NoSheet Privacy Policy
Last Updated: 2026-04-25
1. Who We Are
NoSheet (the "App") is provided by Nicholas Fest, sole proprietor, based in Germany (referred to as "we," "us," or "NoSheet").
Contact for privacy matters: nick@nosheet.app Postal address: Nicholas Fest, Ginhardtstraße 40, 80639 München, Germany
This policy explains what data we collect when you use the NoSheet iOS app, why we collect it, who we share it with, and what rights you have.
2. Summary
- You sign in anonymously — no email, name, phone number, or social login is required or collected by us.
- We generate a device-level random identifier (a UUID) so your progress syncs across launches.
- We collect device info, gameplay data, app settings, and audio captured during exercises (processed on-device; not stored on our servers unless noted).
- If you use the AI coach features, your typed or spoken prompts and relevant learning context are sent to Google's Vertex AI (Gemini) to generate responses, and the resulting conversation is stored in our database so we can reload your session.
- We use third-party service providers for crash reporting, product analytics, subscriptions, and advertising attribution. We do not sell your data.
- The App is intended for users aged 13 and older.
3. Information We Collect
3.1 Pseudonymous account identifier
When you first open the App, we generate a random UUID and store it in your device Keychain. We use this ID to associate your progress, preferences, and chat history with your device across sessions. It is not linked to your name, email, or any other identifier you provide elsewhere. Under the GDPR this is pseudonymous data: it does not directly identify you, but because it persists across your sessions, the law treats it as personal data that you have rights over (see § 9).
3.2 Device information
- Device model, iOS version, App version, build type (development vs. release)
- Screen width and height
- Locale (language/region) and time zone
- A unique device-scoped identifier (separate from Apple's IDFV/IDFA)
3.3 Gameplay and learning data
- Exercises attempted, scores, timing, streaks, and completion state
- Game/challenge configurations you select
- Per-session progress (start, end, duration)
- Session insights generated by our AI features about your learning
3.4 App settings
Your in-app preferences (instrument, note-name display, handedness, vocal range, practice targets, and similar configuration you choose).
3.5 AI coach input and output
When you interact with the AI coach (chat interface, session planner, or similar):
- Your typed prompts and (if you use voice input) the transcribed text of what you said are sent to Google's Vertex AI to produce a response.
- The generated response plus a structured record of the conversation is stored in our database associated with your account ID so you can resume past sessions.
- Do not enter personal information, real names of other people, confidential data, or anything you would not want processed by a generative AI service into the chat.
Voice input is transcribed on your device using Apple's built-in Speech framework. We do not send raw audio from the AI chat to our servers or to Vertex AI — only the resulting text.
3.6 Microphone input for ear-training exercises
The App uses your microphone to detect what you play or sing during exercises. This audio is processed on your device in real time (using Apple frameworks and an on-device CoreML model) to detect pitch and timing. We do not record, store, or transmit this audio. You can revoke microphone permission at any time in iOS Settings.
3.7 Crash and diagnostic data
If the App crashes or throws an error, we collect a crash report (stack trace, device state, App version) via Firebase Crashlytics. These reports do not include your gameplay content or chat history.
3.8 Product analytics events
We log usage events (e.g., "session started," "challenge completed," "onboarding step finished") via PostHog. Events include your account ID, timestamps, and event metadata (such as game ID, score, duration). Events do not include the text of your chats or identifiers that would reveal who you are.
3.9 Subscription and purchase data
If you purchase a subscription, Apple processes the payment. We receive subscription status (active, expired, product identifier, renewal date) via RevenueCat, which is linked to your account ID. We do not receive your payment method or Apple ID.
3.10 Advertising attribution (only with your consent)
If you grant tracking permission through Apple's App Tracking Transparency (ATT) prompt, the App initializes the TikTok Business SDK and Meta (Facebook) AppEvents SDK solely to measure whether an ad led you to install NoSheet. If you decline the ATT prompt, no IDFA (identifier for advertisers) is shared and no per-user attribution occurs. Aggregated, privacy-preserving signals (such as Apple's SKAdNetwork) may still be reported by the operating system to ad networks; these signals do not identify you individually. You can change your tracking choice any time in iOS Settings → Privacy & Security → Tracking.
3.11 Feedback you send us
If you use the "Send Feedback" button, a pre-filled email is opened in your mail app. Your account ID is included in the message body so we can correlate your report with your account's data; your actual email address is only shared with us if you send the email. You can delete it before sending.
4. Why We Use Your Data (Legal Bases under GDPR)
| Purpose | Data used | Legal basis |
|---|---|---|
| Run the App (sync progress, save preferences, generate AI responses) | §§ 3.1–3.6 | Performance of a contract (Art. 6(1)(b) GDPR) |
| Diagnose crashes and improve stability | § 3.7 | Legitimate interest (Art. 6(1)(f)) |
| Understand feature usage to improve the App | § 3.8 | Legitimate interest (Art. 6(1)(f)) |
| Process purchases and manage subscriptions | § 3.9 | Performance of a contract (Art. 6(1)(b)) |
| Measure advertising effectiveness | § 3.10 | Consent (Art. 6(1)(a)) — via ATT prompt |
| Respond to feedback and support | § 3.11 | Legitimate interest (Art. 6(1)(f)) |
You may object to processing based on legitimate interest at any time (see § 9).
5. Who We Share Data With
We share specific categories of data with the following service providers. Most act as processors on our behalf under Art. 28 GDPR; Apple, TikTok, and Meta act as independent or joint controllers for the purposes shown.
| Provider | Role | Purpose | Data shared | Location |
|---|---|---|---|---|
| Supabase | Processor | Database & anonymous auth | Account ID, device info, settings, gameplay data, chat history, AI insights | European Union |
| Google Firebase (Crashlytics, Remote Config, App Check, AI Logic / Vertex AI, Anonymous Auth) | Processor | Crash reports, feature flags, device attestation, AI responses, anonymous sign-in | Crash data, config requests, chat prompts + context (AI Logic only), Firebase UID | USA |
| PostHog | Processor | Product analytics | Account ID, event names, event properties | EU (eu.i.posthog.com) |
| RevenueCat | Processor | Subscription management | Account ID, purchase receipts, subscription status | USA |
| TikTok for Business (only if you accept ATT) | Independent / joint controller | Ad attribution | IDFA, install/open events | USA |
| Meta / Facebook (only if you accept ATT) | Independent / joint controller | Ad attribution | IDFA, anonymous AppEvents ID, install/open events | USA |
| Apple | Independent controller | App Store distribution, in-app purchase processing | Per Apple's terms | Per Apple's terms |
We do not sell your personal information. We do not share data with any third party for their own independent marketing purposes.
6. International Data Transfers
We are based in Germany. Some providers (Firebase, RevenueCat, TikTok, Meta) are based in the United States. Where data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework adequacy decision.
7. AI-Specific Disclosures
- Model provider: Google, via Firebase AI Logic (Vertex AI) using Gemini models.
- Prompts we send: your typed/spoken message, a summary of your learning context (preferences, recent games, curriculum state), and a system instruction describing the coaching role.
- Response storage: AI responses and the conversation thread are stored in Supabase linked to your account ID.
- Training: Prompts sent via Firebase AI Logic / Vertex AI are not used to train Google's generative models under Google's current terms for Vertex AI. If this changes, we will update this policy.
- Accuracy: The AI coach generates responses algorithmically and can be wrong. See our Terms of Service.
- No sensitive data, please: Do not submit anything you wouldn't share with a generative AI service. We cannot retroactively remove content from any prompt that has already been sent.
8. Data Retention
- Account and gameplay data: retained while the App is installed on your device. Deleting the App does not automatically delete server-side data; use the deletion request below to remove it.
- Crash reports: retained by Firebase Crashlytics per Firebase's defaults (typically 90 days).
- Analytics events (PostHog): retained per our PostHog plan defaults.
- Chat history: retained until you request deletion.
- Subscription records: retained as long as required by applicable tax and accounting law (typically up to 10 years in the EU).
9. Your Rights
If you are in the EEA, UK, or Switzerland, you have the following rights under the GDPR (or equivalent local law):
- Access — request a copy of the data we hold associated with your account ID.
- Rectification — correct inaccurate data.
- Erasure — request deletion ("right to be forgotten"). Your account is tied to a device-generated UUID. The easiest way to share it with us is to reply to, or quote, any prior "Send Feedback" email you sent from the App — your account ID is automatically included in the body of those messages. If you've never sent feedback, include the approximate date of first install and your device model so we can locate your record.
- Restriction and Objection — ask us to stop certain processing.
- Portability — receive your data in a machine-readable format.
- Withdraw consent — for ATT-based advertising tracking, change the setting in iOS.
- Complaint — lodge a complaint with your supervisory authority. Our competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany — https://www.lda.bayern.de.
California residents have analogous rights under the CCPA/CPRA (right to know, delete, correct, and opt out of "sale" or "sharing" — we do not sell or share as defined by CCPA, but the ATT-based attribution may qualify; if you disable ATT, no sharing occurs).
To exercise any right, email nick@nosheet.app. We will respond within 30 days.
10. Children
The App is intended for users aged 13 and older. We do not knowingly collect data from children under 13. If you believe a child has used the App without parental consent, contact nick@nosheet.app and we will delete the associated account.
Under § 8(1) GDPR as implemented in Germany, users aged 13 to 15 should use the App only with the consent of a parent or legal guardian.
11. Security
We rely on the security controls provided by our service providers (Firebase, Supabase, RevenueCat, PostHog, Apple) and use encryption in transit (TLS) and at rest. Access to production data is limited to authorized personnel. No method of transmission or storage is 100% secure.
12. App Check and Attestation
To prevent abuse of our backend, the App uses Apple's App Attest (via Firebase App Check) to prove requests come from a genuine build of NoSheet running on a genuine Apple device. App Attest does not identify you personally.
13. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via an in-app notice. The "Last Updated" date at the top of this policy reflects the most recent revision.
14. Contact
Email: nick@nosheet.app Postal address: Nicholas Fest, Ginhardtstraße 40, 80639 München, Germany