Legal

Privacy Policy

Last updated: May 4, 2026 · Finalized Enforcement Edition

Data Controller:Rainbow Kreativ (“Company”, “we”, “us”, or “our”)

Contact: hello@ace-presenter.app

At ACE (Agentic Cue Experience), we design tools built for real-world rooms — worship spaces, conferences, lectures, and theaters. Our guiding engineering philosophy is “native where it counts, on-device by default.” This Privacy Policy outlines how we collect, process, isolate, and safeguard your data across our entire ecosystem, including our website (www.ace-presenter.app), applications (Presenter, Schedule, Editors’ Notes), and upcoming platforms (Manager, World).

1. Important General Disclosures & Compliance Declarations

A. EU Artificial Intelligence (AI) Act Compliance (Regulation (EU) 2024/1689)

In compliance with Article 50 transparency obligations under the EU AI Act, we explicitly notify users that the ACE ecosystem relies on automated algorithmic models and Artificial Intelligence systems to perform its core functions.

  • ACE Presenter: Utilizes an on-device deployment of the OpenAI Whisper model to execute real-time speech-to-text processing for automated lyric and scripture matching.
  • ACE Schedule: Leverages machine learning models and computer vision pipelines to analyze text structures from uploaded images and parse them into interactive project formats.
  • Third-Party Models: Employs external foundational Large Language Models (LLMs), specifically via the Anthropic Claude API, to execute contextual lookups and song identifications.

Our AI systems are classified as local automation assistants. We do not employ any prohibited AI practices, automated biometric categorization, emotional recognition profiling, or behavioral manipulation algorithms.

B. GDPR & UK GDPR Compliance Framework

For individuals located within the European Economic Area (EEA) and the United Kingdom, our processing of your personal data strictly adheres to the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). Rainbow Kreativ serves as the Data Controller for account data, while acting as a Data Processor for any cloud-hosted data managed by organizational accounts.

C. California Consumer Privacy Act (CCPA/CPRA)

This policy aligns with California privacy frameworks. We explicitly state that we do not sell your personal information, nor do we share it with third parties for cross-context behavioral advertising. We do not collect or process sensitive personal information to profile users.

2. Information We Collect and How We Process It

Because our suite is local-first, the data we collect is minimal, heavily siloed, and bound by strict processing limitations.

A. Audio Data (ACE Presenter)

  • Collection Scope:When ACE Presenter is active, the app accesses your device’s physical microphone or line-input audio streams.
  • Processing Mechanic: Audio is transcribed entirely locally on your macOS device using an embedded Whisper engine. Audio buffers are processed purely in volatile system memory (RAM).
  • Retention: Audio segments are automatically overwritten and permanently discarded after each sub-second detection cycle. No audio data or voice prints leave your room, land on our servers, or enter any AI training sets.

B. Document and Image Data (ACE Schedule)

  • Collection Scope: When you photograph or upload a physical syllabus, agenda, timeline, or itinerary.
  • Processing Mechanic: Text fields, event dates, milestones, and task descriptions are parsed using a mix of local OCR frameworks and a secure cloud-based AI structural parsing engine.
  • Retention: Once the extracted scheduling data is structured and written to your local Kanban grid or calendar, the raw source image file is instantly deleted from our temporary processing buffer. We do not permanently store or host your raw imagery.

C. Online Lookups (Optional Cloud Integrations)

When you actively configure and trigger advanced features, ACE calls targeted third-party APIs:

  1. Anthropic Claude: For semantic song queries and contextual metadata matching.
  2. ACRCloud: For matching acoustic audio fingerprints against commercial music registries.
  3. Genius: For retrieving matching lyric text strings.

Privacy Guardrails: Only anonymized metadata strings or mathematical audio hashes are sent to these endpoints. No personally identifying information (PII) is attached to these queries. Our contracts ensure these sub-processors are legally restricted from using our users’ query payloads to train their own commercial models.

D. Account Registry and Licensing Telemetry

  • Data Collected: Email address, account login credentials, public beta verification statuses, and basic hardware parameters (App version, operating system version).
  • Auto-Update Queries: Every six hours, the app queries github.com to check for stable binaries. This check transmits only your current app version and OS version to ensure software integrity.
  • Crash Reports: ACE does not transmit crash telemetry or usage statistics. Any future introduction of debugging tracking will be strictly opt-in.

E. Payment Processing & Financial Transaction Data

When you upgrade from our public beta framework to a paid commercial subscription tier, your payment transaction is facilitated directly via our billing integration partner, Stripe, Inc. (and its global affiliates).

  • Scope of Data Collection: To complete a purchase, modify a subscription, or process an invoice, Stripe collects billing details directly from you. This includes your legal name, billing address, email address, transaction currency, purchase amount, and payment card parameters (credit/debit card numbers, expiration dates, and security codes).
  • The Tokenization Shield (Our No-Card Architecture): To maintain the highest level of security, ACE does not store, see, or process your raw payment card data on our servers. All financial inputs are typed into secure fields hosted directly by Stripe. The raw card metrics are tokenized instantly within your browser, ensuring that our team can only access a secure payment token and non-sensitive metadata (such as the card’s brand, country of origin, and expiration year).
  • Regulatory Compliance & Security: Stripe acts as an independent Data Controller for the financial execution of transactions. Stripe maintains strict compliance with PCI-DSS Service Provider Level 1 standards — the most rigorous security certification available in the global payments sector. To learn more about how they manage your financial privacy, you can review the Stripe Privacy Policy.
  • Legal Basis for Processing: We coordinate with Stripe under the legal basis of Performance of a Contract, as this processing is required to deliver your premium multi-product software licenses and manage automated subscription tiers.

3. Legal Bases for Processing (EEA/UK Users)

We process your personal information under the following robust legal parameters:

4. Web Tracking, Cookies, and LocalStorage

Our marketing website (www.ace-presenter.app) and web console use browser storage mechanisms to maintain session integrity.

5. Your Global Privacy Rights

Regardless of your geographic location, we recognize your right to manage your identity. You may exercise these rights at any time by emailing hello@ace-presenter.app:

6. International Data Transfers

Our technical infrastructure routes and stores primary account indices on secure cloud nodes located globally, including within the United States. To bridge cross-border restrictions safely, all non-EEA data transfers are protected under the European Commission’s approved Standard Contractual Clauses (SCCs), ensuring that an identical standard of digital rights and structural encryption protects your identity everywhere.

7. Security Architecture

We apply comprehensive operational safeguards to protect your ecosystem data: