Privacy Policy

Kadenz · Last updated: 9 August 2026

In short

1. Controller

Henri Irmscher — Appentwicklung
Seckbacher Landstr. 66
60389 Frankfurt am Main
Germany

Email: henri.irmscher@gmail.com

A data protection officer is not legally required and has not been appointed.

2. An anonymous ID instead of a user account

Kadenz has no sign-up. On the welcome screen you accept the terms of service once. Only after that does the app sign in anonymously with our backend (Supabase, anonymous sign-in). This creates a random ID that is stored on your device. That ID serves one purpose only: linking your uploaded clips and your finished videos to your device so that nobody else can reach them.

Before you accept, no data leaves your device. Anyone who opens the app, looks at the welcome screen and deletes it again leaves nothing behind with us. We record your acceptance together with the version of the terms and the timestamp — both on your device only. If we change the terms, we ask again.

We never learn your name, your email address or your phone number. The ID is not linked to any other service. If you delete the app, the ID is gone from your device.

3. What data we process

Data Purpose Legal basis Retention
Anonymous device ID Links uploads and finished videos to your device and blocks access by others Art. 6(1)(b) GDPR (performance of a contract) Until you delete all data in the app. On top of that we delete any ID by ourselves once it has gone unused for 12 months and has not a single video attached to it.
Photos and video clips you select Raw material for your edit Art. 6(1)(b) GDPR The uploaded original is deleted immediately after conversion. The converted version is removed as soon as you close your finished video — at the latest 7 days after the job started. See section 4.
Capture time of your clips Sorts clips into the right order automatically Art. 6(1)(b) GDPR Used only during processing, never stored separately
GPX file of your ride (optional, contains precise location data) Route, elevation, distance and speed as an overlay in the video Art. 6(1)(b) GDPR Never stored. It is read only at the moment of rendering and afterwards exists solely as part of the rendered image.
Details of your edit (title, template, length, timestamps, song, target platform) Shows your videos in the library and tracks running jobs Art. 6(1)(b) GDPR Until you delete the video or all data
Finished video (MP4) So you can watch, save and share it Art. 6(1)(b) GDPR Until you delete it
Search term in the song search (only in the “song in TikTok” mode) Finds the track you later place over your silent video in TikTok or Instagram Art. 6(1)(b) GDPR We do not store it and never get to see it: the query goes straight from your device to Apple. See section 7.
Subscription status and purchase data (product, store, term, RevenueCat ID) Unlocks the paid features and counts your free allowance Art. 6(1)(b) GDPR Until you delete all data — at which point we also delete your customer record at RevenueCat. Messages from the subscription service are deleted after 90 days. The purchase itself is kept by Apple and Google under their own rules, independently of this; an active subscription does not end.
Product-analytics events (which steps in the video flow you reach, whether a render finished, whether the paywall appeared and whether a subscription was completed) and, on app crashes, the error message and stack trace, plus anonymous ID and technical device details Shows us where users drop out of creation and how many subscribe after the free video — so we can improve the app Art. 6(1)(f) GDPR (legitimate interest in improving the app) At PostHog until you delete all data or object. “Delete all my data” deletes you at PostHog as well — the person and every event belonging to it, not just the link on the device
Technical server logs (IP address, timestamp, error code) Operation, troubleshooting, abuse prevention Art. 6(1)(f) GDPR (legitimate interest) 30 days, then deleted automatically

None of this feeds an advertising profile, and we do not sell data. Analytics events only help us understand the video flow and free-to-paid conversion in aggregate — not to target you with ads. There is no matching against data from other services.

4. Where your clips actually go

So you can follow the path your material takes:

  1. You select clips in your operating system's photo picker.
  2. The app uploads each file directly into our private storage at Supabase in Frankfurt am Main. It does not pass through our render server.
  3. Our render server fetches the file from that storage, converts it into a uniform format and puts the converted version back. The uploaded original is deleted immediately. The recording on your phone of course stays where it is — we never touch your gallery.
  4. During rendering the server spreads the drawing of the individual frames across short-lived compute functions at Amazon Web Services (AWS Lambda, Frankfurt am Main region). Those fetch your converted clips through signed links that expire after one hour and put the finished video into private storage at AWS for a short while.
  5. Our render server picks the video up from there, places it in a second private storage at Supabase and deletes the copy at AWS immediately afterwards. If that is interrupted, for instance because our server restarts, the copy at AWS expires automatically within one day at the latest.
  6. As soon as you close your finished video — that is, tap “Back to overview” or “Use this music” — all clips are deleted. From then on only the video exists.

If you never close the job, because you quit the app first or abandon the process halfway, an automatic job clears the job and its clips 7 days after the start.

5. Location data in the GPX file

A GPX file contains the precise course of your ride with coordinates and timestamps. That is sensitive data, so:

6. Access to photos and videos

To select clips, Kadenz opens your operating system's media picker.

We do not scan your gallery and upload nothing you did not select.

7. Music

Kadenz either places royalty-free or AI-generated music into your video, or renders the video silent so you can add a song from TikTok's or Instagram's own catalogue. We never ship a protected original master. Our own tracks sit in our storage in Frankfurt am Main.

The song search does not run through us, it runs through Apple. When you search for a title in the silent mode, your app queries Apple’s public music catalogue directly (the iTunes Search API). The same goes for the suggested titles and for the short audio preview: that streams from Apple’s servers, not from ours. Apple thereby receives your search term and your IP address and processes both under Apple’s own privacy policy — not on our behalf and not under our control. We do not see the search term, do not store it and do not link it to your ID. All that reaches us is the title you finally pick: it is written into your video as a note. Until you finish your job, it sits with that job together with the link to Apple’s audio preview — only so that a repeat render uses the same song. The preview and the song on the job are deleted along with the clips, after seven days at the latest. We keep the title on the finished video in your library so you can still see which song you chose — until you delete that video.

If you want to avoid that, simply do not use the song search. Kadenz still works without it; your video then comes with our own music or with no sound at all.

8. No ad tracking

Kadenz contains no advertising or attribution SDKs and shares nothing with ad networks. We do not sell data. There is no profiling for advertising and no automated decision-making within the meaning of Art. 22 GDPR.

To improve the app we use PostHog (product analytics and crash reports, EU cloud). The SDK starts only after you accept the terms — the same gate as anonymous sign-in. It records event names (for example which video-flow step was visible, whether a render finished, whether the paywall appeared) along with individual details about them — such as which target platform you chose for your video — plus your anonymous ID and usual technical device details. If the app crashes it also records the error message and stack trace (where in the code it happened) — no screenshot and none of your media. It never sees your clips, GPX file or finished video. Session replay is off.

Third-party SDKs included are therefore: the subscription service (RevenueCat) and product analytics (PostHog), both listed below.

9. Recipients and processors

We use the following service providers, who process data on our behalf:

Service Role
Supabase Anonymous sign-in, database and private storage for your clips and finished videos. Region Frankfurt am Main.
Google Cloud (Cloud Run) Runs the render server: fetches your clips from storage, cuts the video and puts the result back. Region europe-west3 (Frankfurt am Main).
Amazon Web Services (AWS Lambda, S3) Draws the individual frames of your video. To do that it fetches your converted clips through signed links that expire after one hour, and for the graphic receives the course of your route as a scale-free drawing without coordinates (see section 5). The finished video sits there only until our render server has picked it up, and is deleted straight afterwards. Region eu-central-1 (Frankfurt am Main).
RevenueCat Manages your subscription. Processes your anonymous ID, the purchase receipt from your app store, product and term, plus technical details about your device. RevenueCat never sees your clips or videos.
PostHog Product analytics and crash reports (EU cloud). Processes anonymous ID, event names for the video flow and paywall, on crashes the error message and stack trace, plus technical device details. PostHog never sees your clips or videos.
GitHub (GitHub Pages) Serves these legal texts. Your IP address appears in the access logs as a result.
Apple App Store / Google Play Distribution of the app and payment processing. These platforms collect their own data under their own privacy policies. We receive no payment details from them, only confirmation that a subscription exists.
Apple (music catalogue, iTunes Search API) Not a processor. The song search and the audio preview run directly between your device and Apple; Apple receives the search term and the IP address and is the controller for that itself. The query only happens if you search for a title in the silent mode. See section 7.

Your videos are processed in Frankfurt am Main: the Supabase instance, the render server (Google Cloud, region europe-west3) and the compute functions that draw the frames (Amazon Web Services, region eu-central-1) are all located there.

We have a data processing agreement under Art. 28 GDPR in place with each of these providers. For Amazon Web Services that is the AWS GDPR Data Processing Addendum, which forms part of the AWS Service Terms. Apple and Google are independent controllers for the data they collect themselves when you buy the app, and do not act on our behalf in that respect. The same applies to Apple’s music catalogue: the song search is a query made by your device to Apple, not a job commissioned by us.

Transfers to the United States

Supabase, Google, Amazon Web Services, RevenueCat and PostHog are US companies. Even though processing technically takes place in the EU (Frankfurt or PostHog’s EU cloud), access from the United States cannot be ruled out. The legal basis for this is the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, unless the provider in question relies on an adequacy decision under Art. 45 GDPR (EU-US Data Privacy Framework). You can request a copy of the clauses at henri.irmscher@gmail.com.

10. Security

11. Your rights

Under the GDPR you have the right to:

Access and export: instantly, in the app

You do not need to write to us. Tap the slider button in the top right, then under Data tap Export my data. You immediately receive a ZIP file containing:

The videos are not inside the ZIP file itself but behind links. They are too large for it, and we do not want to keep a second copy on our servers. The GDPR explicitly foresees this: Recital 63 recommends remote access to a secure system. The links are valid for 7 days. You may request a new export at any time, even several times a day, so you are never stuck with dead links.

Two things matter here. A link is a key: whoever holds it can reach the file, so do not pass the ZIP file on. And clips from jobs you have not finished are deleted after 7 days, possibly before the link expires — download those first.

The export is free of charge and works whether or not you have a subscription. You get your videos the way they turned out, that is, with music. So that nobody uses this route as a loop, there is a cap of 5 exports per day (Art. 12(5) GDPR). No human will reach it.

Erasure: also in the app

Under Data you will find Delete all data. This deletes your videos, everything recorded about them and the anonymous ID itself. It does not stop at our own systems: the same button also deletes your person and its events at PostHog and your customer record at RevenueCat. Details are on the Delete data page.

Two things this button cannot take with it, and we would rather say so plainly: the purchase itself, which sits with Apple or Google and is kept there under their rules, and an active subscription — you cancel that in the store, see the Terms of Use.

Everything else

For rectification, restriction and objection, write to henri.irmscher@gmail.com. We respond within one month.

Important: because Kadenz does not know who you are, we can only handle an email request if you include your anonymous ID. Where to find it is explained on the Delete data page. Without that ID we cannot locate your data and, for security reasons, cannot hand anything over (Art. 11(2) GDPR).

You may also lodge a complaint with a supervisory authority. Ours is the Hessian Commissioner for Data Protection and Freedom of Information, Postfach 3163, 65021 Wiesbaden, Germany.

12. Children

Kadenz is not directed at children under 16. We do not knowingly collect data from children under 16.

13. Changes

When the app changes, we update this policy. The date at the top shows the current version. We point out material changes inside the app.

This English text is a courtesy translation. The binding version is the German Datenschutzerklärung.