This policy explains what information we collect, how we use and protect it, and your rights when you use StringSound.
1. Information We Collect
Account (only if you sign in): a unique user identifier and, if you allow it, an email address from Sign in with Apple or Google Sign-In. We never receive your passwords.
Purchase & entitlement: product identifier, transaction / original transaction identifier, purchase date, subscription expiration date and status. Payments are handled entirely by the Apple App Store; we never see your card details.
Device identifier: a random identifier generated on first launch and stored in the iOS Keychain. It is used to sync purchases before you sign in and to restore entitlements after reinstalling the app. It is not a hardware serial number and is not IDFA/IDFV.
2. How We Use It
To provide, sync and restore premium entitlements (including across devices and after reinstall).
To validate purchases and handle renewals, refunds and expirations.
To keep the service secure and prevent abuse.
3. What We Do Not Do
No advertising tracking and no third-party ad SDKs.
We do not sell or rent your personal information.
We do not collect your location, contacts, photos or microphone recordings — the microphone is used only for real-time pitch detection in the tuner and audio is never recorded or uploaded.
4. Storage & Security
Data is stored on Cloudflare (Workers / D1).
All traffic uses HTTPS/TLS.
5. Third-Party Services
Apple — in-app purchases and Sign in with Apple.
Google — Google Sign-In.
Cloudflare — API and data hosting.
6. Retention & Your Rights
Account data is kept while your account exists.
You may request access to or deletion of your data at any time by emailing us; we respond within 30 days.
7. Children
The app is not directed to children under 13, and we do not knowingly collect their personal information.
8. Changes
Material changes will be posted on this page with an updated effective date.