Privacy Policy
How Manouke handles personal data during the beta.
1. Controller and contact
Manouke is a beta music web application operated from the Czech Republic. Manouke determines why and how personal data is processed in the service.
During the beta, privacy, access and account-deletion requests are handled through the dedicated Privacy / account request form. When possible, submit the request while signed in to the account concerned.
2. Data we may process
The exact data depends on which Manouke features you use.
- Account data: login name, display name, email address, password hash, activation/reset state and account status.
- Profile and preferences: profile image/avatar and display/player preferences.
- Music and user content: songs, grilles, chord voicings, rhythms, instructions and other material you create, publish or share.
- Teaching and learning data: teacher/student relationships, invitations, assignments, assigned repertoire, targets and practice summaries made available through those features.
- Ensemble data: ensemble names, ownership, roles, memberships, invitations, repertoire, rehearsal and part-assignment state.
- Practice data: practice sessions, active time, completion state and related grille identifiers.
- Sync data: session/member state, session codes, timing/transport state, readiness and technical client identifiers needed to reconnect devices.
- Internal product analytics: page/player events, timestamps, grille identifiers and, for signed-in activity, the relevant account identifier.
- Bug reports: text you submit, optional screenshots, source page, browser user agent, viewport and build context.
- Security/verification data: session and CSRF data and, on login/registration, reCAPTCHA verification data including the verification token and IP address sent to Google for verification.
3. Why we process data
- To create and operate your account and provide requested app features — performance of the service relationship or steps requested before it.
- To protect accounts, prevent abuse, maintain reliability, diagnose bugs and understand product usage — legitimate interests in operating and securing Manouke.
- To publish or share content according to the visibility choices and actions you make in the service.
- Where a feature specifically asks for consent, processing may rely on that consent. Consent can be withdrawn for future processing.
- Where required, to comply with legal obligations or establish, exercise or defend legal claims.
4. Who may receive data
We use service providers needed to run Manouke, such as hosting/database and email infrastructure. Login and registration use Google reCAPTCHA. Video features may load the YouTube iframe API. A PayPal page is opened only when you choose the donation action. Some interface resources may be loaded from external CDNs.
If you join teaching or ensemble features, information needed for that relationship is visible to the relevant teacher, student, ensemble owner/leader or member as the feature indicates. Public content is visible to anyone; private/shared content is visible to the recipients you or an authorized leader select.
5. International processing
Some external providers may process technical or account-related data outside the European Economic Area. Where data-protection law requires a transfer mechanism, the relevant provider is expected to use an appropriate lawful safeguard.
6. Retention
Account and private feature data is kept while it is needed to provide the service and for a reasonable period needed for security, integrity, dispute handling or legal obligations. During beta, exact retention periods may differ by dataset while operational rules are being finalized.
Public or collaborative music content may need to be removed, anonymized or reassigned rather than simply deleted if deletion would break a public catalogue or another user’s legitimate collaborative record. Requests are reviewed case by case and applicable legal rights take priority.
7. Cookies and browser storage
Manouke uses an essential PHP session cookie for login/session security and CSRF protection. The app also uses localStorage for display/player preferences, chord-display preferences and a Sync client identifier/panel position, and sessionStorage for temporary Sync session information such as the active session and host recovery token in the current browser tab.
Manouke does not intentionally use advertising or behavioural-marketing trackers. Google reCAPTCHA and optional third-party embeds/services may use their own cookies or storage under their own policies.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. Where processing is based on consent, you may withdraw it for the future. You may also complain to the Czech Office for Personal Data Protection (ÚOOÚ).
9. Children and teaching features
Manouke is not specifically directed at children. Where processing is based on consent and an information-society service is offered directly to a child, the applicable consent age matters. In the Czech Republic a child can give that consent from age 15; below that age parental authorization may be required.
Teachers and ensemble leaders should avoid placing unnecessary sensitive personal information in assignment notes, ensemble names, invitations or other shared fields.
10. Security and beta status
We use reasonable technical and organizational measures to protect the service, but no internet service can guarantee absolute security. Beta features may change and additional privacy information may be added as the service and its infrastructure mature.