models; we have not opted into any data-sharing programme. Google retains limited logs for a defined period for abuse detection.
- We have opted out of ElevenLabs' use of our data for model training, so ElevenLabs does not use our inputs or outputs to train its models.
Abuse monitoring. Our AI providers may inspect inputs and outputs to detect breaches of their content policies. This can include limited human review by the provider. We have no control over the timing of such review.
Automated decision-making. The AI analysis and the resulting music are an automated process, but they do not produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22(1) GDPR. Automated checks may block a request that appears to breach content rules or exceeds your quota; you can always contact us to have such a decision reviewed by a human.
AI transparency. Tracks produced with the App are generated by artificial intelligence, including any vocals. Your obligations regarding the labelling of AI-generated content — including under Art. 50 of the EU AI Act (Regulation (EU) 2024/1689) and the rules of the platform you publish on — are set out in our Terms and Conditions. We make no statement in this policy about the licensing status of generated tracks or their acceptance by any platform.
14. Security
We apply technical and organisational measures appropriate to the risk in accordance with Art. 32 GDPR, including:
- transport encryption (TLS) for all connections between the App, our backend and our providers;
- encryption at rest for database contents on our cloud infrastructure;
- authentication of requests via pseudonymous installation identifiers and short-lived tokens; app attestation via Firebase App Check to reject requests from tampered or emulated clients;
- database access rules that allow each installation to read only its own records, and that prohibit clients from writing quota or billing data;
- API credentials held server-side in a managed secret store, never in the App itself;
- rate limiting to prevent abuse;
- data minimisation in the generation pipeline — only downscaled still frames leave your device, they are sent only to the analysis provider and never to the music provider, and they are never stored on our servers;
- least-privilege administrative access and logging of administrative actions.
No system can be guaranteed to be completely secure.
15. Your rights
Under the GDPR you have the following rights in relation to your personal data:
- Right of access (Art. 15) — to obtain confirmation whether we process your data and a copy of it, together with the information set out in Art. 15(1) and (2).
- Right to rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
- Right to erasure (Art. 17) — to have your data deleted where one of the grounds in Art. 17(1) applies. See "Deletion" below.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — to receive the data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to object (Art. 21) — to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) or (f) GDPR. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
- Right to withdraw consent (Art. 7(3)) — where processing is based on consent, at any time, with effect for the future.
- Right to lodge a complaint (Art. 77) — with a supervisory authority, in particular in the Member State of your habitual residence, place of work or of the alleged infringement. The authority competent for us is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
https://www.lfd.niedersachsen.de
How to exercise your rights. Write to contact@clipmusic.app. We will respond without undue delay and in any event within one month of receipt, extendable by two further months where necessary (Art. 12(3) GDPR). Because the App has no user accounts, we may be unable to link a request to your data without further information, such as an App Store order ID (Art. 11 GDPR). Exercising your rights is free of charge unless a request is manifestly unfounded or excessive (Art. 12(5) GDPR).
Deletion. The App does not use user accounts. Your server-side data (installation identity and music-minute balance) is kept only as long as needed to provide the minutes you purchased, and you can request deletion at any time by writing to contact@clipmusic.app. Deleting the App from your device removes all locally stored content, including the diagnostic log. Please note that this does not cancel an App Store subscription — you must cancel that in your Apple Account settings — and does not affect data we are legally required to retain (section 11).
16. Children
The App is not directed at children. You must be at least 16 years old to use it; if the law of your country of residence sets a higher age for the validity of consent or the conclusion of contracts, that higher age applies. We do not knowingly process the personal data of children below that age. If you believe a child has provided us with personal data, please contact us and we will delete it without undue delay.
17. Access to your photo library and information stored on your device
Photo library. The App asks for access to your photo library only when you tap the button to select a video, and uses it only to read the video you choose and to save the finished video back to your library. You can grant access to selected items only, and change or revoke access at any time in the iOS Settings. We do not scan or upload your library.
The App stores information on your device that is strictly necessary to provide the service you have requested, and may therefore be stored without consent pursuant to § 25(2) no. 2 TDDDG:
- your pseudonymous installation identifier and authentication token;
- your local settings;
- temporary working copies of extracted frames and of the generated audio, which are deleted when the workflow ends;
- the diagnostic log (section 9).
The App does not use browser cookies. It does not use the Apple Advertising Identifier and does not participate in cross-app tracking.
18. The ClipMusic website (clipmusic.app)
This section covers processing that happens when you visit our website at clipmusic.app, including the legal pages hosted there. The website is an information site: it has no user accounts, no sign-in and no shop. It is hosted by ALL-INKL.COM in Germany (see section 8).
18.1 Server log files
Each time a page or file is requested, your browser automatically transmits technical data, which our hosting provider processes in its server log files:
- your IP address;
- the date and time of the request;
- the page or file requested, and the volume of data transferred;
- the HTTP status code returned;
- the referring address, where your browser sends one;
- your browser type and version, and your operating system.
Purpose: delivering the page you asked for, keeping the site stable and available, and detecting and investigating faults and attacks. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure and functioning website. Retention: see section 11. We have no access to the IP addresses in these logs; they are processed only by our hosting provider on our behalf. We do not merge log data with other data, and we do not use it to identify you or to build a profile.
18.2 Cookies and information stored in your browser
The website sets one cookie: it stores the choice you make in the consent banner, so that the banner does not ask you again and your decision is respected on later visits. It contains no identifier, is not transmitted to third parties and cannot be used to recognise you. Storing it is strictly necessary to respect your choice and is therefore permitted without consent under § 25(2) no. 2 TDDDG. It remains until you delete it in your browser or change your choice.
The website sets no other cookies.
18.3 External services
Google Fonts. The website uses fonts provided by Google Ireland Limited / Google LLC (fonts.googleapis.com, fonts.gstatic.com). When a page loads, your browser connects to Google's servers to fetch the fonts. Google receives your IP address, browser and operating system details and the address of the page requesting the font, and may process this data in the USA. Legal basis: Art. 6(1)(a) GDPR — your consent — together with § 25(1) TDDDG. The fonts are loaded only after you have agreed in the consent banner; you can withdraw your consent at any time with effect for the future. Transfers to Google LLC are covered by its EU–US Data Privacy Framework certification and Standard Contractual Clauses. Further information: https://policies.google.com/privacy.
18.4 No analytics and no advertising on the website
The website loads no analytics, no tracking pixels, no social-media plug-ins and no advertising services. We do not track you across sites, we build no profiles, and we share nothing with advertising networks. If we ever add analytics to the website, we will update this policy and ask for your consent first.
18.5 Links to other services
The website links to the Apple App Store, to our Terms and Conditions, our Impressum and this policy, and to our social-media profiles. Following such a link takes you to a service whose operator is responsible for its own processing.
18.6 Contacting us from the website
You can contact us through the contact form on our website or by e-mail. The e-mail links open your own e-mail programme.
What the form processes: your name, your e-mail address, your message and the language version of the page. Our server sends these to our own mailbox (contact@clipmusic.app), which is also hosted by ALL-INKL.COM in Germany. The form data is not stored on the web server, and we send no copy or confirmation to the e-mail address you enter. We use your details only to answer your message. Legal basis: Art. 6(1)(b) GDPR where your message concerns a contract or its preparation; otherwise Art. 6(1)(f) GDPR — our legitimate interest in answering enquiries. Retention: as support correspondence (section 11).
Protection against spam and abuse: to stop automated mass submissions, the form uses a hidden field that people do not see, a signed time stamp that rejects forms sent faster than a person can type, and a limit on the number of messages. For the limit, our server stores a one-way hash of your IP address (it cannot be turned back into the address) together with the time of the request. This data is deleted automatically after one hour. We use no CAPTCHA and no third-party service. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in protecting the form and our mailbox against abuse.
If you write to us, we process your message as described in sections 4.7, 5 and 11.
19. Additional information for residents of the United States
This section supplements the above for residents of California and of other US states with comparable privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, Texas).
Categories of personal information collected in the last 12 months: identifiers (pseudonymous installation identifier, app user ID, device identifiers, and your e-mail address if you contact us); commercial information (subscription and purchase history); internet or other electronic network activity (server logs); visual and audio information (still frames extracted from your videos and the audio generated for them); inferences drawn for the purpose of generating music (mood and style attributes derived from the frames). Sources, purposes and recipients are those described in sections 4, 5 and 8.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA/CPRA. We have not sold or shared personal information of consumers, including minors under 16 years of age, in the preceding 12 months.
Your rights include the right to know, to access, to delete, to correct and to opt out of sale or sharing (not applicable, as we do neither), and the right not to be discriminated against for exercising them. To exercise them, contact us at contact@clipmusic.app. You may use an authorised agent; we will require proof of authorisation. We do not use or disclose sensitive personal information for purposes other than those permitted under the CCPA, so no right to limit its use applies.
Retention: as set out in section 11.
20. Apple App Store privacy information
Apple requires us to publish a summary of our data practices ("privacy nutrition labels") on the App's App Store product page. That summary is a simplified representation prepared according to Apple's categories; this privacy policy is the authoritative and complete description. If the two ever appear to conflict, this policy governs and we will correct the App Store entry.
21. Changes to this privacy policy
We may update this policy to reflect changes in the App, in our service providers or in the law. The current version is always available in the App under Profil → Einstellungen, on the paywall and at https://www.clipmusic.app/privacy/. If a change is material — for example a new category of data, a new purpose or a new third-country recipient — we will notify you in the App before it takes effect (we do not hold your e-mail address). Where the change requires your consent, we will ask for it.
Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 25 September 2026 | Initial version |
| 1.1 | 25 September 2026 | Contact form on the website added (sections 4.7, 5, 8, 11 and 18.6) |
Responsible: Mapionix UG (haftungsbeschränkt) · ClipMusic · Lisa-Weinert-Straße 9, 31079 Sibbesse, Germany
Privacy questions? Contact us at contact@clipmusic.app · Terms and Conditions · Impressum