Privacy policy
Current privacy baseline for scoretransposer.com
This policy describes how ScoreTransposer handles account data, uploaded scores and media, structured revisions, generated outputs, and support records.
Information collected
Account data such as email address, password hash, activation status, and entitlement dates.
Uploaded scores, scans, audio or video, structured MusicXML and Score JSON, generated exports, and correction history.
Operational metadata such as upload timestamps, job status, file names, and support contact records.
How data is used
To authenticate users, verify paid access, and deliver score scanning, editing, conversion, transposition, playback, practice, and export workflows.
To retain source files and generated results for the signed-in user to review and download inside the app.
To investigate failed jobs, respond to support requests, and improve heuristic conversion quality.
Retention and deletion
Account and entitlement records are retained while the account remains active and for follow-up support when needed.
Uploaded source files and generated outputs are retained to support download, review, and service troubleshooting.
Signed-in users can download a structured data copy and request deletion after password verification. Deletion has a 14-day cancellation window.
After the grace period, user scores, classroom data, support records, and stored files are removed; payment records required for audit are de-identified.
Data sharing
Customer files are not sold.
Operational vendors may process traffic, hosting, DNS, storage, logging, and deployment data as part of delivering the service.
Data may be disclosed when required by law or to protect the service from abuse, fraud, or security incidents.
Cookies and analytics
A functional locale cookie remembers the selected interface language.
GA4 or Microsoft Clarity loads only after explicit consent and only when production analytics is enabled.
Visitors can decline analytics without losing access to public content or product workflows.
Security baseline
Access to the conversion tool is gated by user authentication and activation-based entitlement checks.
Production access should be limited to authorized operators, and secrets should be managed in the hosting platform instead of source control.
Users remain responsible for avoiding unlawful or unauthorized uploads and for verifying musical correctness before publication or performance.
Contact and policy changes
Data export and account deletion are available in the signed-in dashboard. If you cannot sign in or need policy clarification, use the public support channel and confirm account identity.
Material changes to hosting, storage, analytics, payments, or account workflows should trigger a policy update before the new flow goes live.
Trust loop
The privacy page should reinforce the about page and the terms page, not stand alone.
If a visitor lands here from search or checkout, they often still want to verify the product position, service boundaries, and purchase path.
Continue exploring
The next common destinations are support, terms, and purchase guidance.
This keeps users moving from privacy into terms, support context, and access guidance instead of dropping out of the trust path.