1. Controller (Verantwortlicher)
Marvin Krüger
Koppenstr. 54
10243 Berlin
Germany
Email: info@mkgames.org
2. Scope and Principles
This privacy policy applies to the application VJ Stage for Apple platforms (iOS and macOS).
Privacy-by-design: The app is designed to minimize data processing.
- No user accounts / no login
- No advertising SDKs
- No third-party analytics tools
- No user tracking across apps or websites owned by other companies
- No App Tracking Transparency (ATT) tracking; no use of IDFA
- No cloud sync backend operated by us
- Subscriptions are handled directly by Apple via StoreKit (no third-party subscription SDK)
This privacy policy is intended to match the information provided in the App Store privacy labels for this app. The information in this privacy policy corresponds to the data categories disclosed in the App Store “Privacy Nutrition Labels”.
The app does not operate its own backend servers for user data processing. Unless explicitly stated otherwise below, data processing occurs locally on your device or by Apple as part of iOS, macOS, and App Store services.
We do not sell personal data and we do not share personal data with third parties for advertising purposes.
3. Data Processing Details
3.1 In-App Purchases & Subscriptions (Apple StoreKit)
The app offers optional paid features and subscriptions (VJ Stage PRO). Payments are processed exclusively by Apple via the App Store and StoreKit. We never receive or store payment details such as credit card numbers.
Subscription status and purchase restoration are handled on-device using Apple’s StoreKit 2 APIs. We do not use a third-party subscription management service (such as RevenueCat).
In this context, Apple may process:
- Your Apple ID–linked purchase history for this app
- Product identifiers and subscription status
- Transaction and receipt information for validation
- Technical metadata necessary to operate App Store billing and fraud prevention
Apple acts as an independent controller for App Store billing and platform services under its own privacy framework.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
Apple Privacy Policy: www.apple.com/legal/privacy
3.2 Media Import (Files / Videos / Images) – Local Processing
The app allows you to import media (e.g., video and image files) from locations you select (such as the Files app, Finder, or other provider apps via the system file picker).
Imported media is processed locally on your device to provide the app’s functionality. We do not upload your imported files to our servers.
Depending on your workflow, the app may create temporary local copies or caches on your device to enable smooth playback, rendering, or export. These temporary files remain on-device and can be removed by deleting the project within the app or by uninstalling the app.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and § 25(2) No. 2 TDDDG (necessary for providing the requested service).
3.3 Camera Access (Optional) – Local Only
If you choose to use live camera or capture-device clips, the app may request access to your device camera. Camera input is processed locally on your device for live visuals. We do not collect, analyze, or transmit camera footage to us.
You can revoke camera access at any time in iOS Settings or macOS System Settings.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and/or Art. 6(1)(a) GDPR (consent via system permission prompt, where applicable).
3.4 Microphone Access (Optional) – Local Only
If you enable audio-reactive visuals, the app may request access to your device microphone. Audio is analyzed locally on your device to drive visuals. We do not record, store, or transmit microphone audio to our servers.
You can revoke microphone access at any time in iOS Settings or macOS System Settings.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and/or Art. 6(1)(a) GDPR (consent via system permission prompt, where applicable).
3.5 Screen Recording (macOS, Optional) – Local Only
On macOS, if you choose to analyze system audio output for audio-reactive visuals, the app may request Screen Recording permission. This permission is used solely to capture system audio output for local analysis. We do not receive or store screen recordings on our servers.
You can revoke this permission at any time in macOS System Settings → Privacy & Security → Screen Recording.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and/or Art. 6(1)(a) GDPR (consent via system permission prompt, where applicable).
3.6 Local Network, NDI, OSC, and Ableton Link – On Your Network Only
The app can use your local network for live performance features you enable, including:
- NDI – publish or receive video streams on the same Wi‑Fi / LAN
- OSC – receive Open Sound Control messages for remote show control (e.g., from TouchOSC or Companion on the same network)
- Ableton Link – tempo synchronization with other Link-enabled apps on the same network
- AirPlay – route output to compatible receivers via Apple’s AirPlay framework
These features send data directly between your device and other devices or apps on your local network. We do not operate servers that receive, store, or analyze this traffic. Network peers you connect to are under your control.
On macOS, the app may also publish video locally via Syphon to other apps on the same Mac. Syphon sharing stays on your device and is not transmitted to us.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and/or Art. 6(1)(a) GDPR (consent via local network permission prompt, where applicable).
3.7 Bluetooth MIDI (iOS, Optional) – Local Only
On iOS, if you connect Bluetooth MIDI controllers or keyboards, the app may use Bluetooth to discover and communicate with those devices. MIDI data is processed locally on your device to control clips, parameters, and performance features. We do not receive or store MIDI performance data on our servers.
You can manage Bluetooth permissions and paired devices in iOS Settings.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and/or Art. 6(1)(a) GDPR (consent via system permission prompt, where applicable).
3.8 Export of Projects and Reports – To Your Device Only
The app allows you to save and export projects (e.g., .vjstudio packages) and validation reports.
Exports are saved only to locations you choose on your device (e.g., Files, Finder, iCloud Drive if you select it).
We do not receive exported content.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
3.9 Local App Data (Projects, Compositions, Settings)
VJ Stage stores compositions, projects, media library references, MIDI/OSC mappings, and app settings locally on your device. This data does not leave the device unless you explicitly export or share it yourself. We do not have access to this data.
Legal basis: § 25(2) No. 2 TDDDG (necessary for providing the requested service).
3.10 Diagnostics & Crash Reporting (Apple)
Apple may collect diagnostic data and crash reports depending on your device settings. For App Store and platform services (including diagnostics), Apple typically acts as an independent controller under its own privacy framework.
Depending on your settings, diagnostics may include:
- device model
- OS version
- crash logs and stack traces
We do not receive personally identifiable crash data from Apple. Where Apple provides diagnostics to developers, it is typically provided in aggregated and/or pseudonymized form and is used solely to improve stability and fix bugs.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in ensuring technical stability, security, and error-free operation of the app.
3.11 Support Communication
If you contact us via email, we process your email address and message content to handle your request. Data subject requests under GDPR can also be submitted via info@mkgames.org.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in customer support) and, where applicable, Art. 6(1)(b) GDPR (contract-related inquiries).
3.12 External Links (e.g., Apple Standard EULA)
The app may include links that open external websites (for example, Apple’s Standard EULA or legal information pages). When you open an external link, you leave the app. The provider of the linked site is responsible for data processing on that site. We do not control and are not responsible for their content or privacy practices.
Depending on your device and network configuration, opening external links may result in the external provider receiving technical data (such as your IP address, device/browser information, referrer, and timestamp) as part of normal web delivery.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing required legal information and improving transparency).
3.13 Automated Decision-Making
No automated decision-making within the meaning of Art. 22 GDPR takes place.
Right to Object (Art. 21 GDPR)
Where processing is based on legitimate interests, you have the right to object at any time for reasons arising from your particular situation.
Contact: info@mkgames.org
4. Data We Do NOT Collect
- Advertising identifiers (IDFA)
- Tracking under App Tracking Transparency (ATT)
- Precise GPS location data
- Contacts
- Biometric or health data
- Behavioral tracking or profiling
- Third-party analytics (Firebase Analytics, AppsFlyer, Mixpanel, etc.)
- Third-party crash reporting SDKs (e.g., Sentry, Crashlytics)
- Third-party subscription SDKs (e.g., RevenueCat)
- Meta SDK and similar advertising/attribution SDKs
- Apple Search Ads attribution data (we do not integrate ASA attribution in this app)
- Photos library access (the app uses the system file picker instead)
- YouTube import / YouTube account access
- User accounts / login
- Email capture inside the app (no newsletter signups or in-app forms)
- Cloud synchronization operated by us
Note: Camera, microphone, local network, Bluetooth, and (on macOS) screen recording permissions are used only to enable features you actively request.
5. Third-Party Services and Embedded Technologies
- Apple – App Store purchases (StoreKit), platform services, AirPlay, optional diagnostics
- NDI SDK (Vizrt Group) – local network video streaming libraries embedded in the app; no data is sent to us
- Syphon (macOS) – local inter-app video sharing on your Mac
- Ableton Link – local network tempo sync between apps you choose to connect
- External websites you open via links – e.g., Apple Standard EULA pages or other legal information
These technologies operate under their respective privacy frameworks. Local-network features (NDI, OSC, Link, Syphon) do not route data through servers operated by us.
Apple Privacy Policy: www.apple.com/legal/privacy
6. International Data Transfers
Apple may process data on servers outside the EU/EEA, in particular in the United States. Transfers are based on appropriate safeguards such as Standard Contractual Clauses (Art. 46 GDPR), adequacy decisions where applicable, and/or other valid transfer mechanisms under GDPR (for example the EU-U.S. Data Privacy Framework, where applicable).
- Apple Inc. (USA) – App Store / platform services
Local-network features (NDI, OSC, Ableton Link, Syphon) transmit data only between devices and apps on networks you control. External websites opened via links may also process data outside the EU/EEA depending on the provider.
7. Data Retention
- Support emails: up to 12 months, unless a longer retention is required to resolve a request or due to legal obligations
- Subscription data (Apple): retained by Apple for the duration of the subscription lifecycle and as needed for billing, purchase restoration, and fraud prevention under Apple’s policies
- Local app data (projects/compositions): stored on-device until deleted by you or upon uninstall
- Temporary media caches: stored on-device as needed for app functionality; removable by deleting projects and/or uninstalling
Data may be retained longer where necessary to establish, exercise, or defend legal claims, or where statutory retention obligations apply.
8. Your Rights
You have rights under GDPR including access, rectification, erasure, restriction of processing, data portability, and the right to lodge a complaint with a supervisory authority.
Supervisory authority (Berlin):
Berliner Beauftragte für Datenschutz und Informationsfreiheit
www.datenschutz-berlin.de
9. Children
The app is not directed to children under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children.
10. Security
We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Access to any personal data is restricted to the extent necessary and protected using industry-standard safeguards. However, no method of transmission or storage is 100% secure.
11. Changes
This policy may be updated when the app or legal requirements change. The current version is available within the app and/or on our website.