Privacy Policy

RandTune is built by Philipp and Angela Meisberger (address see imprint) as a free-time app project. This privacy policy applies to the use of the smartphone application only. For the website please see website privacy policy. If you have any questions about RandTune please contact us via email at team@randtune.de

Scope of application

  1. This privacy policy provides information on the processing of personal data when using the app.
  2. The processing of personal data by RandTune as the person responsible is subject to the General Data Protection Regulation ("GDPR").
  3. By personal data we mean any information relating to an identified or identifiable natural person.

Information about you

RandTune is responsible for the subsequent data processing within the meaning of the GDPR.

RandTune can be used in two different ways: offline and online. No account is required for the offline usage and thus no personal information must be provided. To use RandTune online you must sign up for an account.

Registration

During the registration you provide some information about yourself to use the app (Art. 6 §1 letter b GDPR):

  1. nickname: A unique nickname that other RandTune users can see, e.g. when you use shared Tunebooklets with other users.
  2. username (optional): Besides a nickname you can provide your real name if you wish. Other RandTune users can see this name, e.g. when you use shared Tunebooklets with other users. Providing your real name is not mandatory.
  3. email address and password: You need to provide a valid email address when you sign up for RandTune. The reason for that is as follows: In case you forgot your password we can send you an email to reset it. Your email address is just used for this one purpose, we will not send you any kind of advertisement.

This information will never be shared, sold or given away to anyone. You can update your account at any time by selecting "edit profile" in the app settings. Please remind that you cannot change your nickname.

We store the information as long as this is necessary to provide the service, or as long as this is necessary to pursue or defend against legal claims, or to fulfill statutory storage obligations. In any case, the license agreement ends after a period of 60 months of inactivity.

Error reports

We provide you the possibility to send us error reports if you experience abnormal app behaviour or app crashes. For this case we use and store the following information for error investigation (Art. 6 §1 letter f GDPR):

  1. email address
  2. creation date and time of the error report
  3. app version
  4. OS version
  5. device version

This information will be stored for as long as is necessary process the report and as long as the user has a user account in the app. In any case, the license agreement ends after a period of 60 months of inactivity. Thereafter, personal data processing of invoice data continues until the end of the statutory retention period (currently basically 7 years after the end of the financial year in which the business occurred).

Your contributions

In general you can create Tunebooklets. That are collections which contain the names of tunes, sets and wishes. A freshly created Tunebooklet is only visible for yourself.

Using RandTune without an account will store all data locally on your device. By using it online, Tunebooklets and all its contents will be sent to our online service and kept in sync, provided that there is an internet connection. Other users are not able to see your Tunebooklets, as long as you don't share the Tunebooklet as a link and give this link to other users. If you do, this link is only valid for a short period of time. Users who get this link must be logged in to access the contents. If the link is clicked by someone before it expires, the Tunebooklet appears in his or her list of Tunebooklets.

During the sharing process you will be asked which permission other users should be granted if they click on the link. If you choose at least "read-write" then users can modify/delete/add contents to the Tunebooklet. You can edit/revoke the permission for each user at any time.

Data collection

RandTune does not try to track you. We value your privacy! But, to provide our online service to you (Art. 6 §1 letter b GDPR), the following information are processed by our servers:

  1. your IP address of your device and the access time
  2. URL of your request

We use the information to detect attacks on our systems (Art. 6 §1 letter f GDPR). We store them as long as this is necessary to provide the service, or as long as this is necessary to pursue or defend against legal claims, or to fulfill statutory storage obligations. In any case, the license agreement ends after a period of 60 months of inactivity.

Data deletion

If you no longer want to be a user of RandTune, you can request an account deletion through the app settings. Your account with all your not shared data will be deleted.

Security

Our online service only accepts encrypted (HTTPS) connections, so the entire data exchange between the app and our online service is encrypted. The password you provide to login into our online service is never stored locally. Instead we use JWT for authentication.

Your account password is not stored in plain text on our servers but it is hashed using a cryptographic strong hash function where only the result is stored in a database. So even in the unlikely case of a security breach, nobody will gain access to your password. We do not know your password. If you forget it we cannot give it to you, hence it is important that you provide a valid email address during registration to be contacted in this case.

All your contributions are stored in local files, so-called Tunebooklets. They are located on your device in the app's private storage provided by the Android system. If you have an online account your contributions are also stored on our servers.

Your rights

You have the following rights under the GDPR against RandTune:

  1. The right to information according to Art. 15 GDPR regarding the personal data processed by us.
  2. The right to rectification under Art. 16 GDPR, the right to erasure under Art. 17 GDPR and the right to restriction of processing under Art. 18 GDPR.
  3. The right to object according to Art. 21 GDPR.
  4. The right to data portability according to Art. 20 GDPR.
  5. The right to lodge a complaint with the competent data protection authority in accordance with Art. 77 GDPR.
  6. You can withdraw your consent to the processing of personal data at any time. Please note that the revocation only applies to the future. Processing that took place before the revocation is not affected.

Required permissions

Storage (WRITE_EXTERNAL_STORAGE, READ_EXTERNAL_STORAGE)

Required for exporting and importing Tunebooklets.

Internet (INTERNET)

Required to use our online service.

Changes to our Privacy Policy

We reserve the right to modify our Privacy Policy at any time simply by posting such modification on this site and without any other notification. Any such modification will be effective immediately upon posting on this site. It is your responsibility to review our Privacy Policy from time to time to ensure that you continue to agree with all of its terms.

This privacy policy is valid from 08/31/2022.