Start Produkte Über uns Hilfe
← musaik

Privacy Policy
musaik

Application: musaik (macOS)
Last updated: August 2026

1. Controller

The controller for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

Pondstack Software, represented by Jürgen Frosch
Segeberger Chaussee 162
22851 Norderstedt, Germany
E-Mail: info@pondstack.com
VAT ID: DE 250 223 616

2. Principles of Data Processing

musaik is a pure offline application. All music processing – analysis, stem separation, editing, mixing and export – takes place exclusively on the user's device.

No audio data, project data or music libraries are transmitted to the Provider or to third parties. No user account and no registration are required to use the App. The optional community feature (Section 7) transmits analysis measurements only, never audio or library data.

3. Which Data is Processed Locally?

The following data is processed and stored exclusively on the user's device:

This data remains on the device. The Provider has no access to it.

4. Analysis and Stem Separation

The analysis of tempo, bar grid, key and structure uses methods that run entirely on the device – including operating system functions of macOS and bundled analysis models. Splitting a track into stems is also performed locally.

There is no cloud processing. No audio content is uploaded for analysis.

5. Licence Verification

The licence key is verified locally (cryptographic signature check). No permanent connection to the Provider is required for ongoing use; only the activation of a purchased licence and its renewal need an internet connection from time to time (see below).

Upon purchase, the licence key is delivered by e-mail. Payment is processed by FastSpring (Bright Market, LLC dba FastSpring, Bright Market LLC dba FastSpring Limited and/or FastSpring B.V.), 801 Garden St. #201, Santa Barbara, CA 93101, USA, as Merchant of Record. FastSpring is the controller for the payment and invoicing data entered there; FastSpring's privacy policy applies (fastspring.com/privacy). The Provider receives from FastSpring the information required to issue the licence and the invoice (in particular e-mail address and purchase details). The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

Trial activation: When the free 14-day trial is used, the App transmits an anonymous device value to our licence service: a SHA-256 hash derived from a device identifier and an app-internal salt. The hash cannot be reversed to the device identifier; no name, e-mail address or other personal details are transmitted. The service stores, for this hash only, the date of the first trial start for as long as this is required to limit the trial period, and issues the App a signed "trial ticket" containing the trial period, which is stored locally on the device. The sole purpose is the reliable limitation of the trial period per device (abuse prevention); the legal basis is Art. 6(1)(f) GDPR (legitimate interest). The request is made when the trial starts and at most once per day thereafter; it does not take place once a purchased licence is activated.

Licence activation (device management): When a purchased licence is activated, and on every renewal, the App transmits to our licence service: an identifier derived from the licence key (SHA-256 hash; the key itself is neither transmitted nor stored), an anonymous device hash (SHA-256 of a device identifier and a separate app-internal salt, which cannot be reversed to the device identifier), and the name of the device so that you can tell your activated devices apart in the App. For this the service stores the date of the first and the most recent activation and issues the App a signed ticket, which is stored locally on the device. The purpose is the limitation to three devices per licence key and protection against unauthorised sharing; the legal bases are Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest). The request is made on activation and thereafter for renewal, at the earliest 30 days before the 90-day period expires. If you release a device in the App or the licence ends, the associated entries are deleted.

The licence service is operated on Cloudflare, Inc. (USA) infrastructure (Cloudflare Workers, KV and D1; the device-management database is located in the Western Europe region). For technical reasons, Cloudflare also processes the IP address of the request. A data processing agreement is in place with Cloudflare; the transfer to the USA is safeguarded by the EU-US Data Privacy Framework and EU Standard Contractual Clauses.

6. Update Check

The App can check whether a newer version is available by retrieving a version file from pondstack.com. This transmits technically necessary connection data (IP address, time, requested file) and the installed program version. No personal content, no music data and no device identifiers are transmitted.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing security and functional updates). The check can be permanently disabled in the App settings.

7. Shared Analysis Data (Community Feature, Optional)

musaik includes an optional community feature: users who correct the automatic structure detection of a title can share this correction with other users and in return receive the community's verified corrections. The feature is switched off by default and only becomes active after explicit consent in the App (Art. 6(1)(a) GDPR). Consent can be withdrawn at any time in the settings.

Only analysis measurements are transmitted: an acoustic fingerprint of the title (a sequence of numbers from which the audio material cannot be reconstructed), the section boundaries with their labels (intro, chorus …), a vocal flag per section, tempo, first downbeat, key and loudness, as well as the App's previous automatic estimate. Not transmitted: audio data, file names, paths, track titles, artists, playlists or any other content of the music library.

Pseudonymous identifier instead of an account: When the feature is switched on for the first time, the App transmits the licence key once to the server. From this, a pseudonymous identifier is derived using a secret server key (HMAC procedure); the e-mail address contained in the licence key is not stored and is never transmitted again after this initial enrolment – from then on the App only uses a random access token. The identifier serves solely to attribute submissions, to weight their quality and, in the event of abuse, to exclude individual identifiers from the consensus. The person is not identified.

Retention and deletion: Submissions remain stored for as long as the feature is used and flow into aggregated statistics. “Delete submissions” in the App settings removes all of the user's submissions and the access token from the server; the aggregated statistics are recalculated on the next processing run. Switching the feature off immediately stops both sending and querying; values already adopted in the App remain locally.

Independently of this consent, the App may retrieve signed, highly aggregated structure statistics of the community that contain no reference to any title or person; only the technical connection data described in Section 6 arises in the process (Art. 6(1)(f) GDPR). This retrieval can also be disabled in the settings.

8. No Tracking

musaik contains no analytics or tracking libraries, no advertising networks and no profiling. No usage statistics are collected and no identifiers are used for advertising purposes.

9. Diagnostics and Crash Reports

The Provider does not collect automatic diagnostic or crash data. If the user consents via macOS to sending crash reports to Apple, this takes place solely between the user and Apple under Apple's terms.

If the user sends an error report by e-mail on their own initiative, the information contained is used exclusively to process the enquiry (Art. 6(1)(f) GDPR) and deleted once it is no longer required.

10. Permissions and File Access

The App accesses only those areas the user explicitly selects:

11. Retention

All project-related data remains on the device until the user deletes it. In connection with the App, the Provider stores no personal data with the exception of the details required for licence management and invoicing; these are retained within the statutory retention periods.

12. Rights of Data Subjects

Under the GDPR, data subjects have the following rights:

A message to info@pondstack.com is sufficient to exercise these rights.

13. Right to Lodge a Complaint

Data subjects have the right to lodge a complaint with a data protection supervisory authority, for example: Der Landesbeauftragte für Datenschutz und Informationsfreiheit Schleswig-Holstein, Holstenstraße 98, 24103 Kiel, Germany.

14. Data Security

As processing takes place exclusively locally, the security measures of the operating system and the user's device apply. The Provider recommends disk encryption (FileVault), current system updates and regular backups. Connections to the Provider's web services are always encrypted (HTTPS).

15. Children

The App is not directed at children under the age of 16. No personal data of children is knowingly collected.

16. Changes to this Privacy Policy

This Privacy Policy may be adapted if App features or legal requirements change. The current version is available at pondstack.com/musaik-privacy.

Further legal documents for musaik: Terms of Use  ·  Imprint