Privacy
This page covers what BandBinder collects through the website, the app, and payments. This policy is kept up to date as the product grows.
The app
BandBinder is live on Windows, macOS, Linux, Android, and iOS. It collects the following when you use it:
- Sign-in identity. BandBinder offers three sign-in methods, and we collect an email address plus a Firebase Auth user ID (uid) from whichever one you use. Signing in with Google gives us your Google account's email address. Signing in with Apple gives us the email address Apple provides, which is a private relay address ending in
@privaterelay.appleid.comif you choose Apple's Hide My Email, not your real one. Signing in with email (a one-time code) uses the email address you enter directly. This is used solely to authenticate you and to associate your library with your account. - Library backup and band sync. The songs, setlists, and other content you create in the app are stored in our cloud database so you can restore your library across devices and share it with band members. Only the data you explicitly create in the app is stored, along with minimal backup metadata (a per-device identifier, device name, and backup timestamp) needed to restore your library - no per-action usage telemetry (see "Operational usage signal" below for the one minimal exception).
- Optional reference links (Spotify and YouTube). If you attach a Spotify or YouTube link to a song, the app fetches that item's public title, artist, and artwork from Spotify or YouTube, and playing a YouTube reference loads YouTube's player. Those requests go directly from your device to Spotify or Google - so, as with visiting their websites, they see your IP address and the item requested, under their own privacy policies. This happens only for links you choose to add. We don't send them anything about you, and no Spotify or Google account is required by us or accessed by us.
- Marketing opt-in. If you check "Send me tips and updates" at sign-in, we record that preference and the timestamp. You can withdraw this consent at any time - contact support.
- Operational usage signal. When the app syncs with our servers, it reports your device's platform (e.g. Windows, Android) and the app version you're running, and we record the time of that activity. We use this only to see which platforms and versions are actually in use and roughly how many accounts are active - never per-action tracking, never shared with third parties.
- Automatic usage analytics (Android, iOS, and macOS). On Android, iOS, and macOS, the app uses Firebase Analytics to automatically record a small set of Firebase's standard events - such as app opens (
first_open), session starts (session_start), how long the app stays in the foreground, and app or OS updates - together with the standard properties Firebase attaches to them: device model, OS version, app version, language, and an approximate location (country and city level) Firebase derives from your IP address. Firebase publishes the full list of automatic events and properties in its privacy and security disclosure. Everything is tied to a pseudonymous identifier Firebase generates for the install, not to your account, email, or any content you create, and we've turned off Android advertising ID collection. We don't define any custom events, and no event ever carries app content (band names, song titles, lyrics) or personal information. Firebase Analytics has no Windows or Linux implementation, so those two platforms use the separate desktop usage ping described next instead. - Crash reports (Android, iOS, and macOS). On Android, iOS, and macOS, the app uses Firebase Crashlytics to report crashes. A report carries the crash's stack trace plus the standard diagnostics Crashlytics collects automatically about the device and its state at the moment of the crash - things like the device model, OS version, app version, CPU architecture, free memory and disk space, screen orientation, whether the app was in the background, and whether the device is rooted or jailbroken. Firebase publishes the full list in its privacy and security disclosure. Reports are tied to pseudonymous identifiers Firebase generates for the install and the session, never to your account or email. We add exactly two fields of our own: which build you're running (staging or production) and a yes/no for whether you were signed in when it crashed. We never send band names, song titles, lyrics, your email, or any content you create: the error description the app hands to Crashlytics is reduced to the error's type (and, for Firebase and platform errors, a short error code), with the stack trace giving the location; the error's own message text is never sent, because that text could quote a chart line, a song title, or an email address. Reports go directly to our own Firebase project, which we control; we don't share them with third parties.
- Desktop usage ping (Windows and Linux). Since Firebase Analytics isn't available there, on Windows and Linux the app instead sends a minimal ping directly to our own server when it opens: a random install id generated on your device (never derived from your hardware, and not tied to your account), your platform, a coarse OS version (e.g. "Windows 11"), the app version, and the time. It's throttled to at most once every 15 minutes, and if you're offline - Performance Mode is built to work fully offline, including through a whole rehearsal or gig - it's queued locally and sent the next time the app finds a connection, up to 30 days back. Our server looks up only the approximate country your request came from (never a city, address, or precise location, and never a location permission prompt) and then discards the IP address immediately - it is never stored or logged anywhere. We keep daily counts grouped by platform, country, and app version, never a record tied to one install or request.
App data is stored in Google Firestore and Firebase Cloud Storage, both in accounts we control directly. We don't share it with third parties; on Android, iOS, and macOS, the automatic analytics events and crash reports above go directly to our own Firebase project; on Windows and Linux, the usage ping above goes directly to our own join-api backend (a service we operate, also in Google Cloud) - and the only other third-party traffic is the optional Spotify and YouTube requests described above, which your device makes directly. You can request deletion at any time (see below).
Payments
Subscription payments are processed by Stripe. Your card details go directly to Stripe and never touch BandBinder's servers. What we store is your subscription status and Stripe customer/subscription identifiers tied to your account, used solely to operate your subscription. See Stripe's privacy policy for how Stripe handles your payment data.
Analytics
We don't run any third-party analytics or advertising script on this website - no Google Analytics, no ad pixels, no cross-site trackers. To stop one source flooding the site's forms and endpoints, our server keeps a short-lived count of requests per IP address. That counter is used only for abuse prevention and expires after a few minutes. This is separate from the app's own usage analytics described above under "The app" (Firebase Analytics on Android/iOS/macOS, our own server-side ping on Windows/Linux).
Where this lives
The site is served by Cloudflare, which processes standard server logs to deliver it. App data is stored in Google Firestore and Firebase Cloud Storage, in accounts we control directly.
Manage or delete your data
Contact support to withdraw your marketing consent or delete your app account data. You can also visit the account deletion page for full details on what deletion covers and how to request it.