This policy explains what data the Fret app collects, why it is collected, who it is shared with, and how you can delete it. It applies to the Android app with the package name com.lvsmsmch.fret and to the backend that serves it.
Operator and controller
Lvsmsmch — Andrii Maltsev
Feichtner Str. 23
83349 Palling, Germany iamajavagod@gmail.com
1. What we collect
Account. When you open the app you choose how to sign in. As a guest, your account is tied to a random identifier generated on your device — it is not a hardware identifier and it does not identify you personally. If you sign up with an email address, we store that address and your password as a hash, never as plain text. If you sign in with Google, we receive and store your Google account identifier, email address, name and profile picture URL from the sign-in token.
Profile. Username, display name, bio and avatar, if you add them.
Content you create. Chord arrangements you add or edit, comments you write, songs you mark as favourites, and reports or feedback you send us.
Images. A picture you upload as your avatar.
Technical data. A session token, the IP address a session was created from, the device identifier described above, a push notification token, and usage counters such as how many songs you have added.
Diagnostics. Crash reports and basic performance and usage data collected by Google Firebase.
Fret has no private messaging and no AI features. Nothing you write is sent to an AI provider.
2. Why we use it
To run the app: your account, your favourites and the arrangements you add.
To keep your favourites and your own arrangements when you change or reinstall your phone — this is what linking an email address or a Google account is for.
To apply usage limits and prevent abuse, including keeping limit counters against a device identifier so that deleting and recreating an account does not reset them.
To send push notifications, if you allow them.
To handle reports, including copyright complaints, and to keep the service usable.
To fix crashes and understand which parts of the app are used.
3. Who we share it with
We do not sell your data. We use the following providers, who process data on our behalf:
Google Firebase — crash reporting, analytics and push notification delivery.
Google Play services — sign-in with Google, when you choose it.
Google AdMob — the advertising SDK is part of the app. Where the app shows an ad, Google receives the ad request together with your device's advertising identifier.
DigitalOcean — hosting. Our server and database are located in Frankfurt, Germany.
Some of these providers are established outside the European Economic Area. Where data is transferred outside the EEA, it is done under the safeguards those providers offer, such as the European Commission's Standard Contractual Clauses.
4. Legal bases (GDPR)
Performance of a contract — creating your account, storing your favourites, your arrangements and your comments.
Legitimate interests — keeping the service secure, enforcing usage limits, preventing abuse, handling complaints, fixing crashes.
Consent — push notifications and, where applicable, personalised advertising. You can withdraw consent at any time in your device settings.
5. Retention and deletion
You can have your account and everything in it deleted at any time. How to ask, and the exact list of what is removed and what is not, is on Delete your account. Otherwise, data is kept while your account exists.
6. Security
All traffic between the app and our server is encrypted with TLS. Access to the server is restricted, and account passwords are stored only as hashes and never in plain text.
7. Age
Fret is intended for people aged 16 and over. If you are younger than 16 but at least 13, you may use it only with the consent of a parent or guardian. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, write to us and we will remove it.
8. Your rights
Under the GDPR you have the right to access your data, to correct it, to have it deleted, to restrict or object to its processing, and to receive a copy in a portable format. To exercise any of these, write to iamajavagod@gmail.com. You also have the right to lodge a complaint with your local data protection authority.
9. Changes
If this policy changes, the new version is published on this page with a new date at the top. Significant changes will also be announced in the app.