Privacy policy

Last updated: 4 June 2026.

This policy explains what personal data we collect when you use chord.run, why, and what rights you have over it. It's written in plain language; if anything's unclear, ask.

Data controller

Giuseppe Barletta, Italian sole proprietor, VAT ID IT11194240963. Contact: privacy@chord.run.

What we collect

We try to collect as little as possible. The categories are:

We do not collect: tracking cookies for advertising, device fingerprints, cross-site behavioral data, or anything from third-party trackers. The Service uses only strictly necessary cookies (session). See the cookie policy for details.

Why we process it

Who processes it on our behalf

We use the following sub-processors. Each is bound by a Data Processing Agreement and has been selected for their compliance posture.

Sub-processorPurposeLocation
Hetzner Server hosting Germany / Finland (EU)
Amazon Web Services Transactional email delivery (SES) EU regions
Cloudflare DNS Global
Stripe Payment processing EU / US (SCCs in place)

Data transfers outside the EU

Some sub-processors (Stripe, Cloudflare) are based outside the EU. Transfers happen under the European Commission's Standard Contractual Clauses or under adequacy decisions where applicable.

How long we keep it

Your rights

Under GDPR, you have the right to:

To exercise any of these rights, email privacy@chord.run. We respond within 30 days.

Security

Application databases are encrypted at rest. Network traffic uses TLS. Authentication uses argon2id password hashing and httpOnly session cookies. We log security events and review them periodically. We don't claim perfection; if you find a vulnerability, please report it to security@chord.run.

Changes to this policy

We'll announce material changes by email and on this page at least 30 days before they take effect.