Phrases

Privacy Policy

Last updated 30 August 2026 · replaces the version of 20 August · see §11

Phrases is a practice app for musicians. It is built to work at a piano, offline, without an account, and almost everything you put into it never leaves your device.

Two things leave, and only if you choose them: feedback you write, and a bundle you publish. An account is needed for the second and for nothing else.

Section 1Who is responsible

Gavin Cox is the data controller for the personal data described here.

Contact for anything in this policy, including requests to see or delete your data: phrases@sourcemungo.com

Section 2What stays on your device

All of the following is stored only in a database on your phone or tablet. It is never uploaded, and we cannot see it:

Two clarifications that matter, because the general statement above is not the whole truth on its own:

Audio and video you record inside the app will leave if you publish or send a bundle containing it. That is the point of a bundle — a lick you cannot hear is half a lick — and the send screen tells you exactly how many recordings will travel before you do it. Photographs never travel, whatever you do. Practice recordings — the takes you record against the metronome — never travel either.

Automatic phone backups are the platform's, not ours. The app asks Android not to include its data in Google's automatic backup, so your library and recordings are not copied to your Google account by it.

If you export a backup yourself, that file is written to storage you choose and shared using your own device's sharing features. It does not pass through us. The file does not contain your sign-in credentials — restoring a backup onto a new phone will ask you to sign in again, deliberately, so that a backup file is not a key to your account.

If you delete the app, the data on your device is deleted with it. We hold no copy, so we cannot restore it for you.

Section 3What leaves your device

3.1 Feedback you send us

If — and only if — you write something in Settings → Tell me something and press Send it, the following is transmitted to our server:

WhatWhy
The text you wroteIt is the message
The category you chose (bug / idea / confusing / praise / other)So it can be triaged
The time you wrote itTo make sense of a sequence of reports
An anonymous installation identifierSo two reports from the same install can be recognised as related

The installation identifier is a random number generated on your device the first time it is needed. It is not your name, your email address, your phone number, or any identifier issued by Apple, Google or your network. It is not shared with anyone and is not used to build a profile of you. It travels in your exported backup, so restoring a backup keeps the thread between your past and future reports.

Please note: the message box is free text, and we receive whatever you type into it. Do not put anything in it that you would not want us to hold — your address, health information, or anything about another person.

Feedback does not require an account and is not connected to one.

3.2 Technical details, only if you switch them on

Beneath the message box is a toggle marked "Include app and device details". It is off by default. The exact values that would be sent are printed on the screen next to it before you decide. They are:

If the toggle is off, none of this is sent.

3.3 Your account

You only need an account to publish a bundle. Capturing, practising, drilling, backing up, and sending a bundle to somebody as a file all work signed out, and always will.

WhatWhyWho can see it
Your email address It is how you sign in, and the only way to reach you about something you published Us, and Supabase as our processor. Never shown to other users
Your username It is the name published bundles are attributed to Public. Anyone can see it, and that is what attribution means
The times you signed in Ordinary security logging Us and Supabase

There is no password. Signing in sends a six-digit code to your address, and the code is single-use and short-lived. We never hold a password of yours because there is none to hold.

Your email address is not shown to other users, not used for marketing, and not shared.

3.4 Bundles you publish

If you press Publish on the send screen, the bundle is uploaded to our storage and a row describing it is created. What travels is listed on that screen before you press anything:

What never travels, whatever you select: photographs and images, anything you imported from elsewhere, your practice history, your per-key progress, your practice recordings, your routines and your settings.

Who can reach a published bundle. Every bundle gets a ten-character share code. A bundle is reachable by anyone you give that code to. If we put a bundle in the in-app catalogue — which we do by hand, one at a time, and never automatically — it becomes visible to everybody using the app.

Treat publishing as public. The share code makes a bundle hard to find rather than impossible: anyone you give it to can pass it on, and anyone who downloads a bundle has a copy we cannot recall. Do not publish anything you would not be content to have read by a stranger, and do not publish recordings of anyone but yourself.

You can withdraw a bundle at any time, from the account screen. Withdrawing stops the code working and deletes the file. It cannot take back copies already downloaded.

3.5 Instrument sound downloads

When you choose to download an instrument, the app fetches sound files from a public open-source repository hosted by GitHub (gleitz.github.io). Like any web request, GitHub will see your IP address and can log it under their own policies. No information about you, your library or your practice is sent — it is an anonymous file download, and it happens only when you ask for an instrument.

3.6 That is the complete list

The app contains no analytics, no advertising, no tracking, no crash-reporting service and no third-party SDKs that collect data. Nothing is transmitted when you open the app, capture a phrase, practise, or record yourself.

Section 4Why we are allowed to hold this

DataLawful basis (UK GDPR Art. 6)
Feedback and the installation identifier Legitimate interests (6(1)(f)) — understanding what is broken in order to maintain the app
Technical details, when the toggle is on Consent (6(1)(a)) — a separate switch, off by default, withdrawable by turning it off
Your email address and account Contract (6(1)(b)) — we cannot provide publishing without an account
Your username and published bundles Contract (6(1)(b)) — publishing is what you asked us to do

None of it is used for marketing, profiling, or any automated decision-making.

Section 5Where it is held, and by whom

Feedback, accounts and published bundles are held in Postgres and object storage operated by Supabase Inc., who act as our data processor and hold the data on our instructions only.

Nobody else receives your data. It is not sold, and it is not shared with advertisers, brokers or analytics companies — there are none.

Section 6How long it is kept

DataKept for
FeedbackAs long as it is useful for improving the app, and no longer than three years
Your account and email addressUntil you delete your account
Published bundlesUntil you withdraw them, or you delete your account
Withdrawn bundlesThe file is deleted immediately. A record that the bundle existed and was withdrawn is kept, so we can answer questions about what was published

Feedback that has been acted on and closed is deleted sooner where there is no reason to keep it.

Section 7Your rights

Under the UK GDPR you have the right to ask us to:

For your account, you do not have to ask. Open the account screen and use Delete my account. Your email address, your username and everything you have published are deleted immediately and for good. Your library on your phone is not touched.

For feedback, we may need your help to find it. Feedback carries no name or address, so please include the wording of your message and roughly when you sent it. Without that we may not be able to identify your data, and we will say so rather than guess.

Write to phrases@sourcemungo.com. We will respond within one month.

You also have the right to complain to the Information Commissioner's Office (ico.org.uk), though we would appreciate the chance to put things right first.

Section 8Content other people publish

Bundles in the catalogue are made by other users, not by us. If something published through Phrases infringes your copyright, misrepresents you, or should not be there for any other reason, write to phrases@sourcemungo.com with the share code or the title and we will take it down.

Section 9Children

Phrases is not directed at children and we do not knowingly collect anything from a child. Publishing requires an account, and an account requires an email address.

If you believe a child has sent us feedback or created an account, tell us and we will delete it.

Section 10Changes

If this policy changes materially, the date at the top changes and the new version is published here. If a change means the app starts collecting something it does not collect today, you will be told inside the app before it happens.

Section 11What changed on 30 August 2026

The previous version was accurate for an app with no accounts and no way to publish. It said feedback was the only thing that left your device, and that we could not know who you were. Both stopped being true when accounts and bundle publishing were added, and this version says so.

Added: accounts and email addresses (§3.3), published bundles and who can reach them (§3.4), public usernames, account deletion (§7), takedowns (§8), and per-category lawful bases and retention (§4, §6).

Corrected: the feedback category is "bug", not "broken"; automatic phone backups are now excluded by the app; exported backups no longer contain your session.

Section 12Contact

Gavin Cox

phrases@sourcemungo.com