Privacy Policy
Practice Timer ("Practice Timer", "we", "us", "our") is operated by Koraii, an individual entrepreneur (entreprise individuelle, EI) established in France, SIREN 849 827 894, 149 avenue du Maine, 75014 Paris, France. Koraii is the data controller responsible for the personal data described in this policy. This policy explains what we collect, why, how it's shared, how long we keep it, and the choices and rights you have.
If you have any questions, contact us at contact@practicetimer.app.
The short version
- Your practice plans and detailed session history stay on your device. We don't upload the exercises you create or the contents of your sessions.
- When you create an account, we sync a small set of aggregate stats (like total practice time and streaks), your onboarding answers, and your subscription status so your progress is backed up and available across devices.
- We use privacy-respecting product analytics to understand how the app is used and improve it. We don't record your screen, and we don't put your exercise text into analytics. In the EU/UK we ask for your consent and you can opt out anytime.
- We don't sell your personal information and we don't use it for cross-context behavioral advertising.
- You can delete your account and all synced data at any time from Settings.
This summary is for convenience only and does not replace the full policy below.
1. Who we are
The data controller is Koraii, 149 avenue du Maine, 75014 Paris, France. You can reach us about anything in this policy at contact@practicetimer.app.
2. Information we collect
a) Information you provide
Account information. When you sign up, our authentication provider (Clerk) collects your email address and password, or — if you use Sign in with Apple or Google — the identifier and email those services share with us. We may store your email and display name.
Onboarding answers. During setup you tell us things like your instrument, experience level, primary goal, practice frequency, daily time target, pace, whether you work with a teacher, the focus areas you choose, and where you heard about us. We use these to generate and personalize your plan.
Communications. If you email us or submit a request, we keep your message and contact details so we can respond and keep a record of the request.
b) Information created as you use the app
Practice content (stored on your device). The practice plans, exercises, names, musical keys, durations, and detailed session-by-session history you create are stored locally on your device, in the app's on-device database. This content is not uploaded to our servers.
Aggregate practice stats (synced when signed in). When you have an account, we sync summary figures: total sessions, total practice minutes, current and longest streak, last practice date, and counts of your plans and exercises. These back up your progress and let it follow you across devices.
Subscription status. Your subscription product/plan, whether you're in a free trial, and your renewal/expiry date.
c) Information collected automatically
Device & app info. App version, platform (iOS/Android), language/locale, time zone, and an approximate "last seen" timestamp.
Product analytics events. We record in-app events (for example: completing onboarding steps, starting and completing a practice session, viewing the paywall, subscribing) together with non-identifying properties (such as counts, durations, your chosen instrument/level, and whether you're a Pro user). Analytics are processed by PostHog. We do not use session or screen recording, and we do not send the free-text names of your exercises into analytics — only category labels and counts. Once you sign in, analytics events are associated with your account identifier. See Cookies and similar technologies for how we handle consent.
d) Payment information
We never receive or store your credit-card or payment details. All purchases are processed by the Apple App Store (and, in the future, Google Play) and managed through RevenueCat, which tells us only whether an entitlement is active and basic, non-sensitive transaction metadata.
3. How we use your information & legal bases
We use the information above for the purposes below. Where the EU General Data Protection Regulation (GDPR), the UK GDPR, or the French Data Protection Act (Loi n° 78-17 "Informatique et Libertés") applies, we rely on the following legal bases:
| What we do | Data used | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Provide the core service — build your plan, run sessions, track progress | Account info, onboarding answers, aggregate stats | Performance of a contract (Art. 6(1)(b)) |
| Back up and sync your stats and subscription across your devices | Aggregate stats, subscription status, device info | Performance of a contract (Art. 6(1)(b)) |
| Operate subscriptions, trials, and entitlements | Subscription status, store/entitlement identifiers | Performance of a contract (Art. 6(1)(b)); legal obligation for tax/accounting (Art. 6(1)(c)) |
| Send the reminders you turn on (daily nudge, streak saver, trial-ending) | Push token, relevant stats | Consent (Art. 6(1)(a)) — given via device notification permission |
| Understand product usage, fix bugs, measure conversion, improve the app | Analytics events & properties, device info | EU/UK: consent (Art. 6(1)(a)). Elsewhere: legitimate interests (Art. 6(1)(f)) in improving and securing our product |
| Maintain security, prevent fraud and abuse | Account info, device info, limited logs | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
| Respond to your requests and exercise of rights | Communications, account info | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms; you may object at any time (see Your rights). Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
4. Cookies and similar technologies
The website (practicetimer.app) does not use cookies, and we do not run any analytics or third-party tracking on it. Because the website sets no cookies and uses no non-essential tracking technologies, no cookie-consent banner is needed.
The mobile app does not use advertising cookies or third-party tracking SDKs for advertising. It uses a first-party analytics SDK (PostHog) and a local identifier to measure how features are used, as described above.
Your analytics choice. In the EU/UK we ask for your consent to product analytics in the app, and everywhere you can turn analytics off at any time using the in-app analytics toggle (Settings → Privacy). Turning it off stops new analytics events from being collected.
5. Notifications
If you allow notifications, we use the system push services (Apple Push Notification service / Firebase Cloud Messaging, via Expo) to deliver the reminders you turn on. You can disable them anytime in the app or in your device settings. We don't send marketing spam.
6. How we share information
We don't sell your personal information and we don't share it for cross-context behavioral advertising or targeted advertising. We share data only with service providers ("processors") who help us run the app, under contracts that require them to protect it and use it only on our instructions:
| Provider | Purpose | Data involved |
|---|---|---|
| Clerk | Authentication / account management | Email, password or OAuth identifiers, name |
| Convex | Backend database & sync | Account record, onboarding profile, aggregate stats, device info, subscription status |
| RevenueCat | Subscription management | Purchase/entitlement status, store identifiers, the account id linked to your purchase |
| Apple App Store / Google Play | Payment processing & app distribution | Payment handled entirely by the store; we receive only entitlement status |
| PostHog | Product analytics | Pseudonymous usage events and properties, tied to your account id once you sign in |
| Expo / push services (APNs, FCM) | Delivering reminders | Push token |
We may also disclose information if required by law or valid legal process, to protect our rights, users, or the public, or in connection with a merger, acquisition, financing, or sale of assets — in which case we will require the recipient to honour this policy, and we will notify you of any change in who controls your data.
7. Where your data is processed
Some of our providers are based in, or process data in, the United States; others process data in the European Union. When personal data is transferred outside the European Economic Area or the UK, we put appropriate safeguards in place, principally the European Commission's Standard Contractual Clauses (and the UK Addendum), together with additional technical and organisational measures where needed.
Where a US provider is certified under the EU–US Data Privacy Framework (and the UK extension), transfers to it may also rely on that framework. The Framework remains in force but is subject to a pending legal challenge before the Court of Justice of the EU; we monitor its status and maintain Standard Contractual Clauses as a backstop. You can ask us for a copy of the relevant safeguards using the contact details below.
8. Data retention
- Account, profile and aggregate stats — kept while your account is active; deleted when you delete your account (see below), subject to short technical backup cycles.
- On-device practice content — stays on your device until you delete it, reset the app, or uninstall it.
- Subscription / transaction records — retained as needed to operate your subscription and to meet accounting and tax obligations (up to 10 years under French commercial law).
- Analytics data — retained for up to 14 months, then deleted or aggregated, in line with our analytics provider's settings.
- Support communications — kept for up to 3 years after our last exchange.
9. Security
We use reputable providers and industry-standard safeguards, including encryption in transit, access controls, and the principle of least privilege. No method of transmission or storage is 100% secure, but we work to protect your information and review our practices regularly. If a personal data breach is likely to affect your rights, we will notify the competent supervisory authority and, where required, you, in line with applicable law.
10. Your rights & choices
If you are in the EEA, the UK, or Switzerland, you have the right to: access your personal data; have it corrected or erased; restrict or object to its processing; data portability; and withdraw consent at any time. To exercise these rights, use the in-app tools or email contact@practicetimer.app. We will respond within the timeframes required by law (generally one month).
If you are in France, you also have the right to give us instructions (directives) on how your personal data should be handled after your death, under Article 85 of the French Data Protection Act. You can lodge a complaint with the CNIL (see Contact & complaints).
If you are in the United States, your state may give you privacy rights. Twenty US states now have comprehensive privacy laws (including California's CCPA/CPRA, Virginia, Colorado, Connecticut, Texas, and others). Depending on your state, you may have the right to know/access, correct, delete, and obtain a portable copy of your personal information; to opt out of the "sale" or "sharing" of personal information and of targeted advertising; to limit the use of sensitive personal information; and to not be discriminated against for exercising these rights. We do not sell or share your personal information and do not use it for targeted advertising, so there is no sale/share to opt out of. To exercise other rights, use the in-app deletion tools or email us; you may use an authorized agent where your state allows, and you may appeal a decision by replying to our response.
Everywhere, you can: turn product analytics off (Settings → Privacy), manage notifications in the app or device settings, and delete your account and synced data at any time (see below). We do not require you to pay or accept lower service for exercising your rights.
11. Deleting your account and data
You can permanently delete your account anytime: Settings → Delete account in the app. This deletes your synced server data — profile, stats, device records, and subscription record — and your authentication account, and removes your associated analytics person record. This action cannot be undone.
You can also reset all on-device data from Settings → Reset all data, or uninstall the app to remove local content from that device.
Deleting your account does not cancel an active App Store or Google Play subscription — manage and cancel that in your store account settings. See our Subscription Terms.
12. Automated decisions & profiling
We use your onboarding answers to automatically generate and personalize a practice plan. This personalization does not produce legal or similarly significant effects about you, and we do not make decisions about you based solely on automated processing within the meaning of Article 22 GDPR. You can change your answers or delete your account at any time.
13. Children's privacy
Practice Timer is a general-audience app and is not directed to children under 13, and we do not knowingly collect personal information from them. Where local law sets a higher age for a child to consent on their own to online services — for example 15 in France under Article 45 of the French Data Protection Act, and up to 16 in some other countries — users below that age should only use the app with the involvement and consent of a parent or guardian. If you believe a child has provided us personal data without the required consent, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. We will post the new version here with a revised effective date and, for material changes, provide a more prominent notice (for example, in the app). Your continued use after an update means you have read the revised policy.
15. Contact & complaints
Questions or requests: contact@practicetimer.app · Koraii, 149 avenue du Maine, 75014 Paris, France.