The short version
Tutti is a practice log, not an advertising business. We collect what the app needs to work and nothing else: your practice history, your repertoire, the profile you choose to show other players, and — if you sign in — an email address to attach it all to.
We do not run ads, use advertising identifiers, collect your location or contacts, or sell or share your personal information. The microphone is used only while the tuner is open, is analysed entirely on your device, and is never recorded or uploaded. You can use the entire app offline without ever creating an account.
The app does record product analytics — which screens get opened and which features get used — so we can tell what's working and what's broken. It is never used for advertising, never sold, and never applied to your practice content, and it runs with IP collection switched off, so it carries no location either. §2.9 spells out exactly what that covers.
Tutti Pro is a paid subscription. Apple and Google take the payment — we never see your card details — and §2.8 covers what we do keep.
Because other players can see some of what you write, you can report anything you shouldn't have to see and block anyone you'd rather not deal with. Doing either creates a record — including a copy of what you reported — that we read in order to act on it. §2.10 is the detail.
The rest of this page is the detail behind those sentences. Questions: tuttipracticeapp@gmail.com.
1. Who we are
Tutti ("Tutti", "we", "us") is a mobile application operated by Tony Jin, an individual based in Texas, United States. For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the personal data described in this policy.
This policy covers the Tutti mobile app on iOS and Android and the website at
tuttipracticeapp.com. It does not cover anything you reach by following a
link out of the app or the site.
Contact: tuttipracticeapp@gmail.com. We answer privacy requests at that address; there is no separate privacy inbox.
2. What we collect
Almost everything below is information you type into the app yourself. Nothing here is bought from a data broker or scraped from anywhere else.
2.1 Account information
Only if you choose to create an account. The app works fully signed out, with your data stored on your device and nowhere else.
- Email and password. If you sign up with an email address, we store the address and a cryptographic hash of your password — never the password itself.
- Sign in with Apple. Apple sends us an account identifier, your email address, and the name you agree to share. If you choose Apple's Hide My Email, we only ever see the private relay address, not your real one.
- Sign in with Google. Google sends us an account identifier, your email address, your name, and your Google profile picture URL. We do not receive your Google password, and we do not get access to any other Google service.
- Timestamps for when the account was created and last signed in.
2.2 Your profile
The public half of your account — what other players can find. You choose every value, and everything except the username is optional and can be left blank:
- A username (your handle). Every account has one, it is unique to you, and it is required — you pick it when you create the account, and it is how other players find you to add you as a friend. You can change it later, but not remove it while the account exists.
- Display name
- A short bio
- Your instrument
- A profile photo, if you set one
A note on profile photos. Profile pictures are stored so that they can be loaded by anyone who can see your profile, which means the image file is reachable by anyone who has its web address. Treat a profile photo as public. Don't upload anything you wouldn't be comfortable being seen — and remember the general rule of the internet: a photo, once published anywhere, can be copied.
2.3 Practice data
The reason the app exists. For each session you log:
- The date, the exact time you finished, and how many minutes you practised
- A name for the session, if you give it one — sessions are titled by time of day ("Morning Session") unless you rename them
- Your own one-to-five rating of how the session went
- What you focused on, and which pieces and scales you worked on
- An optional breakdown of how the time was split
- Your streak as it stood when you logged the session
Alongside that, we store:
- Your repertoire — title, composer, category, level, and status (learning, polishing, performance-ready) for each piece
- Your goals and settings — daily target, weekly target, days per week, your default session breakdown, and your chosen instrument
- Streak and progress state — current streak, whether a streak freeze is available, which weeks have been forgiven, quests you've claimed, and your in-app note balance
2.4 Social features
Only generated if you use them:
- Friendships, and friend requests you send or receive
- The practice feed. Each session you log is shared with your friends as a post in their feed — what a post shows is spelled out in §6. The feed is built from the practice data in §2.3; using it creates no additional data beyond the session itself.
- Nudges you send to friends, and who you've pinned
- Practice battles — who challenged whom, the mode, the stake, the days each side practised, and the outcome
- Leaderboard and profile statistics — your streak, consistency score, weekly minutes, overall rank, how many pieces you have performance-ready, and the last date you practised, plus the aggregate figures shown on your profile page: your longest-ever streak, your total practice minutes, and your total number of sessions
- Friend suggestions. To suggest people worth adding, we look at the friend connections between accounts — who is connected to whom, and how many friends two people have in common. This is computed on our servers at the moment you open the discovery screen; we do not build or store a profile of your social graph beyond the friendships themselves.
Leaderboard statistics are visible to your friends. They are visible on the global leaderboard only if you switch global ranking on yourself; it is off by default, and turning it off again removes you.
2.5 Device and technical information
- Push notification token and which platform it belongs to (iOS or Android), if you allow notifications. This is a device address for delivering notifications, not an advertising identifier.
- Your UTC offset — the number of minutes your clock differs from UTC. A streak has to roll over at your midnight, not ours. This is a time zone offset, not a location: it is the same value for everyone on your meridian.
- Ordinary server logs kept by our hosting provider, which include IP addresses and timestamps of requests. These exist for security and debugging and are not used to build a profile of you.
2.6 Microphone
The tuner needs to hear your instrument. When you open the tuner and grant permission, the app listens to the microphone and works out the pitch on your device.
- The audio is never recorded to a file.
- The audio is never transmitted off your device — not to us, not to anyone.
- Nothing derived from the audio is stored, beyond the note shown on screen.
- The microphone stops as soon as you leave the tuner.
You can refuse the microphone permission and every other part of Tutti keeps working — you just won't get a working tuner. You can revoke it at any time in your device settings.
2.7 Photos
If you set a profile picture, the app asks for access to your photo library so you can pick one. Only the single image you select leaves your device. We do not read, scan, or upload anything else in your library.
2.8 Subscriptions and purchases
Tutti Pro is a paid subscription. Buying one is handled entirely by Apple's App Store or Google Play — we never see your card number, billing address, or any other payment detail, and neither does any provider of ours.
To know whether to unlock Pro for you, we use RevenueCat, which sits between the app and the store and keeps a record of your entitlement. What it holds:
- Your account identifier — the same id our database uses — or, if you subscribe before signing in, a random anonymous id that is merged into your account when you do.
- Your subscription state — which product you bought, whether you are in a free trial, when the period renews or expires, and the purchase and cancellation events behind that.
- A store receipt identifier from Apple or Google, which is how a purchase is verified and how "Restore purchases" finds it again.
We do not send RevenueCat your email address, your name, or anything you have practised. The store also tells us nothing about you beyond the purchase itself.
2.9 Product analytics
We use PostHog to understand how the app is actually used — which screens people open, which features they reach for, where a flow gets abandoned, and when something errors. Without it we're guessing about what to build and what's broken.
What that involves:
- Events, meaning a record that something happened — a screen was viewed, a session was logged, the tuner was opened — along with the time, your app version, and your device type and operating system.
- An analytics identifier. Events are tied to a random identifier for your install so we can tell one person's ten sessions from ten different people. If you're signed in we may associate that identifier with your account, so a single person's activity across their devices isn't counted as several.
Analytics events are sent with IP address collection switched off. Our analytics provider discards the address on arrival rather than storing it or turning it into a location, so no country, region, city or coordinate is derived from it and none is kept. See §2.11.
What it never involves:
- No advertising. Analytics data is not used to target ads, is never combined with advertising identifiers, and is never shared with ad networks or data brokers.
- No practice content. We record that you logged a session, not what you played, how you rated it, or what's in your repertoire. Piece titles, composers, session notes, your bio and your messages to friends are never sent to PostHog.
- No microphone data, ever. See §2.6.
- No email address, username or profile. Events are tied to your account id and nothing else. Your address is never sent to our analytics provider, so it cannot be used to look you up there.
- No cross-app or cross-site tracking. We don't follow you anywhere outside Tutti.
Opting out. Turn off Settings → Share usage data in the app. Nothing further is sent from that moment, on that device, and the choice survives signing out and back in. To also have the events already collected erased, email tuttipracticeapp@gmail.com from your account's address; we answer these within 45 days and usually much sooner. Deleting your account also deletes the events tied to it.
2.10 Reports and blocks
Tutti carries content other players write — comments, profile names and bios, session titles — so it has to carry the means to deal with content that shouldn't be there.
If you block someone, we store the fact of the block: who blocked whom, and when. A block is mutual and total — neither of you can see the other's posts, comments or profile, and neither can find the other in search or friend suggestions — and it removes any friendship, pending request or open challenge between you. The person you blocked is never told. You can see and undo your blocks in the app, under Settings → Blocked accounts.
If you report something, we store a record of the report:
- Who reported it and whose content it was
- What was reported — a comment, a session, or a profile
- The reason you chose (spam, harassment, hate, sexual content, violence, self-harm, impersonation, or "something else") and the optional note you wrote
- A copy of the content you reported, taken at the moment you reported it. This is the part worth being plain about: the record has to survive the content, because either party can delete a comment before anyone has looked at it. It means we hold a snapshot of something another person wrote.
- The time, and where the report has got to (open, reviewed, actioned, dismissed)
Who sees a report. Only us — the account that operates Tutti. A report is never shown to the person reported, never shown to other players, and never used for anything except deciding what to do about it. Reporting is not anonymous to us: we can see who filed it, which is how we deal with people who abuse the report button.
How a report reaches us. A new report triggers a push notification to
the operator's device and appears in a once-daily summary email to
tuttipracticeapp@gmail.com. Both carry a short excerpt of the reported
content — up to 80 characters in the notification, 200 in the email — so the email
provider named in §5 handles that excerpt in passing. Our
Terms of Use commit us to reviewing a report within 24 hours.
Filtering before the fact. Comments, display names and bios are checked when you submit them. If something is rejected you're asked to reword it; the rejected text is not stored and never reaches anyone else.
2.11 What we do not collect
Stated plainly, because these are the things people reasonably worry about:
- No advertising. The app contains no ad network, no attribution or measurement SDK, no social media pixel, and no advertising identifier (IDFA / Google Advertising ID). We do use product analytics, which is a different thing and is described in §2.9.
- No location, of any kind. We do not request GPS or precise location, and we do not derive an approximate one either — analytics runs with IP collection switched off, so there is no country, region or city on file. The only geographic thing we store is your UTC offset, which is a clock setting (see §2.5).
- No contacts. We never read your address book. Friends are added by handle.
- No audio or video recordings. See §2.6.
- No health or biometric data.
- No payment card details. Tutti Pro is sold through the App Store and Google Play, and they handle the payment. We never see your card number, and we store no financial data beyond whether your subscription is active — see §2.8.
- No cookies or tracking on this website. tuttipracticeapp.com sets no cookies, loads no third-party scripts, runs no analytics, and self-hosts its fonts specifically so that visiting it doesn't hand your IP address to a font CDN. The analytics in §2.9 are in the app only; reading this page is not measured.
3. Why we use it
| What | Why |
|---|---|
| Account information | To let you sign in, keep your data attached to you, and recover your account |
| Practice data and repertoire | To show your history, streaks, goals and statistics, to sync them between your devices, and to share your finished sessions with your friends in the practice feed |
| Profile | So friends can find you and recognise you |
| Social data | To run friend lists, the practice feed, nudges, battles and leaderboards |
| Friend connections | To suggest people you might know or want to practise alongside, and to show how many friends you have in common |
| Reports and blocks | To keep the app usable — to review what gets reported and act on it, to keep two people apart when one of them has asked for it, and to spot people who misuse the report button |
| Push token | To deliver reminders you asked for, streak warnings, nudges from friends and battle results |
| UTC offset | To roll your day over at your midnight rather than ours |
| Server logs | To keep the service secure, find abuse, and debug failures |
| Analytics events | To see which features are used and which are ignored, find where flows break, and decide what to build next. Never for advertising |
| Subscription state | To unlock Tutti Pro on every device you sign in on, to restore a purchase you have already made, and to answer billing questions you write to us about |
| Your email address | To answer you when you write to support, and to send essential service notices (a security issue, or a material change to this policy). If — and only if — you ask us to, also to send you an occasional newsletter about the app. That is off unless you turn it on, and every newsletter has an unsubscribe link in it |
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.
4. Legal bases (EEA and UK users)
If GDPR or UK GDPR applies to you, we rely on:
- Contract (Art. 6(1)(b)) — for everything needed to actually provide the app: your account, your practice data, syncing, and social features you use.
- Consent (Art. 6(1)(a)) — for push notifications, microphone access, photo library access, appearing on the global leaderboard, and the newsletter. You can withdraw any of these at any time, in the app or in your device settings, without losing access to the rest of Tutti.
- Legitimate interests (Art. 6(1)(f)) — for product analytics; for moderation, meaning the reports and blocks in §2.10, where our interest and yours are the same one, in an app that isn't a place to be harassed; and for keeping the service secure, preventing abuse and fraud, and debugging. Analytics is limited to how the app is used, carries no advertising identifier, no IP address and no location, and is never combined with third-party data — which is what makes our interest in knowing what to build proportionate to your privacy. You have the right to object at any time by emailing us, and we will stop and erase what's there. We've weighed these against your rights and limited the data involved to what security actually requires.
- Legal obligation (Art. 6(1)(c)) — where the law requires us to retain or disclose something.
5. Who we share it with
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so, including in the twelve months before this policy took effect.
We use a small number of service providers ("processors") to run the app. Each one only gets what it needs to do its job, and is contractually bound to use it only for that:
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication and file storage — this is where your account, practice data and profile actually live | United States (US East) |
| Expo | Relays push notifications to Apple and Google. Receives the notification and your push token, not your practice history. A notification telling us a report has arrived carries a short excerpt of the reported content (§2.10) | United States |
| Resend | Sends the daily summary of open reports to our own inbox. Receives that email, which lists the reason, the accounts involved and a 200-character excerpt of the reported content (§2.10). Receives nothing else — no practice data, no profiles, and no mail to you | United States |
| PostHog | Product analytics — receives the events, analytics identifier and device details in §2.9. Never receives your practice content, your email address or your IP address, and is contractually barred from using any of it for its own purposes | United States |
| RevenueCat | Subscription management — receives your account identifier, your Tutti Pro subscription state and the store receipt identifier behind it (§2.8). Never receives your email address, your profile or your practice data, and never sees your payment details | United States |
| Apple | Sign in with Apple, push notification delivery (APNs), and App Store distribution and billing | United States and global |
| Google Sign-In, push notification delivery (FCM), and Google Play distribution and billing | United States and global |
Beyond those providers, we disclose personal information only:
- To other users, as described in §6 — the parts of Tutti that are social by design.
- When the law requires it — a valid subpoena, court order or legal process. We will tell you when we're permitted to.
- To protect people — where we believe in good faith that disclosure is necessary to prevent serious harm, fraud, or a threat to someone's safety.
- In a business transfer — if Tutti is ever sold or merged, your data may transfer with it. You'll be notified before your data becomes subject to a different privacy policy, and the buyer will be bound by commitments at least as protective as these.
6. What other people can see
Worth being precise about, because "social app" covers a lot of ground.
- Anyone who searches your handle can see your display name, username, bio, instrument and profile photo.
- Profile pages. Tapping a player's picture anywhere in the app opens their profile page. For any signed-in player, yours shows the profile fields above. The rest of the page — your rank and tier, the statistics listed below, and your current repertoire — appears only for your friends, or for everyone if you have turned the global leaderboard on.
- Anyone using friend discovery may be shown your profile. Signed-in players see suggestions of people to add, and every account is eligible to appear — including yours, whether or not you have any friends yet. A suggestion shows your display name, username, instrument and profile photo, plus how many friends you have in common with the person seeing it. Suggestions are ranked three ways: people connected to your friends, people with the most friends, and a random selection. Your bio, your practice history and your statistics are never part of a suggestion.
- Your friends can additionally see your streak, your rank and tier, your weekly practice minutes, your consistency score, how many pieces you have performance-ready, and when you last practised; on your profile page they also see your longest-ever streak, your total practice time, your total number of sessions, and your current repertoire — each piece's title, composer, category, level and status. They can nudge you and challenge you to battles.
- Your friends also see your sessions themselves, in two places: each session you log appears as a post in their practice feed, and your practice log is readable from your profile. A session shows its name (the time-of-day default, or whatever you renamed it to), the date and time you logged it, the minutes, your one-to-five rating, how the time was split, the scales you worked on, the titles of the pieces you practised, and the streak you were on at the time. If you would rather a session carried no title of your choosing, leave the default name in place.
- The global leaderboard shows your profile and your statistics to other users, and turning it on also makes your full profile page — the statistics, repertoire and practice log described above — viewable by any signed-in player. It is off by default, and turning it off again restores the friends-only rule. The practice feed itself is never global: only your friends' feeds carry your sessions.
- Nobody sees your practice notes — what you write about a session is a diary entry, and no part of the app shows another player's writing — and nobody sees your goals, your notes balance, or your email address.
Anyone you have blocked, or who has blocked you, sees none of it — not your profile, not your posts, not your comments, and not you in search or in friend suggestions. That works in both directions and doesn't depend on who did the blocking. See §2.10.
Every table in our database is protected by row-level security rules that enforce the above at the database itself, not just in the app.
Being suggested to other people
Friend discovery currently has no opt-out: if you have an account, you can be suggested to other players. We are adding a setting to turn this off, and until it ships you can email tuttipracticeapp@gmail.com and we will exclude you by hand. Signing out or deleting your account also removes you immediately. We'd rather tell you this plainly than describe a switch that isn't there yet.
7. How long we keep it
- While your account is open: your account, practice history, repertoire and profile are kept for as long as you keep the account — that's the point of a practice log.
- When you delete your account: delete it from Settings → Delete account in the app and the account row itself goes at once, taking every table that hangs off it with it. The remainder — anything left in our live systems — is gone within 30 days, and purged from encrypted backups within 90 days, when those backups rotate out.
- On your device: data stored locally is removed when you delete the app. Deleting the app alone does not delete a synced account — see deleting your account.
- Server logs: retained for a short period for security and debugging.
- Reports and blocks: a block lasts until you lift it. A report — and the snapshot of content in it — is kept after it has been dealt with, because a pattern across several reports is often the only way to see that someone is a problem. Deleting your account removes both the reports you filed and the reports filed about you, along with any blocks either side of you.
- Analytics events: retained for up to 12 months, then deleted or aggregated into counts that can no longer be linked back to you. Deleting your account also deletes the events tied to it.
- Subscription records: kept while the subscription is active and for a period afterwards, so a lapsed subscriber can restore a purchase and so we can meet tax and accounting obligations. These are records of a transaction, so deleting your account does not always erase them immediately.
- Support emails: kept while we work through your issue and for a reasonable period afterwards, so we have the history if you write again.
- We may keep data longer where the law requires it, or where it's needed to resolve a dispute or enforce our agreements.
8. How we protect it
- All traffic between the app and our servers is encrypted in transit (TLS).
- Data is encrypted at rest by our hosting provider.
- Every database table enforces row-level security, so one account cannot read another account's rows even if the app were tampered with.
- Passwords are stored only as salted cryptographic hashes.
- Access to production systems is limited and protected by multi-factor authentication.
No system is perfectly secure, and we won't pretend otherwise. If a breach affects your personal data, we'll notify you and the relevant regulators as required by law. Keep your password to yourself and use a unique one.
9. Children
Tutti is intended for people aged 13 and over. It is not directed to children under 13, and we do not knowingly collect personal information from them.
If you are between 13 and 18, please read this policy and our Terms of Use together with a parent or guardian, and only use Tutti with their permission.
If we learn that we have collected personal information from a child under 13, we will delete that information and the associated account promptly. If you are a parent or guardian and believe your child under 13 has given us information, email tuttipracticeapp@gmail.com and we will delete it. Parents and guardians may also request to review or delete their child's information, or refuse further collection, at that address.
10. Your rights and choices
Everyone, everywhere
Whatever jurisdiction you're in, you can exercise all of the following by emailing tuttipracticeapp@gmail.com from your account's email address:
- Access — get a copy of the personal data we hold about you
- Correction — fix anything inaccurate (most of it is editable in the app)
- Deletion — delete your account and its data. You don't need to email us for this one: Settings → Delete account in the app does it immediately. See deleting your account.
- Portability — receive your data in a portable, machine-readable format
- Withdraw consent — turn off notifications or Share usage data in the app, revoke microphone or photo access in your device settings, or switch off the global leaderboard in the app
We respond within 45 days and will tell you if we need an extension. We never charge for a request, and never discriminate against you for making one. We may need to verify that the request really comes from you — usually by confirming you control the account's email address.
Texas residents
Under the Texas Data Privacy and Security Act, you have the right to confirm whether we process your personal data, to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling with legal or similarly significant effects.
We do not engage in targeted advertising, sell personal data, or carry out that kind of profiling, so those three opt-outs have nothing to act on — but the right stands, and if that ever changes this policy will change first. If we deny a request you may appeal by replying to our decision; if the appeal is denied you may complain to the Texas Attorney General.
California residents
Under the CCPA as amended by the CPRA, you have the rights to know, delete, correct, and to opt out of sale or sharing, plus the right to limit use of sensitive personal information and the right not to be discriminated against for exercising any of them.
- We have not sold or shared personal information as those terms are defined by the CCPA in the preceding twelve months, including the personal information of anyone under 16.
- The categories we collect map to CCPA categories as: identifiers (email, account ID, username, push token, analytics identifier, store receipt identifier), customer records (name, photo), commercial information (your Tutti Pro subscription state and purchase history, per §2.8), internet or network activity (server logs, and the in-app usage events in §2.9), audio (processed on-device only, never collected), and inferences (streak, consistency and rank, all derived from what you log). We collect no geolocation category at all. The sources, purposes and disclosures for each are described in §2, §3 and §5.
- We do not use or disclose sensitive personal information beyond the purposes permitted by the CCPA without a right to limit.
An authorised agent may submit a request on your behalf with written proof of authorisation.
Other US states
Residents of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Oregon, Montana and others as they take effect — have substantially the same rights of access, correction, deletion, portability and opt-out. Use the same email address and we'll handle your request under your state's law.
EEA, UK and Swiss users
In addition to the rights above, you have the right to restrict or object to processing, the right not to be subject to solely automated decision-making (we don't do any), and the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office. We'd appreciate the chance to sort it out first.
Canadian users
Under PIPEDA and equivalent provincial laws you may access and correct your personal information and withdraw consent, subject to legal and contractual limits, and may complain to the Office of the Privacy Commissioner of Canada.
Do Not Track and Global Privacy Control
Tutti does not track you across other apps or websites, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honour them by not doing the thing in the first place.
11. International data transfers
Tutti is operated from the United States and your data is stored on servers in the United States. If you use Tutti from outside the US — including from the EEA or UK — your personal data will be transferred to and processed in the United States, which may have different data protection laws than your country.
Where required, these transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with our service providers, together with supplementary technical measures including encryption in transit and at rest. You can request a copy of the relevant safeguards at tuttipracticeapp@gmail.com.
12. Links to other services
Tutti and this website may link to services we don't operate — the App Store, Google Play, or a page a friend shares. Their privacy practices are their own, and this policy doesn't cover them. Read theirs before handing over anything.
13. Changes to this policy
We'll update this page when our practices change, and always update the "Last updated" date at the top. If a change is material — a new category of data, a new purpose, a new recipient — we'll give you prominent notice in the app or by email before it takes effect, and get your consent where the law requires it.
Continuing to use Tutti after a change takes effect means you accept the updated policy. Old versions are available on request.
14. Contact us
Questions about this policy, a privacy request, or something that looks wrong — write to us and a human will answer:
Tutti · Tony Jin · Texas, United States
Postal address available on request for formal legal notices.