SyncSheets Privacy Policy
Last updated: August 13, 2026
Contact: support@syncsheets.io
1. Who we are
SyncSheets ("we", "us") provides a mobile app for musicians to view, organize, and share sheet music, including band collaboration features.
2. Information we collect
| Data | Source | Purpose |
|---|---|---|
| Name, email, profile photo | Google or Apple Sign-In | Account and display |
| Username, phone (optional) | You | Discoverability, band invites |
| Sheet music files & annotations | You | Core app functionality; backed up to SyncSheets Cloud unless you turn backup off (see Section 5) |
| Band/setlist/calendar data | You + server | Collaboration |
| FCM device token | Firebase | Push notifications |
| Usage/diagnostics (if enabled) | App | Stability and improvement |
| Subscription status | Apple App Store / Google Play (via RevenueCat) | Pro access |
We do not sell your personal data.
3. How we use information
- Authenticate you and sync data across devices
- Operate band features (invitations, setlists, events, rehearsal sync)
- Send notifications you opt into
- Respond to support requests
- Manage subscriptions and trials
- Comply with law
4. Third-party services
- Google — Sign-In (name, email, profile). Google Drive access, limited to the
drive.filescope, is requested only on the web dashboard when you import from Drive (see Section 6) - Apple — Sign-In, iCloud sync (if you use iCloud on Apple devices)
- Firebase (Google) — push notifications
- RevenueCat — subscription management
- SyncSheets server — band account data and shared band files hosted on our infrastructure
- Cloudflare R2 (Cloudflare, Inc.) — object storage for SyncSheets Cloud backup and band score files
- Railway — hosting for the SyncSheets server and database
Each provider has its own privacy policy. These providers act as processors on our instructions: they store and serve your files, and do not use them for their own purposes.
5. SyncSheets Cloud backup
SyncSheets keeps a backup of your library on our own infrastructure so you can restore it if you lose or replace a device. This section explains exactly what that means, because it involves us storing your files.
What is backed up
- Your sheet music files (PDF and MusicXML) and any parts derived from them
- Your annotations, markings and page-crop settings
- Setlists, folders, calendar events and the metadata that organises your library
Where it is stored
Files are stored as objects in Cloudflare R2, in a location namespaced to your account. The index that describes them lives in our PostgreSQL database, hosted on Railway. Only your account can read your files: downloads are served through short-lived links issued to you after you sign in.
Backup is on by default, and you can turn it off
We enable backup by default, because the backup nobody switched on is the one that is missing when a tablet fails the night before a concert. You can turn it off at any time in Settings → Sharing & Sync → Cloud Backup. When it is off, nothing further leaves your device. Files already backed up stay until you delete them.
You can delete your cloud backup at any time, and keep the app
Settings → Sharing & Sync → Delete my cloud backup permanently erases everything we hold for you in the cloud — every score, part, setlist and annotation — while leaving the sheet music on your device untouched. We keep no copy and cannot restore it afterwards.
This control is available to every user, including on the Free plan and after a Pro subscription ends. Using cloud backup is a paid feature; withdrawing your data from it never is.
When you delete your account
Deleting your account erases your cloud backup as part of the same operation, along with your profile, band memberships, setlists, calendar events and support correspondence. If the files cannot be erased for any reason, we do not delete the account — we report the failure so you can retry, rather than leaving files behind that no one can reach.
We keep records of subscription transactions where tax law requires it, but they are detached from your identity when your account is deleted.
We also keep one small record that your account has already used its free trial. It stores no readable personal data — your email address and sign-in ID are kept only as one-way cryptographic hashes, which cannot be turned back into an address — together with the date the trial ended. We keep it so the free trial cannot be taken repeatedly by deleting an account and signing up again, which is a legitimate interest in preventing misuse of the service (GDPR Art. 6(1)(f)). If you sign up again with the same address, you continue the original trial rather than starting a new one.
6. Google user data
When you sign in with Google or import files from Google Drive, SyncSheets accesses Google user data only to provide features you enable. We request only the minimal, non-sensitive drive.file Drive permission.
Data we access
- Google Sign-In: your name, email address, and profile photo to create and identify your SyncSheets account.
- Google Drive (
drive.filescope, optional, web dashboard only):- Individual files you explicitly choose with the Google Picker when importing scores into a band library. Only the files you select become accessible; nothing else in your Drive is read, listed, or indexed.
The mobile app does not request Drive permission at all. Drive import happens on the web dashboard, which asks for it at the moment you use it and not before. Backup and cross-device restore do not use Google Drive — your library is backed up to SyncSheets Cloud, as described in Section 5.
How we use it
- Authenticate your account and display your profile
- Import the specific scores you pick from Drive into a band library
We do not scan, index, or read any other files in your Google Drive.
How we store it
- Google OAuth tokens are stored securely on your device or in your browser session
- The Drive access token used by the Picker is short-lived and is used only to download the files you selected
- Files in your Google Drive stay in your Drive under your control; importing copies the file into SyncSheets and does not change the original
- Band shared files are distributed through SyncSheets' own servers, not Google Drive
Sharing and disclosure
We do not sell, rent, or transfer Google user data to third parties. We do not use Google user data for advertising, analytics profiling, or training AI/ML models. Google user data is shared only with Google to perform the Sign-In and Drive operations you request.
SyncSheets' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
- Google Sign-In data is retained while your SyncSheets account is active
- Files in your Google Drive remain there until you delete them
- You can revoke SyncSheets' access anytime via Google Account permissions
- Deleting your SyncSheets account erases your server-side data including your cloud backup (Section 5). It cannot delete files stored in your own Google Drive — those stay under your control
Security
We protect Google credentials using HTTPS for all network requests and secure token storage on your device. Access to Google APIs is limited to the scopes shown in the Google consent screen.
7. Data retention
Account data is kept while your account is active.
When you delete your account in the app, we delete your server-side profile, collaboration data and cloud backup files. Two things are deliberately kept: subscription transaction records, where tax law requires it and with your identity removed, and the hashed record that your free trial was used (both described in Section 5). Encrypted infrastructure backups are overwritten on a rolling cycle and are not used to restore deleted accounts.
If you delete a band you own, its shared score files are deleted from our storage too.
Files stored locally on your device, or in your own Google Drive or iCloud, remain under your control and are not affected by account deletion.
8. Your rights
Depending on your region you may have the right to:
- Access or export your data
- Correct inaccurate data
- Stop us backing up your library (Settings → Sharing & Sync → Cloud Backup)
- Erase the data we hold in the cloud while keeping the app (Settings → Sharing & Sync → Delete my cloud backup)
- Delete your account and everything with it (Profile → Delete Account in the app)
- Withdraw consent where applicable
Contact support@syncsheets.io for requests we cannot fulfill in-app.
9. Children
SyncSheets is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect data from children.
10. Security
We use HTTPS, secure token storage on device, and industry-standard practices on our servers. No method is 100% secure.
11. International transfers
Data may be processed in countries where we or our providers operate.
12. Changes
We may update this policy. We will post the new date at the top of this page. Continued use after changes constitutes acceptance.
13. Contact
Email: support@syncsheets.io
Web: https://syncsheets.io/support