Legal

Privacy Policy

Last updated 2 August 2026Audio never leaves your device

SightReadingTraining is a practice tool, not an advertising business. We collect the small amount of data we need to save your drills, grade your playing and keep your streak — nothing more. This policy explains exactly what that means, and it forms part of our Terms of Service.

The short version: your microphone audio is never recorded or uploaded

  • Microphone audio is analysed entirely inside your browser with the Web Audio API and the pitchy library. No audio is recorded, transmitted or stored — only the detected note name is used, locally, to grade the note in front of you.
  • MIDI messages from a connected keyboard are read in the browser via Web MIDI and likewise never leave your device.
  • We do not sell or share your personal information, and we run no advertising or tracking cookies.

1. Who we are and what this policy covers

SightReadingTraining ("we", "us") operates the web app at sightreadingtraining.com. We are the data controller for the personal information described here. This policy covers the website and the practice app; it does not cover third-party sites we link to.

Questions, requests or complaints can go to support@sightreadingtraining.com.

2. Information we collect and why

We collect only these categories of data:

  • Account data. Your email address, and the name and avatar image URL that Google, Apple or Facebook share with us when you use social sign-in. If you sign in with an email magic link, we only hold your email address. We need this to identify your account and to email you sign-in links and essential service notices.
  • Saved drills. The configurations you create: selected key signatures, note ranges per clef, drill length and your chosen input method. We store these so your drills are waiting for you on any device.
  • Practice session results. For each completed session: the score, which notes were correct or incorrect, per-note response timings and accuracy. This is what powers your statistics and per-note weak-spot analysis. We also record which of the built-in drills you have opened, and when, so the drill list can pick up where you left off.
  • Progress counters. Your daily streak, experience points and unlocked achievements.
  • Billing records. If you subscribe to Pro, Stripe holds your payment details and shares with us your subscription status, plan, renewal date and invoice history. We never receive or store your card number.
  • Technical and usage data. Standard server logs kept by our host (IP address, user agent, requested URL, timestamp) for security and debugging, plus aggregated page-view counts from Vercel Analytics.

We do not collect audio recordings, MIDI performance streams, precise location, contact lists, or any special-category data. We do not ask for information we have no use for.

3. Microphone and MIDI stay on your device

This is the most important part of this policy, so we will be very specific.

When you choose microphone input, your browser asks for permission to access the microphone. The incoming audio is fed into an analyser node using the Web Audio API, and the pitchy library estimates the fundamental frequency many times per second. That frequency is converted to a note name and compared against the note currently highlighted on the staff. All of this happens in JavaScript running on your own device.

No part of the audio stream is written to disk, buffered for upload, sent to us, or sent to any third party. There is no server-side audio processing and no speech or voice analysis of any kind. When you leave the drill, the audio stream is released and nothing about it remains. Only the outcome — for example "expected F4, played E4, 620 ms" — is saved as part of your session results.

The same is true for MIDI. If you allow Web MIDI access, note-on and note-off messages from your keyboard are read directly in the browser and used to grade the current note. MIDI data is never transmitted off your device or stored as a performance recording.

You can revoke microphone or MIDI permission at any time in your browser settings; the on-screen virtual piano will still work.

4. How we use your information

  • to create and secure your account, and to sign you in;
  • to store, render and run the drills you build;
  • to grade your playing, calculate accuracy statistics, weak-note analysis, streaks, XP and achievements;
  • to determine whether you are on the free tier or Pro, and to bill you;
  • to send transactional email such as magic links, receipts and important service notices;
  • to reply to your support requests and to investigate abuse, fraud or technical faults;
  • to understand, in aggregate, which pages and features are used so we can improve them;
  • to comply with legal obligations such as tax and accounting rules.

We do not use your data to train third-party advertising models, and we do not build profiles for marketing. We do not make automated decisions about you that have legal effects — grading a note is not one of those.

6. Service providers we share data with

We do not sell your personal information and we do not share it for advertising. We use a short list of processors to run the Service, each bound by contract to handle data only on our instructions:

ProviderPurposeData involved
SupabaseDatabase, authentication and file storageEmail address, name and avatar URL from your sign-in provider, saved drills, session results, streak and XP counters
StripeCheckout, subscription billing and the Billing PortalEmail address, subscription and invoice records, payment details you enter directly with Stripe (we never receive card numbers)
VercelHosting, content delivery and Vercel AnalyticsStandard request logs (IP address, user agent, timestamp) and aggregated, cookie-free page-view metrics
Google, Apple, FacebookOptional OAuth sign-in providers you chooseThey confirm your identity to us and share your email address, name and avatar. We never receive your provider password

We may also disclose data if required by law, to enforce our Terms, to protect someone's safety, or as part of a merger or acquisition — in which case we would notify you and this policy would continue to apply until replaced.

7. Cookies and local storage

We use only what is essential. There are no advertising cookies and no cross-site trackers, so we do not show a cookie consent banner for tracking we do not do.

  • Authentication cookies set by Supabase, which keep you signed in and refresh your session. Removing them signs you out.
  • Stripe cookies, set during checkout and in the Billing Portal, used by Stripe for fraud prevention and to complete your payment.
  • Local storage in your browser, used to remember preferences such as your last input method, instrument volume and unsaved drill settings. This stays on your device.

8. Analytics

We use Vercel Analytics, a privacy-friendly, cookie-free analytics product. It records aggregated page views and performance metrics without setting tracking cookies, without fingerprinting and without building a cross-site profile of you. We use it to see which pages are popular and which are slow — not to identify individuals.

9. How long we keep your data

  • Account, drills and progress — for as long as your account exists.
  • Practice session history — kept while your account exists so you can see long-term trends. On the free tier only the last 7 days are shown in the app, though earlier sessions may remain stored and become visible again if you upgrade.
  • Server logs — kept by our host for a short rolling window (typically about 30 days) for security and debugging.
  • Billing records — retained by us and by Stripe for as long as tax and accounting law requires, usually seven years, even after you close your account.
  • Deleted accounts — account data is removed promptly on request and purged from encrypted backups within 30 days.

10. How we protect your data

All traffic is served over HTTPS. Data at rest in our database is encrypted, and access is restricted by row-level security policies so that one account cannot read another's drills or sessions. We hold no passwords: sign-in is handled by your OAuth provider or by a one-time magic link. We hold no card details: payments are handled entirely by Stripe. Administrative access is limited to the people who need it.

No online service can promise perfect security, but if a breach ever affects your personal data we will notify you and the relevant regulators as required by law.

11. Your privacy rights

Whatever country you are in, you can ask us to:

  • access a copy of the personal data we hold about you;
  • export your drills and practice history in a machine-readable format;
  • correct inaccurate details such as your name or email address;
  • delete your account and its associated data;
  • restrict or object to certain processing, or withdraw a consent;
  • stop non-essential email — every optional email includes an unsubscribe link.

Under the UK/EU GDPR you also have the right to data portability and the right to lodge a complaint with your local supervisory authority. Under the California Consumer Privacy Act, as amended by the CPRA, you have the rights to know, delete, correct and opt out of sale or sharing of personal information — we do not sell or share personal information, so there is nothing to opt out of, and we will never discriminate against you for exercising a right. Nevada and other US state residents have comparable rights.

Email support@sightreadingtraining.com from your account address and we will respond within 30 days. We may need to verify your identity before acting on a request. An authorised agent may submit a request on your behalf with proof of authorisation.

12. International data transfers

We are based in the United States and our providers may process data in the United States and other countries. Where data is transferred out of the UK or EEA, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) in our agreements with Supabase, Stripe and Vercel, together with encryption in transit and at rest. You can ask us for more detail about these safeguards.

13. Children's privacy

The Service is intended for users aged 13 and over. Users under the age of majority should have a parent or guardian's consent. We do not knowingly collect personal information from children under 13, and we do not direct advertising at anyone. If you believe a child under 13 has created an account, email us and we will delete the account and its data promptly.

14. Changes to this policy

We will update this policy when our practices or providers change. The "Last updated" date at the top always reflects the current version, and for material changes we will notify you in the app or by email before they take effect. We will never quietly weaken the microphone and MIDI guarantee described in section 3 — it is a design decision, not a setting.

15. How to contact us

For any privacy question, data request or complaint, email support@sightreadingtraining.com. We read every message and aim to reply within a few business days.