🎸 Guitar Practice Routine App

Privacy Policy

Last Updated: August 2nd, 2026

I take your privacy seriously. This policy explains what data I collect and why, how I use it, and the control you have over your information. I'm into transparency, so I've written this in plain English instead of legalese.

What gets collected and why

Practice Data:
What: The items, routines, chord charts, practice events, and practice stats you create while using GPRA. This is your data. You own it, I just store it for you.
Why: The 'why' here is pretty self-explanatory.

Account information:
What: Your email address, username, and (if you signed up with Google or Tidal) your encrypted OAuth ID from those services. (Btw, if you sign up / login with Tidal, I don't get your email address, because they don't send it by default, and I don't request it, because I don't have a newsletter, I don't spam people with annoying upsell attempts, nor do I sell email addresses to spammers.)
Why: Your email address is needed for you to reset your password. For Google and Tidal logins, I have to keep the OAuth ID in order to be able to log you back in to the correct account. (Side note for Tidal users: If someone pays for the app for three months in a row without logging in at all, I'll send an email saying something along the lines of "Hey, you haven't been using the app, do you really mean to keep paying for it?" so, you'll need to add your email address on the Account/Settings page if you'd like to get those emails.)

Subscription data:
What: If you're on a paid tier, I store your Stripe customer ID, subscription tier, and payment history. (Stripe handles all the actual payment processing, I never see your credit card number.)
Why: I have to store your Stripe customer ID in order to connect your payments to the correct account. I store your payment history so I can keep your data for you for 90 days in case you miss a month, or if you purposefully pause your subscription for a couple of months. (Payment history also helps me keep an eye out for people who are trying to abuse the system to steal free or discounted use.)

Account activity:
What: I use PostHog for traffic analytics, feature flags, tracking my usage of the Anthropic API, error tracking, and to provide some of the features of the app, like your practice stats. PostHog tracks activity on the site.
Why: I'm not using it to "spy" on people, I'm using it to understand how the app is being used, where people are running into difficulty, and how I can make changes to improve the app to make it easier to use.
(Full disclosure: I work at PostHog, but GPRA is my own personal project, unrelated to PostHog beyond my use of PostHog as a customer.)

Optional stuff:
What: If you add your own Anthropic API key (the "byoClaude" feature), it's encrypted (I can't see it) and stored so it works. You can remove it anytime on the Account/Settings page.
Why: So you can use the autocreate feature with the free, Dollar Store, and Basic tier plans.

What I do with your info

I use your data to provide GPRA's functionality, and to understand how people use the app so I can improve it. That's it. I'm not in the business of selling or sharing your information (email addresses, usage info, etc.), and I never will be. I can't, don't, and won't track your activity on other websites. I didn't build this app to "get rich", I'm just hoping I'll make enough to pay for the cost of hosting it, to break even. (Don't get me wrong, it'd be really cool if it makes a profit, but that seems quite unlikely with the low fees and the fact that it's kinda niche.) More specifically:

  • Process payments via Stripe (they're PCI compliant, so your payment info is kept secure)
  • Send password reset emails (via Mailgun) if you forget your password and need to reset it.
  • Improve the app with PostHog's platform (you can opt out of PostHog cookies in Account/Settings.)
  • If I notice you had trouble using the app, I may send you an email to try to help and/or ask for your feedback about how to improve the app.
  • Read logs of website activity to troubleshoot broken bits of code to fix any problems you may encounter.
  • Send you an email if you pay for 3 months without using the app (a reminder to stop paying if you've stopped using it.)
  • Send you an email reminder 7 days before your data is deleted, if you haven't downloaded it yet.

What I don't and won't do with your info

  • Your data will never be sold to, shared with, or otherwise divulged to third parties. Ever. Period.
  • I won't send you a 'newsletter' or 'app updates'
  • I won't send you marketing noise to try to get you to spend more money
  • I won't save any files you upload to autocreate chord charts (they're not saved at all, they're just shown to Claude so he can create the chord charts, and then they vanish into the ether.)
  • I won't use your info to "increase shareholder value" (narrator's voice: he's the only shareholder.)
  • I won't judge your music. If you like it, it's good for you. I'm pretty polyjamorous myself, I like most kinds of music (with a couple of strong exceptions).
  • I won't steal something you wrote (I don't have the time or the interest to be poking around in your routines or chord charts. Also, I don't write music, I just play covers myself, so I don't want any part of your mediocre break-up songs. 😉)

Your Rights (GDPR & CPRA)

You have complete control over your data via the Account/Settings page (gear icon in the upper-right):

  • Download your data: Export your items, routines, and chord charts
  • Opt out of analytics: Deletes PostHog cookies, prevents them from being reloaded. (Heads up: your practice stats are powered by those cookies, so opting out also stops stats tracking.)
  • Delete your account: Remove all your data permanently. You can schedule deletion for your next renewal date, or delete immediately (no refunds though.) See Account Settings.
  • Update your information: Change your email*, username, or API key anytime
    *Unless you signed up with Google, their OAuth system doesn't work that way. Use the chat widget or open an issue on GitHub if you need your data moved from one login to another.

Third-party services

I use these services to make GPRA work. Each has their own privacy policy. I've linked to their privacy policies below, so you don't have to go find them yourself if you want to read them...

Stripe

Handles all payment processing for subscriptions. I can't see your credit card numbers, Stripe keeps them safe and encrypted.

PostHog

Analytics to help me improve GPRA. I track things like which features you use and how, and where bugs happen. PostHog also crunches the numbers for the practice stats you see on the Stats page. I use other parts of the PostHog platform too — the help/chat widget, feature flags, error tracking, session replay, etc. (there's a full rundown in the Cookies section below). You can opt out of PostHog cookies at anytime in Account/Settings (though opting out means no practice stats, since that's where they come from.)

Anthropic (Claude)

Claude makes the chord chart autocreation feature happen. When you upload images or PDFs for chord charts, the images are sent to Claude for analysis so he can create the chord. (AFAIK, Anthropic doesn't save those files, but you can also bring your own Anthropic API key if it makes you feel better.)

Google OAuth and reCAPTCHA

Optional Google sign-in method using your Google account, and the tool to try to make sure you're human so my site doesn't get overwhelmed by bot farms.

Tidal OAuth

Optional sign-in method using your Tidal account. Note: Tidal doesn't provide your email address to me by default, and I don't request it, so I create a fake email address as a placeholder for your account. You can add your real email address in Stripe's Customer Portal if you like (in case you want an email reminder when you pay for 3 months in a row without using the app.)

Mailgun

To send password reset emails and account notifications. That's all. I don't send marketing emails or spam. Ever. Period. (I'm not even comfortable using a spam-cannon company to send these emails, but they're free and dependable so...)

Data Retention

Practice Items, Routines, Chord Charts, Notes, Practice Stats: If you stop paying for your account, I keep your stuff for 90 days, in case you want to come back and pick up where you left off. After that I give it an extra 30-day buffer before anything is actually deleted, so nobody loses data they meant to keep by cutting it close. You'll get a reminder 7 days before deletion if you haven't downloaded your data yet.

Deleted Accounts: When you delete your account (either scheduled or immediate), I permanently erase all your data. There's no way to recover it, after deletion it's gone for good.

Cookies

Here's everything GPRA uses cookies (and other browser storage) for:

  • Session cookies: Required for logging in and staying logged in. (If you sign in with Google or Tidal there's also a "remember me" cookie, so you don't have to log in again every visit.) These are "functional cookies" and so they don't require consent.
  • PostHog cookies: These do more than analytics, so here's the whole list of what they're doing:
    • Usage analytics: Which features get used, and where people get stuck, what's broken. So I know what to fix.
    • Your practice stats. The Stats page is built entirely out of PostHog data, so no cookies means no stats.
    • The help/chat widget in the bottom-right corner. It's part of PostHog's script, so it only exists on the page if cookies are allowed. (If you'd rather not have cookies but still need to reach me, open an issue on GitHub instead.)
    • Error tracking, so I find out when something breaks for you instead of waiting for you to tell me.
    • Feature flags, which decide which version of a feature you get.
    • Session replay: Only applies if you've accepted cookies.

      Note on session replay: I cannot access the camera on your device, and session replay recordings are not actual videos. They are a visual reconstruction based on logs. I do not record every session, it's randomized. I use it to learn things how I need to improve the site, and to notice when people are trying to abuse the system to do harm. I can't see anything you type into any field in the recordings. Everything you type is replaced by dots, I can't see what you type. So, I can watch a visual reconstruction of your clicks on my site, which is less invasive than when you go into a retail store, bank, movie theater, mall, etc. where the managers and owners can watch videos of you walking around on their property. If you don't like the idea of a visualization built from logs, you can reject cookies to prevent your sessions from being recorded (but if that really concerns you, I'll also suggest you stop using the web and apps, most of which are now doing the same, and maybe stop going to brick-and-mortar stores and businesses, because most of them are now recording you when you do.)
  • If you say no to cookies: no practice stats, no help/chat widget, and no session replay. You can change your mind either way, anytime, on the Account/Settings page.
  • No cross-site tracking, ever: if you do allow cookies, they cannot and will not be used to follow you around other websites. I don't load tracking pixels or third-party cookies from Facebook, Instagram, X, TikTok, LinkedIn, Google Analytics, or anyone else. There are none on this site. What happens on GPRA stays on GPRA.
  • Which cookie banner you see depends on the laws where you are: in the EU/EEA, UK, Switzerland, and California, analytics cookies stay off until you click "Accept all". Everywhere else they're on by default and the banner lets you turn them off. Note: Dismissing the banner with the X isn't a decision either way. ("If you choose not to decide, You still have made a choice") It just hides the banner for that visit.
  • Your cookie choice itself: is saved in your browser's localStorage and on your session on my server, so you won't be pestered with the cookie banner on every page.
  • reCAPTCHA: the login, signup, and password reset pages load Google's reCAPTCHA to tell humans apart from bots, and it sets its own `_GRECAPTCHA` cookie for that (Google's info about it). That's a security thing, not a tracking thing, and it's used regardless of your choice on optional cookies. I don't get any information from it, and I can't use it to track you across other websites (nor would I if I could).
  • Settings kept in your browser: things like light/dark mode, chord chart density, auto-scroll speed, and timer volume. These live in your browser's localStorage so the app works the way you left it. They stay on your device and aren't sent anywhere. So yes, the app will remember if you're one of those weirdos who prefers light mode.

Questions or Concerns?

The code is open source, the repo is here. You can also use the chat widget in the bottom-right corner, or open an issue on GitHub.

Back to GPRA · Find a chord chart · About · Why · Help · Pricing · Terms · Login · Sign up
Switch to Light Mode