Privacy Policy
Last updated: May 4, 2026 · Finalized Enforcement Edition
Data Controller:Rainbow Kreativ (“Company”, “we”, “us”, or “our”)
Contact: hello@ace-presenter.app
At ACE (Agentic Cue Experience), we design tools built for real-world rooms — worship spaces, conferences, lectures, and theaters. Our guiding engineering philosophy is “native where it counts, on-device by default.” This Privacy Policy outlines how we collect, process, isolate, and safeguard your data across our entire ecosystem, including our website (www.ace-presenter.app), applications (Presenter, Schedule, Editors’ Notes), and upcoming platforms (Manager, World).
1. Important General Disclosures & Compliance Declarations
A. EU Artificial Intelligence (AI) Act Compliance (Regulation (EU) 2024/1689)
In compliance with Article 50 transparency obligations under the EU AI Act, we explicitly notify users that the ACE ecosystem relies on automated algorithmic models and Artificial Intelligence systems to perform its core functions.
- ACE Presenter: Utilizes an on-device deployment of the OpenAI Whisper model to execute real-time speech-to-text processing for automated lyric and scripture matching.
- ACE Schedule: Leverages machine learning models and computer vision pipelines to analyze text structures from uploaded images and parse them into interactive project formats.
- Third-Party Models: Employs external foundational Large Language Models (LLMs), specifically via the Anthropic Claude API, to execute contextual lookups and song identifications.
Our AI systems are classified as local automation assistants. We do not employ any prohibited AI practices, automated biometric categorization, emotional recognition profiling, or behavioral manipulation algorithms.
B. GDPR & UK GDPR Compliance Framework
For individuals located within the European Economic Area (EEA) and the United Kingdom, our processing of your personal data strictly adheres to the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). Rainbow Kreativ serves as the Data Controller for account data, while acting as a Data Processor for any cloud-hosted data managed by organizational accounts.
C. California Consumer Privacy Act (CCPA/CPRA)
This policy aligns with California privacy frameworks. We explicitly state that we do not sell your personal information, nor do we share it with third parties for cross-context behavioral advertising. We do not collect or process sensitive personal information to profile users.
2. Information We Collect and How We Process It
Because our suite is local-first, the data we collect is minimal, heavily siloed, and bound by strict processing limitations.
A. Audio Data (ACE Presenter)
- Collection Scope:When ACE Presenter is active, the app accesses your device’s physical microphone or line-input audio streams.
- Processing Mechanic: Audio is transcribed entirely locally on your macOS device using an embedded Whisper engine. Audio buffers are processed purely in volatile system memory (RAM).
- Retention: Audio segments are automatically overwritten and permanently discarded after each sub-second detection cycle. No audio data or voice prints leave your room, land on our servers, or enter any AI training sets.
B. Document and Image Data (ACE Schedule)
- Collection Scope: When you photograph or upload a physical syllabus, agenda, timeline, or itinerary.
- Processing Mechanic: Text fields, event dates, milestones, and task descriptions are parsed using a mix of local OCR frameworks and a secure cloud-based AI structural parsing engine.
- Retention: Once the extracted scheduling data is structured and written to your local Kanban grid or calendar, the raw source image file is instantly deleted from our temporary processing buffer. We do not permanently store or host your raw imagery.
C. Online Lookups (Optional Cloud Integrations)
When you actively configure and trigger advanced features, ACE calls targeted third-party APIs:
- Anthropic Claude: For semantic song queries and contextual metadata matching.
- ACRCloud: For matching acoustic audio fingerprints against commercial music registries.
- Genius: For retrieving matching lyric text strings.
Privacy Guardrails: Only anonymized metadata strings or mathematical audio hashes are sent to these endpoints. No personally identifying information (PII) is attached to these queries. Our contracts ensure these sub-processors are legally restricted from using our users’ query payloads to train their own commercial models.
D. Account Registry and Licensing Telemetry
- Data Collected: Email address, account login credentials, public beta verification statuses, and basic hardware parameters (App version, operating system version).
- Auto-Update Queries: Every six hours, the app queries github.com to check for stable binaries. This check transmits only your current app version and OS version to ensure software integrity.
- Crash Reports: ACE does not transmit crash telemetry or usage statistics. Any future introduction of debugging tracking will be strictly opt-in.
E. Payment Processing & Financial Transaction Data
When you upgrade from our public beta framework to a paid commercial subscription tier, your payment transaction is facilitated directly via our billing integration partner, Stripe, Inc. (and its global affiliates).
- Scope of Data Collection: To complete a purchase, modify a subscription, or process an invoice, Stripe collects billing details directly from you. This includes your legal name, billing address, email address, transaction currency, purchase amount, and payment card parameters (credit/debit card numbers, expiration dates, and security codes).
- The Tokenization Shield (Our No-Card Architecture): To maintain the highest level of security, ACE does not store, see, or process your raw payment card data on our servers. All financial inputs are typed into secure fields hosted directly by Stripe. The raw card metrics are tokenized instantly within your browser, ensuring that our team can only access a secure payment token and non-sensitive metadata (such as the card’s brand, country of origin, and expiration year).
- Regulatory Compliance & Security: Stripe acts as an independent Data Controller for the financial execution of transactions. Stripe maintains strict compliance with PCI-DSS Service Provider Level 1 standards — the most rigorous security certification available in the global payments sector. To learn more about how they manage your financial privacy, you can review the Stripe Privacy Policy.
- Legal Basis for Processing: We coordinate with Stripe under the legal basis of Performance of a Contract, as this processing is required to deliver your premium multi-product software licenses and manage automated subscription tiers.
3. Legal Bases for Processing (EEA/UK Users)
We process your personal information under the following robust legal parameters:
- Contractual Necessity: To maintain your single unified account, validate software licensing, deliver stable binary updates, and execute requested cloud/calendar sync workflows.
- Legitimate Interests: To deliver technical customer support via hello@ace-presenter.app and defend our application infrastructure against fraud or security breaches.
- Explicit Consent: When you opt into cloud-lookup services, third-party syncing integrations, or sign up for product waitlists.
4. Web Tracking, Cookies, and LocalStorage
Our marketing website (www.ace-presenter.app) and web console use browser storage mechanisms to maintain session integrity.
- Essential LocalStorage:We store secure, encrypted authentication web tokens locally in your browser. This enables our single sign-on (SSO) engine, letting you transition between Presenter, Schedule, and Editors’ Notes without logging in repeatedly.
- Cookie Controls: We do not run third-party marketing, tracking, or retargeting pixels. You can sweep your cookies or disable LocalStorage via your browser settings, though doing so will break web-console access.
5. Your Global Privacy Rights
Regardless of your geographic location, we recognize your right to manage your identity. You may exercise these rights at any time by emailing hello@ace-presenter.app:
- Right to Access & Portability: Request a full digital export of all profile data, billing logs, and support communications linked to your account.
- Right to Rectification: Correct any inaccurate or incomplete database fields under our control.
- Right to Erasure (“Right to be Forgotten”): Terminate your account and request complete erasure of your cloud record. Note: Erasing your cloud account does not alter, delete, or affect offline local asset files or project timelines saved locally on your physical Mac.
- Right to Restrict or Object: Halt any automated notification pipelines or object to processing activities driven by legitimate interests.
6. International Data Transfers
Our technical infrastructure routes and stores primary account indices on secure cloud nodes located globally, including within the United States. To bridge cross-border restrictions safely, all non-EEA data transfers are protected under the European Commission’s approved Standard Contractual Clauses (SCCs), ensuring that an identical standard of digital rights and structural encryption protects your identity everywhere.
7. Security Architecture
We apply comprehensive operational safeguards to protect your ecosystem data:
- All web network traffic and endpoint requests utilize Transport Layer Security (TLS/SSL) encryption.
- Our on-device application execution isolates audio and video streams within volatile RAM blocks.
- We adhere to strict data minimization concepts, ensuring data is never duplicated onto secondary cloud layers.