Privacy Policy
Last updated: September 12, 2026
chords.live (“we”, “us”) makes an iPad app and companion cloud service that helps musicians perform live. This policy explains what we collect, why, and what we do with it. We aim to collect only what the product actually needs to work.
Information we collect
When you sign in, we collect the identifiers required to create and secure your account:
- Email address — used to send verification codes (via Resend) and to identify your account across devices.
- Apple / Google user ID — if you sign in with Apple or Google, we store the opaque provider ID so we can log you back in. If you use Apple’s private-relay email, we store the relay address, not your real one.
- First and last name (optional) — only if you enter them or your Apple/Google account provides them.
- Songs, sets, MIDI configurations, and audio/PDF files you create in the app — stored so you can access them from other iPads, restore them after reinstalling, and share sets with your bandmates.
- Subscription status — we receive a signed transaction from Apple confirming an active Pro subscription. We do not receive or store your payment details; Apple handles billing.
- Server logs — standard request logs (timestamp, path, response code) for debugging and abuse prevention. Not used for advertising.
What we do NOT collect
- We do not sell your data. Ever.
- We do not run third-party ad trackers.
- We do not have access to your microphone, camera, contacts, location, or health data.
- Bluetooth & MIDI device discovery happens on your iPad and is not transmitted to our servers.
- Band Sync between iPads uses your local Wi-Fi (Multipeer Connectivity) and does not route through our servers.
Where your data lives
Content and account data is stored on infrastructure operated by us, tunneled through Cloudflare for public access. Audio and PDF files live in a MinIO (S3-compatible) object store. Backups run nightly to encrypted local storage. Sub-processors we rely on:
- Apple — App Store distribution, Sign in with Apple, in-app purchases.
- Google — Sign in with Google (email + user ID verification only).
- Resend — delivery of verification-code emails.
- Cloudflare — DNS, TLS termination, and secure tunneling to our server.
How we use it
- To sign you in and keep you signed in.
- To sync your library across your iPads.
- To let you share sets with band members you invite.
- To enforce free-tier limits and honor Pro entitlements.
- To fix bugs and keep the service secure.
Sharing with others
If you share a set with your band, the songs in that set become readable by the band members you’ve invited. That is the only case where your content is visible to another user, and it only happens because you asked for it. You can revoke share access at any time.
Your rights
- Access & export — email us and we’ll send you a copy of everything associated with your account.
- Deletion — email us to delete your account and associated content. Some backups may persist for up to 30 days before rolling off.
- Correction — most fields you can edit in the app; for the rest, email us.
Children
chords.live is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
If we make material changes we’ll update the “Last updated” date and, for logged-in users, surface a notice in the app.
Contact
Questions or requests: [email protected].