Privacy Policy
Last Updated: January 10, 2026
1. Introduction
SongList ("we", "our", "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Service.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address (used for authentication)
- Song Data: Song titles, composers, arrangers, keys, tempo, practice notes
- Practice Logs: Practice session details, durations, notes
- Uploaded Files: Leadsheets, charts, or other files you upload
2.2 Automatically Collected Information
- Log Data: IP address, browser type, pages visited, timestamps
- Session Data: Login times, activity patterns
- Device Information: Operating system, device type
2.3 Payment Information
Payment processing is handled by Stripe. We do not store your full credit card numbers. Stripe may collect payment information, billing address, and transaction details. See Stripe's Privacy Policy.
3. How We Use Your Information
We use collected information to:
- Provide and maintain the Service
- Process your subscription payments
- Send you magic link authentication emails
- Send important service announcements
- Improve and personalize the Service
- Prevent fraud and abuse
- Comply with legal obligations
- Respond to your support requests
4. Information Sharing and Disclosure
We do NOT sell your personal information. We may share your information only in these limited circumstances:
- Service Providers: Stripe (payments), Gmail/SMTP (emails), AWS (hosting)
- Legal Requirements: If required by law, court order, or legal process
- Business Transfers: In the event of a merger, acquisition, or sale of assets
- Protection: To protect our rights, safety, or property, or that of others
5. Data Storage and Security
We implement industry-standard security measures to protect your data:
- HTTPS encryption for all data in transit
- Encrypted database storage
- Secure authentication using magic links (no passwords stored)
- Regular security audits and updates
- Access controls and monitoring
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide services. When you delete your account:
- Your personal data is permanently deleted within 30 days
- Backups may retain data for up to 90 days
- Some data may be retained longer if required by law
7. Your Privacy Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct your information
- Deletion: Request deletion of your account and data
- Export: Download your song data and practice logs
- Opt-out: Unsubscribe from marketing emails (service emails cannot be opted out)
To exercise these rights, contact us at songlist.app.noreply@gmail.com
8. Cookies and Tracking
We use essential cookies to:
- Maintain your login session
- Remember your preferences (e.g., dark mode)
- Prevent CSRF attacks
We do NOT use advertising cookies or third-party tracking cookies. You can disable cookies in your browser, but this may affect Service functionality.
9. Third-Party Services
Our Service integrates with:
- Stripe: Payment processing - Privacy Policy
- Gmail/SMTP: Email delivery - Privacy Policy
- AWS: Cloud hosting - Privacy Policy
These services have their own privacy policies and we are not responsible for their practices.
10. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect information from children under 13. If we learn we have collected such information, we will delete it immediately.
11. International Users
The Service is operated in the United States. If you access from outside the US, your information will be transferred to and processed in the US, which may have different data protection laws than your country.
12. Do Not Track
We do not track users across third-party websites and do not respond to Do Not Track signals, as we do not use tracking for advertising purposes.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or prominent notice on the Service. Continued use after changes constitutes acceptance of the updated policy.
14. California Privacy Rights (CCPA)
California residents have additional rights under the CCPA:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed (we do not sell)
- Right to delete personal information
- Right to opt-out of sale of personal information (not applicable)
- Right to non-discrimination for exercising CCPA rights
15. GDPR Rights (European Users)
If you are in the European Economic Area, you have rights under GDPR:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
16. Contact Us
For privacy-related questions or to exercise your rights, contact us at:
Email: songlist.app.noreply@gmail.com
We will respond to privacy requests within 30 days.