Privacy
Octotune keeps your progress on your own device. It has no ads and no analytics. Children are never asked to sign in or give any details. A grown-up can choose to sign in with Google, and then a copy of the progress is kept in their account until they delete it.
This page explains, in plain words, what Octotune keeps, where it keeps it, and who else is involved. It describes the app as it works today.
The short version
- Your progress stays on your device. No account is needed.
- No ads, and no analytics. Octotune contains no advertising or analytics code, and nothing that follows you around the web.
- Children are never asked for anything. No name, no age, no sign-in, no chat.
- Signing in is optional, and for grown-ups. Sign in with Google and a copy of your progress is kept in your account, so it is safe and the same on every device.
- A few outside services are used: the recorded instrument sounds and, if you sign in, Google's sign-in and storage. They are listed below.
- No microphone, no camera, no location. Octotune never asks for them.
What stays on your device
Everything Octotune needs to work is kept in your browser's own storage, on your device:
- Progress: which stops on the path are done and their crowns, stars for lessons and songs, how quickly and accurately you read each note, your practice days, and (in Kids mode) the note friends your child has met.
- Preferences: things like tempo, finger hints, your daily goal and how you like songs shown.
- Settings for this device only: Kids or Adult, sound on or off, and which keyboard you use. These never leave the device, even if you sign in.
- Songs you open from your own files (MIDI or MusicXML). They are kept on the device and never uploaded.
- Files for playing offline: the app itself and its fonts, songs and lessons you have opened, and the instrument sounds.
Kids and Adult keep separate progress on the same device.
Backups. In Adult's settings and in the Kids grown-ups' drawer, "Save a backup" writes your progress to a file that you keep. Nothing is sent anywhere. "Restore from a backup" reads it back.
To remove it all, clear this site's data in your browser's settings. If you have saved backup files, delete those too.
If a grown-up signs in
Signing in is optional. It sits in Adult's settings and behind the hold in the Kids grown-ups' drawer, never on a screen a child uses. Today the only way to sign in is with a Google account.
When you sign in, we use Google's Firebase services:
- Firebase Authentication keeps your sign-in profile: your name, your email address, and that you signed in with Google.
- Cloud Firestore keeps one document for your account: a copy of the progress and preferences listed above (not the device-only settings), and the time it was last saved. The progress of both players on a device, Kids and Adult, belongs to the grown-up signed in on it.
- A plan record says which plan your account is on. The app can read it but never change it.
Our security rules let a signed-in grown-up read and write only their own document, and nobody else's.
When it syncs. When you sign in, when the app starts, a few seconds after your progress changes, and when the app goes into the background. Nothing is sent unless your progress has changed.
Signing out leaves this device's progress where it is.
Deleting your account. In the settings, "Delete account" asks once more, then deletes your account's copy of the progress and then the account itself. If you signed in a while ago, Google asks you to sign in again first, to make sure it is you. The progress on your device stays until you clear it.
The sign-in code isn't loaded until it is needed: when a grown-up opens the settings while signed out, or on a device where someone has signed in before. If you never sign in, the app never contacts Google's sign-in or storage services.
Children
Kids mode is for children from about 2½. It asks a child for nothing: there is no name, no profile, no sign-in, no chat and nothing to buy. There is no voice, and the app never listens. Anything a grown-up might change, including signing in, sits behind a gear that has to be held down for a second and a half.
Outside services the app uses
Like most websites, Octotune loads a few things from other companies' servers. Each request tells that server your device's IP address, as every web request does. Our pages tell them only that the request came from Octotune, never which page you were on.
| What | From | When |
|---|---|---|
| The grand piano's sounds | A sample library on GitHub Pages (smpldsnds.github.io) | When the piano first plays; then kept on your device |
| The other instruments' sounds | A sound library on GitHub Pages (gleitz.github.io) | When you first choose another instrument; then kept |
| Sign-in and your account's copy | Google (Firebase) | Only if a grown-up signs in |
Hosting. Octotune's pages and the app are served by Firebase Hosting, a Google service. As with any website, the server receives your IP address and the address of each file requested, in order to send it.
MIDI keyboards
If you connect a MIDI keyboard, your browser asks first whether Octotune may use MIDI devices. The notes you play are used inside the app to check your playing. They are not sent anywhere.
Changes
If what Octotune keeps changes, this page will change with it, and the date at the top will show when.
The rules for using Octotune are in the terms of service.
Questions about privacy? Email us at hello@octotune.com, or see About Octotune.