Chough chough.app

Privacy policy

Last updated 30 August 2026

The short version. No analytics, no ads, no tracking, no selling of data. The service stores what it needs to run your library — your account, your files, your listening state — and nothing else. Your library is private to your account and is never made public. You can export everything and delete your account yourself, in the app.

1. Who is responsible

The controller for all data processing described here is:

Nikita Ermilov
Koloniestraße 71
13359 Berlin
Germany
[email protected]

2. This website

chough.app sets no cookies, runs no scripts, and loads nothing from third parties. The site is delivered through Cloudflare (Cloudflare, Inc.), which technically processes your IP address to serve the page and keeps its own short-term security logs. Our own web server keeps no access logs for this site. Downloads of the app and its source are served directly from our server (api.chough.app), not through Cloudflare.

3. Your account

Signing up stores your email address, your password, confirmation and reset codes, and timestamps. Legal basis: performance of the service you signed up for (Art. 6(1)(b) GDPR).

An honest technical note: the authentication scheme the app uses requires the server to be able to read your password, so it is stored encrypted, not hashed. Please use a password you use nowhere else.

If you sign in with Google, Google confirms your identity to us and we receive your email address. That sign-in is also governed by Google's own privacy policy; we receive nothing from Google beyond the email address.

4. Your library

The service stores what you put in it: audio files added from your device, their metadata, cover art and lyrics, the source URL a track was added from, and your playlists, favourites, play counts, pins and storage totals. Legal basis: Art. 6(1)(b) GDPR.

Your library is private to your account. It is never made public, never shared with other users, and not looked at by us except where strictly needed to operate the service (for example, investigating a fault or an abuse report) or where the law requires it.

5. Technical logs

The app server writes technical request logs, including IP addresses, used only to operate the service, debug faults and prevent abuse (rate limiting keeps short-lived per-IP counters in memory). Logs are kept short-term and are not evaluated for any other purpose. Legal basis: legitimate interest in a working, secure service (Art. 6(1)(f) GDPR).

6. Email

The service sends only transactional email — sign-up confirmation and password reset codes. Delivery is handled by Resend (Resend, Inc., a US provider), sending from an EU region. There is no newsletter and no marketing email.

7. Where your data lives

The server and all stored content run on Hetzner (Hetzner Online GmbH, Germany) in Falkenstein, Germany — both the application server and the object storage holding your files. Apart from the email delivery above and the website delivery through Cloudflare, your data stays on this infrastructure in the EU.

8. How long we keep things

9. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). The app covers the two big ones directly: export your whole library (Settings → Collection → Export), delete your account (Settings → Account → Delete). For everything else, write to [email protected]. You also have the right to complain to a data protection supervisory authority.

10. Changes

If this policy changes in a way that matters, the date at the top changes and material changes are announced in the app or by email.