Tonika PL

Privacy Policy

Effective: [EFFECTIVE DATE]

This is a courtesy translation. The legally binding version is the Polish original, available at Polityka prywatności.

This Privacy Policy explains how we process personal data of Users of the Tonika application — a music practice companion available as a web app and iOS application (“Service”).

We respect your privacy and are committed to transparency. We collect only what is necessary to provide the Service and never sell your data.

§ 1. Data Controller

The controller of personal data is Artur Kondas, operating as a sole proprietor under the business name BB Services Artur Kondas, registered in CEIDG:

  • Address: Smolki 12b, 30-513 Kraków
  • NIP (Tax ID): 6793315806
  • REGON (Statistical Number): 540284210
  • Email: privacy@playtonika.com
  • Phone: 535319016

§ 2. Definitions

  • Personal data — any information relating to an identified or identifiable natural person.
  • Processing — any operation performed on personal data (collection, storage, use, deletion, etc.).
  • Controller — the entity that determines the purposes and means of processing personal data (the Service Provider).
  • Processor — an entity that processes personal data on behalf of the Controller.
  • User — a natural person using the Service.
  • Service — the Tonika application.
  • GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.

§ 3. Categories of Data Collected

3.1 Account Data

When creating an Account, we collect your email address (required) and an optional display name. Registration is possible via email and password, Apple Sign In, or Google Sign In. Account data is stored in Supabase.

3.2 Practice Data

If the User is signed in, practice data is synced to the cloud. This includes:

  • Practice records (notes played, accuracy, duration)
  • Total XP and level progression
  • Practice streaks and daily practice time
  • Proficiency scores per scale and key
  • Saved session templates

This data is also stored locally in the browser’s localStorage. Without signing in, practice data remains on the User’s device only and is never transmitted.

3.3 Preferences

App settings — theme, language, guitar configuration, practice preferences — are stored in localStorage and synced to Supabase when signed in.

3.4 Microphone Audio

Tonika uses the device’s microphone exclusively for real-time pitch detection. The audio stream is processed in the browser:

  • Audio is never recorded
  • Audio is never saved — not locally, not on any server
  • Audio is never transmitted over the network
  • The microphone stream is stopped immediately upon leaving the practice view

Without microphone access, practice mode will not function — the app has no way to detect played notes.

3.5 Payment Data

Card payments are processed by Stripe. Brudne Brzmienie does not store card numbers or sensitive payment data. We receive from Stripe only:

  • Subscription ID
  • Payment status
  • Next renewal date
  • Transaction amounts (for accounting purposes)

3.6 Waitlist Data

When joining our waitlist, we collect your email address, IP address, and browser user agent string. If you opt in to marketing communications, we also record the consent timestamp and the specific consent given. This data is stored in Supabase.

3.7 Analytics Data

We use Vercel Analytics to understand general usage patterns:

  • Page views
  • Browser and operating system type
  • Country-level location (derived from IP address)

Vercel Analytics does not use cookies and does not track users across sessions.

We also use PostHog (EU-hosted) to understand how visitors use our website — page views, clicks, scroll depth, and conversion actions (e.g. newsletter sign-ups). On this website PostHog runs cookieless (in-memory only): it stores no cookies, sets no persistent identifier, and does not track users across sessions. PostHog also processes technical metadata (IP-derived approximate location, browser and operating system, referrer). When you click through to our app, a per-visit analytics identifier may be included in the link so that a single visit can be connected to a sign-up; this identifier is not stored on this website or retained between sessions.

3.8 Advertising Data

Free-tier users may see ads served by Google AdSense. When the User consents to personalized advertising:

  • Google may place advertising cookies on the User’s device to serve relevant ads based on browsing behavior
  • Google collects anonymized interaction data (ad impressions, clicks)
  • Google’s Privacy Policy applies to their data collection: https://policies.google.com/privacy

Premium subscribers are never shown ads and no advertising cookies are set for them.

If the User declines personalized advertising, Google may still serve non-personalized ads. These do not use tracking cookies for ad targeting.

3.9 Authentication Tokens

When signing in via Apple Sign In or Google Sign In, OAuth tokens are passed directly to Supabase. They are not stored locally on the device.

§ 4. Information We Do Not Collect

We want to be explicit about what we never collect:

  • Location or GPS data
  • Contacts or address book
  • Photos, camera access, or media library
  • Health or fitness data
  • Advertising identifier (IDFA) or cross-app tracking data (on iOS; web advertising is handled via Google Consent Mode)
  • Card numbers or sensitive payment data (Stripe handles those)
  • Phone number

§ 5. Purposes and Legal Bases for Processing

DataPurposeLegal Basis (GDPR)
Account (email, name)Providing the Service, authenticationArt. 6(1)(b) — performance of contract
Practice dataProgress tracking, synchronizationArt. 6(1)(b) — performance of contract
PreferencesService personalizationArt. 6(1)(b) — performance of contract
MicrophoneReal-time pitch detection (locally)Art. 6(1)(a) — consent (browser permission)
Payment data (Stripe)Subscription management, billingArt. 6(1)(b) — performance of contract
Waitlist emailLaunch notificationArt. 6(1)(a) — consent
Marketing consentProduct updates, music tipsArt. 6(1)(a) — explicit consent (double opt-in)
AnalyticsService improvementArt. 6(1)(f) — legitimate interest
Advertising cookies (Google)Serving relevant ads (free tier)Art. 6(1)(a) — consent (cookie preferences)
IP, user agent (consent audit)Proving consent was obtainedArt. 6(1)(f) — legitimate interest (compliance)
Billing dataTax and accounting obligationsArt. 6(1)(c) — legal obligation

§ 6. Data Processors and Recipients

ProviderPurposeData SharedLocation
SupabaseAuthentication, database, syncAccount data, practice data, preferencesUSA (SCCs)
StripePayment processingCard data (directly to Stripe), subscription IDUSA/EU (SCCs, PCI DSS)
Vercel AnalyticsAnonymous page-view analyticsPage views, browser/OS, countryUSA (SCCs)
PostHogCookieless product & web analyticsPage views, clicks, scroll depth, conversion eventsEU (Frankfurt)
ResendTransactional and marketing email deliveryEmail addressUSA (SCCs)
Apple Sign InOptional authentication methodOAuth token (passed to Supabase)USA
Google Sign InOptional authentication methodOAuth token (passed to Supabase)USA
Google AdSenseAdvertising (free-tier users only)Ad cookies, anonymized interaction dataUSA/EU (SCCs)

We do not sell or rent your data. Free-tier users see ads via Google AdSense; ad-related data processing is governed by Google’s privacy policy and requires your consent.

§ 7. International Data Transfers

The processors listed in § 6 may process data on servers located in the United States. These transfers are protected by:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • EU-US Data Privacy Framework where applicable
  • Processor-specific certifications (e.g., Stripe — PCI DSS)

§ 8. Data Retention Periods

DataRetention Period
Account + practice data + preferencesUntil Account deletion; permanently deleted upon deletion
Payment data (Stripe references)Until Account deletion; Stripe retains per its own policy
Billing data (invoices, amounts)5 years from the end of the tax year (legal obligation)
WaitlistUntil Service launch or opt-out, maximum 24 months
Consent audit log (IP, user agent)5 years from consent withdrawal
Analytics (Vercel)Anonymized, no association with individual users
Advertising cookies (Google)Managed by Google; revocable via Cookie preferences in app
localStorageControlled by the User (browser data clearing)

§ 9. Profiling and Automated Decision-Making

Tonika does not:

  • Profile Users for marketing or advertising purposes
  • Make automated decisions producing legal effects or similarly significantly affecting the User

XP scores, proficiency ratings, and streak counts are user-facing practice tools — they are not used for any decision-making about the User.

§ 10. Cookies and Tracking Technologies

10.1 Categories of Cookies

CategoryPurposeRequires Consent
NecessaryApp functionality (localStorage for preferences, practice data, authentication tokens)No
AdvertisingPersonalized ads via Google AdSense (free-tier users only)Yes

10.2 Cookie Consent

When ads are enabled, free-tier users are shown a cookie consent bar on first visit. Users may:

  • Accept all — enables personalized advertising cookies
  • Manage preferences — choose which categories to enable
  • Decline — no advertising cookies are set; non-personalized ads may still appear

10.3 Managing Preferences

Users can change their cookie preferences at any time:

  • In the app: Settings → Cookie preferences
  • In the browser: Clear cookies or use browser cookie settings

10.4 What We Do Not Use

  • No cross-site tracking pixels (Facebook Pixel, etc.)
  • Vercel Analytics — cookieless, anonymous analytics (no consent required)
  • PostHog — cookieless, in-memory analytics; no cross-session tracking (no consent required)
  • No fingerprinting or covert tracking technologies

10.5 Premium Users

Premium subscribers are never shown ads and no advertising cookies are set, regardless of consent preferences.

§ 11. User Rights (GDPR)

Under the GDPR (Articles 15–22), the User has the following rights:

  • Right of access (Art. 15) — request a copy of your personal data
  • Right to rectification (Art. 16) — request correction of inaccurate data
  • Right to erasure (Art. 17) — request deletion of your personal data (“right to be forgotten”)
  • Right to data portability (Art. 20) — export your practice data in JSON format (available in app Settings)
  • Right to restrict processing (Art. 18) — request limitation of how we process your data
  • Right to object (Art. 21) — object to processing based on legitimate interest (e.g., analytics)
  • Right to withdraw consent — withdraw your consent at any time (delete Account, unsubscribe from marketing)

Every marketing email includes an unsubscribe link. You can withdraw marketing consent at any time by clicking the link in any email or by contacting us at privacy@playtonika.com.

To exercise any of these rights, contact us at privacy@playtonika.com. We will respond within 30 days as required by the GDPR.

You also have the right to file a complaint with the supervisory authority:

President of the Personal Data Protection Office (PUODO) ul. Stawki 2, 00-193 Warsaw, Poland https://uodo.gov.pl

§ 12. Children’s Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected such data, we will delete it promptly. If you believe a child under 16 has provided us with personal data, please contact us at privacy@playtonika.com.

§ 13. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • All data transmitted between your device and our servers is encrypted via HTTPS/TLS
  • Authentication is handled by Supabase Auth with industry-standard security practices
  • Passwords are never stored in plaintext
  • Server-side API keys are stored as environment variables and never exposed to the client
  • Payments are handled by Stripe with PCI DSS certification

While we implement reasonable safeguards, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

§ 14. Changes to This Privacy Policy

  1. The Controller may update this Privacy Policy periodically.
  2. When changes are made, the “Effective” date at the top of this page will be updated.
  3. We will notify you of material changes through the app or via email.
  4. We encourage you to review this policy periodically.

§ 15. Contact

For privacy and data protection inquiries, contact us at:

  • Email: privacy@playtonika.com
  • Full Controller details: see § 1

Complaint to the supervisory authority: President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl

Privacy Policy · Terms of Service · Home