Privacy Policy

Version 2026-10-05 · In effect since 5 October 2026

This policy explains what personal data schickit processes, why, for how long, and what rights you have. It covers the website at schickit.com, the waitlist, the link page where you listen to a track someone sent you, the studio in the browser, and the schickit app for iOS and Android.

schickit is in a closed beta. It is free, and accounts are by invitation.

1. Who is responsible

The controller under the General Data Protection Regulation (GDPR) is:

Temprana UG (haftungsbeschränkt), An der Stadtmauer 7, 89522 Heidenheim an der Brenz, Germany

Privacy questions and requests: privacy@schickit.com

Full provider details are in the legal notice.

We have not appointed a data protection officer, because we are not legally required to. Please use the address above for anything about your data.

2. The short version

  • schickit is a private way to send unreleased music. You upload a track, get a private link, and send it to someone. They listen in the browser without an account. You see whether and how far they listened.
  • Nothing on schickit is public. There are no public profiles, no search across other people's tracks, and no feed.
  • In the beta we use no advertising, no advertising pixels, no third-party analytics, and no tracking across websites. We show no cookie banner because we set no cookies that need consent.
  • On the link page we set no cookies and use no browser storage at all.
  • We do not keep the IP address of someone who opens a link. We use it to answer the request, to compute a short-lived device identifier and an approximate location (city and country), and to limit the number of requests for up to a minute. It is not written to our database or to logs.
  • We do not sell personal data.
  • Nobody at schickit listens to your tracks.

3. If someone sent you a link

This section is for you if you opened a schickit link and have no account. You never signed up for anything, so we keep this as small as we can.

3.1 What we process when you open a link

DataWhat it isWhy
Device identifierA short value computed on our servers from your IP address, your browser's user-agent text, the link you opened, and a secret value that changes every day. We store only the result, not the IP address and not the user-agent.To tell a reload from a second device, to count how many devices opened a link, and to pause a link that is opened by more devices than the sender allowed.
Approximate locationCity and country, derived from your IP address by our network provider at the moment of the request.The sender sees roughly where a link was opened.
Listening progressWhen you opened the link, how often, the furthest position you reached in the track, whether you finished it, and whether you downloaded it (if the sender allowed downloads). Individual playback events: open, play, progress signals during playback, seek, complete, download.The sender sees whether and how far the track was heard. This is the purpose of the product.
CommentsThe text you write, the name you type in, the position in the track, and the time.Feedback to the sender. Writing a comment is optional.
Password attemptsIf a link is protected by a password, we count failed attempts for a short time, keyed by a fingerprint of the address they came from. The password you type is checked and not stored.To slow down guessing.
Technical request dataIP address, time, requested address, browser type, as they arrive with every request on the internet.To deliver the page and the audio, and to protect the service against abuse (rate limiting). See section 12 on logs.

We do this without cookies, without local storage, and without any other storage on your device. The device identifier is computed on our side from data your browser sends with every request.

3.2 What this means in practice

  • The secret value changes every day. The same device opening the same link on the next day produces a new identifier. We cannot follow a device from day to day, and we cannot link it across different links.
  • Because of that, the number of "opens" and "devices" a sender sees can be slightly higher than the real number of people. We accept this. The alternative would be to recognise you for longer.
  • The link page loads nothing from third parties. No advertising pixel, no analytics script, no external fonts.
  • When you follow a link from the link page to another website, your browser does not tell that website which schickit link you came from.

3.3 Who sees it

The sender of the link sees, for each listener: the name you entered in a comment (if any), city and country, number of opens, furthest position, whether the track was downloaded, first and last time seen, and your comments. The sender does not see your IP address or the device identifier.

Comments you write on a link are visible to the sender and to other people who open the same link.

3.4 How long we keep it

  • The listener record for a link (device identifier, city, country, progress): deleted 90 days after the link ended (expired or turned off). For a link without an end date: 90 days after you last opened it.
  • Individual playback events: deleted after 13 months.
  • Comments: kept with the track until the sender deletes the comment, the track, or the account. After the listener record is deleted, the comment stays, with the name you typed.
  • Password attempt counters: minutes to one hour.

3.5 We usually cannot tell who you are

We do not know your name or your e-mail address, and we do not keep your IP address. The device identifier changes every day. For this reason we normally cannot find "your" data when you ask us, and we cannot honestly promise to delete or hand over data we cannot match to you.

If you want to exercise your rights, write to privacy@schickit.com and give us details that let us find the record: the link you opened, the date and approximate time, the city, and the name you used in a comment. If we can match a record with reasonable certainty, we will act on your request. A comment you wrote can be removed on request in the same way. Without such details the data is deleted automatically after the periods above.

3.6 Legal basis

We process this data on the basis of legitimate interests (Art. 6(1)(f) GDPR). The interests are: the sender's interest in knowing whether a private, unreleased track was heard and in keeping it from spreading further than intended; and our interest in providing this service and protecting it against abuse. We keep the processing limited: no IP address kept beyond the request and short-lived rate limiting (section 12), location only at city level, a daily-rotating identifier, fixed deletion periods, and no third parties on the page.

You can object to this processing at any time on grounds relating to your particular situation (section 18).

3.7 If you save a track to your own library

If you choose "Save to my library" and sign in, the track is linked to your account. From then on section 6 applies to you as an account holder. The sender sees how many times a link was saved, not by whom.

4. The website schickit.com

When you visit schickit.com, our network provider processes your IP address and technical request data to deliver the page and to protect it against abuse. The website sets no cookies, uses no analytics, and loads nothing from third-party servers. Fonts are served from our own domain.

Legal basis: legitimate interests in operating a secure website (Art. 6(1)(f) GDPR).

5. The waitlist

If you join the waitlist, we process:

  • your e-mail address;
  • optionally, what you make and which music software you use, if you tell us;
  • whether you came from a link page or directly;
  • the time of your request and of your confirmation.

We send you one e-mail with a confirmation link (double opt-in). Only a confirmed entry counts. We use the list to invite people to the beta. We do not store your IP address, user-agent, or referrer with the entry. To prevent abuse of the form we count requests per network address and per e-mail address for a short time.

Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time by writing to privacy@schickit.com; we then delete your entry. Withdrawal does not affect processing before it.

Storage: unconfirmed entries are deleted 7 days after the last confirmation e-mail. Confirmed entries are kept until you are invited or ask us to delete them, at the latest 12 months after you confirmed.

6. Your account

6.1 Registration and profile

To create an account we process your e-mail address and, if you enter one, a display name. We also store your plan (in the beta: free), your language setting, and the times your account was created and changed. Your display name is shown to recipients of your links and next to your comments.

When you register, we record that you accepted the Terms and were shown this policy: which version, in which language, when, and on which surface (studio or app).

Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR). For the acceptance record: our legitimate interest in being able to prove which version applied (Art. 6(1)(f) GDPR).

6.2 Signing in

You sign in with a code or link we send to your e-mail address. You can additionally set a password. Passwords are stored only in hashed form by our authentication provider.

For each sign-in we keep a session record: a hashed token, how you signed in, when the session was created, last used, and when it expires. Sessions expire after 30 days without use. We pass your IP address to our authentication provider during sign-in so that it can limit the number of attempts per address. We count failed and repeated attempts for a short time to protect accounts.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in account security (Art. 6(1)(f) GDPR).

6.3 Second factor

You can protect your account with an authenticator app (TOTP). Our authentication provider stores the secret needed to verify your codes. If you lose your second factor, you can start a recovery; we store when it was requested, when it becomes effective, and whether it was cancelled or completed, and we send you e-mails about it.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

6.4 Deleting your account

You can delete your account in the studio or the app. All your links stop working immediately. For 30 days you can restore the account by signing in. After 30 days we delete your tracks, audio files, links, playlists, and the comments on your tracks, delete your account at our authentication provider, and remove your e-mail address and name from our records. Comments you wrote on other people's tracks stay, without your name.

7. Uploads and audio files

When you upload a track we store the original file, the versions we create for playback, waveform and analysis data, and the details you give (title, version label), plus technical details such as format, duration, and file size. Files are stored with our storage provider and are reachable only through your private links or your own account.

Audio files and titles can contain personal data, for example your artist name or your voice. We process them only to provide the service.

Nobody at schickit listens to your tracks. If a track is reported to us, we assess the report, the track's details (title, file name, duration, upload date, number of links and listeners), and your statement.

If you delete a track, we delete its files from storage shortly afterwards, normally within hours.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

8. Links and listening statistics

For each link you create we store its settings: label, optional password (hashed), whether downloads are allowed, expiry date, device limit, and whether it was turned off or paused.

The statistics you see are built from the data described in section 3. We are the controller for this processing. You receive the statistics about your own links.

A link pauses automatically when more devices open it within 24 hours than its device limit allows. This protects your music; it is not a decision about a person.

People. If you add someone to your people, or someone adds you, you can send each other tracks directly, and each of you sees the other's name and how far they've listened to what you send them. Either of you can remove the other at any time.

Please use the statistics only to understand how your music was received, and tell people you send links to that you can see whether they listened.

9. Comments

Comments from account holders are stored with your display name, the position in the track, the text, and the time. The owner of the track and the people with access to it can read them. You can delete your own comments; the owner of a track can delete any comment on it.

Comments from recipients without an account are described in section 3.

Legal basis: performance of the contract for account holders (Art. 6(1)(b) GDPR); legitimate interests for recipients without an account (Art. 6(1)(f) GDPR).

10. Reports and privacy requests

If you report content to abuse@schickit.com, we process your e-mail address, what you tell us, the link or track concerned, and the steps we take (acknowledgement, decision, removal, notice to the uploader, appeal). We keep your contact details and the text of your report for 3 years after the case is closed, then delete them.

If you write to privacy@schickit.com to exercise your rights, we process your request and the data needed to answer it, and keep the correspondence for the same period to be able to show how we handled it.

Legal basis: compliance with legal obligations (Art. 6(1)(c) GDPR) and our legitimate interest in handling reports and being able to demonstrate what we did (Art. 6(1)(f) GDPR).

11. E-mails

We send only e-mails needed to run the service: sign-in codes and links, confirmation of your registration or waitlist entry, security notices about your account (for example recovery or deletion), and answers to your messages. We send no newsletters and no advertising.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for the waitlist confirmation, your consent (Art. 6(1)(a) GDPR).

12. Logs and security

Our servers process your IP address with every request. We use it to deliver the response, to limit the number of requests per address, and to derive city and country on the link page. Rate-limit counters are kept for seconds up to one hour. Counters that we store for longer than a minute are keyed by a fingerprint of the address, not the address itself.

For the link page, the API, audio delivery, and the endpoint that receives playback events, we have switched off request logs, so that private link addresses and the requests of listeners are not written to logs. Our own log lines record technical facts such as the type of request, status, timing, and internal identifiers. For the studio, which only signed-in account holders use, request logs are kept for up to 7 days; they can contain technical request data such as the requested address, time, status, and network metadata.

When our operators act on accounts or content with elevated rights, we record who did what, when, and why. These records are deleted after 13 months.

Operators cannot play tracks, cannot see lists of listeners, cannot access original files, and cannot sign in as a user. E-mail addresses are masked by default in the operator console.

Legal basis: legitimate interests in a secure and reliable service (Art. 6(1)(f) GDPR).

13. The app

The app for iOS and Android processes the same account, track, link, and comment data as the studio.

  • Storage on your device: your session tokens are kept in the protected storage of your device (Keychain on iOS, Keystore on Android). We also store two small markers there: that you have seen the introduction and the name prompt.
  • Files: when you pick a file to upload, the app gets access to that file only. A temporary copy is kept in the app's cache for the upload.
  • Permissions: the app plays audio in the background. It does not ask for the microphone, camera, contacts, location, or advertising identifiers. It sends no push notifications.
  • Links: the app can open schickit links and sign-in links directly.
  • No analytics or advertising software is built into the app.

If you download the app from the Apple App Store or Google Play, Apple or Google process data about the download as independent controllers. Their privacy policies apply.

14. Cookies and local storage

We use only storage that is strictly necessary for a function you asked for. We use no cookies for analytics, advertising, or tracking. This is why there is no cookie banner.

SurfaceWhat is stored on your device
Link pageNothing. No cookies, no local storage, no session storage.
schickit.com and waitlistNothing.
StudioThe cookies in the next table, and one session-storage entry that remembers keyboard focus while you reorder a playlist. It is removed as soon as it is read.
AppSession tokens and two markers in the device's protected storage (section 13).

Cookies in the studio. All are encrypted, not readable by scripts, sent only over HTTPS, and limited to the studio's own host.

CookiePurposeLifetime
__Host-ts_studioKeeps you signed in.30 days
__Host-ts_studio_anfrageBinds a sign-in request to the browser that started it. Contains your e-mail address and, during registration, your name.15 minutes
__Host-ts_studio_mfaCarries the sign-in through the second-factor step.10 minutes
__Host-ts_studio_einrichtenLets you set up a second factor right after signing in.10 minutes
__Host-ts_studio_restoreLets you restore an account that is scheduled for deletion.10 minutes
__Host-ts_studio_speichernKeeps a "Save to my library" code while you sign in.10 minutes
__Host-ts_studio_zurueckReturns you to the page you were on after you confirm your identity again.15 minutes

Legal basis for storing and reading this information: it is strictly necessary to provide the service you requested (Section 25(2) no. 2 of the German TDDDG). The processing of the data itself is based on Art. 6(1)(b) GDPR.

15. Who receives data

We use the following service providers as processors. They process data on our instructions under a data processing agreement.

RecipientWhat forDataWhere
Cloudflare, Inc., USANetwork, servers (Workers), storage of audio files (R2), short-lived state (KV, Durable Objects), queues, audio conversion (Containers), sending and forwarding e-mailAll data described in this policy passes through or is stored on Cloudflare systems, including IP addresses in transit and audio filesWorldwide network; see section 16
Supabase (contracting entity: Supabase Pte. Ltd., Singapore), with Amazon Web Services as its hosting providerDatabase and authenticationAccount data, sign-in data, tracks' details, links, listener records, playback events, comments, reports, waitlistFrankfurt, Germany (AWS region eu-central-1)
Google Workspace (Google Ireland Limited, Dublin, Ireland)Mailboxes of our operators, which receive messages sent to hello@, privacy@ and abuse@Your message and e-mail addressIreland and other Google locations; see section 16

Other recipients:

  • Senders receive the listening statistics and comments for their own links (section 3.3).
  • Recipients of a link see the track's title, the sender's display name, and comments on that link.
  • Apple and Google, if you get the app from their stores, as independent controllers.
  • Authorities and courts, where we are legally obliged to disclose data, and in cases of serious illegal content that we must report.

We do not share data with advertisers, data brokers, or analytics providers.

16. Transfers outside the EU

Our database is in Germany. Some processing takes place outside the European Economic Area:

  • Cloudflare operates a worldwide network. A request is handled by a data centre near the person making it, which can be outside the EU, especially when a recipient opens a link from outside the EU. Cloudflare, Inc. is based in the USA and is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision. In addition, the standard contractual clauses of the European Commission are part of our agreement with Cloudflare.
  • Supabase stores our data in Frankfurt. Our contract partner, Supabase Pte. Ltd., is based in Singapore, and support or maintenance access from outside the EU cannot be excluded. For this, the standard contractual clauses of the European Commission are part of our agreement with Supabase.
  • Google may process e-mail you send us on servers outside the EU, including in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework, and the standard contractual clauses of the European Commission are part of our agreement with Google.

You can ask us for a copy of the safeguards at privacy@schickit.com.

17. How long we keep data

DataPeriod
Account (e-mail address, name, settings)Until you delete the account, plus the 30-day restore period
Tracks, audio files, links, playlistsUntil you delete them or your account. Files are removed from storage shortly after deletion
Sign-in sessionsExpire after 30 days without use
Recovery of the second factorUntil the account is deleted
Record of accepted termsUntil the account is deleted
Listener records of a link (device identifier, city, country, progress)90 days after the link ended; for links without an end date, 90 days after the listener's last visit
Playback events13 months
CommentsUntil deleted by the author (account holders), by the owner of the track, or when the track or the track owner's account is deleted
Waitlist, unconfirmed7 days after the last confirmation e-mail
Waitlist, confirmedUntil invitation or withdrawal, at the latest 12 months after you confirmed
Reports and privacy requests (contact details and text)3 years after the case is closed
Records of operator actions13 months
Rate-limit and password-attempt countersSeconds to one hour
Request logs (studio)Up to 7 days
Backups of the database30 days; deleted data disappears from backups within that time

Where the law requires us to keep data longer, for example under commercial or tax law, we keep it for that period and restrict its use.

18. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have data erased (Art. 17);
  • have processing restricted (Art. 18);
  • receive data you gave us in a portable format (Art. 20);
  • object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21). We will then stop unless we have compelling legitimate grounds;
  • withdraw consent at any time, with effect for the future (Art. 7(3)).

To use these rights, write to privacy@schickit.com. We answer within one month. We may ask for information to confirm that a request comes from the person concerned.

If you are a recipient without an account, please read section 3.5 on what we can and cannot do.

Account holders can do much of this themselves: change the display name, delete comments, tracks, and links, and delete the account.

19. Right to complain

You can lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work. The authority responsible for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany — www.baden-wuerttemberg.datenschutz.de, poststelle@lfdi.bwl.de

20. No obligation to provide data, no automated decisions

You are not required by law to give us any data. Without an e-mail address we cannot create an account or a waitlist entry. You can listen to a link without giving us any information beyond what your browser sends.

We make no decisions based solely on automated processing that have legal or similarly significant effects on you (Art. 22 GDPR). We do not combine your data across different links or different senders, and we do not use it for advertising. What a sender sees about the listeners of their own link is described in sections 3 and 8.

21. Children

schickit is not directed at children. You must be at least 18 years old to create an account or join the waitlist. We do not knowingly open accounts or waitlist entries for anyone under 18. The link page does not ask for a listener's age.

22. No advertising and no tracking in the beta

During the beta we do not measure visits or behaviour with analytics tools, do not run advertising, and do not pass data to advertising platforms. If this changes, we will update this policy first, and ask for your consent where the law requires it. The link page stays free of third parties.

23. Changes to this policy

We update this policy when the service or the law changes. Every version has a date. The current version is always at schickit.com/legal/privacy. All earlier versions stay available at schickit.com/legal/privacy/history.

If a change affects how we use the data of account holders in a significant way, we will tell you by e-mail or in the product before it takes effect.

The Terms are at schickit.com/legal/terms.