Privacy Policy
Last updated: 24 September 2026
This Privacy Policy applies to opensoundmeter.com, OSM user accounts and the online features of Open Sound Meter.
1. Data controller
Ehrenaudio GmbH
Subbelrather Straße 15a
50823 Köln, Germany
Managing Director: Aleksandra Smokotnina
Email: alex@opensoundmeter.com
2. Website and hosting
Our website, user accounts and Cloud services are hosted on a dedicated server operated by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The server is located in Germany.
When you access our services, the server processes your IP address and technical connection data. Server logs may also contain the time of access, the requested page or file, the response status, and information about your browser and operating system. We use this information to deliver the website and downloads, troubleshoot errors and prevent misuse.
The legal basis is our legitimate interest in operating secure and reliable services (Article 6(1)(f) GDPR).
Server logs are deleted when no longer needed, and no later than one year after collection. Entries needed to investigate a specific security incident may be retained until the investigation is complete.
3. User accounts, devices and updates
When you register, we process your email address, account type, country and any name or company name you provide. Your password is stored only as a hash.
When you sign in through the application, it sends your email address, password for authentication, device identifier (UUID), operating system and version, processor architecture, language and country. Your IP address is also processed.
We use this information to authenticate you, manage your account and activated devices, and assign your licences and subscriptions. The legal basis is performance of our contract with you (Article 6(1)(b) GDPR). Without the information required for these purposes, we cannot provide account-based features.
We retain account data for as long as your account exists. When you remove a device from your account, we delete its server-side association with your account.
When checking for updates, the application sends your operating system type. Your IP address is processed as part of the connection. We use this information to provide suitable updates (Article 6(1)(b) GDPR).
4. Cloud and SPL Logger
When you use Cloud features, we store measurement data associated with your account: audio device information, measurement settings, measurement results including LAeq, LAFmax and LCpeak, timestamps and time zone.
Audio recordings and raw audio data are not transmitted to or stored in the Cloud.
Location data is transmitted only if you enable this feature. The legal basis is your consent (Article 6(1)(a) GDPR). You can disable location transmission at any time and delete previously stored location information together with the associated Cloud data.
We process the other measurement data to provide Cloud features under our contract with you (Article 6(1)(b) GDPR).
You can delete your Cloud data yourself. It is also deleted when you delete your account. After your Cloud subscription ends:
Your data remains stored and available to view for six months.
It remains stored but hidden for a further six months. If you renew during this period, access is restored.
If you do not renew, your data is deleted twelve months after the subscription ends.
Section 10 explains how deletion applies to backups.
5. Purchases and payments
Purchases through our website are handled by Paddle as the reseller and payment provider. Paddle processes contact, billing and payment information as an independent data controller. The relevant Paddle entity is identified during checkout.
We receive information needed to manage licences and provide support, including customer, transaction and subscription identifiers, the product purchased, payment and subscription status, and information about refunds. We do not receive full credit card details.
For purchases through the Apple App Store, Apple processes payments as an independent data controller. When a purchase is linked to your OSM account, we process the purchase verification and status information needed to assign your entitlement.
Our legal bases are performance of our contract and compliance with statutory retention obligations (Articles 6(1)(b) and 6(1)(c) GDPR).
Paddle also processes data outside the European Economic Area. According to Paddle, transfers to countries without an adequacy decision are protected by EU Standard Contractual Clauses and additional safeguards. You can request a copy by contacting privacy@paddle.com.
Apple processes data in the United States and other countries and uses EU Standard Contractual Clauses for international transfers of personal data from the European Economic Area.
For more information, see the Paddle Privacy Policy and Apple Privacy Policy.
6. Contact and emails
When you contact us, we process your contact details, message and any files you choose to attach so that we can respond. For enquiries relating to a contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries, it is our legitimate interest in responding to your request (Article 6(1)(f) GDPR).
Enquiries and related documents are deleted no later than one year after the enquiry is resolved, unless statutory retention obligations or ongoing legal claims require longer retention.
We send necessary account and service messages through our own server infrastructure to fulfil our contract with you. Payment providers also send payment-related messages.
We send marketing emails only with your consent (Article 6(1)(a) GDPR). You can withdraw your consent at any time using the unsubscribe link or by emailing us. We record your consent and any withdrawal and retain these records where necessary to demonstrate compliance or defend legal claims.
7. Cookies and privacy settings
We use essential cookies or similar storage technologies for sign-in, session management and your privacy preferences. The legal bases are Section 25(2), point 2, of the German Telecommunications Digital Services Data Protection Act (TDDDG) and, depending on the purpose, Article 6(1)(b) or 6(1)(f) GDPR.
We use TermsFeed Cookie Consent to manage your choices. Your privacy preferences are stored in your browser so that they can be respected on later visits. This serves our legal obligations concerning consent (Article 6(1)(c) GDPR).
When the externally hosted TermsFeed software loads, your IP address and technical connection data are transmitted to the server delivering it. An additional request includes our website’s domain name. For more information, see the TermsFeed Privacy Policy.
We use Google Analytics with your consent. This covers website analytics and the sharing of data for Google’s own purposes as described in Section 8. You can change your choices at any time through “Cookie settings” in the website footer.
8. Google Analytics
We use Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It helps us analyse page views, download clicks and website use to improve our content and technical compatibility.
The data processed includes pages viewed, interactions, traffic sources, timestamps, pseudonymous identifiers, and browser, operating system and device information. Detailed device and location data collection is enabled. Approximate locations such as country, region or city are derived from IP addresses; GPS coordinates are not collected for this purpose. According to Google, IP addresses from EU visitors are discarded after location information is derived.
We also allow Google to use shared Analytics data to improve its own products and services. Google acts as an independent data controller for this use. Data sharing for aggregated modelling and statistics, technical support, and business recommendations to us is also enabled.
Google Signals and the user-provided data collection feature are disabled. Our Analytics property is not linked to Google Ads.
Event and user data retention is set to 14 months. New activity resets the retention period for the user identifier; it does not restart the retention period for previously collected events. This setting does not apply to aggregated standard reports. Google’s retention rules apply to its processing for its own purposes.
The legal bases are your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time through “Cookie settings” with effect for future processing.
Data may be transferred to Google LLC in the United States. Google LLC is certified under the EU–US Data Privacy Framework. Transfers to that entity rely on the European Commission’s corresponding adequacy decision under Article 45 GDPR.
For more information, see Google’s Privacy Policy and data transfer frameworks.
9. External resources and spam protection
Our website loads some libraries, icons and images from external servers. Their providers receive your IP address, the requested file and technical connection data.
We use:
jsDelivr and BootstrapCDN, operated by Volentio JSD Limited, for Bootstrap, Popper and Bootstrap Icons. Their published data processing terms provide for EU Standard Contractual Clauses for relevant international transfers. Privacy Policy · Data Processing Agreement.
jQuery CDN through Fastly for the jQuery library. Fastly, Inc., United States, participates in the EU–US Data Privacy Framework. Privacy Policy.
Font Awesome, operated by Fonticons, Inc., United States, for icons. Fonticons processes CDN usage data for delivery, troubleshooting, security and statistics and describes its participation in the EU–US Data Privacy Framework in its Privacy Policy.
UNPKG through Cloudflare’s network for the country selector on the registration page.
GitHub for images on the Releases page. GitHub participates in the EU–US Data Privacy Framework. Privacy Statement.
LEaTcon / Ebner Media Group for the background image in our event announcement.
These resources support the website’s display and functionality. Where processing is limited to the connection data necessary to deliver them, we rely on our legitimate interest in reliably providing the website (Article 6(1)(f) GDPR).
We also use Google reCAPTCHA, provided by Google Ireland Limited, on the registration page to detect automated registrations. Google processes information including IP addresses, browser and device details, and interactions with the page. The purpose is to protect our accounts and servers from spam and misuse.
Transfers to Google LLC in the United States are covered by the EU–US Data Privacy Framework described in Section 8. Further information is available in Google’s Privacy Policy.
These providers retain their own technical logs according to their respective privacy policies.
10. Deletion and retention
We delete personal data when it is no longer needed for its purpose. Specific retention periods are set out in the sections above.
After deletion from the live system, personal data may remain in backups for no more than one year. Backups are used only for recovery following data loss and are overwritten or deleted as part of the backup cycle.
Contractual and accounting records subject to statutory retention requirements are kept for the applicable periods under commercial and tax law (Article 6(1)(c) GDPR). Data needed to establish, exercise or defend legal claims may be retained until the relevant limitation period expires (Article 6(1)(f) GDPR).
Access is limited to people responsible for operations and support and the service providers described in this policy, to the extent necessary for their tasks. Disclosures required by law, including to public authorities, are based on Article 6(1)(c) GDPR.
11. Your rights
Subject to the applicable legal conditions, you have the right to access, rectify or erase your personal data, restrict its processing and receive it in a portable format.
You may object to processing based on legitimate interests on grounds relating to your particular situation. You may object to processing for direct marketing at any time.
You can withdraw consent at any time, with effect for future processing. Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.
To exercise your rights, contact alex@opensoundmeter.com.
You may also lodge a complaint with a data protection supervisory authority, particularly in the country of your habitual residence, place of work or the alleged infringement. Our competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Germany.