Last updated: 15 July 2026
This policy explains what data aChordion (the “Service”) collects, why, and the choices you have. We aim to collect as little as the Service needs to work.
What we store
- Account: your email address and a chosen username (and an optional display name), used to sign you in and to show who you are to your bandmates.
- Your content: the songs, chords, lyrics, set lists, and personal notes you create or import, so the Service can store and show them back to you and, where you choose, your band.
- Technical basics: standard request information needed to operate and secure the Service.
- Usage analytics: to understand how the Service is used and improve it, we collect product-usage events (for example, that a song was created or a set list opened). These are attributed to your account by an internal user identifier — never your email — and never include the content of your songs, lyrics, or notes. Basic, privacy-friendly traffic measurement runs on our public landing page. See “Who processes it” below.
- Billing references: if you are the owner of a paid band subscription, we store a Paddle customer ID and a Paddle subscription ID linked to your account. We do not store your card number, bank details, or any other payment instrument — those are entered directly into Paddle’s hosted checkout overlay and never reach our servers. See “Payment and billing data” below.
You can sign in with an email and password, or with your Google account. If you use Google sign-in, we receive your name, email address, and profile picture from Google to create and identify your account. See “Who processes it” below.
We do not store your password — sign-in is handled by our authentication provider, which keeps credentials on our behalf.
Personal vs. shared
Your personal notes and per-song settings (your key, capo, autoscroll) are private to you. A song shared into a band is visible to that band’s members; your notes on it stay private. Leaving or being removed from a band ends that access.
Payment and billing data
Band subscriptions (Gigging and Ensemble tiers) are billed through Paddle, which acts as the Merchant of Record for all transactions. Paddle is the legal seller of record: they collect payment, calculate and remit applicable VAT and sales tax, issue compliant invoices, and handle refund and chargeback processes under their own buyer terms.
When you subscribe, your payment details are entered into Paddle’s hosted checkout overlay — your card number and bank details go directly to Paddle and are never transmitted to or stored on aChordion’s servers. We receive from Paddle only a customer ID and a subscription ID, which we store to manage your band’s subscription status.
Paddle’s own privacy policy governs how Paddle processes the payment data you provide to them. We encourage you to review it at paddle.com/legal/privacy.
On cancellation or downgrade, your band moves to the free Session tier at the end of the current billing period. Your songs and set lists are never deleted — content that is over the free tier’s limit becomes read-only until you upgrade again or reduce it below the limit.
Who processes it
We don’t sell your data, and we don’t share it with third parties except with the service providers below that we rely on to run the Service, or as required by law. Each acts as our processor (or, for payments, as an independent controller as noted) and is permitted to use your data only to provide their service to us:
- Supabase — hosting, database, and authentication. Stores your account, your content, and billing reference IDs.
- Google — sign-in (Google OAuth), used only if you choose to sign in with your Google account. When you do, Google shares your basic profile information (name, email, profile picture) with us to authenticate you. Google’s handling of your data is governed by its own privacy policy.
- Vercel — application hosting and delivery, and privacy-friendly, cookieless traffic measurement on our public landing page.
- Paddle — payment processing and Merchant of Record for band subscriptions. Card details go to Paddle’s systems directly and are not held by us (see “Payment and billing data” above). As Merchant of Record, Paddle acts as a separate data controller for the payment data you provide to it.
- PostHog — product-usage analytics (hosted in the EU), used to understand and improve the Service. Events are keyed to an internal user identifier, not your email, and never include your song content.
- Resend — delivery of transactional and account emails (for example, password resets), which involves processing your email address.
- Cloudflare — DNS and routing of email sent to our contact addresses.
Your rights
You can view and update your username and display name, and reset your password, from your profile. You can permanently delete your account and data at any time from your profile settings — this erases your songs and personal notes and removes you from your bands.
Depending on where you live (for example, under the EU/UK GDPR), you may also have rights to access, correct, export, or restrict the processing of your data. To make such a request, email privacy@achordion.app.
Retention
We keep your data for as long as your account exists. When you delete your account, your songs and personal notes are removed; content you shared into a band that other members rely on may persist with the band (set lists you created stay with the band but are no longer attributed to you). The Paddle customer ID and subscription ID associated with your account are also removed when you delete your account, though Paddle may retain transaction records independently under their own retention policies.
Changes
We’ll update the date above when this policy changes and, for significant changes, aim to give notice in the app.
Contact
Questions about your data? Email privacy@achordion.app.