Privacy Policy
Last updated: 27 September 2026
This Privacy Policy explains how Strumfolio (“we”, “us”) collects, uses, and protects your personal data when you use this service.
1. Who we are
Strumfolio (strumfolio.com) is run by an individual developer, with no company behind it, offering a free plan and paid plans — see our Pricing page for details. That individual is the data controller for the personal data described in this policy, and can be reached at the contact address below. If you need the controller's full identity — for example to exercise your rights or to file a complaint — write to that address and we will provide it without delay. Paid plans are sold through Paddle, our payment partner, which is a separate controller for the payment itself — see section 4.
For any privacy-related question, you can contact us at: info@strumfolio.com.
2. What data we collect
Account data. Your first and last name, the email address you use to sign in, and:
- if you sign in with an email address and password, a cryptographic hash of your password — we never store or see the password itself. Until you confirm your address, the registration waits in a pending list with a hashed one-time link that expires after 24 hours;
- if you sign in with Google, the email address and basic profile information (your name and profile picture) that we receive from your Google account; we never receive your Google password.
We also keep a count of your sign-ins and the time of the last one, and — if you ask for a password reset — a hashed one-time link that expires after one hour.
Plan and billing status. Which plan your account is on, including any paid plan, its renewal or expiry date, any upgrade, downgrade or cancellation you have scheduled, and a history of your purchases and plan changes (date, plan, amount, billing cycle), and any plan we have given you, with a short note of why. When you buy a plan, the payment itself is handled by Paddle, our merchant of record: Paddle collects your payment details, billing address and the tax information it needs, and Strumfolio never receives your full card number. What we receive back from Paddle is the confirmation of the payment, the plan, amount and status, and the identifiers Paddle assigns to the transaction and the subscription, so that we can match them to your account.
Discounts. If you arrive through a link carrying one of our discount codes, or type one in, the code is kept on your device as described in our Cookie Policy. When you are signed in, we record that your account was shown that offer — which offer, and when you first and last saw it. If you buy with it, we record the redemption: the offer, the plan and billing cycle, the full and the discounted amount, and until when the discount runs. That record is what lets us apply each offer once per account and honour the limit on how many people can use it.
Newsletter preference. Whether you asked to receive our newsletter and how often, with the dates you subscribed or unsubscribed. You can change it at any time from the settings inside the app. We have not sent a newsletter yet; every issue will carry a link to unsubscribe. If you register with Google, nothing asks you at sign-up: the preference starts switched off, and the settings are where you turn it on.
Courtesy emails. Within a few weeks of signing up, the person who runs Strumfolio may send you one or two personal emails — not marketing, and not part of the newsletter above — asking about your instrument and repertoire, or whether there is something you are looking for and cannot find. They contain your first name when we have one on file, and nothing else personal. Each carries its own link that stops them with one tap, independent of your newsletter setting, and at most one further such email is ever sent after the first.
Preferences. Display and reading settings you choose — theme, zoom, scroll speed, notation, instrument — and, per song, the key, capo, tempo and chord shapes you last used, whether you starred it, and when you last opened it, so that your recent and favourite songs can be listed. They are stored with your account, and on your device so that the app behaves the way you left it even offline.
Content you create. The songs, lyrics, chords, songbooks, sections and private comments you personally import or create. Apart from the Example songbook — a small, fixed set of songs — one written for Strumfolio, the rest in the public domain — that a new account starts with, described in our Content & Copyright Notice — Strumfolio does not host or provide any pre-existing lyrics, chords, or song library: all content in your collection comes from you, entered manually or imported from files on your own device.
AI access. If you create a token to connect an AI assistant to your songbooks, we keep the name you give it, its first few characters and a cryptographic hash of it — never the token itself — with when it was created, last used and revoked. When an assistant changes one of your songs through it, we keep the text it replaced (and the one it wrote, if you later overwrite it in the app), so that you can restore it. What the assistant reads is sent to it by your own request, with your token: the provider of that assistant is not our processor, and what it does with your songs is governed by your agreement with it.
Feedback and feature requests. If you send us feedback from within the app, we receive your message, the category you chose, an optional screenshot you attach, your email address and your plan. It arrives in our inbox as an email we can reply to, and stays there until we delete it — ask and we will.
Usage and technical data. Basic technical information needed to run and secure the service: log data, device and browser type, and IP address as processed by our hosting provider. To limit abuse, we count attempts to sign in, register, resend a verification email, reset a password, send feedback, try a discount code, join a Strum Together session and reach our payment provider — by IP address, by email address or both — over ten-minute windows. On registration, when a verification email is sent again, and on password recovery, a Cloudflare Turnstile challenge tells humans from automated scripts; it processes your IP address and technical signals from your browser, and we receive from it only a pass or fail.
Where you came from. When you arrive from a link carrying campaign parameters, or from another website, we record the campaign labels in that link (its source, medium and campaign name, and the optional term and content values), the identifier the advertising network added to the click, the website you came from and the first page you opened — for your first arrival and for your most recent one, with the date of each. It is kept in a cookie on your device that lasts 90 days from your most recent such arrival, and it is read once — when you begin a registration, or sign in for the first time — from which moment it is stored with your registration and then with your account. It tells us which channels bring musicians here; it records nothing about what you do inside the app, and it is shared with nobody. If you never begin a registration, none of it ever reaches us: it stays in your own browser and disappears with the cookie. Opening the one-time link in a verification or password-reset email is never recorded as an arrival.
Aggregated analytics. We use Vercel Web Analytics and Speed Insights to understand overall traffic and page performance. These tools do not use cookies and do not build cross-site profiles: visitors are identified by a temporary hash that is discarded within 24 hours, and only aggregated data is available to us.
Strum Together sessions. When you create or join a session, we process the session identifier and the synchronisation data needed to keep devices in step. Participants can join a session through a shared link without creating an account; for those participants we process only a random device identifier stored in a cookie, so that a browser counts as one device towards the leader's plan limit, the time it was last seen, and the minimum technical data needed to run the session — see section 6 for how long that data lasts. The identifier is not linked to a name or an email address.
Notifications to us. A few events send a short message to the developer, through a private Telegram chat, so that the Service can be run without watching a dashboard: that an account was created, that a plan was bought or renewed (which plan, and the amount), that a piece of feedback arrived, and that a payment needs a person to look at it — for example two subscriptions billing on one account, or a discount applied more often than it should have been.
The message sent when an account is created names the email address that registered and, where we have it, the first and last name given at registration. Every other message of this kind carries no name, no email address and none of your words: only the kind of event, for a purchase the plan and the amount, and for a payment that needs looking at the internal number of the account and the identifiers Paddle gave the payment or the subscription, so that we can find it. See section 5 on where these messages travel.
For details on cookies, local storage and the offline cache, see our Cookie Policy.
3. Why we collect it, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and manage your account | Performance of a contract — Art. 6(1)(b) |
| Store, sync and let you access your song collection and preferences, including through an AI assistant you connect, and keep the earlier versions of songs it changes | Performance of a contract — Art. 6(1)(b) |
| Sell you a plan, apply it to your account, and keep your payment history | Performance of a contract — Art. 6(1)(b) — and, for keeping records of payments, our legal obligations in tax and accounting matters — Art. 6(1)(c) |
| Run Strum Together sessions, including for participants without an account | Performance of a contract — Art. 6(1)(b) — and, for participants without an account, our legitimate interest in delivering the session requested by the leader — Art. 6(1)(f) |
| Send service emails (email verification, a welcome message, password reset, purchase and plan-change notices, and notice of a plan we give you) | Performance of a contract — Art. 6(1)(b) |
| Send you the newsletter | Your consent — Art. 6(1)(a) — which you can withdraw at any time from the settings |
| Send you one or two personal emails after you sign up | Legitimate interest in understanding how musicians use Strumfolio and being reachable by the person who reads your replies — Art. 6(1)(f). You can object at any time — see section 7, or use the link in the email itself |
| Answer feedback and feature requests you send us | Performance of a contract — Art. 6(1)(b) |
| Keep the service secure and working properly (logs, rate limiting, Turnstile) | Legitimate interest in preventing abuse, diagnosing faults and protecting the service and its users — Art. 6(1)(f) |
| Tell the developer, through a private chat, about new accounts, purchases, feedback and payments that need attention | Legitimate interest in running the Service without watching a dashboard — Art. 6(1)(f). You can object at any time — see section 7 |
| Measure aggregate traffic and performance | Legitimate interest in maintaining and improving the service — Art. 6(1)(f) |
| Remember a discount you followed, apply it once per account within its limit, and measure which offers are seen and used | Legitimate interest in running our own offers fairly and measuring how well they work — Art. 6(1)(f). You can object at any time — see section 7 |
| Understand which channels and campaigns bring people to Strumfolio | Legitimate interest in measuring and improving how we reach musicians — Art. 6(1)(f). You can object at any time — see section 7 |
Is providing this data required? Providing a name and an email address is necessary to create an account and use Strumfolio: without them we cannot provide the Service, and no account can be created. Everything else — the songs you add, the preferences you set, the newsletter, the feedback you send — is entirely up to you.
Automated decision-making. We do not carry out automated decision-making or profiling that produces legal effects for you or similarly significantly affects you. The Turnstile challenge and the rate limits only decide whether a single request goes through.
4. Who processes data on our behalf, and who receives it
Strumfolio is a small project built on a limited number of technical providers. The following act as our data processors, under a data processing agreement:
- Vercel Inc. — hosting, application delivery, and Vercel Web Analytics / Speed Insights.
- Neon — the PostgreSQL database where your account and content are stored, provisioned through Vercel.
- Resend — delivery of the emails we send you (email verification, the welcome email, password reset, purchase and plan-change notices, notice of a plan we give you, the newsletter once it exists, and the two courtesy emails a new account may receive), and of the feedback you send from the app, which it delivers to our own inbox.
- Cloudflare, Inc. — the Turnstile challenge on registration, on sending a verification email again and on password recovery, which processes your IP address and browser signals to tell a person from a script.
Telegram FZ-LLC receives the private notifications described in section 2, under Telegram's own terms for bots; it offers no data processing agreement, and section 5 explains what that means for the transfer. For the message sent when an account is created this is your email address and, where we have it, your name; a message about a payment that needs looking at contains the internal number of the account and Paddle's identifiers for it; the others contain no personal data.
Two providers are different, because they are independent data controllers for their part:
- Google LLC — if you choose to sign in with Google, Google acts as an independent controller for your Google account and for the sign-in process itself, under its own privacy policy. We only receive the account details listed in section 2 as a result of that sign-in.
- Paddle (Paddle.com Market Ltd, United Kingdom, and its affiliate Paddle.com Inc. for some countries) — the merchant of record for every purchase. Paddle collects and processes your payment details, billing address and tax information as an independent controller, issues your invoice, and handles refunds, under its own privacy policy. We do not give Paddle your email address: you type the one you want on the receipt into Paddle's own form. To match the payment to your account we pass Paddle the internal number of your account, with a signature from our server so that it cannot be altered, and — where one applies — which of our offers you are using or which plan you are moving from. That happens each time you open the checkout page, whether or not you complete the purchase. We receive back what section 2 describes.
We do not sell your data, and we do not share it with anyone for advertising or marketing purposes. We may disclose data where required to do so by law.
5. International transfers
Our database and hosting run in the United States (Neon and Vercel, on Amazon Web Services in the us-east-1 region), so your account and your songs are stored there, and some of the other providers are established in the United States or may process data outside the European Economic Area. Where that happens, transfers are covered by appropriate safeguards under Chapter V GDPR: the EU-U.S. Data Privacy Framework where the provider is certified (Vercel, Google and Cloudflare are), and the European Commission's Standard Contractual Clauses in the remaining cases. Paddle.com Market Ltd is established in the United Kingdom, which the European Commission recognises as providing adequate protection. You can obtain a copy of the safeguards in place, or further details about them, by writing to the contact address above.
Telegram FZ-LLC is the exception, and we say so plainly. It is established in the United Arab Emirates, which is not covered by an adequacy decision, and it is not certified under the EU-U.S. Data Privacy Framework. Two of the messages described in section 2 reach it with personal data: the one announcing that an account was created, with an email address and, where we have it, a name, sent once at that moment; and the rare one about a payment that needs looking at, with the internal number of the account and Paddle's identifiers for the payment, which name nobody on their own. You can ask us to delete either from that chat by writing to the contact address above.
6. How long we keep your data
We keep your account and content data for as long as your account is active. When you delete your account from within the app, your account, your songs, your preferences, your comments and your newsletter preference are removed immediately from the live service. Residual copies remain for a short time in two places, and then disappear on their own: our database provider's restore history, kept for a few days, and our hosting provider's technical logs, also kept for a few days — in both cases no longer than 30 days, except where we are required to retain data by law.
AI access. A token stops working when you revoke it or after six months without use, and its record (name, first characters, hash and dates) is kept with your account until the account is deleted, so that the history can say which assistant wrote what. Earlier versions of a song are kept up to twenty per song, the oldest removed first — except the last version you wrote yourself, which stays until a newer one of yours replaces it — and are deleted with the song or with your account.
Payment records — the history of purchases and plan changes, with the account's email address — are kept after the account is deleted, for as long as tax and accounting rules require (ten years in Italy). Paddle keeps its own records of the sale as merchant of record, under its own policy.
What stays after an account is deleted. Besides the payment and discount records below, we keep the address with the number of times it signed in and the date of the last time, and a record of which of the personal emails in section 2 were sent to it, so that none is sent twice. The record of an unused password-reset link stays until that address asks for another. Emails and feedback you sent us stay in our inbox, and the notifications in section 2 in that private chat, until we delete them. To have any of these removed, write to us at info@strumfolio.com.
Where you came from. The attribution cookie in your browser lasts 90 days from your most recent qualifying arrival. Once recorded with a registration or an account it has no fixed expiry, because comparing one year's campaigns with the next is the whole point of keeping it; it is deleted together with the account, at the same moment and by the same action — or, for a registration never confirmed, when we remove it. If you would rather we did not keep it while keeping your account, write to us at info@strumfolio.com.
Discounts. The discount cookie lasts at most 30 days and the copy of the code in your browser's local storage until you clear your site data. The record that your account was shown an offer, and the record of a redemption, keep the email address they were made with after the account is deleted. For a redemption that is so that deleting an account and registering again does not hand out the same offer twice, and it is also part of the payment records above; the record of an offer being shown is kept as a count of how far each offer reached. To have either removed, write to us at info@strumfolio.com.
Short-lived data. The one-time link in a verification email stops working after 24 hours, and a password-reset link after one hour. A registration that is never confirmed is not deleted automatically: the address and name given stay on our pending list, unusable for signing in, until we remove them by hand. The counters that limit repeated attempts hold an IP address or an email address for the ten-minute window they measure, and are deleted within a day. Strum Together session data is deleted as soon as the leader ends the session, and a session that is never explicitly ended stops being usable after eight hours of inactivity; a participant's device stops counting two minutes after it was last seen, and the device cookie in its browser lasts one year. Analytics data is aggregated and retained in non-identifying form.
7. Your rights
If you are in the EU/EEA, under the GDPR you have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- request deletion of your data;
- request a copy of your data in a portable format;
- restrict certain processing;
- withdraw any consent you have given, without affecting processing carried out before withdrawal;
- lodge a complaint with your national data protection authority (in Italy, the Garante per la Protezione dei Dati Personali).
If you are in the United Kingdom, you have the same rights under the UK GDPR, and you can complain to the Information Commissioner's Office (ICO). Wherever else you live, you can exercise the same rights by writing to us, and where the law of your country — for example Canada's PIPEDA or New Zealand's Privacy Act 2020 — grants you rights over your data, we honour them the same way, and you can turn to your own privacy authority.
Your right to object. Where we process your data on the basis of our legitimate interest — namely to keep the Service secure, to measure aggregate traffic and performance, to understand which channels bring people to Strumfolio, to run and measure our discount offers, to tell the developer about new accounts and payments, and to send you the one or two personal emails described in section 2 — you have the right to object to that processing at any time, on grounds relating to your particular situation. If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. To object, write to info@strumfolio.com. For the two personal emails specifically, the link each of them carries does the same thing without writing to us at all.
Strumfolio lets you export your full collection, change your newsletter preference and delete your account directly from within the app, at any time and without having to ask us — a paid subscription that will renew has to be cancelled first, and one that is paused or has a payment overdue is cancelled by us when you write to us, as the Terms of Service explain, so that nothing is charged after the account is gone. For anything else, or if a self-service option is not working, contact us at info@strumfolio.com. We aim to respond within 30 days.
8. Data security
We take reasonable technical and organisational measures to protect your data against unauthorised access, loss, or misuse, including encrypted connections, hashed passwords and one-time links, and access limited to what is needed to run the service. No system is 100% secure, and we encourage you to keep your account credentials confidential.
9. Children
Strumfolio is a general-purpose tool and is not directed at children. If you are a minor under the law of your country, you should use Strumfolio only with the involvement and permission of a parent or guardian. If we become aware that we hold data relating to a child in a way that is not permitted under applicable law, we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you through the app or by email before they take effect.
11. Contact
For any question about this policy or your data, contact us at info@strumfolio.com.