Privacy policy
Last updated 10 September 2026
The short version: we store your email address, the exercises you upload and the practice sessions you record. We do not sell anything to anyone, we do not run advertising, and we do not track you across other apps or websites. Deleting your account deletes your data.
Who is responsible
Emanuel Amaral is the data controller for the information described here. You can reach a human at [email protected] about anything on this page.
What we collect, and why
| What | Why | Legal basis |
|---|---|---|
| Email address | It is how you sign in, and how we send verification and password-reset links. It is the only way we can contact you. | Performance of a contract |
| Display name, instrument, language and theme preference | To address you by name, to offer the app in your language, and to let the shared exercise list be filtered by instrument. | Performance of a contract |
| Password (hashed) | Stored only as a one-way hash, never as text. Nobody here can read it, including us. | Performance of a contract |
| Scores and photographs you upload | They are the exercises. Held privately to your account unless you mark an exercise public. | Performance of a contract |
| Routines, sessions, notes and tempos | The practice record the app exists to keep, and the statistics drawn from it. | Performance of a contract |
| Server logs (IP address, request paths, timestamps) | To keep the service up, to find faults, and to rate-limit abuse. Not used to build a profile of you. | Legitimate interests |
If you sign in with Google we receive your email address, your name and whether Google has verified the address — nothing else. We do not receive your Google password, your contacts, your calendar or your files, and we do not ask Google for any further access.
What we do not collect
- No advertising or analytics identifiers, and no third-party trackers.
- No location data.
- No contacts, no microphone recordings, and no camera access except when you photograph a score, which is uploaded as the exercise you asked for and nothing else.
- No payment details, because there is nothing to pay for.
Who else sees it
A small number of service providers process data on our behalf, under contract, and only to run the service:
- Hetzner Online GmbH (Germany) — the servers and database where everything is stored. Data stays in the EU.
- Cloudflare — sits in front of the service to absorb attacks and filter abusive traffic. It sees the IP address of requests.
- Resend — sends the verification and password-reset emails. It handles your email address for that purpose.
- Google — only if you choose to sign in with Google, and only for that sign-in.
Nobody else. We do not sell, rent or trade personal data, and we do not share it for advertising. We would disclose data if a court with jurisdiction over us ordered it, and we would tell you unless legally prevented from doing so.
Exercises you choose to share
Marking an exercise public is a deliberate act with a visible effect: the exercise, and the display name on your account, become visible to every other signed-in user through the shared exercise list. Nothing else about your account is shown — not your email address, not your practice history, not your other exercises. Making an exercise private again removes it from the list, though anyone who already copied it keeps their copy.
How long we keep it
- Account data, exercises and sessions — until you delete them, or until you delete your account.
- An account that never completed email verification — removed after 30 days.
- Server logs — 30 days, then discarded.
- Backups — held for up to 30 days after deletion, then overwritten in the normal rotation.
Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to processing based on legitimate interests. You can also ask for your data in a portable form.
Most of this you can do yourself in the app: settings hold your name, instrument and language, exercises and routines can be edited or deleted individually, and deleting your account removes everything at once — see deleting your account. For anything else, write to [email protected] and we will answer within 30 days.
If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority: Comissão Nacional de Proteção de Dados (CNPD).
Security
Everything travels over HTTPS. Passwords are stored only as hashes. Sign-in uses short-lived tokens that expire and can be revoked. Administrative access to the servers is not exposed to the public internet at all, and is restricted to a private tunnel with key-based authentication. We do not claim this makes a breach impossible; if one happens and it puts you at risk, we will tell you and the relevant authority within 72 hours of finding out.
Children
The app is not directed at children under 13, and we do not knowingly collect their data. Younger musicians do use practice tools, often through a teacher or a parent — if you are a parent or guardian and believe a child has created an account, write to [email protected] and we will remove it.
Changes
If this policy changes in a way that affects you, the date at the top changes and we will say so in the app before the change takes effect. We will not quietly start doing something with your data that this page does not describe.