Privacy Policy

Last updated: 9 September 2026

On-device practice

Browsing, playback, ABC import, tune identification and microphone analysis run on device. Microphone audio is analysed live and is not recorded, stored or uploaded. Imported tunes and local practice results stay on your device. If you create a practice card and open the share sheet, you choose its destination; the card contains no audio.

Optional account

You can use the free tools, buy or restore a subscription, and use on-device Pro teaching tools without signing in to an app account. Sign in with Apple is used for the optional live technique coach and to link verified purchases to that account. Your app account does not require your name or email. We store a one-way-derived account identifier, session records, Apple sign-in tokens and verified entitlement state in encrypted storage in AWS Sydney. Apple sign-in tokens let us verify account access and revoke the sign-in connection when you delete your account. Account identifiers and purchase records are linked to your app account.

Optional live coach

Starting with version 1.1.1, before your first live question the app asks you to agree to sharing your typed question with DeepSeek. You can choose Cancel or use Turn off AI sharing in the coach to withdraw permission for future questions. When you are signed in, have allowed sharing and choose Send in the live coach, your typed question and app version go to our server with your account session. The server sends the question to DeepSeek to generate a technique answer. We do not include your app account identifier, session token or app version in the DeepSeek request. The app does not attach tune titles, notation, imported tunes, practice results or microphone audio. The server rejects corpus fields and obvious tune notation; keep your question about general technique and leave out personal information and tune content. Questions are handled as account-linked content.

Our application uses your question to return an answer. It does not save the question in the account database or include its text in application error logs. DeepSeek may retain request data under its service terms and privacy policy. We have not verified a zero-retention setting for that provider. Turning off AI sharing prevents future questions from being sent; it does not erase questions already handled by DeepSeek.

We store a monthly coach-use count linked to your account to enforce the allowance. No question is sent automatically when you open the coach. Guests receive labelled on-device tips.

Purchases

Apple processes payment; we never receive card details. StoreKit uses an app-specific purchase token saved on your device. After you sign in, we verify signed StoreKit transactions and server notifications and retain transaction identifiers, product, subscription state and account purchase links. Signing out does not cancel your subscription or remove verified on-device Pro access.

How long we keep records

We keep current account records and stored Apple sign-in tokens until account deletion. App access tokens last 30 days, and refresh-session records have a 180-day expiry. A monthly coach-use counter expires 70 days after it is first created. We keep a one-way fingerprint of an accepted sign-in credential with a 10-minute expiry to prevent it from being reused through an older sign-in flow. That record contains no account identifier and remains separate from account deletion. These expiry periods do not guarantee immediate physical removal from the database, and a renewed session can have a later expiry.

After account deletion, we retain transaction-state records without the app-account link for subscription renewals, refunds and purchase integrity. These records have no automatic expiry. Apple keeps its own purchase ledger.

Deletion

Use Settings → Delete Account to request removal of your current app account, its sessions, coach-use counts and user-linked entitlement pointers. The app confirms completion only after the current server reports success. If completion cannot be confirmed, it explains that you should retry. We revoke stored Apple sign-in tokens before completing deletion. For older accounts or interrupted sign-ins without usable tokens, the app gives instructions to remove the Apple connection in your device settings.

The current AWS database has a 35-day backup recovery window. Records removed from the active database may remain recoverable in those backups until that window passes. In-app deletion does not erase Apple's purchase ledger, files you exported or shared, or copies held by a support-email or AI provider. Deleting an app account does not cancel an Apple subscription; manage subscriptions in your Apple Account settings.

Account requests from older app versions are handled by the current account service. In-app deletion removes the account data managed by that service as described above. Earlier anonymous coach versions used device and network-address counters with a two-hour expiry; these counters are separate from an app account. Older diagnostic logs and copies held by service providers may follow separate retention periods.

Service operation

Current AWS diagnostic logs are retained for 30 days. Application error logs record an error category, not your typed questions, microphone audio or Apple tokens. Hosting providers process network requests needed to run the service; their own operational records may have separate retention periods. We do not use advertising trackers or sell your practice data.

Contact

Email mitsi@playsoloist.com.