Privacy policy
Effective
The short version: your recordings are yours. Songbook works without an account, nothing leaves your phone until you sign in, and then your library goes only to your own account so your other devices can reach it. We do not sell your data, show you ads, track you, or use your recordings to train anything.
The rest of this page says the same thing in more detail: what the app collects, why, where it is kept, who helps us run it, and how to see or delete it.
Who is responsible
Songbook is operated by SOR White Rock Music Education Ltd., White Rock, British Columbia, Canada — “we” and “us” on this page.
The person accountable for privacy at SOR White Rock Music Education Ltd. is [to be confirmed: privacy contact name]. Reach them at [to be confirmed: contact email] with any question or request about your information.
We handle personal information under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia’s Personal Information Protection Act (PIPA).
You don’t need an account
The app is fully usable without one. Until you sign in, everything you record and write stays on your device — nothing is sent to us.
Signing in is what turns on sync between your devices. You can sign in with an emailed code or link, with Google, or with Apple.
What we collect, and why
Only what the app needs to work, and nothing else. There are five kinds.
Your recordings stay yours
Audio recordings — the app’s purpose. They are stored on your device. When you are signed in, they are uploaded to your own account so your other devices can play them, and to nobody else’s.
Names, notes and tags
The names you give recordings and folders, your notes and lyrics, your tags, and any text you share into the app from another app. They are used to organize your library, and they sync to your account the same way recordings do.
When you share text into the app, only the text you selected is kept, as a note. Nothing else from the page you shared it from is read.
Location is optional
Off unless you turn it on. The app offers it once, after your third recording, and never asks again if you decline.
With it on, an approximate location — roughly a neighbourhood, never precise GPS — is saved with each new recording, so you can remember where an idea came from and name takes after the place. It is saved only with a recording; it is never tracked in the background, and it syncs only as part of that recording in your own library.
To turn a location into a place name, the app asks your phone’s built-in maps service (Apple’s, on iPhone; the system geocoder, on Android). That lookup is handled by Apple or Google under their own privacy policies; we do not receive it.
Your account
If you sign in, we hold your email address and an account ID, so the app knows whose library is whose. Your sign-in session is kept in your device’s secure keychain.
We use your email address only for your account. No newsletters and no marketing unless you ask for them.
Crash reports
When the app crashes or hits an error it could not recover from, it sends a diagnostic report so the bug can be fixed. Before the report is sent, recording names, note text, tag names and file paths are stripped out of it. Reports carry no email address and no IP address — if you are signed in, only your account’s ID, so a fault in one library can be told apart from another.
End-to-end encryption
Off unless you turn it on (Settings → Account & Sync → End-to-end encryption). When on, names, notes, tags and recordings are sealed on your phone with a key only your devices hold, before they are uploaded. We can’t read them, and we can’t recover them without your recovery key — the 24 words the app shows you when you turn it on, and again only from “Show recovery key” on a device that has the key. If you lose every device and your recovery key, your recordings cannot be recovered, not by you and not by us.
Our servers still keep what sync needs to work: ids, sizes, dates, and which folder a recording is in. Turning it on collects nothing new.
The microphone
Used only while you are recording, and asked for the first time you press record — never before. The app does not listen at any other time.
Camera
Optional, and only to scan the code that adds a device. Nothing is saved or sent. With end-to-end encryption on, a phone that already has your key can show a code (Settings → Account & Sync → End-to-end encryption → Add a device), and a newly signed-in phone scans it instead of typing the 24-word recovery key. The camera is asked for only when you tap “Scan from another device”, and no photo or video is taken, kept or uploaded: the code is read on your phone. On iPhone that is done by iOS itself. On Android it is done by Google’s ML Kit barcode library, which is built into the app; Google says ML Kit may send Google anonymous usage and performance information about the library. You can always type your recovery key instead.
No tracking, no ads
No advertising identifiers, no analytics tracking, no third-party trackers, and nothing about you is shared with or sold to data brokers. (The one third-party library that may report anything about itself is Google’s ML Kit on Android, described under “Camera” above.) Nothing you record or write is used to train anything.
When you share something yourself
Some things leave the app only when you send them, and only to where you send them:
- Backups. A backup is a single file of your whole library that you save wherever you choose — iCloud Drive, Google Drive, Dropbox, your computer. We never receive it.
- Sharing a recording to Messages, AirDrop, email or anywhere else sends that audio file where you chose, and nothing else with it.
- A diagnostics report (Settings → About) is built on your phone and shared only if you send it — for example, to us when asking for help. It lists ids, counts and your account’s email address. You choose whether to add your recent activity history, which includes recording and folder names.
The community forum
Our community forum, linked from the support page, is a separate service run on Discourse. The app sends nothing to it. If you sign up and post there, Discourse handles your account and posts under the forum’s own terms and privacy policy, and anything you post is public. Don’t post anything private there, such as a diagnostics report with your history added: email it to us instead.
Where your data is stored
On your device, and — only if you sign in — with our hosting provider, Supabase, in the United States (Northern Virginia). That means your synced library is stored outside Canada and may be subject to the laws of the United States, including lawful access by its courts and authorities. Crash reports are processed by Sentry, which may also process them outside Canada.
Everything travels encrypted over HTTPS.
Who processes data for us
We use a small number of service providers, only to run the app. Each handles your information on our behalf and under its own privacy policy:
| Provider | What it does | Its privacy policy |
|---|---|---|
| Supabase | Accounts, sign-in, and storage for your synced library | supabase.com/privacy |
| Sentry | Crash reports, with your content stripped out | sentry.io/privacy |
| Sign-in, only if you choose Continue with Google | policies.google.com/privacy | |
| Apple | Sign-in, only if you choose Sign in with Apple | apple.com/legal/privacy |
We do not sell, rent or trade your information, and we share it with nobody else unless the law requires it.
Keeping and deleting your data
Your data is kept for as long as you keep it.
- Individual items — any recording, note, folder or tag can be deleted in the app at any time. Deleted items sync as deleted to your other devices.
- Your whole account — Settings lets you delete your account. That removes your library from our servers along with it. What is on your device stays until you delete the app or its contents.
- By email — you can also ask us to delete your account and data at [to be confirmed: contact email].
Crash reports are kept by Sentry for a limited period to fix bugs, and are not linked to you.
Seeing and correcting your information
You can ask what personal information we hold about you, ask us to correct it, or withdraw your consent to our holding it (which means deleting your account). Email [to be confirmed: contact email]. We will answer within 30 days, and tell you if we need longer and why, as PIPEDA allows.
If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada or to the Office of the Information and Privacy Commissioner for British Columbia.
Children
Songbook is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, contact us and we will delete it.
Changes to this policy
When this policy changes, we update the effective date at the top and add a line to the change log below, saying what changed. We will not start collecting a new kind of information without updating this page first.
Change log
- Added the camera, used only to scan the code that adds a device to an encrypted library, and Google’s ML Kit, which reads that code on Android.
- Added optional end-to-end encryption, and what it means for recovering your library.
- First published.