Controller: Ing. Marek Hrdina, Ph.D., Hředle 153, 267 51 Hředle, Czech Republic, Business ID (IČO) 29698642. Privacy contact: support@stringpitch.app.
1. Short version
- Live microphone audio is analysed locally on your device; ordinary use does not upload or retain raw recordings.
- Settings and practice data are stored locally and, for signed-in users, selected data may be synchronized to the backend.
- For Premium, Link acts as merchant of record and handles the transaction, tax, receipts and payment support; Donate uses standard Stripe payment processing. StringPitch does not store full card numbers.
- Donation and subscription payments/refunds are kept as separate private ledger entries and shown only as account totals.
- Account, trial and entitlement checks are partly automated, but you may request manual review.
- Protected account forms use Cloudflare Turnstile to reduce automated abuse; Cloudflare processes technical browser, device, network and challenge-interaction signals for that security purpose.
- StringPitch does not sell personal data and does not use advertising or marketing cookies in the current web release.
2. Scope
This Policy covers the public website and browser app at stringpitch.app. Native mobile editions are not currently released.
3. Sources of data
We receive data directly from you when you create an account, change settings, play, purchase, donate or contact support; automatically from your browser or device when the service is used; from enabled identity providers such as Google or Apple; from Cloudflare when Turnstile protects an authentication request; from Stripe in connection with checkout, donations and billing; and from internal calculations such as trial eligibility, discount stage, entitlement status and payment totals.
4. Data we process
| Category | Examples | Purpose | Required? |
|---|---|---|---|
| Microphone signal | Live audio frames, input level, detected pitch, confidence and tuning deviation. | Real-time tuning and pitch exercises. Raw recordings are not retained in ordinary use. | Only for microphone-based functions; alternative button/fretboard input may be available. |
| Local app data | Settings, notation, instruments, custom tunings, valid statistics, graph/tuner takes, trial and interface preferences. | Remember configuration and practice state on the device. | Functional storage is required for persistence but can be cleared. |
| Account data | Email, user ID, optional display name, authentication provider and session/security metadata. | Create and protect accounts, sign users in and associate synchronized data and purchases. | Email or provider identity is required for an account; display name is optional. |
| Synchronized practice data | Settings, custom tunings and valid game results where cloud sync is enabled. | Restore data across signed-in sessions and provide operator-only aggregate usage counts. | Required only for requested cloud synchronization. |
| Trial and entitlement | Eligibility, remaining active time, discount stage, plan, contract start, withdrawal deadline, renewal/expiry and provider references. | Apply trial rules, prevent repeated first-time trials, display legal billing actions and unlock paid access. | Required for trial or paid access. |
| Web purchase data | Stripe customer/subscription references, selected plan, price, status, document versions, consent time, cancellation and withdrawal records. | Form and evidence the contract, verify access, stop renewal, process withdrawal/refunds and handle disputes. | Required for a web purchase. |
| Donation and payment-ledger data | Account ID, chosen amount and symbolic level, currency, Stripe checkout/payment/refund references, status, timestamps and gross/refunded/net donation and subscription totals. | Process and confirm the requested contribution, prevent duplicate charging/recording, show account totals, handle refunds, accounting, fraud, chargebacks and disputes. | Required only when a signed-in user chooses to donate or has a recorded payment/refund. |
| Feedback and support | Rating, message, signed-in account email where available, support emails and details voluntarily provided. | Deliver and answer feedback or support requests. | Optional. |
| Authentication anti-abuse data | A short-lived Turnstile challenge token and validation result supplied to Supabase Auth. To produce that result, Cloudflare processes technical browser, device, network and challenge-interaction signals, which can include the IP address and browser characteristics. | Protect sign-up, sign-in, current-password verification and password-recovery requests against automated abuse. | Required when a protected authentication action is requested. |
| Technical and security data | Request time, IP/server logs, browser/device information, compatibility headers, errors and a short-lived pseudonymous feedback rate-limit token. | Security, troubleshooting, abuse prevention and reliable operation. | Some processing is necessary to operate the service securely. |
5. Microphone processing
Your browser requests microphone permission. You may refuse or revoke it in browser or operating-system settings. When permitted, StringPitch processes the live signal locally to estimate pitch and tuning deviation. The normal web app does not send raw microphone audio to StringPitch servers. Note-button and fretboard input remain available in Play a Note without a microphone. If cloud audio analysis is introduced later, it will not be enabled without an updated notice and any required choice.
6. Local storage, cookies and sessions
The app uses localStorage or equivalent browser storage for essential and functional data. Authentication may use session tokens or provider storage needed to keep you signed in. Stripe may use its own cookies or identifiers when you open checkout. Details are in the Cookie & Storage Notice.
7. Accounts and authentication
The account service uses Supabase Auth and may offer email/password, Google or Apple sign-in where enabled. The selected provider supplies identifiers necessary to authenticate you. Passwords and provider tokens are handled by the relevant secure authentication flow; StringPitch application code does not receive a readable password from an OAuth provider.
Protected email-authentication forms load Cloudflare Turnstile from challenges.cloudflare.com. Cloudflare processes technical browser, device, network and challenge-interaction signals to assess automated abuse and issue a short-lived, single-use challenge token. StringPitch sends that token with the requested authentication action to Supabase Auth for server-side validation. StringPitch does not use Turnstile for advertising or analytics. If the challenge cannot be completed or validated, the protected authentication action cannot proceed.
8. Feedback delivery
When you press Submit, the app sends the rating, message and signed-in account email (if available) to the same-origin feedback endpoint. The website emails that content to support. Feedback messages and unresolved feedback operations are not stored in browser local storage. If delivery cannot be confirmed, the form keeps the original text only in the currently open app session while a status-only check resolves whether the server accepted the message; reloading or closing the app discards that in-memory recovery state. A pseudonymous token derived from the request IP address is kept in temporary server storage for no more than approximately two hours to limit spam.
9. Purchases, donations, cancellation and withdrawal
For Premium subscriptions and Lifetime purchases, Link acts as merchant of record. Stripe and Link process checkout, payment methods, billing address, tax location, fraud controls, receipts or invoices, transaction support, cancellation and related transaction records under their own terms and privacy notices. StringPitch receives the identifiers, product/price information and status needed to provision the digital service, reconcile renewals, process supported cancellation or withdrawal actions, handle product support and meet legal record-keeping obligations.
Donate is not a Managed Payments purchase. It uses standard Stripe payment processing for a voluntary contribution to StringPitch. Stripe processes the payment data and StringPitch receives the verified payment/refund references needed for the private ledger and support.
The checkout request records the Terms and Privacy versions, acceptance time and the customer’s request for immediate performance. A withdrawal request records a unique operation identifier, statement version, receipt time, server-confirmed eligibility, resulting entitlement and refund status. Full card numbers are not stored by StringPitch.
A donation order records a random operation identifier, exact integer minor-unit amount, optional symbolic level, account ownership and Stripe references. Successful payment and refund events are appended to a private ledger. The Donate screen receives only aggregated EUR totals. Donation records do not activate Premium, and browser roles cannot read the underlying financial tables.
10. Legal bases
Where the GDPR applies, processing is based on performance of a contract or steps requested before a contract (accounts, synchronization, trial, purchases and paid access), carrying out the donor’s requested payment, legitimate interests (security, duplicate-payment prevention, abuse prevention, support, service reliability and establishment or defence of claims), legal obligations (consumer, tax, accounting and regulatory records), and consent where it is the appropriate basis. Browser microphone permission controls device access but is not used to justify unrelated processing.
11. Automated checks and manual review
Automated rules may determine trial eligibility, discount stage, entitlement status, billing compatibility, rate limits and whether the backend currently identifies an online withdrawal option. These rules are not used for advertising profiling. If an automated check incorrectly refuses trial access, Premium access, cancellation or another account function, contact support and request manual review. The backend remains authoritative for payment status and statutory eligibility; a client-side indicator does not itself create or remove a legal right.
Cloudflare Turnstile may complete its assessment without user interaction or present an interactive challenge. Supabase Auth rejects the protected request if the resulting token cannot be validated. This assessment is used only to protect authentication workflows; it does not decide trial, billing or Premium entitlement.
12. Recipients and international transfers
Data may be processed by: the production web-hosting and email providers; Supabase for database, authentication and server functions; Cloudflare for Turnstile authentication abuse prevention; Stripe and Link as payment providers and, for Premium, Link as merchant of record for checkout, tax, receipts/invoices, fraud prevention and transaction support; Google or Apple when their sign-in is selected; and professional advisers, auditors, payment-dispute participants or authorities where necessary. Donate uses Stripe as a standard payment processor rather than Link Managed Payments. We do not authorize these providers to use StringPitch account data for StringPitch advertising.
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another legally recognized safeguard. Current provider details and available transfer information can be requested from the privacy contact.
13. Retention
- Local app data remains until you reset the app, clear browser storage or remove it through an available control.
- Active account and synchronized data remains while the account exists and is needed to provide requested functions.
- After deletion of an account without paid history, restricted trial/anti-abuse identifiers and deletion evidence may be retained for up to five years where proportionate.
- Purchase, subscription, donation, consent, cancellation, withdrawal, refund and deleted-account billing history may be retained for up to ten years where needed for accounting, tax, consumer claims, chargebacks, fraud prevention or legal defence.
- Processed billing events may be retained for approximately 180 days and failed/dead-letter billing records for up to one year.
- Feedback and ordinary support correspondence is normally retained for up to 24 months after the request is resolved, unless a longer period is needed for an unresolved contract, security or legal issue.
- Temporary feedback rate-limit data is pruned after approximately two hours. Ordinary security and server logs are retained only for the period configured by the relevant provider and needed for security or troubleshooting.
- StringPitch does not create a separate local profile from Cloudflare’s underlying Turnstile challenge signals. Provider-side processing and retention of those signals are governed by the provider’s applicable service and privacy terms.
- Deleted data may remain temporarily in protected rolling backups until routine rotation. Backup copies are not used for ordinary operations and, if restored for disaster recovery, deletion controls must be reapplied.
14. Your rights, access and export
Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability, and withdraw consent where processing relies on it. You may also request a machine-readable export of available profile, settings, custom tuning and practice data. Contact support@stringpitch.app. We may verify identity proportionately before acting.
Account deletion is described on the Data Deletion page. You may lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, uoou.gov.cz, or another competent supervisory authority.
15. Aggregate administration data
The private operator dashboard reports aggregate counts from registered accounts, paid-access records, redeem campaigns and saved game results. Authorized operators using multi-factor authentication can also view recipient email addresses, billing confirmation references, delivery failures and immutable recovery audit records when needed to resolve delivery incidents. It does not display raw game results, and the current release does not create anonymous advertising identifiers for this dashboard.
16. Children and education
StringPitch is useful to musicians of different ages, but purchasing, donating and data-protection capacity varies by country. A person under 18 must not purchase a subscription or lifetime access or make a donation without valid adult authorization. Where a child cannot lawfully create an account or consent to the relevant processing independently, a parent, guardian or authorized school must provide the required authorization and supervision. Do not include unnecessary information about a child in feedback or support messages.
If we learn that a child’s account or purchase was created without required authorization, we may restrict the account while contacting the responsible adult and will delete or retain data according to legal obligations and the child’s interests.
17. Security and incidents
We use HTTPS, secure authentication flows, server-side entitlement verification, input validation, rate limiting, least-privilege access and limited production administration. No system is perfectly secure. Where a personal-data breach creates a legally reportable risk, we will notify the competent authority and affected individuals as required.
The current web release does not send a custom third-party analytics or crash-reporting feed and does not use advertising trackers.
18. Changes and document history
We may update this Policy when the product, providers, laws or data flows change. The effective date and internal version will be updated. Material changes will be communicated through the app or account email where required. A new Policy does not retroactively change the legal basis of processing already completed. The Policy version accepted during account creation or checkout is recorded where needed to identify the applicable notice.