Privacy Policy
Last updated 16 September 2026.
The short version: we collect what is needed to give you an account and sell you access, and nothing else. There is no advertising, no tracking across other sites, and nothing is sold to anyone.
What we hold
- Your account — name, email address, and either a hashed password or the fact that you sign in with Google. We never store a readable password.
- Your purchases — what you bought and when, and Stripe's reference for the payment. We do not hold your card number; Stripe does.
- Institutional membership — if you signed up with an institutional email or invite code, which institution you belong to, so your access can follow their licence.
- Messages you send us — if you write through the contact form, your name, email address and the message itself, kept so we can answer you and so the request is not lost if an email fails to arrive.
- Server logs — ordinary technical records of requests, kept briefly for security and debugging.
We do not use advertising or analytics cookies. The only cookie that matters is the one that keeps you signed in, plus a short-lived one during Google sign-in.
When you make a song available offline, its transcription and recording are stored in your browser on that device, not sent anywhere. They are removed when you remove them, when you sign out, or when your access to that song ends and the device is next online.
Why we are allowed to hold it
Your account and purchase data are processed to perform the contract between us — you cannot have access to something bought without a record of having bought it. Keeping records of payments is a legal obligation under tax law. Server logs rest on our legitimate interest in running the service securely.
Who else sees it
- Stripe — payment processing. They receive your email and payment details and are the ones who actually handle the card.
- Google — only if you choose to sign in with Google, and only to confirm who you are.
- Our hosting provider — the servers and storage this runs on.
That is the complete list. Nobody buys this data from us, because we do not sell it.
How long we keep it
Your account lasts as long as you want it. Delete it and your name, email and sign-in details are erased immediately.
The record that a payment happened outlives the account, because tax law requires payment records to be retained for several years. What is left is an amount, a date and Stripe's reference — with no name or email attached to it.
Your rights
If the GDPR applies to you, you can ask for a copy of your data, ask us to correct it, ask us to erase it, object to how we use it, or ask for it in a portable form. Two of these you can exercise yourself, immediately, from your account page: correcting your password and deleting your account. For anything else write to hello@singpolish.com and we will respond within a month.
If you think we have handled your data badly, you can complain to the data protection authority where you live.
Security
Traffic is encrypted in transit. Passwords are stored hashed and salted. Recordings are served through short-lived links that expire in minutes rather than as public files. None of this makes any system perfect, and we would tell you promptly if something happened that affected you.
Children
This is aimed at singers, students and teachers, not children. We do not knowingly create accounts for under-16s except through an institution that has the appropriate consent.
Changes
If this policy changes, the date at the top changes with it, and we will tell signed-in customers about anything significant.
See also our Terms of Service.
