1. At a glance
This summary is not a substitute for the full policy below, but it covers the parts people most want to know.
| Question | Short answer |
|---|---|
| What do you collect? | Your account details, the sheet music you scan and the scores derived from it, your subscription status, crash diagnostics, and anything you email us. |
| Do my scans leave my phone? | Yes. To turn a photo into a playable score we send it to our recognition provider, ScoreFlow. See section 7. |
| Do you sell my data? | No. We do not sell personal information and do not share it for cross-context behavioural advertising. |
| Do you track me for ads? | No. There is no advertising SDK in the app, we do not use the advertising identifier, and we do not track you across other apps or websites. |
| Can other people see my scores? | Only the ones you save as Community. Scores saved as Only me are not published. See section 8. |
| How do I delete everything? | Settings → Delete account in the app, which deletes your account and its data. See section 13. |
2. Who we are
This policy explains how Rhythm Reader (“we”, “us”, “our”) handles personal information when you use the Rhythm Reader mobile app, the website at rhythmreader.com, and related services (the “Service”). For the purposes of the EU and UK GDPR we are the data controller for that information.
Contact: hello@rhythmreader.com. Our Terms & Conditions govern your use of the Service.
3. What we collect
3.1 Account information
You can sign in with an email address and password, or with Google, Apple, or your phone number. Depending on the method, we receive and store:
- a user ID that identifies your account, your email address, your name where the sign-in provider supplies one, and the date your account was created;
- your phone number, if you choose phone sign-in;
- your in-app preferences — for example your chosen instrument, score scale, and playback-line setting.
Authentication is handled by Google Firebase Authentication. If you use a password, it is stored by Firebase in hashed form and we never see it. If you use Sign in with Apple and choose to hide your email, we receive only Apple’s relay address.
3.2 Content you create
- Photos of sheet music you capture with the camera or select from your photo library, including any cropping you apply;
- the digital score produced from each scan (its musical notation data and a preview image);
- the details you attach to it — title, chosen instrument, visibility (Community or Only me), tempo preference, and creation date;
- library actions such as saving or liking a score, so your library persists across devices.
3.3 Subscription and purchase information
Paid features are sold through the Apple App Store and Google Play. Those stores process the payment — we never receive or store your card number or bank details. Through our subscription-management provider Adapty we receive and store your subscription status and entitlement level, the plan and store involved, transaction and receipt identifiers, renewal and expiry dates, trial status, and country. Adapty is given your Rhythm Reader user ID so your subscription follows your account across devices.
3.4 Device and diagnostic information
When the app crashes or hits a serious error, Google Crashlytics collects a diagnostic report so we can fix it. Those reports typically include the device model, operating-system version, app version, locale, the time of the crash, the technical stack trace, and a randomly generated installation identifier. They are not used to build a profile of you or to advertise to you.
3.5 Messages you send us
If you email us or use the contact form on our website, we receive what you put in it. The website form is submitted through your own email application and may include your name, email address, age, school or organisation, instrument, musical affiliation, and your message. Only fill in the fields you are comfortable sharing.
3.6 Website visits
The rhythmreader.com website does not set advertising or analytics cookies. Like almost all websites it is served by a hosting provider that keeps short-lived technical server logs (IP address, request time, page requested, user agent) for security and reliability.
4. What we do not collect
To be explicit, the app does not collect or use:
- advertising identifiers (IDFA / Android Advertising ID), and there is no advertising SDK in the app;
- tracking data — we do not track you across other companies’ apps or websites, and we do not share data with data brokers;
- precise or coarse location data;
- microphone audio, your contacts, calendar, health data, or your browsing history;
- photos from your library other than the ones you actively pick for a scan.
5. Camera and photo library
The app asks for camera access so you can photograph sheet music, and for photo-library access so you can pick an existing image instead. Both are used only while you are scanning — nothing is captured in the background, and we only receive the specific images you choose to scan. You can refuse or withdraw either permission in your device settings; scanning will not work without at least one of them, but the rest of the app continues to function.
6. How we use your information
The table below lists our purposes and, for people in the EU, UK, and other GDPR jurisdictions, the legal basis for each.
| Purpose | Information used | Legal basis (GDPR) |
|---|---|---|
| Create and maintain your account; sign you in | Account information | Performance of our contract with you |
| Convert your scans into playable scores and store your library across devices | Photos you scan, derived scores, score details | Performance of our contract with you |
| Publish scores you mark as Community, and make them searchable | Score, preview, title, instrument, creator ID | Performance of our contract, at your instruction |
| Sell, activate, and restore subscriptions; prevent purchase abuse | Subscription and purchase information | Performance of our contract; our legitimate interests |
| Diagnose crashes, fix bugs, keep the Service secure and reliable | Device and diagnostic information | Our legitimate interests in a working, secure product (and consent where required) |
| Respond to your support requests and questions | Messages you send us | Performance of our contract; our legitimate interests |
| Enforce our Terms, handle copyright notices, prevent abuse | Account information, content, diagnostics | Our legitimate interests; compliance with legal obligations |
| Comply with law and respond to lawful requests | As required | Compliance with legal obligations |
We do not use your scans or your library to train machine-learning models for unrelated purposes, and we do not make decisions about you by automated means that have legal or similarly significant effects.
7. Who we share it with
We do not sell your personal information. We share it only with service providers who process it on our behalf, under contract and only for the purposes below.
| Provider | What it receives | Why |
|---|---|---|
| ScoreFlow (scoreflow.app) | The sheet-music image you scan, sent as a document for conversion, plus the resulting notation data | Optical music recognition — turning your photo into a machine-readable score. This is the step that makes the app work. |
| Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions, Crashlytics) | Account information, score metadata and preview images, crash diagnostics | Authentication, database and file hosting, backend logic, crash reporting |
| Adapty | Your user ID and subscription/purchase status | Subscription management, entitlement checks, purchase restoration |
| Algolia | Metadata of scores published to the community (title, instrument, creator ID) and search queries | Powering search across the community library |
| Apple and Google Play | Purchase and billing data, which they collect directly from you | Processing payments, renewals, and refunds under their own privacy policies |
We may also disclose information:
- to other users, but only the content you chose to publish — see section 8;
- when the law requires it — to comply with a valid legal request, or to establish, exercise, or defend legal claims, including responding to copyright notices;
- to protect people — where we reasonably believe disclosure is necessary to prevent fraud, abuse, or harm to someone;
- in a corporate transaction — if the Service is involved in a merger, acquisition, or sale of assets, in which case we will notify you and the acquirer will be bound by a policy no less protective, or you can delete your account first.
8. What community sharing makes public
Saving a score as Community publishes it to other Rhythm Reader users. Saving it as Only me does not.
For a score you publish to the community, other users can see its preview image, title, instrument, and notation, can find it through search, and can save it to their own library and play it back. Choose Only me for anything you would rather keep private.
You can change your mind: deleting a score, or your account, stops us serving it from the community library going forward. We cannot, however, retrieve copies other users already saved.
9. International transfers
We and our providers operate primarily in the United States, so if you use the Service from elsewhere your information will be transferred to and processed in the US and in other countries where our providers operate. Those countries may have different data protection laws than yours.
Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on an appropriate safeguard under Chapter V of the GDPR — normally the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant) in our contracts with providers, or a valid adequacy decision or certification where one applies. You can ask us for details using the contact address below.
10. How long we keep it
| Information | Retention |
|---|---|
| Account information | Until you delete your account |
| Your scores, previews, and library | Until you delete the item or your account |
| Scans sent for recognition | Kept by our recognition provider only as long as needed to perform and support the conversion, under its own retention policy |
| Subscription and purchase records | For the life of the subscription and afterwards where we need them for accounting, tax, or dispute purposes |
| Crash diagnostics | Retained on a rolling basis by Crashlytics, typically up to 90 days |
| Support correspondence | Normally up to 24 months after the matter is resolved |
| Backups | Deleted data may persist in encrypted backups for a short cycle before erasure |
11. Security
We use industry-standard measures to protect your information, including encryption in transit (HTTPS/TLS) for everything the app sends, encryption at rest at our cloud providers, access controls that restrict who on our side can reach production data, and server-side rules that check a request’s identity before it can read or write your data.
No system is perfectly secure, so we cannot guarantee absolute security. Please use a strong, unique password and tell us promptly at hello@rhythmreader.com if you suspect a problem with your account. Where the law requires it, we will notify you and the relevant regulator of a personal data breach.
12. Your privacy rights
12.1 Everyone
Whatever your location, you can access most of your information directly in the app, change your account details and preferences, choose the visibility of every score, withdraw camera and photo-library permissions in your device settings, and delete individual scores or your entire account.
12.2 EEA, UK, and Switzerland (GDPR)
You have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data (“right to be forgotten”);
- restrict or object to processing based on our legitimate interests;
- data portability — receive data you provided in a structured, machine-readable format;
- withdraw consent at any time, where we rely on consent;
- lodge a complaint with your local supervisory authority — though we would appreciate the chance to resolve it first.
12.3 California (CCPA/CPRA) and other US states
If you are a California resident you have the right to know what personal information we collect, use, and disclose and to receive a copy of it; to correct inaccurate information; to delete it; and to opt out of its sale or sharing for cross-context behavioural advertising and of profiling in furtherance of significant decisions.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for that kind of profiling, so there is nothing for you to opt out of. We collect the categories described in section 3 — identifiers, commercial information relating to your subscription, internet or device activity in the form of crash diagnostics, and the audio/visual content you scan — for the business purposes in section 6, and we disclose them to the service providers in section 7. We do not knowingly collect sensitive personal information for the purpose of inferring characteristics about you. We will not discriminate against you for exercising your rights. Residents of other US states with comparable laws have similar rights and may use the same contact route.
12.4 How to exercise your rights
Email hello@rhythmreader.com from the address on your account, or tell us which account the request concerns. We will verify your identity — normally by confirming control of the account email — before we act, and will respond within the time the applicable law allows (one month under the GDPR, 45 days under the CCPA, each extendable where permitted with notice to you). Exercising these rights is free unless a request is manifestly excessive. An authorised agent may submit a request on your behalf with proof of authority. If we refuse a request, we will explain why, and you may ask us to reconsider by replying to that decision.
13. Deleting your data
In the app: open Settings and choose Delete account. This permanently deletes your account and the associated data, including your scores and library. It cannot be undone.
By email: write to hello@rhythmreader.com from your account address with the subject “Delete my account”.
Full instructions, and details of what is deleted and what we are required to keep, are on our account deletion page. Note that deleting your account does not cancel a subscription — cancel that in your Apple or Google Play account settings, or you may continue to be billed.
14. Children and schools
The Service is intended for people aged 13 and over. We do not knowingly collect personal information from children under 13. If we learn that we have, we will delete it promptly.
If you are a parent or guardian and believe your child under 13 has given us information, contact hello@rhythmreader.com and we will remove it and close the account.
Teachers and schools: Rhythm Reader is not currently offered as a school-administered service and we do not sign student-data agreements or act as a school official under FERPA. Students should use the app with individual accounts under these terms, and staff should not create accounts on behalf of under-13 pupils.
15. Do Not Track and Global Privacy Control
Because we do not track users across sites or apps and set no advertising cookies, there is no cross-site tracking for a browser signal to switch off. Our website does not respond differently to Do Not Track or Global Privacy Control signals, and no behaviour changes as a result.
16. Changes to this policy
We will update this policy when our practices change. The “Last updated” date at the top always reflects the current version. If a change is material — for example a new category of data, a new provider, or a new purpose — we will give notice in the app, on this page, or by email before it takes effect, and will obtain your consent where the law requires it.
17. How to contact us
For privacy questions, data requests, or deletion requests: hello@rhythmreader.com.
Rhythm Reader
Email: hello@rhythmreader.com
Web: www.rhythmreader.com