Privacy policy
Last updated 30 August 2026
The short version. No analytics, no ads, no tracking, no selling of data. The service stores what it needs to run your library — your account, your files, your listening state — and nothing else. Your library is private to your account and is never made public. You can export everything and delete your account yourself, in the app.
1. Who is responsible
The controller for all data processing described here is:
Nikita ErmilovKoloniestraße 71
13359 Berlin
Germany
[email protected]
2. This website
chough.app sets no cookies, runs no scripts, and loads nothing from third parties. The site is delivered through Cloudflare (Cloudflare, Inc.), which technically processes your IP address to serve the page and keeps its own short-term security logs. Our own web server keeps no access logs for this site. Downloads of the app and its source are served directly from our server (api.chough.app), not through Cloudflare.
3. Your account
Signing up stores your email address, your password, confirmation and reset codes, and timestamps. Legal basis: performance of the service you signed up for (Art. 6(1)(b) GDPR).
An honest technical note: the authentication scheme the app uses requires the server to be able to read your password, so it is stored encrypted, not hashed. Please use a password you use nowhere else.
If you sign in with Google, Google confirms your identity to us and we receive your email address. That sign-in is also governed by Google's own privacy policy; we receive nothing from Google beyond the email address.
4. Your library
The service stores what you put in it: audio files added from your device, their metadata, cover art and lyrics, the source URL a track was added from, and your playlists, favourites, play counts, pins and storage totals. Legal basis: Art. 6(1)(b) GDPR.
Your library is private to your account. It is never made public, never shared with other users, and not looked at by us except where strictly needed to operate the service (for example, investigating a fault or an abuse report) or where the law requires it.
5. Technical logs
The app server writes technical request logs, including IP addresses, used only to operate the service, debug faults and prevent abuse (rate limiting keeps short-lived per-IP counters in memory). Logs are kept short-term and are not evaluated for any other purpose. Legal basis: legitimate interest in a working, secure service (Art. 6(1)(f) GDPR).
6. Email
The service sends only transactional email — sign-up confirmation and password reset codes. Delivery is handled by Resend (Resend, Inc., a US provider), sending from an EU region. There is no newsletter and no marketing email.
7. Where your data lives
The server and all stored content run on Hetzner (Hetzner Online GmbH, Germany) in Falkenstein, Germany — both the application server and the object storage holding your files. Apart from the email delivery above and the website delivery through Cloudflare, your data stays on this infrastructure in the EU.
8. How long we keep things
- Account and library — until you delete them. Deleting your
account (
Settings → Account → Deletein the app, or by email) removes your files and records immediately. - Backups and storage versions — deleted data ages out of backups and object-storage versioning within 30 days of deletion.
- Technical logs — short-term, then gone.
9. Your rights
You have the right to access, rectification, erasure, restriction of processing,
data portability and objection (Art. 15–21 GDPR). The app covers the two big ones
directly: export your whole library (Settings → Collection → Export),
delete your account (Settings → Account → Delete). For everything else,
write to
[email protected]. You also have the right to
complain to a data protection supervisory authority.
10. Changes
If this policy changes in a way that matters, the date at the top changes and material changes are announced in the app or by email.