Legal
Privacy Policy
Last updated: · effective immediately for all users of cueradar.app and CueRadar for macOS.
Plain-language summary
- Your music library stays on your Mac. CueRadar never uploads files or fingerprints them in a cloud.
- Anything the app sends back is opt-in, off by default, and never includes filenames or audio.
- The website uses first-party analytics (Matomo, self-hosted in Denmark) to count visits. No third-party trackers, no advertising IDs.
- If you sign up for the newsletter, your email is used only to send release announcements. Unsubscribe in one click.
- All EU GDPR rights apply: access, correction, deletion, portability, complaint. Email thomas@cueradar.app.
1. Who is the data controller?
The "data controller" — the legal entity responsible for your data under the EU General Data Protection Regulation (GDPR) — is:
Hosting.gl ApS
Aarhus, Denmark
Contact: thomas@cueradar.app
CueRadar is a product operated by Hosting.gl ApS, a Danish private limited company. Thomas Gravesen is the responsible person you reach when you exercise any of the rights described in section 5.
2. What data we collect, and why
2.1 Visiting cueradar.app
The web server records standard request metadata for every page view: IP address, user agent, referrer, and the path requested. This is needed to serve the page and to detect abuse — lawful basis: Article 6(1)(f) GDPR, legitimate interest. Raw server logs are kept for 14 days and then deleted.
We also use Matomo, a privacy-friendly first-party analytics tool we self-host at statistics.hosting.gl, to count visits and understand which pages are useful. Matomo is configured to:
- Anonymise the last byte of your IP address before storing it.
- Respect the Do-Not-Track browser header.
- Store data only on infrastructure operated by us in the EU (Denmark).
- Use first-party cookies only — no third-party trackers, no advertising IDs.
See the Cookie Policy for the exact cookies used and how to opt out.
2.2 Using the CueRadar macOS app
The CueRadar app runs entirely on your Mac. The audit — quality scoring, fingerprinting, key detection, device compatibility — reads files from your local disk and writes results to a local database inside the app's container. No audio and no library metadata leave your Mac during a scan.
The app supports an opt-in anonymous usage signal that's off by default. If you choose to enable it, the app may report aggregate, non-identifying usage information to help us improve the product. It never includes filenames, audio, or anything that identifies you or your tracks. You can disable it at any time. Lawful basis: Article 6(1)(a) GDPR, your consent.
2.3 Newsletter signup
If you enter your email in any signup form on cueradar.app, we store the email address, the source page, the IP address at signup time (for spam protection), and the consent timestamp. The address is used only to send release announcements and occasional development updates — usually a few times a month, never more than once a week.
Lawful basis: Article 6(1)(a) GDPR, your consent. Every email contains a one-click unsubscribe link. Unsubscribing removes you from the list and stops all future sends within 24 hours.
2.4 Contacting us by email
If you email thomas@cueradar.app or support@cueradar.app, your message and email address are stored on the mail server until the conversation concludes plus a reasonable record-keeping period (typically 24 months) — lawful basis: Article 6(1)(f), legitimate interest in being able to recall earlier support conversations.
2.5 Downloading the DMG
Downloads are logged with timestamp, version, IP address truncated to the first three octets (a /24 network), and user agent. This is used to count total downloads per release and to detect abuse. Lawful basis: Article 6(1)(f), legitimate interest. Logs retained for 90 days.
3. Who we share data with
We don't sell, rent, or share your data with advertisers, brokers, or any third parties for marketing purposes. Ever.
The infrastructure that delivers the service is operated by us. There are no third-party data processors:
- Hosting: an EU-based VPS runs the application and database under our control.
- Email delivery: self-hosted mail infrastructure operated by us. Transactional and newsletter emails are sent directly — there is no third-party SMTP service involved.
- Analytics: Matomo, self-hosted on infrastructure we operate. No third-party analytics services are used.
All data stays within the EU/EEA. No personal data is transferred to countries outside the EU/EEA.
4. How long we keep your data
| Data | Retention |
|---|---|
| Web server logs | 14 days |
| Matomo analytics | 13 months |
| App usage signal (if opted in) | 13 months, or until you ask for deletion |
| Newsletter subscription | Until you unsubscribe, then 30 days for opt-out audit log |
| Support emails | 24 months from last reply |
| Download logs | 90 days |
5. Your rights under the GDPR
You have the right to:
- Access — request a copy of all data we hold about you.
- Correction — ask us to fix anything inaccurate.
- Deletion — ask us to delete your data ("right to be forgotten").
- Portability — get your data in a structured, machine-readable format.
- Object — to processing based on legitimate interest.
- Withdraw consent — at any time, for any consent-based processing (newsletter, telemetry).
- Complain — to the Danish Data Protection Agency (Datatilsynet), datatilsynet.dk/english, or to your local EU supervisory authority.
To exercise any of these rights, email thomas@cueradar.app. We respond within 30 days — almost always within a few days.
6. Children
CueRadar is not directed at people under 16, and we don't knowingly collect data from anyone under 16. If you believe a minor has provided us with data, email thomas@cueradar.app and we'll delete it.
7. Cookies
See the Cookie Policy for a full breakdown of cookies used on cueradar.app and how to disable them.
8. Security
Data in transit is always encrypted with TLS 1.3 (cueradar.app is HTTPS-only). Data at rest sits on disks encrypted at the host level. The CueRadar app's Sparkle auto-updater verifies every DMG with an ed25519 signature before installing — we cannot push you an unsigned update even if we wanted to.
9. Changes to this policy
If we change how we handle your data, we'll update the "Last updated" date at the top. For changes that expand what we collect or who we share with, we'll notify you via the newsletter (if you're subscribed) and in-app on the next release that touches data collection.
10. Contact
Questions, complaints, or exercise of any right above: thomas@cueradar.app. Replies come from Thomas Gravesen directly.