Tontaube Logo Tontaube
Research App Books Voice Studio API Pricing API Platform
English Deutsch Español Français Italiano Português Русский हिन्दी 中文 العربية
Home Books Voice Studio API Pricing App
Research
EN English DE Deutsch ES Español FR Français IT Italiano PT Português RU Русский HI हिन्दी ZH 中文 AR العربية

This Privacy Policy covers general visitors to tontaube.ai. If you are looking for the Privacy Policy for the Tontaube Developer API, please click here. If you are looking for the Privacy Policy for our iOS/Android Mobile App, please click here.

Privacy Policy for tontaube.ai

Version: 19 March 2026

We, Cremer & Cremer Technologies UG (haftungsbeschränkt), located in Berlin, Germany, take the protection of your personal data seriously. This Privacy Policy informs you how we collect, process, and protect your data when you visit our website tontaube.ai (the “Website”). The processing is carried out in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

In this Privacy Policy, we use the term “Personal Data” as defined by the GDPR, meaning any data that is or can be potentially attributed to an identifiable individual.

1. Controller

The controller responsible for data processing within the meaning of the GDPR is:

Jonathan Cremer
Herderstraße 22, 12163 Berlin, Germany
data-protection@craitech.io


2. Legal Bases for Processing

We base every processing of your personal data on one of the following legal bases of the GDPR (Art. 6):

  • Consent — Art. 6(1)(a) You have given your explicit consent to the processing for a specific purpose (e.g., analytics). You may withdraw your consent at any time with effect for the future.
  • Contract — Art. 6(1)(b) Necessary to fulfill the user agreement and to provide you with the Website’s features.
  • Legitimate Interest — Art. 6(1)(f) Serves security purposes (abuse and fraud prevention), website improvement, and internal analysis, provided your interests do not override ours.
  • Legal Obligation — Art. 6(1)(c) Required to comply with tax and commercial law retention obligations, as well as other legal requirements.

3. Categories of Personal Data We Collect

(a) Data Provided by You

CategoryExamples
Communication & FeedbackSupport requests, error reports, feature requests submitted via contact forms or email

(b) Automatically Collected Data

CategoryExamples
Server Log DataIP address (stored max. 30 days), browser type and version, operating system, referring URL, pages visited, timestamps
Analytics DataPseudonymous usage profiles: session duration, interaction paths, page views (via Google Analytics 4)
Diagnostic DataError logs, performance metrics

4. Purposes of Processing and Legal Bases

PurposeDescriptionLegal Basis (Art. 6 GDPR)
Website DeliveryServe pages, load balancing, technical stabilitylit. b / lit. f
Security & Abuse PreventionAnalyze server logs, IP logslit. f
Reach Measurement & ImprovementPseudonymous usage statistics via Google Analytics 4 (no advertising remarketing)lit. a
Customer Support & CommunicationRespond to your inquirieslit. b / lit. f
Error AnalysisCrash reports, performance monitoringlit. f

Where we rely on consent (lit. a), you may withdraw it at any time via our cookie banner or by contacting us — this does not affect the lawfulness of processing before withdrawal. Where we rely on legitimate interest (lit. f), you can object to the processing at any time (see “Your Rights”).


5. Recipients of Your Data

5.1 Processors (Art. 28 GDPR)

Service ProviderLocation / Data CentersPurposeGuarantees
Google Cloud Platform / Firebase (Google Ireland Ltd.)EU / worldwideWebsite hosting (Firebase Hosting), backend infrastructureDPA + DPF / SCCs
Google Analytics 4 (Google Ireland Ltd.)EU / USAReach measurement, website statistics (no ads remarketing activated)DPA + DPF / SCCs

All processors handle personal data exclusively according to our instructions and are contractually bound to confidentiality and appropriate technical and organizational measures (Art. 28(3) GDPR).

5.2 Other Recipients

  • Authorities / Courts — exclusively when legally required or for the enforcement of rights.
  • Successors in the context of a merger, acquisition, or similar transaction.

6. International Data Transfers

Some of our service providers operate servers in third countries, particularly in the USA. Transfers of personal data only occur if one of the following protective measures is in place:

  • Standard Contractual Clauses (SCCs) of the EU Commission (Art. 46(2)(c) GDPR).
  • EU–US Data Privacy Framework (DPF) for certified US companies (e.g., Google LLC).

Copies of the SCCs or proof of DPF certification are available upon request at data-protection@craitech.io.


7. Storage Periods

Data TypeRetention PeriodReason
Server Log Files (IP, browser)Up to 30 daysWebsite security and technical stability. Automatic rotation; longer storage only in case of security-relevant incidents.
Analytics Data90 days (pseudonymized)Reach measurement and product improvement. Fully anonymized statistics may be retained indefinitely.
Support Correspondence6 yearsMandatory retention under German commercial law (§ 257 HGB).

Unless legal obligations prevent it, we will also delete or anonymize data earlier if you request it.


8. Cookies

We do not currently use cookies or similar tracking technologies that would require consent. Google Analytics 4 is configured to operate without setting consent-requiring cookies.


9. Your Rights

As a data subject, you have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR) – You can request a copy of your stored personal data.
  • Right to rectification (Art. 16 GDPR) – You can have incorrect or incomplete data corrected.
  • Right to erasure (Art. 17 GDPR) – You can request that your data be deleted, provided no legal retention obligations prevent it.
  • Right to restriction of processing (Art. 18 GDPR) – You can restrict the processing of your data under certain conditions.
  • Right to data portability (Art. 20 GDPR) – You have the right to receive your data in a machine-readable format.
  • Right to object (Art. 21 GDPR) – You can object to processing based on legitimate interest (Art. 6(1)(f)).

To exercise your rights, please contact us at data-protection@craitech.io.

9.1 Right to Lodge a Complaint (Art. 77 GDPR)

If you believe that the processing of your personal data violates the GDPR, you can contact a supervisory authority. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
Website: https://www.datenschutz-berlin.de


10. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy to adapt it to legal or technical changes. Material changes will be published on our website. Changes take effect upon publication, unless otherwise specified.

Terms & Conditions Privacy Policy DPA Refund Policy Legal Notice

© 2025 Cremer & Cremer Technologies UG (haftungsbeschränkt). All rights reserved.

We use cookies to analyze site traffic and improve your experience.