Legal

Privacy Policy

Effective: August 2, 2026  ·  Last updated: August 2, 2026

The short version

Tutti is a practice log, not an advertising business. We collect what the app needs to work and nothing else: your practice history, your repertoire, the profile you choose to show other players, and — if you sign in — an email address to attach it all to.

We do not run ads, use advertising identifiers, collect your location or contacts, or sell or share your personal information. The microphone is used only while the tuner is open, is analysed entirely on your device, and is never recorded or uploaded. You can use the entire app offline without ever creating an account.

The app does record product analytics — which screens get opened and which features get used — so we can tell what's working and what's broken. It is never used for advertising, never sold, and never applied to your practice content. §2.8 spells out exactly what that covers.

The rest of this page is the detail behind those sentences. Questions: tuttipracticeapp@gmail.com.

1. Who we are

Tutti ("Tutti", "we", "us") is a mobile application operated by Tony Jin, an individual based in Texas, United States. For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the personal data described in this policy.

This policy covers the Tutti mobile app on iOS and Android and the website at tuttipracticeapp.com. It does not cover anything you reach by following a link out of the app or the site.

Contact: tuttipracticeapp@gmail.com. We answer privacy requests at that address; there is no separate privacy inbox.

2. What we collect

Almost everything below is information you type into the app yourself. Nothing here is bought from a data broker or scraped from anywhere else.

2.1 Account information

Only if you choose to create an account. The app works fully signed out, with your data stored on your device and nowhere else.

  • Email and password. If you sign up with an email address, we store the address and a cryptographic hash of your password — never the password itself.
  • Sign in with Apple. Apple sends us an account identifier, your email address, and the name you agree to share. If you choose Apple's Hide My Email, we only ever see the private relay address, not your real one.
  • Sign in with Google. Google sends us an account identifier, your email address, your name, and your Google profile picture URL. We do not receive your Google password, and we do not get access to any other Google service.
  • Timestamps for when the account was created and last signed in.

2.2 Your profile

The public half of your account — what other players can find. All of it is optional and editable, and you choose every value:

  • Display name and username (your handle)
  • A short bio
  • Your instrument
  • A profile photo, if you set one

A note on profile photos. Profile pictures are stored so that they can be loaded by anyone who can see your profile, which means the image file is reachable by anyone who has its web address. Treat a profile photo as public. Don't upload anything you wouldn't be comfortable being seen — and remember the general rule of the internet: a photo, once published anywhere, can be copied.

2.3 Practice data

The reason the app exists. For each session you log:

  • The date and how many minutes you practised
  • Your own one-to-five rating of how the session went
  • What you focused on, and which pieces and scales you worked on
  • An optional breakdown of how the time was split

Alongside that, we store:

  • Your repertoire — title, composer, category, level, and status (learning, polishing, performance-ready) for each piece
  • Your goals and settings — daily target, weekly target, days per week, your default session breakdown, and your chosen instrument
  • Streak and progress state — current streak, whether a streak freeze is available, which weeks have been forgiven, quests you've claimed, and your in-app note balance

2.4 Social features

Only generated if you use them:

  • Friendships, and friend requests you send or receive
  • Nudges you send to friends, and who you've pinned
  • Practice battles — who challenged whom, the mode, the stake, the days each side practised, and the outcome
  • Leaderboard statistics — your streak, consistency score, weekly minutes, overall rank, how many pieces you have performance-ready, and the last date you practised

Leaderboard statistics are visible to your friends. They are visible on the global leaderboard only if you switch global ranking on yourself; it is off by default, and turning it off again removes you.

2.5 Device and technical information

  • Push notification token and which platform it belongs to (iOS or Android), if you allow notifications. This is a device address for delivering notifications, not an advertising identifier.
  • Your UTC offset — the number of minutes your clock differs from UTC. A streak has to roll over at your midnight, not ours. This is a time zone offset, not a location: it is the same value for everyone on your meridian.
  • Ordinary server logs kept by our hosting provider, which include IP addresses and timestamps of requests. These exist for security and debugging and are not used to build a profile of you.

2.6 Microphone

The tuner needs to hear your instrument. When you open the tuner and grant permission, the app listens to the microphone and works out the pitch on your device.

  • The audio is never recorded to a file.
  • The audio is never transmitted off your device — not to us, not to anyone.
  • Nothing derived from the audio is stored, beyond the note shown on screen.
  • The microphone stops as soon as you leave the tuner.

You can refuse the microphone permission and every other part of Tutti keeps working — you just won't get a working tuner. You can revoke it at any time in your device settings.

2.7 Photos

If you set a profile picture, the app asks for access to your photo library so you can pick one. Only the single image you select leaves your device. We do not read, scan, or upload anything else in your library.

2.8 Product analytics

We use PostHog to understand how the app is actually used — which screens people open, which features they reach for, where a flow gets abandoned, and when something errors. Without it we're guessing about what to build and what's broken.

What that involves:

  • Events, meaning a record that something happened — a screen was viewed, a session was logged, the tuner was opened — along with the time, your app version, and your device type and operating system.
  • An analytics identifier. Events are tied to a random identifier for your install so we can tell one person's ten sessions from ten different people. If you're signed in we may associate that identifier with your account, so a single person's activity across their devices isn't counted as several.
  • Approximate location, no more precise than country or region, derived by PostHog from your IP address. We do not collect GPS location — see §2.9.

What it never involves:

  • No advertising. Analytics data is not used to target ads, is never combined with advertising identifiers, and is never shared with ad networks or data brokers.
  • No practice content. We record that you logged a session, not what you played, how you rated it, or what's in your repertoire. Piece titles, composers, session notes, your bio and your messages to friends are never sent to PostHog.
  • No microphone data, ever. See §2.6.
  • No cross-app or cross-site tracking. We don't follow you anywhere outside Tutti.

Opting out. Email tuttipracticeapp@gmail.com and we will switch analytics off for your account and delete the events already collected. We are adding a toggle in the app's settings so you won't have to ask; until it ships, the email route is the way, and we'd rather say so plainly than describe a switch that isn't there yet.

2.9 What we do not collect

Stated plainly, because these are the things people reasonably worry about:

  • No advertising. The app contains no ad network, no attribution or measurement SDK, no social media pixel, and no advertising identifier (IDFA / Google Advertising ID). We do use product analytics, which is a different thing and is described in §2.8.
  • No location. We do not request or collect GPS or precise location.
  • No contacts. We never read your address book. Friends are added by handle.
  • No audio or video recordings. See §2.6.
  • No health, biometric, or financial data.
  • No payment card details. If Tutti offers paid features in future, purchases are handled by Apple or Google. We never see your card number.
  • No cookies or tracking on this website. tuttipracticeapp.com sets no cookies, loads no third-party scripts, runs no analytics, and self-hosts its fonts specifically so that visiting it doesn't hand your IP address to a font CDN. The analytics in §2.8 are in the app only; reading this page is not measured.

3. Why we use it

What Why
Account information To let you sign in, keep your data attached to you, and recover your account
Practice data and repertoire To show your history, streaks, goals and statistics, and to sync them between your devices
Profile So friends can find you and recognise you
Social data To run friend lists, nudges, battles and leaderboards
Push token To deliver reminders you asked for, streak warnings, nudges from friends and battle results
UTC offset To roll your day over at your midnight rather than ours
Server logs To keep the service secure, find abuse, and debug failures
Analytics events To see which features are used and which are ignored, find where flows break, and decide what to build next. Never for advertising
Your email address To answer you when you write to support, and to send essential service notices (a security issue, or a material change to this policy)

We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.

If GDPR or UK GDPR applies to you, we rely on:

  • Contract (Art. 6(1)(b)) — for everything needed to actually provide the app: your account, your practice data, syncing, and social features you use.
  • Consent (Art. 6(1)(a)) — for push notifications, microphone access, photo library access, appearing on the global leaderboard, and product analytics. You can withdraw any of these at any time, in the app, in your device settings, or by emailing us, without losing access to the rest of Tutti.
  • Legitimate interests (Art. 6(1)(f)) — for keeping the service secure, preventing abuse and fraud, and debugging. We've weighed these against your rights and limited the data involved to what security actually requires.
  • Legal obligation (Art. 6(1)(c)) — where the law requires us to retain or disclose something.

5. Who we share it with

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so, including in the twelve months before this policy took effect.

We use a small number of service providers ("processors") to run the app. Each one only gets what it needs to do its job, and is contractually bound to use it only for that:

Provider What it does Where
Supabase Database, authentication and file storage — this is where your account, practice data and profile actually live United States (US East)
Expo Relays push notifications to Apple and Google. Receives the notification and your push token, not your practice history United States
PostHog Product analytics — receives the events, analytics identifier and device details in §2.8. Never receives your practice content, and is contractually barred from using any of it for its own purposes United States
Apple Sign in with Apple, push notification delivery (APNs), and App Store distribution and billing United States and global
Google Google Sign-In, push notification delivery (FCM), and Google Play distribution and billing United States and global

Beyond those providers, we disclose personal information only:

  • To other users, as described in §6 — the parts of Tutti that are social by design.
  • When the law requires it — a valid subpoena, court order or legal process. We will tell you when we're permitted to.
  • To protect people — where we believe in good faith that disclosure is necessary to prevent serious harm, fraud, or a threat to someone's safety.
  • In a business transfer — if Tutti is ever sold or merged, your data may transfer with it. You'll be notified before your data becomes subject to a different privacy policy, and the buyer will be bound by commitments at least as protective as these.

6. What other people can see

Worth being precise about, because "social app" covers a lot of ground.

  • Anyone who searches your handle can see your display name, username, bio, instrument and profile photo.
  • Your friends can additionally see your streak, your rank and tier, your weekly practice minutes, your consistency score, how many pieces you have performance-ready, and when you last practised. They can nudge you and challenge you to battles.
  • The global leaderboard shows your profile and those same statistics to other users — but only if you turn global ranking on. It is off by default.
  • Nobody sees your individual session entries, your session ratings, your goals, your notes balance, or your email address.

Every table in our database is protected by row-level security rules that enforce the above at the database itself, not just in the app.

7. How long we keep it

  • While your account is open: your account, practice history, repertoire and profile are kept for as long as you keep the account — that's the point of a practice log.
  • When you delete your account: your account and the personal data attached to it are deleted from our live systems within 30 days, and purged from encrypted backups within 90 days, when those backups rotate out.
  • On your device: data stored locally is removed when you delete the app. Deleting the app alone does not delete a synced account — see deleting your account.
  • Server logs: retained for a short period for security and debugging.
  • Analytics events: retained for up to 12 months, then deleted or aggregated into counts that can no longer be linked back to you. Deleting your account also deletes the events tied to it.
  • Support emails: kept while we work through your issue and for a reasonable period afterwards, so we have the history if you write again.
  • We may keep data longer where the law requires it, or where it's needed to resolve a dispute or enforce our agreements.

8. How we protect it

  • All traffic between the app and our servers is encrypted in transit (TLS).
  • Data is encrypted at rest by our hosting provider.
  • Every database table enforces row-level security, so one account cannot read another account's rows even if the app were tampered with.
  • Passwords are stored only as salted cryptographic hashes.
  • Access to production systems is limited and protected by multi-factor authentication.

No system is perfectly secure, and we won't pretend otherwise. If a breach affects your personal data, we'll notify you and the relevant regulators as required by law. Keep your password to yourself and use a unique one.

9. Children

Tutti is intended for people aged 13 and over. It is not directed to children under 13, and we do not knowingly collect personal information from them.

If you are between 13 and 18, please read this policy and our Terms of Use together with a parent or guardian, and only use Tutti with their permission.

If we learn that we have collected personal information from a child under 13, we will delete that information and the associated account promptly. If you are a parent or guardian and believe your child under 13 has given us information, email tuttipracticeapp@gmail.com and we will delete it. Parents and guardians may also request to review or delete their child's information, or refuse further collection, at that address.

10. Your rights and choices

Everyone, everywhere

Whatever jurisdiction you're in, you can exercise all of the following by emailing tuttipracticeapp@gmail.com from your account's email address:

  • Access — get a copy of the personal data we hold about you
  • Correction — fix anything inaccurate (most of it is editable in the app)
  • Deletion — delete your account and its data
  • Portability — receive your data in a portable, machine-readable format
  • Withdraw consent — turn off notifications, revoke microphone or photo access in your device settings, or switch off the global leaderboard in the app

We respond within 45 days and will tell you if we need an extension. We never charge for a request, and never discriminate against you for making one. We may need to verify that the request really comes from you — usually by confirming you control the account's email address.

Texas residents

Under the Texas Data Privacy and Security Act, you have the right to confirm whether we process your personal data, to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling with legal or similarly significant effects.

We do not engage in targeted advertising, sell personal data, or carry out that kind of profiling, so those three opt-outs have nothing to act on — but the right stands, and if that ever changes this policy will change first. If we deny a request you may appeal by replying to our decision; if the appeal is denied you may complain to the Texas Attorney General.

California residents

Under the CCPA as amended by the CPRA, you have the rights to know, delete, correct, and to opt out of sale or sharing, plus the right to limit use of sensitive personal information and the right not to be discriminated against for exercising any of them.

  • We have not sold or shared personal information as those terms are defined by the CCPA in the preceding twelve months, including the personal information of anyone under 16.
  • The categories we collect map to CCPA categories as: identifiers (email, account ID, username, push token, analytics identifier), customer records (name, photo), internet or network activity (server logs, and the in-app usage events in §2.8), approximate geolocation no finer than region, derived by our analytics provider from your IP, audio (processed on-device only, never collected), and inferences (streak, consistency and rank, all derived from what you log). The sources, purposes and disclosures for each are described in §2, §3 and §5.
  • We do not use or disclose sensitive personal information beyond the purposes permitted by the CCPA without a right to limit.

An authorised agent may submit a request on your behalf with written proof of authorisation.

Other US states

Residents of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Oregon, Montana and others as they take effect — have substantially the same rights of access, correction, deletion, portability and opt-out. Use the same email address and we'll handle your request under your state's law.

EEA, UK and Swiss users

In addition to the rights above, you have the right to restrict or object to processing, the right not to be subject to solely automated decision-making (we don't do any), and the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office. We'd appreciate the chance to sort it out first.

Canadian users

Under PIPEDA and equivalent provincial laws you may access and correct your personal information and withdraw consent, subject to legal and contractual limits, and may complain to the Office of the Privacy Commissioner of Canada.

Do Not Track and Global Privacy Control

Tutti does not track you across other apps or websites, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honour them by not doing the thing in the first place.

11. International data transfers

Tutti is operated from the United States and your data is stored on servers in the United States. If you use Tutti from outside the US — including from the EEA or UK — your personal data will be transferred to and processed in the United States, which may have different data protection laws than your country.

Where required, these transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with our service providers, together with supplementary technical measures including encryption in transit and at rest. You can request a copy of the relevant safeguards at tuttipracticeapp@gmail.com.

Tutti and this website may link to services we don't operate — the App Store, Google Play, or a page a friend shares. Their privacy practices are their own, and this policy doesn't cover them. Read theirs before handing over anything.

13. Changes to this policy

We'll update this page when our practices change, and always update the "Last updated" date at the top. If a change is material — a new category of data, a new purpose, a new recipient — we'll give you prominent notice in the app or by email before it takes effect, and get your consent where the law requires it.

Continuing to use Tutti after a change takes effect means you accept the updated policy. Old versions are available on request.

14. Contact us

Questions about this policy, a privacy request, or something that looks wrong — write to us and a human will answer:

tuttipracticeapp@gmail.com

Tutti · Tony Jin · Texas, United States
Postal address available on request for formal legal notices.