MySongBook – Privacy Policy
- MySongBook is an offline‑first songbook. Your songs are stored on your device; their text leaves it only if you turn on backup. Song titles appear in usage analytics (Section 2.3).
- Optional backup uses your own Google Drive (hidden app folder) or a local folder you choose. We do not operate any server of our own and cannot see your songs.
- The App shows banner ads from Google AdMob. AdMob processes your device’s advertising ID, IP address and ad interactions (Section 4.3).
- The App uses Firebase Analytics and Firebase Crashlytics from Google: usage events, including the titles of songs you work with, and crash reports (Section 4.2).
- We do not sell personal data.
- Signing in with Google is optional and is used only to access the Google Drive app folder for backup.
1. Scope
This Privacy Policy describes how the MySongBook Android application (the “App”) handles information when you use it. It applies to the App as distributed on Google Play and to any other build of the App published by us. By using the App you agree to the practices described here.
2. Information the App handles
2.1 Content you create (stored on your device)
The App stores the songs you add in a local database on your device. A song may contain: title, music author, lyric author, album, genre, an optional recording link (URL), capo setting, chord voicing preferences, the song text with chords, an optional imported Guitar Pro tablature file, and timestamps. This content is created and controlled entirely by you. It is processed on your device; the song text is transmitted only if you enable backup (Section 3). Song titles and technical details are included in usage analytics (Section 2.3).
2.2 Google account information (only if you sign in)
If you choose the Google Drive backup option, the App asks you to sign in with your Google account using Google Sign‑In. The App receives your account e‑mail address and display name and shows them in the backup settings so you can see which account is connected. This information is kept in memory only while the App is running, is not written to the App’s database or to persistent storage, and is discarded when you sign out. OAuth tokens are issued, stored and refreshed by Google Play services on your device; the App never has access to your Google password.
2.3 Information sent to Google services
- Advertising (Google AdMob): advertising ID and other device identifiers, IP address, device and app information, app interactions, diagnostics and ad interactions (Section 4.3). The AdMob SDK adds the
AD_IDpermission, which lets the App read the advertising ID. - Usage analytics (Firebase Analytics): an app‑instance identifier, device model, OS version, approximate country derived from the IP address, and events about using the App: automatic events such as the first launch, sessions and screens, and our own events when a song is created, edited, opened, deleted, backed up or synced. Song events include the song’s title (up to 100 characters) and its first 30 characters, its random and local IDs, type (lyrics, tab or ABC), size, a hash of its text, its revision and whether it has an attachment; backup and sync events include technical details of the run. The song text itself is not sent (Section 4.2).
- Crash reports (Firebase Crashlytics): the stack trace, device model, OS version, app version, an installation identifier and the latest analytics events (“breadcrumbs”) when the App crashes (Section 4.2).
Analytics and crash reporting are turned off in debug builds, which also show only Google’s test ads. The App does not collect your precise location, contacts, photos, microphone, camera or SMS data, and no account is created with us.
3. Backup and synchronisation
Backup is optional and off by default. You can choose one of two destinations in Backup settings:
3.1 Google Drive (hidden application data folder)
The App uses the Google Drive API with the restricted drive.appdata scope. This scope grants access only to a hidden, application‑specific folder (appDataFolder) in your own Google Drive. The App cannot read, modify or delete any of your other Drive files. Within that folder the App stores, for each song, a meta.json file (metadata), a content.txt file (song text with chords) and, when present, a score.gp file (imported tablature). Songs you delete are first marked as deleted so that the deletion propagates to your other devices, and the corresponding files are subsequently removed.
Data travels directly between your device and Google’s servers over encrypted connections (HTTPS). We do not run an intermediate server and have no access to the contents of your Drive. Google’s handling of data stored in Google Drive is governed by the Google Privacy Policy.
Google API Services User Data Policy. MySongBook’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to provide the backup and restore feature you requested; it is not used for advertising, is not sold, and is not transferred to humans or third parties except as necessary to provide the feature, to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
3.2 Local folder
Alternatively you can select a folder on your device or removable storage using the Android system file picker (Storage Access Framework). The App writes the same songs/ structure described above into the folder you selected and keeps a persistable permission for that folder only. No other part of your storage is accessed. Folder contents are never uploaded by the App; if the folder you choose is itself synchronised by another app (for example a cloud‑storage client), that app’s privacy policy applies to the copies it makes.
3.3 Switching or turning off backup
When you switch from one backup destination to another, the App migrates your songs to the new destination and removes the songs/ folder from the previous one. Signing out of Google stops all communication with Google Drive; your songs remain on your device.
4. Google Play, Google Play services and Firebase
4.1 Google Play and Play services
The App is distributed through Google Play and relies on Google Play services on your device for Google Sign‑In and for secure token handling. Google Play may independently collect information about app installs, updates and, if you have enabled it in your device settings, aggregated crash and performance statistics (“Android vitals”). This collection is performed by Google under the Google Privacy Policy and the Google Play Terms of Service. Aggregated statistics shown to us in the Google Play Console are used only to maintain and improve the App.
4.2 Firebase
The App is registered in a Google Cloud / Firebase project, which also provides the OAuth 2.0 client credentials for Google Sign‑In and Google Drive. Release builds include two Firebase SDKs:
- Firebase Analytics – usage events described in Section 2.3. We use them to understand how the App is used and to find problems with saving and syncing songs. Google keeps this data according to the project’s data‑retention setting.
- Firebase Crashlytics – crash reports, used only to find and fix bugs. Google starts deleting them 90 days after they are collected.
Google processes this data as our processor under the Firebase Data Processing Terms and the Google Privacy Policy. The App does not use Firebase Cloud Messaging, Authentication, Firestore, Realtime Database or Remote Config.
4.3 Advertising
The App shows banner ads from Google AdMob on the home, song list and category list screens. When an ad is requested or shown, Google and its partners may process your device’s advertising ID, IP address (and the approximate location derived from it), device and app information, and ad interactions, under the Google advertising policies and the Google Privacy Policy. You can reset or delete your advertising ID, or opt out of ad personalisation, in Android settings (Privacy → Ads). The App does not pass your songs to AdMob.
5. Third‑party components and external links
- Google API Client for Java / Google Sign‑In – used only for the Google Drive backup described in Section 3.
- alphaTab – an open‑source music notation library used to read Guitar Pro files. Parsing happens entirely on your device; files are not uploaded.
- Chord library – chord diagrams are computed from a database bundled inside the App; no online lookup is performed.
- Recording links – if you add a recording URL to a song and tap it, the App hands the link to your default browser or media app. The App does not embed a web view and has no control over the website you open.
- Sharing – when you use Share or Copy, the song text is passed to the app you select or to the clipboard. This happens only on your explicit action.
6. How information is used
Information handled by the App is used to: store and display your songs; back up and restore them across your devices when you enable backup; show which Google account is connected; understand how the App is used and fix bugs (Firebase); and show ads (AdMob). We do not sell or rent your information, and we share it only with the Google services described above.
7. Data retention and deletion
| Where | How long | How to delete |
|---|---|---|
| Local database on your device | Until you delete a song or uninstall the App | Delete individual songs in the App, or uninstall the App (Android removes all app data). |
| Your Google Drive app folder | Until you delete the songs or disconnect the App | Delete songs in the App (deletions are synced); or in Google Drive open Settings → Manage apps → MySongBook → Delete hidden app data; or revoke the App’s access at myaccount.google.com/permissions. |
| Local backup folder | Until you delete the files | Delete the songs/ folder with any file manager, or switch backup destination in the App. |
| Google account e‑mail and name | In memory only, while signed in | Sign out in the App’s Backup settings. |
Analytics events and crash reports are kept by Google as described in Section 4.2. They are linked to an identifier of your installation, not to your name or Google account; clearing the App’s data or reinstalling it gives the App a new identifier. If you need help with a request about this data, contact us using the details in Section 11.
8. Security
All network communication between the App and Google is encrypted using TLS. Access to your Google Drive is limited to the application‑specific folder and can be revoked by you at any time. Data on your device is stored in the App’s private storage, which Android protects from other apps. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Children
The App is a general‑audience utility and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal information through the App, please contact us so that we can assist in removing it.
10. Your rights
Depending on where you live (for example in the European Economic Area, the United Kingdom, Switzerland or California), you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. Because the App stores your data on your device and in storage you control, you can exercise these rights directly: view and edit songs in the App, export them via Share, and delete them as described in Section 7. For any request you cannot fulfil yourself, contact us and we will respond within the period required by applicable law. You also have the right to lodge a complaint with your local data‑protection authority.
11. Changes to this policy and contact
We may update this Privacy Policy when the App changes or when required by law. The current version is always available at https://usharik.github.io/mysongbook/privacy-policy.html; the “Last updated” date at the top indicates the latest revision. Material changes will also be noted in the App’s Google Play release notes.
The controller of your personal data is Aleksei Usharovskii, sole trader, IČO 17943744, Netovice 47, 274 01 Slaný, Czech Republic. Questions, requests or concerns about this policy or your data can be sent to:
aleks.usharik@gmail.com · github.com/usharik