Legal

Privacy Policy

Last updated: 26 August 2026

1. Introduction

vocumi(“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights.

1. Who We Are (Controller)

The data controller for all personal data processed in connection with the vocumiplatform (“Service”) is:

vocumi UG (haftungsbeschränkt)

Schönhausenstr. 41, 28355 Bremen, Germany

Register court: Amtsgericht Bremen

Register number: HRB 42762 HB

E-mail: contact@vocumi.com

2. Scope of This Policy

This Privacy Policy applies to all personal data processed when you visit our public website (vocumi.com), register for an account, or use the vocumi web application. It applies to individual users and to members of team workspaces.

Our public marketing pages may use optional, consent-based analytics (Matomo) — only if you accept Statistics in the cookie banner. The authenticated product application does not load Matomo. See §3.9 and §4.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection laws.

3. Data We Collect and Legal Basis

3.1 Account & Profile Data

When you register, we collect and store the following:

  • Email address — required for login and transactional communications
  • Full name — displayed within your workspace
  • Avatar / profile image URL — optional, if you set one in your profile
  • Password — stored as a secure hash; we never store your plaintext password. Accounts use email and password only (we do not offer Sign in with Google or other social login)
  • Plan tier & account preferences — including weekly digest opt-out preference

Legal basis: Art. 6(1)(b) GDPR — performance of a contract (the subscription agreement you entered into with us).

3.2 Workspace & Collaboration Data

When you use the platform, we store:

  • Artists and podcasts you add to your roster, including notes and status labels you assign
  • Tags and custom labels applied to artists
  • Artists you mark as personal favourites
  • In-app notifications (e.g., team invitations accepted, access changes)
  • Your workspace membership role (owner, admin, member, viewer) and the date you joined

Legal basis: Art. 6(1)(b) GDPR — necessary to deliver the core functionality of the Service.

3.3 Vibe Search Queries (Processing, Not Retention)

When you use Vibe Search for artists or podcasts, the text you enter is processed to return matching results. We do not retain your vibe query text in our database for quota enforcement or as searchable history. Plan limits are enforced with usage counters only (how many searches you used, not what you typed). Artist and podcast Vibe searches share one daily (or grant/monthly) counter per user.

During artist Vibe requests, your query may be transmitted to OpenAI (vector embedding for similarity matching) and to Google Gemini (ranking and discovery). Podcast Vibe requests are processed by Google Gemini only. Those providers process the query for that request under their API terms; we do not use Vibe queries to build an advertising profile.

Legal basis: Art. 6(1)(b) GDPR — necessary to deliver Vibe Search and enforce plan limits as contracted.

3.4 Direct Search Queries (Processing, Not Retention)

When you use Direct Search for artists or podcasts, the text you enter is processed to find matches. We do not retain your Direct Search query text in our database. Plan limits are enforced with usage counters only (how many Direct searches you used, not what you typed). Artist and podcast Direct searches share one daily counter per user.

Depending on your query and entity, Direct Search may transmit your search text to Spotify (artist name search), Soundcharts (fallback artist discovery when Spotify returns no results), Apple Podcasts / iTunes Search (podcast name and catalogue lookup), public RSS feeds (podcast metadata when a feed URL is resolved), and/or Google Gemini (keyword-style artist queries that are not a single artist name). Those providers process the query for that request under their API terms; we do not use Direct Search queries to build an advertising profile.

Legal basis: Art. 6(1)(b) GDPR — necessary to deliver Direct Search and enforce plan limits as contracted.

3.5 Billing & Subscription Data

We store your subscription status, plan type, renewal date, and a reference ID linking your account to your Lemon Squeezy customer record. We do not store your payment card details — all payment processing is handled by Lemon Squeezy, which acts as the merchant of record.

Legal basis: Art. 6(1)(b) GDPR — performance of the subscription contract; Art. 6(1)(c) GDPR — compliance with tax and accounting obligations.

3.6 Weekly Digest Emails

We send a weekly summary of your workspace activity (roster updates, metric changes, team activity) to your registered email address. This feature is enabled by default but you can opt out at any time in your account settings. We use your email address and workspace data to generate these digests.

Legal basis: Art. 6(1)(f) GDPR — legitimate interests (keeping you informed about activity in your workspace). You have the right to object to this processing at any time under Art. 21 GDPR by disabling the digest in your account settings.

3.7 Email Communications Log

For operational reliability, we log the type and send status of transactional emails sent to your address (e.g., welcome, password reset, workspace invitation). Email content is not stored in our database.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in ensuring reliable delivery of account-critical communications.

3.8 Feature & AI Usage Counters

To enforce plan limits and manage AI cost, we store usage counters such as daily Direct/Vibe search counts and weekly Pulse counts (linked to your user and workspace), plus organisation-level AI token consumption records. These records contain counts and technical metadata — not the text of your Vibe queries. They are not used to build advertising profiles.

Legal basis: Art. 6(1)(b) GDPR — necessary to manage plan limits and billing; Art. 6(1)(f) GDPR — legitimate interest in cost management.

3.9 Public Website Visits, Marketing Analytics & Server Access Logs

Our public marketing pages (vocumi.com) do not use advertising pixels, session recordings, or third-party ad networks. We do not sell marketing visit data or build advertising profiles from our website.

Marketing analytics (Matomo, opt-in only)

If you accept Statistics in our cookie banner, we load Matomo Analytics, which we operate ourselves on analytics.vocumi.com (Hetzner Cloud VPS, EU/EEA). Matomo is not loaded until you opt in. It may collect:

  • Pages visited, referrer URL, and campaign parameters (UTM tags)
  • Browser/device type and language (from the user-agent)
  • Anonymised IP address (last bytes masked in Matomo)
  • Interaction events (e.g. which marketing button was clicked) — no form field contents or search queries

This data is used only to understand how our marketing site is used. It is not linked to your vocumi account, roster data, or in-app product telemetry (§3.11). Raw visit logs are deleted after 6 months. You can withdraw consent at any time via Cookie settings in the site footer.

Legal basis: Art. 6(1)(a) GDPR — your consent; § 25 TDDDG — consent before non-essential cookies or client-side analytics run on your device.

Server access logs

We do not store marketing analytics IP addresses in our application database. Like most web services, our hosting infrastructure generates server access logs when you visit the site or use the application. On our Hetzner Cloud VPS (reverse proxy and application containers), these logs may include your IP address, request timestamp, URL path, HTTP status code, referrer, and browser user-agent. We use these logs for security, abuse prevention, and troubleshooting — not for advertising or behavioural profiling.

Retention on our VPS:Docker log rotation keeps up to three log files of 10 MB each per service container (the effective time window depends on traffic volume). Hetzner Cloud servers are unmanaged: we configure and operate application logs ourselves. Separately, Hetzner logs logins and administrative changes in your Hetzner customer account portal under their own GDPR-compliant deletion schedule (see Hetzner TOMs). Hetzner does not access or retain the contents of our application databases.

Legal basis: Art. 6(1)(f) GDPR — legitimate interests in secure and reliable operation of the Service.

3.10 Product Feedback

When you submit feedback through the in-app feedback form (hosted at feedback.vocumi.com), we collect your feedback title and description, the board you selected, your Vocumi account identifier, email address, and name. Your name is not shown to other users when they browse feedback.

If you opt in via the contact checkbox on a specific submission, we may email you about that feedback. Without that opt-in, we use your identity only to operate and triage feedback internally.

Legal basis: Art. 6(1)(b) GDPR — necessary to operate the feedback feature; Art. 6(1)(a) GDPR — outreach about a specific submission where you opt in.

3.11 Product Telemetry (In-App Feature Adoption)

Within the authenticated web application, we record product telemetry events to understand which features are used (for example: discovery mode used, artist tabs opened, checkout started, help opened). Each event may include:

  • Event name and non-sensitive properties (e.g. tab name, plan tier, query length — not the query text)
  • Your user ID and workspace (organisation) ID when you are signed in
  • A daily session identifier derived from your user ID and the calendar date (not a persistent cross-day tracking cookie)
  • Page path, HTTP referrer, and browser user-agent
  • Country code (ISO 3166-1 alpha-2) derived at write time from CDN headers or GeoIP — we do not store your raw IP address in telemetry

Telemetry is used for internal product improvement and operations. It is not sold, not used for advertising, and not combined into a marketing behavioural profile. Public marketing pages do not run this product telemetry.

Legal basis: Art. 6(1)(f) GDPR — legitimate interests in improving the Service and understanding feature adoption. You may object under Art. 21 GDPR by contacting us at contact@vocumi.com.

4. Cookies and Local Storage

We use strictly necessary cookies and local storage for the Service to function. Optional statistics cookies are set only if you accept analytics in our cookie banner (§ 3.9). We do not use advertising or third-party marketing cookies.

Authentication Cookies (Supabase SSR)

  • sb-[project]-auth-token — Encrypted session token, HttpOnly, required for login
  • sb-[project]-auth-token-code-verifier — PKCE verification token used by Supabase Auth flows, HttpOnly

Application Cookie

  • active_org — Stores your currently active workspace ID to maintain context between page navigations

These cookies are session-bound or expire after a short period. They are not shared with third-party advertising networks. Because these cookies are strictly necessary for the Service to function, we do not require your consent to set them (§ 25(2) No. 2 TDDDG).

Consent storage (local storage)

  • vocumi_consent_v1 — Stores your cookie choice (essential only or analytics) and timestamp so we do not ask on every visit. Strictly necessary to honour your preference.

Statistics (optional — consent required)

If you choose Accept analytics, Matomo may set first-party cookies on vocumi.com, for example:

  • _pk_id.* — Distinguishes returning visitors (visitor ID); up to 6 months
  • _pk_ref.* — Stores campaign referrer; shorter session-based lifetime
  • _pk_ses.* — Short-lived session cookie

Data is processed on our self-hosted Matomo instance (EU). Withdraw consent via Cookie settings in the footer; this stops future tracking. Clearing site data removes Matomo cookies from your browser.

Legal basis: Art. 6(1)(a) GDPR — consent; § 25 TDDDG.

5. Third-Party Processors

We share personal data only with the following trusted sub-processors, each bound by data processing agreements and applicable data protection law. We do not sell your personal data.

5.1 Supabase (Authentication & Database)

We use the Supabase open-source stack for authentication and our primary database. This is self-hosted by us on a Hetzner Cloud VPS in Helsinki, Finland (EU/EEA). Your personal data — including your email address, hashed password, and all application data (profile, workspace, artists) — is stored on that server within the European Union. We do not use Supabase's managed cloud hosting. No international transfer to a third country occurs for this data.

Supabase Privacy Policy →

5.2 Hetzner (Application Hosting)

Hetzner Online GmbH (Germany) provides the cloud infrastructure on which we host the vocumi web application and marketing pages. Application servers run on a VPS in Helsinki, Finland (EU/EEA). Server access logs are described in §3.9. Hosting data remains within the EU/EEA. Hetzner Cloud servers are unmanaged — we are responsible for configuring application logs and security on the VPS; Hetzner retains only its own customer-account portal logs per Hetzner's GDPR deletion schedule.

Hetzner Privacy Policy →

5.3 Lemon Squeezy (Payment Processing & Merchant of Record)

Lemon Squeezy (a Stripe company, USA) processes all payments and acts as the merchant of record for your subscription. When you purchase a subscription, you enter into a payment relationship directly with Lemon Squeezy. They collect and process your billing name, email address, payment card details, and billing address. We receive only non-sensitive subscription metadata (status, plan type, renewal date, customer reference ID).

Lemon Squeezy Privacy Policy →

5.4 Resend (Transactional Email)

Resend Inc. (USA) delivers transactional emails on our behalf — including welcome emails, password reset links, workspace invitations, access change notifications, and weekly digest emails. To deliver these emails, we transmit your email address and, where applicable, your first name to Resend. Resend processes this data solely to deliver the email and may retain delivery logs for a limited period. Resend is GDPR-compliant via SCCs and acts as a data processor under our instruction.

Resend Privacy Policy →

5.5 Google (Gemini AI)

We use Google Geminivia Google's generative AI APIs for features such as Vibe Search, Similar Artists, Pulse / AI Profile, metadata enrichment, and Insights. We do not offer Sign in with Google.

Vibe Search: the text you type is included in the Gemini request so the model can rank or discover matching artists.

Other Gemini features: prompts contain publicly available or platform-derived artist information (names, biographies, tags, metrics summaries) — not your account email, password, or billing details.

Google processes these inputs as our AI provider. Review Google's API / generative AI data policies for how inputs are handled. Transfers to Google (USA) rely on Standard Contractual Clauses (Art. 46(2)(c) GDPR) or other appropriate safeguards.

Google Privacy Policy →

5.6 OpenAI (Vector Embeddings)

vocumi uses OpenAI's text-embedding-3-small model to generate vector embeddings. Embeddings power similarity matching for Vibe Search and related discovery features.

Vibe Search: your vibe query text is sent to OpenAI to create an embedding for that search.

Artist embeddings: publicly available or platform-stored artist text (names, genres, tags, descriptions) may be sent to OpenAI — your personal account data is not included in those artist-embedding requests.

OpenAI Inc. is based in the United States. Data is transferred under Standard Contractual Clauses (SCCs) (Art. 46(2)(c) GDPR). OpenAI's API data usage policy states that API inputs are not used to train models by default.

OpenAI Privacy Policy →

5.7 Brave Search (Web Intelligence)

vocumi uses the Brave Search API to enrich artist profiles with publicly available web information (news, interviews, descriptions). Only artist names and publicly known identifiers are sent as search queries — your personal data is not transmitted.

Brave Software Inc. is based in the United States. Data is transferred under Standard Contractual Clauses (SCCs) (Art. 46(2)(c) GDPR).

Brave Privacy Policy →

5.8 Apify (Social Media Data Collection)

vocumi uses Apify to collect publicly available social media metrics for artists (e.g., Instagram follower counts, engagement data). Only publicly visible artist profile data is collected via Apify — your personal data as a vocumi user is never sent to Apify.

Apify Technologies s.r.o. is incorporated in the Czech Republic (European Union) and is subject to EU data protection law. No international transfer applies for Apify-processed data.

Apify Privacy Policy →

5.9 Soundcharts (Licensed Artist Metrics)

vocumi uses Soundcharts as a licensed data provider for streaming and market metrics that power artist scores and tracking. We send artist identifiers and names (for example Soundcharts UUIDs or Spotify artist IDs associated with artists in our catalogue) to retrieve metrics. We do not send your account email, password, billing details, or workspace notes to Soundcharts.

Soundcharts is a commercial third-party data provider. Artist metrics we receive may be stored in our EU-hosted database to deliver the Service. Transfers of any personal data (if any) outside the EEA rely on appropriate safeguards such as Standard Contractual Clauses where required.

Soundcharts Privacy Policy →

5.10 Spotify (Artist Search & Identity)

vocumi uses the Spotify Web API for artist search, identity resolution, and display assets (such as artist images and profile links) in discovery flows. Requests contain artist names or Spotify artist IDs — not your vocumi account credentials or personal profile.

Spotify API metrics are not used to calculate our proprietary Vocumi Score. On production, all score inputs come from Soundcharts (see §5.9). Spotify popularity or follower numbers may appear on search result cards for display only; they are not persisted for scoring and are not substituted when Soundcharts data is missing — in that case we skip the metrics refresh rather than calculate from Spotify.

Spotify Privacy Policy →

5.11 Hetzner (Product Feedback Hosting)

Product feedback submitted through feedback.vocumi.com is stored in a self-hosted OpenCan database on a separate Hetzner Cloud VPS, also in Helsinki, Finland (EU/EEA). This database is operated by us as data controller and is separate from our primary Supabase database, but subject to the same privacy obligations described in this policy.

5.12 MusicBrainz (Artist Identity)

vocumi queries the MusicBrainz open music encyclopedia (musicbrainz.org, operated by the MetaBrainz Foundation) to enrich artist profiles with identity metadata — for example real name, gender, birth year, nationality, and official social links. We send artist names and, when known, MusicBrainz IDs as search parameters. We do not send your account email, password, billing details, or workspace notes to MusicBrainz. MusicBrainz data is publicly contributed under open licences; we store matched MBIDs and derived fields in our EU-hosted database to avoid repeated lookups.

MusicBrainz API documentation →

5.13 Matomo (Self-Hosted Marketing Analytics)

When you accept Statistics on our public website, we use Matomo Analytics hosted by us at analytics.vocumi.com on the same Hetzner Cloud VPS (EU/EEA) as our application. Matomo is not a third-party SaaS processor — it is software we operate as data controller. Processing details, cookies, and retention are in §3.9 and §4. No data is shared with Matomo Cloud or other Matomo-hosted services.

5.14 Apple Podcasts, RSS & Podcast Catalogue Data

vocumi uses the Apple Podcasts / iTunes Search API and public RSS feeds to discover podcasts, resolve show metadata, and refresh episode cadence metrics. We send show names, feed URLs, and catalogue identifiers — not your account email, billing details, or workspace notes. We do not access private podcast analytics, listener counts from hosting dashboards, or subscriber PII.

Podcast metrics we derive (for example episode count, publish cadence, and derived scores) are calculated from publicly available feed data and stored in our EU-hosted database. AI features such as podcast Vibe Search and Similar Podcasts send show titles, descriptions, and genres to Google Gemini for matching — see §3.3.

Apple Privacy Policy →

6. Artist Data & Third-Party Music Platforms

The artist intelligence data displayed in vocumi is aggregated from publicly available sources and licensed providers, including Soundcharts, Spotify, MusicBrainz, Instagram, TikTok, YouTube, SoundCloud, Last.fm, and other music or social platforms. This data relates to artists as public figures, not to our users as private individuals.

vocumi uses automated tools (including Google Gemini, OpenAI embeddings, Brave Search, Apify social data collection, Spotify search, and Soundcharts metrics APIs) to collect and update artist information on a regular schedule or on demand. We do not use this artist data to build profiles of individual private persons who are not the artists themselves.

7. International Data Transfers

The vocumi application, our self-hosted Supabase database, and product feedback (OpenCan) are all operated on servers in Helsinki, Finland (EU/EEA). This hosting does not involve international transfer to a third country. Some providers used for specific features — Lemon Squeezy, Resend, Google (Gemini), OpenAI, and Spotify — are based outside the EEA or process data globally. Soundcharts and Apify process requests according to their own hosting footprint; Apify is incorporated in the Czech Republic (EU). Where personal data is transferred outside the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46(2)(c) GDPR) or other appropriate safeguards to ensure an adequate level of data protection.

8. Data Retention

  • Account & profile data: Retained for the duration of your account plus up to 30 days after deletion request, unless legal retention obligations apply.
  • Vibe query text: Not retained in our database. Processed transiently by OpenAI and Google Gemini during the search request (see §3.3).
  • Direct Search query text: Not retained in our database. Processed transiently by Spotify, Soundcharts, and/or Google Gemini during the search request (see §3.4).
  • Server access logs: Rotated on our VPS at up to three files of 10 MB per service container (see §3.9). Effective retention in days depends on traffic volume.
  • Marketing analytics (Matomo): Raw visit and event data deleted after 6 months (180 days) by automated purge on our Matomo instance; aggregated reports may be kept per Matomo configuration.
  • Feature & AI usage counters: Retained for approximately the current period plus 3 months for quota verification and cost management; deleted automatically on a scheduled job.
  • Product telemetry: Retained for 60 days, then deleted automatically by a scheduled cleanup job (Art. 5(1)(e) GDPR storage limitation).
  • Billing data: Retained for 10 years in accordance with German commercial and tax law (§ 147 AO, § 257 HGB).
  • Email logs: Retained for up to 2 years; automatically deleted by a scheduled database job thereafter (Art. 5(1)(e) GDPR storage limitation).
  • Workspace & artist data: Retained until you delete the workspace or close your account. Upon account closure, we will delete or anonymise your personal data within 30 days.
  • Product feedback: Retained for up to 24 months or until account deletion, whichever comes first. Post content may be retained in anonymised form after deletion for product prioritisation.

9. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights (Articles 15–22 GDPR):

  • Right of access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to erasure / “right to be forgotten” (Art. 17): Request deletion of your personal data where there is no overriding legal basis for continued processing.
  • Right to restriction of processing (Art. 18): Request that we restrict processing of your data in certain circumstances.
  • Right to data portability (Art. 20): Receive your personal data in a structured, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interests (Art. 6(1)(f) GDPR).
  • Right to withdraw consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint (Art. 77): Lodge a complaint with a supervisory authority — in Germany, this is the relevant Landesbeauftragte für Datenschutz. For Bremen: datenschutz.bremen.de.

To exercise any of these rights, contact us at contact@vocumi.com. We will respond within one month as required by GDPR. Your account settings export includes product feedback linked to your Vocumi account where applicable.

Weekly digest opt-out (Art. 21 right to object): The weekly activity digest is sent on the basis of legitimate interests (Art. 6(1)(f) GDPR). You can exercise your right to object at any time by disabling the digest in your account settings — no justification required.

Marketing analytics (Art. 7(3) withdrawal): Where you have accepted statistics cookies, withdraw consent at any time via Cookie settings in the site footer (marketing pages). This stops future Matomo tracking; it does not delete data already collected before withdrawal.

Product telemetry (Art. 21): In-app feature-adoption telemetry is processed on legitimate interests (Art. 6(1)(f) GDPR). To object, contact contact@vocumi.com. Telemetry rows older than 60 days are deleted automatically.

10. Security

We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, or disclosure — including encryption in transit and at rest, access controls, and secure credential handling.

For a full overview of our security practices and how to report a vulnerability, see our Security page.

No method of transmission over the internet is 100% secure. If you suspect a security incident affecting your data, please contact us immediately at contact@vocumi.com.

11. Children's Privacy

The Service is intended for professional use by adults. We do not knowingly collect personal data from individuals under the age of 16. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify registered users of material changes via email at least 14 days before the changes take effect. The “Last updated” date at the top of this page reflects the current version. Continued use of the Service after changes constitutes acceptance of the updated Policy.

13. Contact & Data Protection Enquiries

For any privacy-related questions, requests, or complaints, contact us:

vocumi UG (haftungsbeschränkt)

Schönhausenstr. 41, 28355 Bremen, Germany

Register court: Amtsgericht Bremen

Register number: HRB 42762 HB

E-mail: contact@vocumi.com

We do not currently have a formally appointed Data Protection Officer (DPO) as we do not fall within the mandatory DPO categories under Art. 37 GDPR. Privacy inquiries are handled directly by the company management.