Politique de confidentialité
Effective date: 2026-09-11 Version: 2026-09-11
This Privacy Policy explains how Chord Collect ("we", "us", or "our") collects, uses, discloses, and protects personal data when you use the Chord Collect application, website, and related services (the "Service").
Data controller: Chord Collect Contact (privacy requests): [email protected] Contact (copyright notices): see Copyright Policy
This Policy should be read together with the Terms of Service, Cookie Policy, and, for users in Türkiye, the KVKK Disclosure Notice (Türkiye).
1. Data we collect
| Category | Examples |
|---|---|
| Account data | Email address, display name, password hash, sign-in method (email, Google, Apple) |
| Profile & preferences | Locale, chord display settings, transpose preferences, community-sharing default |
| Content you provide | Songs, chord charts, lyrics, playlists, PDFs and images you upload, tags, group notes and arrangements, group chat messages |
| Usage & device data | App version, session identifiers, IP address, user agent, device model and OS, connectivity, screen size, timezone |
| Behavioral / product analytics | In-app product events (e.g. feature usage, search terms you enter, songs you open, onboarding milestones), recorded together with the device details listed above (app version, device model and OS, language, IP address), tied to your account or to a device identifier if you are not signed in. We also keep a daily record of which days and on which devices you used the app, together with the approximate country our network provider (Cloudflare) derives from your IP address, so that we can measure active use and which app versions are still in circulation |
| Presence data | Online/offline status and session duration when you use live Band Mode sessions, visible to other members of the same group |
| Diagnostics | Crash reports, "report a problem" submissions (your message, stack traces, device details, reporter IP, and an optional log file) |
| Subscription data | Product SKU, entitlement status, purchase and renewal dates, amount paid and currency, store and country from the app stores (via RevenueCat) |
| Communications | Support messages, verification and password-reset emails |
| OAuth identifiers | Provider name and subject ID when you sign in with Google or Apple |
| Advertising identifiers | Mobile advertising ID and ad-interaction data, only for accounts on the free plan, via Google AdMob |
| Photos submitted for Scan Chord Sheet | Images you photograph for the AI chord-recognition feature. They are processed and not stored as part of your library; see §4 |
| Images submitted for moderation | The avatars, group photos, song image pages, and Scan Chord Sheet photos listed above are also sent to an automated content-moderation service to screen for policy-violating content; see §2 and §4 |
| Report and copyright-notice data | If you submit a Community report or a copyright notice, we keep the information you provide (and, for a copyright notice, the details required by our Copyright Policy) to act on it and to track repeat violations |
| Microphone audio (tuner) | If you use the in-app tuner, audio from your microphone is analyzed on your device to detect pitch; we do not transmit or store this audio |
We do not intentionally collect special categories of data (e.g. health data, political opinions, biometric identifiers) through the Service.
2. How we use data
We use personal data to:
- Create and manage your account and authenticate you
- Provide sync, storage, search, transpose, performance, metronome, tuner, offline, Band Mode, and Community features
- Process subscriptions, enforce plan limits, and communicate about your subscription status
- Run the Scan Chord Sheet (photo-to-chords) feature
- Automatically screen uploaded images for content that violates our Terms of Service or Community Guidelines, and act on Community reports and copyright notices
- Send transactional emails (verification, password reset, security notices)
- Send announcements about the Service as in-app messages and, unless you turn them off, push notifications, addressed to groups of users by app language, approximate country, platform, app version, plan, account age or recent activity
- Show advertising to free-plan users and measure ad performance
- Understand product usage in aggregate to improve reliability, features, and support
- Detect abuse, fraud, and violations of our Terms
- Comply with legal obligations and respond to lawful requests
Automated content moderation under this Policy can result in content being hidden pending human review, as described in §9 of the Terms of Service; every such decision is reviewed by our team on request and can be appealed, so it is not automated decision-making that produces a legal or similarly significant effect on you without human involvement. Outside of that, we do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.
3. Legal bases (GDPR / UK GDPR / KVKK)
Where the EU General Data Protection Regulation (GDPR), the UK GDPR, or Turkish Law No. 6698 (KVKK) applies, we rely on:
- Performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5/2(c)): to create your account and provide the Service you requested
- Consent (GDPR Art. 6(1)(a); KVKK Art. 5/1): for non-essential cookies, publishing content to the Community, and (where offered) personalized advertising
- Legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5/2(f)): for security, fraud and abuse prevention (including automated content moderation), product analytics, and service improvement, balanced against your rights
- Legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5/2(ç)): to meet tax, accounting, and regulatory requirements, and to respond to lawful government or court requests
If you are in Türkiye, see the KVKK Disclosure Notice (Türkiye) for the disclosure required by KVKK Art. 10 and a description of which processing activities require your explicit consent (açık rıza) under KVKK Art. 5/1.
4. Sub-processors and third-party sharing
We use the following categories of service providers to operate the Service. We do not sell your personal data, and we do not share it for cross-context behavioral advertising except through the ad network listed below.
| Provider | Purpose | Data involved |
|---|---|---|
| Google Cloud Storage | Stores uploaded PDFs, song images, avatars, group photos, and diagnostic log files | File contents, file metadata |
| OpenAI | Powers the Scan Chord Sheet feature (converts a photo into a draft chord chart), chord-diagram generation, and automated moderation of uploaded avatars, group photos, song image pages, and Scan Chord Sheet photos | The photo(s) you submit for these features; the resulting draft chart is not sent back to OpenAI for storage, and images are not retained by OpenAI or by us for longer than needed to process them |
| Google Cloud Vision | May be used as an alternative provider for the Scan Chord Sheet feature's optical character recognition | The photo(s) you submit for that feature, only if this provider is active |
| RevenueCat | Manages in-app subscription entitlements | Your account identifier, subscription product and status |
| Apple App Store / Google Play | Process in-app purchase payments and receipts | Purchase and billing data handled by the store, subject to Apple's and Google's own privacy policies |
| Google (Firebase Crashlytics, Firebase Cloud Messaging, Firebase Analytics) | Crash reporting, push notifications, app analytics | Device and crash diagnostics, push token, in-app events |
| Google AdMob | Serves advertising to free-plan users | Advertising identifier, ad interaction data |
| Google Sign-In / Sign in with Apple | Social login | Provider account identifier, name and email you authorize |
| Brevo and Resend | Send transactional email (verification, password reset, notifications) | Email address, message content |
| Seq (self-hosted) | Structured application logging for operating the Service | Technical log data, which may include IP addresses and identifiers in error context |
We may also share data with professional advisers (lawyers, accountants) under confidentiality, and with public authorities where required by law or to respond to a valid legal process.
Each provider acts on our instructions under a data processing agreement or equivalent terms and may only use the data to provide the contracted service.
5. International transfers
Chord Collect is operated from Türkiye. The providers listed in §4 may process data in other countries, including the United States and countries within the European Economic Area. Where personal data of an EEA, UK, or Turkish user is transferred outside that jurisdiction, we rely on the transfer mechanism applicable to the recipient, such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or, for transfers out of Türkiye, the conditions set out in KVKK Art. 9.
6. Retention
| Data | Retention |
|---|---|
| Account and content data | While your account is active |
| Account, after you delete it | Deleted immediately and permanently (see §9 and Terms of Service §15). This is an irreversible action, not a soft delete. |
| Pseudonymized deletion record, after you delete your account | Retained indefinitely for abuse prevention and product analytics. It holds a masked e-mail (e.g. a***@example.com), the e-mail domain, the internal identifier of the deleted account, the dates on which the account was created and deleted, its account type and subscription status, the platform the deletion was made from, the number of songs, playlists and groups deleted with it, and the reason and comment you gave for leaving, if you gave one. It never holds your name, your full e-mail address, or any of your content. |
| Payment records, after you delete your account | Retained indefinitely for accounting, tax and revenue reporting. Each record holds the amount and currency, the store, the product, the country, the transaction identifier and the date. When you delete your account, the record is detached from you: your account identifier and the raw subscription notification are removed, and we can no longer link what remains to you. |
| Soft-deleted songs (before permanent purge) | Purged, including associated files, 30 days after deletion |
| Sync tombstones (deletion markers used to keep devices in sync) | 180 days |
| Product analytics events | 90 days |
| Daily activity records (which days, and on which devices, you used the app) | 400 days |
| Revoked or expired sign-in sessions | 30 days |
| Backups | Up to 90 days |
| Security and incident logs | Retained as needed for incident response; typically no longer than 12 months |
| Content-moderation flags and decisions | Retained for as long as needed for audit, appeal, and repeat-violation tracking, and in any case no longer than the underlying content or account exists |
| Copyright notices, counter-notices, and Community reports | Retained for as long as needed to act on the notice or report and to track repeat violations under our Copyright Policy and Community Guidelines |
We keep data only as long as needed for the purposes described in this Policy, or as required by applicable law.
7. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (see §9 for in-app account deletion, which is immediate)
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time, without affecting processing carried out before withdrawal
- Lodge a complaint with a supervisory authority, for example the Turkish Personal Data Protection Board (KVKK Kurulu), your EEA member state's data protection authority, or the UK Information Commissioner's Office
You can export your song library and playlists as a personal backup at any time from within the app; this is the self-service way to receive your content in a portable format. For a copy of other personal data we hold about you, or to exercise any other right in this section, contact [email protected]. We will respond within 30 days, or sooner where local law requires. We may ask you to verify your identity before acting on a request.
8. Security
We use technical and organizational measures including encryption in transit, access controls, and salted password hashing. Access to user data by our own personnel, including for support purposes, is limited to what is needed and is logged. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify affected users and the relevant authority as required by applicable law.
9. Account deletion
You can permanently delete your account from within the app (Profile → Account → Delete account). Deletion requires your password and typing a confirmation phrase. It cannot be completed while you own a group that still has other members; you must transfer ownership of that group first. Once confirmed, deletion is immediate and irreversible: your songs, playlists, group content you authored, and uploaded files are permanently removed, and we cannot restore them. The one exception is the messages you wrote in the chat of a band that continues to exist: they stay so that the other members' conversation remains readable, but they are shown as written by a "Deleted user" and are no longer linked to you. If you can no longer sign in to request deletion yourself, see our public Account Deletion page for how to request it another way.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from children under that age. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
11. Cookies and similar technologies
Our website uses cookies as described in our Cookie Policy. The mobile and desktop apps do not use browser cookies, but use comparable device identifiers (such as the advertising ID and push token described in §4) for the purposes listed there.
12. California and other US state privacy rights
We do not sell personal data, and we do not "share" it as that term is defined under the California Consumer Privacy Act for cross-context behavioral advertising, other than through the advertising described in §4. If you are a California resident, you may have additional rights under the CCPA/CPRA; contact [email protected] to exercise them.
13. Changes to this Policy
We may update this Policy. We will post the new version here with an updated effective date and, for material changes, notify you by email or in-app notice.
14. Contact
Privacy questions or requests: [email protected]