Phrases
Last updated 30 August 2026 · replaces the version of 20 August · see §11
Phrases is a practice app for musicians. It is built to work at a piano, offline, without an account, and almost everything you put into it never leaves your device.
Two things leave, and only if you choose them: feedback you write, and a bundle you publish. An account is needed for the second and for nothing else.
Gavin Cox is the data controller for the personal data described here.
Contact for anything in this policy, including requests to see or delete your data: phrases@sourcemungo.com
All of the following is stored only in a database on your phone or tablet. It is never uploaded, and we cannot see it:
Two clarifications that matter, because the general statement above is not the whole truth on its own:
Audio and video you record inside the app will leave if you publish or send a bundle containing it. That is the point of a bundle — a lick you cannot hear is half a lick — and the send screen tells you exactly how many recordings will travel before you do it. Photographs never travel, whatever you do. Practice recordings — the takes you record against the metronome — never travel either.
Automatic phone backups are the platform's, not ours. The app asks Android not to include its data in Google's automatic backup, so your library and recordings are not copied to your Google account by it.
If you export a backup yourself, that file is written to storage you choose and shared using your own device's sharing features. It does not pass through us. The file does not contain your sign-in credentials — restoring a backup onto a new phone will ask you to sign in again, deliberately, so that a backup file is not a key to your account.
If you delete the app, the data on your device is deleted with it. We hold no copy, so we cannot restore it for you.
If — and only if — you write something in Settings → Tell me something and press Send it, the following is transmitted to our server:
| What | Why |
|---|---|
| The text you wrote | It is the message |
| The category you chose (bug / idea / confusing / praise / other) | So it can be triaged |
| The time you wrote it | To make sense of a sequence of reports |
| An anonymous installation identifier | So two reports from the same install can be recognised as related |
The installation identifier is a random number generated on your device the first time it is needed. It is not your name, your email address, your phone number, or any identifier issued by Apple, Google or your network. It is not shared with anyone and is not used to build a profile of you. It travels in your exported backup, so restoring a backup keeps the thread between your past and future reports.
Please note: the message box is free text, and we receive whatever you type into it. Do not put anything in it that you would not want us to hold — your address, health information, or anything about another person.
Feedback does not require an account and is not connected to one.
Beneath the message box is a toggle marked "Include app and device details". It is off by default. The exact values that would be sent are printed on the screen next to it before you decide. They are:
If the toggle is off, none of this is sent.
You only need an account to publish a bundle. Capturing, practising, drilling, backing up, and sending a bundle to somebody as a file all work signed out, and always will.
| What | Why | Who can see it |
|---|---|---|
| Your email address | It is how you sign in, and the only way to reach you about something you published | Us, and Supabase as our processor. Never shown to other users |
| Your username | It is the name published bundles are attributed to | Public. Anyone can see it, and that is what attribution means |
| The times you signed in | Ordinary security logging | Us and Supabase |
There is no password. Signing in sends a six-digit code to your address, and the code is single-use and short-lived. We never hold a password of yours because there is none to hold.
Your email address is not shown to other users, not used for marketing, and not shared.
If you press Publish on the send screen, the bundle is uploaded to our storage and a row describing it is created. What travels is listed on that screen before you press anything:
What never travels, whatever you select: photographs and images, anything you imported from elsewhere, your practice history, your per-key progress, your practice recordings, your routines and your settings.
Who can reach a published bundle. Every bundle gets a ten-character share code. A bundle is reachable by anyone you give that code to. If we put a bundle in the in-app catalogue — which we do by hand, one at a time, and never automatically — it becomes visible to everybody using the app.
Treat publishing as public. The share code makes a bundle hard to find rather than impossible: anyone you give it to can pass it on, and anyone who downloads a bundle has a copy we cannot recall. Do not publish anything you would not be content to have read by a stranger, and do not publish recordings of anyone but yourself.
You can withdraw a bundle at any time, from the account screen. Withdrawing stops the code working and deletes the file. It cannot take back copies already downloaded.
When you choose to download an instrument, the app fetches sound files from a public
open-source repository hosted by GitHub (gleitz.github.io). Like any web request,
GitHub will see your IP address and can log it under their own policies. No information
about you, your library or your practice is sent — it is an anonymous file download,
and it happens only when you ask for an instrument.
The app contains no analytics, no advertising, no tracking, no crash-reporting service and no third-party SDKs that collect data. Nothing is transmitted when you open the app, capture a phrase, practise, or record yourself.
| Data | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Feedback and the installation identifier | Legitimate interests (6(1)(f)) — understanding what is broken in order to maintain the app |
| Technical details, when the toggle is on | Consent (6(1)(a)) — a separate switch, off by default, withdrawable by turning it off |
| Your email address and account | Contract (6(1)(b)) — we cannot provide publishing without an account |
| Your username and published bundles | Contract (6(1)(b)) — publishing is what you asked us to do |
None of it is used for marketing, profiling, or any automated decision-making.
Feedback, accounts and published bundles are held in Postgres and object storage operated by Supabase Inc., who act as our data processor and hold the data on our instructions only.
Nobody else receives your data. It is not sold, and it is not shared with advertisers, brokers or analytics companies — there are none.
| Data | Kept for |
|---|---|
| Feedback | As long as it is useful for improving the app, and no longer than three years |
| Your account and email address | Until you delete your account |
| Published bundles | Until you withdraw them, or you delete your account |
| Withdrawn bundles | The file is deleted immediately. A record that the bundle existed and was withdrawn is kept, so we can answer questions about what was published |
Feedback that has been acted on and closed is deleted sooner where there is no reason to keep it.
Under the UK GDPR you have the right to ask us to:
For your account, you do not have to ask. Open the account screen and use Delete my account. Your email address, your username and everything you have published are deleted immediately and for good. Your library on your phone is not touched.
For feedback, we may need your help to find it. Feedback carries no name or address, so please include the wording of your message and roughly when you sent it. Without that we may not be able to identify your data, and we will say so rather than guess.
Write to phrases@sourcemungo.com. We will respond within one month.
You also have the right to complain to the Information Commissioner's Office (ico.org.uk), though we would appreciate the chance to put things right first.
Bundles in the catalogue are made by other users, not by us. If something published through Phrases infringes your copyright, misrepresents you, or should not be there for any other reason, write to phrases@sourcemungo.com with the share code or the title and we will take it down.
Phrases is not directed at children and we do not knowingly collect anything from a child. Publishing requires an account, and an account requires an email address.
If you believe a child has sent us feedback or created an account, tell us and we will delete it.
If this policy changes materially, the date at the top changes and the new version is published here. If a change means the app starts collecting something it does not collect today, you will be told inside the app before it happens.
The previous version was accurate for an app with no accounts and no way to publish. It said feedback was the only thing that left your device, and that we could not know who you were. Both stopped being true when accounts and bundle publishing were added, and this version says so.
Added: accounts and email addresses (§3.3), published bundles and who can reach them (§3.4), public usernames, account deletion (§7), takedowns (§8), and per-category lawful bases and retention (§4, §6).
Corrected: the feedback category is "bug", not "broken"; automatic phone backups are now excluded by the app; exported backups no longer contain your session.
Gavin Cox