← repertuvar.app
Türkçe

Privacy Policy

Effective date: 26.07.2026 · Last updated: 08.09.2026

This English text is provided for information only. The binding version of this policy is the Turkish one, available at repertuvar.app/privacy. In case of any discrepancy, the Turkish text prevails.

This privacy policy explains how Repertuvar (the "App", "we") collects, uses and protects your personal data through its mobile application and the repertuvar.app website. Repertuvar is a tool built for musicians to manage their repertoire, with particular support for Turkish music.

1. Data Controller

The controller of your personal data is:

2. What Data We Collect

a) Account information

When you sign in with Google (and, in future, Apple), we receive your email address and name from the identity provider. You may add further details yourself, such as the display name shown on your profile.

b) Content you create

Data you enter while using the App: pieces (title, makam, usul, form, lyrics, chords), setlists, your personal chord sheets, the groups you belong to and your group memberships, in-group messages and notifications.

c) Technical data

Technical data required for the App to work (session tokens, data stored locally on your device for offline use). The App shows no advertising and uses no third-party tracking or analytics cookies.

d) Usage measurement

We measure usage on our own infrastructure in order to improve the service; this data is not transferred to any third party and is not used for advertising.

Inside the App: the name of the page opened, the page it was reached from, session ID, user ID, device type (mobile/desktop), platform, time zone, and a coarse location derived from the IP address (country, region, city). The IP address itself is not stored.

On the marketing site (repertuvar.app): the address of the page opened, the referring site and device type. No user ID, cookie or location data is collected here; visitors are not identified.

e) Purchase information

In-app purchases are handled through the App Store and Google Play; we have no access to your payment card details — these are processed by Apple and Google.

3. Why We Process Data and on What Legal Basis

PurposeLegal basis (GDPR)
Creating your account and providing the servicePerformance of a contract (Art. 6(1)(b))
Running setlist and group featuresPerformance of a contract
Sending invitation and notification emailsPerformance of a contract / legitimate interest
Security and prevention of misuseLegitimate interest (Art. 6(1)(f))
Measuring and improving how the service is usedLegitimate interest (Art. 6(1)(f))
Legal obligationsLegal obligation (Art. 6(1)(c))

4. Who We Share Data With

We do not sell your data. We use the following service providers (processors) in order to deliver the service:

These providers process data only to the extent needed to provide the service and strictly on our instructions.

5. International Transfers

Your data is stored primarily on Supabase servers in the European Union. That said, some providers — Google (sign-in), Resend (email delivery) and Apple/Google (distribution) — may process data outside the European Economic Area (for example in the United States). Such transfers are covered by the safeguards required under the GDPR, for example Standard Contractual Clauses.

6. How Long We Keep Data

We keep your account information and the content you create for as long as your account is active. Specific retention periods apply to usage measurement records:

DataRetention
Account information and content you createAs long as the account is active
User ID, session ID, city and region in in-app usage recordsDeleted after 30 days
Usage records in fullDeleted after 180 days
Marketing site visit records (contain no identifiers)180 days

Only data we are legally required to retain falls outside these periods.

7. Deleting Your Account and Data

You can delete your account yourself from within the App, under Settings → Delete My Account. Deletion takes effect the moment you confirm it, and permanently removes your account, your personal setlists, your group memberships, your personal chord sheets and your messages; your user ID is also removed from usage records. You may also request deletion via privacy@repertuvar.app.

Two kinds of shared content are deliberately preserved, because other people's work depends on them:

8. Your Rights

Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw consent you have given. Contact us to exercise any of these rights.

You also have the right to lodge a complaint with a data protection supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

9. Cookies and Local Storage

The App uses local storage on your device (IndexedDB) so that it can work offline, and the technical storage required to keep you signed in. On the marketing site, a session key that lives only until the tab is closed is used so that the same visit is not counted twice. We use no marketing or third-party tracking cookies.

10. Children's Privacy

The App is not directed at children under 16, and we do not knowingly collect data from anyone under that age.

11. Security

We take reasonable technical and organisational measures to protect your data — for example restricting access through authentication and row-level security rules, and encrypting data in transit. No system is 100% secure, but we take security seriously.

12. Changes to This Policy

We may update this policy from time to time. For significant changes we will notify you in the App or on the website. The current version is always published on this page.

13. Contact

For any question or request regarding privacy: privacy@repertuvar.app