Legal
Privacy
This plain-language summary sits above the full legal text. If the two ever seem to disagree, this summary is what we mean — tell us and we will fix the legal text.
The short version
- You don't need an account to play. The instrument is fully usable signed out. An account only adds sharing with attribution, your purchases, and — with a Plus subscription — syncing your sessions across devices. It never gates playing.
- Your music stays on your device unless you choose to share a link or turn on sync. Saving your work locally happens on your device and is not tracking.
- No non-essential tracking before you say yes. Analytics are off until you opt in through a real consent banner. If you opt in, what we collect is anonymous and aggregated — counts, not identities. You can change your mind at any time.
- Crash reports are sent only with your consent. If the app crashes, you choose whether to send a technical report. With your consent it includes the session state so the fault can be reproduced and fixed; without your consent, nothing is sent.
- Share links carry no personal data. A shared setup is a tiny settings snapshot with no name, email, or account in it. If you are signed in and choose to be credited, only an opaque account id is attached — never your email or name.
- You can export or delete everything, anytime. One click exports all your sessions as portable files; one click deletes your account and its data for real, and our backups age out within 30 days.
- We keep little, for not long. We practise data minimization and keep product telemetry for no more than 13 months.
Who we share data with (subprocessors)
We run as little as possible, so the list is short. Each provider below is contracted under a data processing agreement (DPA), and we never build our own password store or handle your card details.
- Managed identity provider (OAuth + email magic-link)
- Authentication. Sign-in and session tokens; no password store is ever built (§10.3). Data: email address, OAuth account identifier, session tokens.
- Managed serverless database + object storage (row-level secured)
- Data storage. Accounts, saved sessions (tiny state vectors), and public share blobs + social cards (§9.3, D). Data: account id, session state vectors, share blobs (no personal data).
- CDN + serverless functions + edge bot-protection
- Hosting & delivery. Serve the static app and the stateless /v1 functions; challenge automated traffic at the edge (§9.2, §10.2). Data: IP address (transient, rate-limiting + abuse prevention), request metadata.
- PCI-DSS billing processor (Stripe-class)
- Payments. Hosted checkout + customer portal for the one-time unlock and Plus subscription; we never touch card data (§9.2, §10.3). Data: billing email, entitlement flags (synced back via webhook).
Your rights
You can access, export, correct, or delete your data, and withdraw analytics consent, from the account page or by contacting us. We comply with GDPR, UK GDPR, and CCPA/CPRA. We do not knowingly collect children's data.
The full policy
The plain-language summary above — together with the subprocessor list and your rights — is the privacy policy Fenophone operates by today. An expanded formal policy document is in preparation for public launch and will be published on this page. It will add legal detail; it will never subtract from the promises above.
Questions
Questions about privacy or your data? Write to evanatlas@gmail.com.
