Ostinaut — Privacy Policy
Last updated: 8 July 2026
Draft pending final legal review. This policy describes how Ostinaut handles your data. The data controller is Ithilmere, contact privacy@ostinaut.com.
The short version
- Ostinaut requires an account. We store your email and your practice progress so it syncs across your devices — and that’s the heart of what we keep.
- Audio or MIDI files you choose for the “play along to a real song” feature are analysed on your device and are never uploaded to us. Ostinaut does not record from your microphone.
- You can delete your account and all associated data at any time from Account → Danger zone → Delete account.
What we collect
- Account — your email address and a securely hashed password (PBKDF2; we never store your password in readable form). If you sign in with Google, we receive your Google account ID, name, profile image and email from Google’s OAuth service.
- Practice data — sessions you complete (bars played, chords seen, tempo reached, mode, timestamps) and your app settings, so we can show your streak/progress and sync settings across devices.
- Sign-in cookie — a single
HttpOnly,Secure,SameSite=Laxsession cookie. We do not use advertising or cross-site tracking cookies. - Usage analytics — we use PostHog to understand how the app is used: coarse product events such as “app opened”, “signed up”, “started a practice loop”, and purchase-funnel steps, tied to your account ID. This is product analytics, not advertising: no ad networks, no cross-site tracking, and we never sell or share this data for marketing.
We use third-party payment processors (RevenueCat and Stripe) to take purchases and PostHog for product analytics — see “Who processes your data” below.
What we do NOT collect
- We never record from your microphone. The audio/MIDI files you pick for the “play along to a real song” feature are processed entirely in your browser and never leave your device.
- We do not sell your data, use it for advertising, or run ad-network / cross-site trackers of any kind.
Why we’re allowed to (legal basis, GDPR Art. 6)
- Contract — to provide the account, sync and purchase features you ask for.
- Legitimate interests — to keep the service secure and to maintain and improve it.
Retention
Account and practice data are kept while your account exists. Delete your account and everything associated with it is erased from our database (sessions, settings, practice history and the account record). Expired sign-in sessions and verification tokens are purged automatically.
Who processes your data
- Cloudflare — hosts the app and runs our database (D1), where your account and practice data are stored.
- Resend — sends transactional email (e.g. the address verification link) on our behalf.
- Google — only if you choose “Sign in with Google”, which shares your Google account ID, name, profile image and email with us.
- RevenueCat & Stripe — process your purchase if you buy Ostinaut. They handle the payment; we store only the resulting entitlement record (that you’re a paid user, and when) as account data — we never see or store your card details.
- PostHog — hosts our product analytics (the usage events described above). Data is processed on our behalf and not shared with advertisers.
Your rights
You can access, correct, or delete your data, and object to processing. Account deletion is self-serve in-app (Account → Danger zone → Delete account) and erases everything associated with your account. To request a copy of your data, or for anything else, email privacy@ostinaut.com and we’ll handle it manually. If you’re in the EU/UK you may complain to your local data-protection authority.
Children
Ostinaut is not directed at children under 13 (under 16 in some regions) and we do not knowingly collect their data.
Changes
We’ll update the date above when this policy changes and, for material changes, notify you in-app.