Privacy Policy
Note – this document needs completing and legal review. The highlighted fields must be filled in with the controller's details before sales begin. The description reflects how the application actually works as of the date of writing – it must be updated whenever the scope of collected data changes. The Polish version is the binding one; this translation is provided for information only.
1. Data controller
The controller of your personal data is [CONTROLLER NAME], registered office at [ADDRESS], tax ID [NIP]. Contact for data protection matters: [EMAIL ADDRESS].
2. What data we collect
When you use the app without an account
- Technical data recorded in server logs: IP address, date and time of the request, the page requested, browser type.
- If an error occurs in the app, your browser sends us its description together with the page address and browser information. Such a report contains neither your files nor the content of your practice sessions.
When you have an account
- The email address given at purchase.
- Your password – only as a cryptographic hash (PBKDF2-SHA256). We neither know nor are able to recover your password.
- A session identifier stored in a cookie, valid for 30 days.
- MIDI files you upload and the per-part settings saved for those songs.
- The account creation date and the date of your last sign-in.
What we do not collect
We use no analytics or advertising tools, we do not profile users, we make no automated decisions, and we do not pass data to data brokers. We do not collect audio recordings – playing happens entirely in your browser.
3. Purposes and legal bases
- Running your account and providing the full version – Article 6(1)(b) GDPR (performance of a contract).
- Handling payments and tax settlements – Article 6(1)(c) GDPR (legal obligation).
- Service security, server logs and error reports – Article 6(1)(f) GDPR (legitimate interest in keeping the service working and secure).
- Handling complaints and pursuing claims – Article 6(1)(f) GDPR.
4. Recipients of the data
- Server provider – [HOSTING PROVIDER], infrastructure located in [SERVER LOCATION].
- Payment provider – [PAYMENT PROVIDER]. You enter card details directly with the provider; we never receive them.
- Email provider – [SMTP PROVIDER], used to send messages containing password-setting links.
We do not sell data and we do not share it for marketing purposes.
5. How long we keep data
- Account data – until you ask us to delete the account.
- Uploaded MIDI files – until you delete them or the account is deleted.
- Accounting records – for the period required by tax law (as a rule 5 years from the end of the year in which the tax obligation arose).
- Server logs and error reports – [PERIOD, e.g. 30 days].
- Expired sessions and used password links are deleted automatically.
6. Your rights
You have the right to access your data, rectify it, erase it, restrict its processing, port it, and object to processing based on legitimate interest. A request sent to the contact address in section 1 is enough.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).
Providing an email address is voluntary but necessary to create an account and use the full version.
7. Cookies and local storage
We use one cookie, strictly necessary for the service to work:
pianomaster_session– keeps you signed in. Valid for 30 days, markedHttpOnlyandSameSite=Lax, and alsoSecureover an encrypted connection. It is not used for tracking.
We use no analytics or marketing cookies, which is why the service shows no cookie consent banner – cookies strictly necessary to provide the service you requested do not require consent.
In addition, the app stores in your browser's local storage your appearance and sound settings, language choice, and your scores and records. This data is not sent to the server – it stays on your device and you can remove it by clearing the site data in your browser.
8. Transfers outside the EEA
We store data on servers within the European Economic Area. If the payment provider or the email provider transfers data outside the EEA, this takes place on the basis of standard contractual clauses approved by the European Commission. [TO BE COMPLETED ONCE PROVIDERS ARE CHOSEN]
9. Security
The connection to the service is encrypted (HTTPS). Passwords are stored only as hashes with an individual salt. Access to the server is restricted, and sign-in attempts are rate limited to make automated attacks harder.
10. Changes to this policy
We will inform you of any significant changes by email at the address linked to your account at least 14 days in advance. The current version is always available at this address.