Practuoso Privacy Policy
Effective: September 7, 2026
Practuoso is operated by Sookyoung Jang ("Practuoso," "we," "us," or "our") in Alabama, United States. This policy applies to the Practuoso iOS app and related support and legal pages. It explains what information we process, why we use it, how it may be shared and retained, and the choices available to you.
1. Information we process
Account information. We process your email address, account identifier, email-verification state, display name, and authentication information handled by Firebase Authentication so you can create, secure, recover, and delete an account. The current app supports email-and-password authentication.
Profile and onboarding information. We process your app-provided avatar, selected instrument, self-declared age range, practice preferences, goals, motivations, and optional musical milestones.
Practice and learning information. We process practice sessions and durations, goals, milestones, optional private notes or reflections, generated plans and next steps, quest progress, XP, level, streaks, Beats, Energy, and results or progress from current training features.
Friends information. If you use Friends, we process your friend code, requests, connections, limited profile information, practice activity you choose to share, and reactions. Current v1 has no direct messages, comments, public profiles, public user search, stranger recommendations, user-uploaded media, or clickable external links in Friends content.
Safety information. If you report a person or activity, we process the reporting and reported account identifiers, the selected reason, an optional activity identifier, optional details you submit, status, and timestamps. If you block someone, we process the two account identifiers needed to enforce that block. We do not show the reported person who submitted the report.
Security and technical information. Practuoso and its providers may process request, network, app, device, operating-system, authentication, rate-limit, and app/device-integrity information reasonably needed to operate and secure the service, prevent abuse, and troubleshoot failures. Production and staging builds prepare Firebase App Check using Apple App Attest with DeviceCheck fallback; server enforcement is activated only after deployment validation.
2. Information and device access not used by current v1
Current Practuoso v1 does not record or upload microphone audio. It does not request access to precise location, contacts, camera, photo library, Health data, financial or payment information, or biometric identifiers. It does not support user-uploaded photos, videos, audio, sheet music, PDFs, or MusicXML. It does not send practice recordings or sheet music to an external AI provider. It does not register remote push-notification tokens or schedule local notifications.
3. How we use information
We use information to:
- provide authentication, account recovery, cloud synchronization, and account security;
- personalize practice plans, milestones, quests, progression, and training;
- operate closed Friends connections, intentionally shared activity, and reactions;
- maintain XP, levels, streaks, Beats, Energy, and similar virtual items;
- prevent abuse, enforce rate limits, investigate reports, apply blocks, and enforce our Terms and Community Guidelines;
- troubleshoot failures and improve reliability; and
- respond to account, privacy, safety, accessibility, and support requests.
Firebase Analytics and Firebase Crashlytics collection are disabled in the current checked-in Production release configuration. Account, database, functions, security, and provider operational processing still occur. We do not sell personal information, use Practuoso data for third-party targeted advertising, or include third-party advertising in current v1.
4. Friends, sharing, and teen privacy
Friends connect through a private 10-character friend code rather than public discovery. People involved in a request and accepted Friends may see the display name, app-provided avatar, optional instrument, and relationship information needed for the feature. Email addresses are not placed in Friends collections or displayed to other users.
During onboarding, every new user must make an explicit choice to turn future practice-activity sharing on or off; neither option is assumed. You can change that choice in Settings. Turning sharing off stops future activity summaries but does not automatically remove prior shares. Settings provides a separate confirmed action to remove eligible previously shared activity and associated reactions.
Shared summaries contain only the display name, avatar, completion type, a short app-generated description, time, and sometimes duration. Private goals, private notes or reflections, email, credentials, precise location, raw exercise data, and audio do not appear in the Friends feed.
Blocking removes the friendship and prevents the two accounts from viewing Friends profiles or activity, sending friend requests, or reacting to each other's posts. Reports are limited to safety review and enforcement purposes.
5. Service providers and international processing
Google Firebase provides authentication, Firestore database and synchronization, callable cloud functions, hosting for the public legal pages, and security/integrity services. Apple provides platform and device-integrity services. These providers may process information in countries other than where you live under their applicable terms and safeguards.
The current policy is written for the present U.S.-based operator and initial current-v1 release. Practuoso will complete additional legal and operational review before intentionally distributing in territories that require additional disclosures or mechanisms.
6. Local storage
Practuoso stores account-scoped practice state, preferences, recovery information, pending synchronization data, and conflict copies on your device so the app can resume reliably. Authentication state is handled with platform and Firebase storage. Signing out is not account deletion and may leave account-scoped recovery copies on the device. The account-deletion flow clears current-device data Practuoso controls for that account.
An unfinished onboarding draft omits email and password, expires after seven days, and expires after 24 hours when the selected range identifies the user as under 13.
7. Retention and deletion
Account, practice, and Friends records generally remain while your account is active or until you delete eligible shared activity or the account. We retain information only as reasonably needed for the purpose, service security, dispute handling, fraud prevention, or legal compliance.
You can initiate full account deletion inside Practuoso from Profile → Settings → Delete Account, including from the verification and ineligible-account gates. The deletion workflow removes the Firebase Authentication account and associated cloud practice, eligibility, social profile, friend directory, request, friendship, activity, reaction, block, rate-limit, and other account data that we are not legally permitted or required to retain. Moderation records may be retained in de-identified or limited form where reasonably needed for safety, dispute resolution, or legal compliance.
Deletion may take time to propagate through active requests, provider logs, backups, cached copies, or other devices. A restricted deletion-status record remains temporarily to prevent an old session from recreating deleted data and is eligible for automated expiry after its token-safety interval. Contact support if a deletion appears incomplete.
8. Your choices and rights
You can update supported profile and practice settings, choose whether future activity is shared, remove eligible prior shares, report or block people/content, sign out, and delete your account. Depending on where you live, you may also have rights to request access, correction, deletion, or a copy of personal information. Email practuoso.support@gmail.com. We may reasonably verify your identity before acting on a request.
9. Children and age eligibility
Practuoso's current account experience is intended for people age 13 and older and is not designed for Apple's Kids Category. It does not provide a verified parental-consent system for under-13 accounts. A neutral age-range screen stops a person who identifies as under 13 before account creation or cloud practice access. If we learn that we collected a child's personal information where parental consent is required, we will take appropriate steps to stop further collection and delete it as required.
10. Security and incidents
We use reasonable technical and organizational safeguards appropriate to Practuoso, including authentication, authorization rules, encrypted connections supplied by platform services, server-side validation, rate limiting, least-data social projections, and app/device integrity architecture. No online service can guarantee absolute security. We investigate incidents and provide legally required notices based on the applicable facts and law.
11. Changes
We may update this policy as Practuoso changes. We will update the effective date and provide additional notice or choice where required. Material data-practice changes will not be shipped under an outdated policy.
12. Contact
Privacy, account deletion, support, moderation, copyright, and accessibility questions: practuoso.support@gmail.com
Operator: Sookyoung Jang Location: Alabama, United States Privacy Policy: https://practuoso.web.app/privacy.html