Cantoralis
Pricing Free Tools Open the app

Privacy Policy

Last updated: 23 July 2026

This policy explains how Cantoralis handles personal data when you use cantoralis.com — the training app and the free tools (the "Service"). We collect very little, we do not sell it, and we say plainly below what never leaves your device. This policy forms part of our Terms of Service.

1. Who is responsible

The data controller is Cantoralis, Reykjavík, Iceland. For anything in this policy, write to privacy@cantoralis.com.

2. What we collect

  • Account email. If you create an account, we store the email address you sign up with, and your authentication credentials are handled by our authentication provider (passwords are stored only in securely hashed form).
  • Learning progress and settings. Your course progress, exercise results, and app settings are synced to our database so they follow you across devices.
  • Local preferences. Some preferences (for example, tool settings) are stored only in your browser's local storage and stay on your device.

You can use the free tools without an account, in which case we hold no account data about you at all.

3. What we do not collect

  • No payment card data. When payments launch, they will be handled by Polar as Merchant of Record. Polar processes your payment details; we never see or store your card number.
  • No microphone uploads. The tuner (and, in the future, sight-singing exercises) use your microphone with your permission, but the audio is processed entirely on your device. It is never recorded by us, never uploaded, and never leaves your browser.
  • No precise location data.
  • No sale or rental of personal data, and no third-party advertising or ad tracking of any kind.

4. How we use your data

We use your data to run the Service: to authenticate you, to sync your progress and settings, to respond when you contact us or report an issue, and to send essential service emails (for example, password resets). If you consent to analytics, we also use usage and error data to understand how the Service is used and to fix problems. We do not use your data for advertising.

5. Legal bases (EEA/UK)

Where the GDPR applies, we process your data on the basis of: performance of a contract (providing the Service you signed up for) and legitimate interests (keeping the Service secure and improving it). For optional product analytics and error monitoring, we rely on your consent, which you give or decline in the cookie banner and can withdraw at any time.

6. Where your data lives

Our database and authentication are hosted on Supabase, running on Amazon Web Services in the European Union (region eu-west-1). Your data is stored in the EU. If you consent to analytics, product-analytics events are processed by PostHog in the European Union and error reports by Sentry in the European Union (Germany). Any transfers by our subprocessors' own subprocessors are governed by their data processing agreements and the safeguards they contain (such as standard contractual clauses).

7. Subprocessors

Current subprocessors:

  • Supabase — database and authentication (EU region).
  • Resend — delivery of transactional email (account confirmation, password resets, receipts).
  • PostHog — privacy-respecting product analytics (EU region), used only if you consent to analytics.
  • Sentry — error and crash monitoring (EU region, Germany), used only if you consent to analytics.
  • Google — only if you choose “Continue with Google”, which uses Google as your sign-in identity provider.

Future subprocessors, as the Service grows:

  • Polar — payments, as Merchant of Record, when payments launch.

We will update this policy before adding a subprocessor that processes your personal data.

8. Cookies and local storage

The Service uses essential local storage for your preferences and an authentication session so you stay signed in. If you consent to analytics, PostHog sets analytics cookies and local storage to measure how the product is used; if you decline, none are set. There are no advertising cookies and no ad-tracking of any kind.

9. Retention

We keep your account data for as long as your account exists. If you ask us to delete your account, we delete your personal data; residual copies in encrypted backups are removed according to our hosting providers' backup schedules. Data stored only in your browser is under your control and can be cleared through your browser settings.

10. Your rights

Where the GDPR or similar laws apply, you have the right to access your data, to have it rectified or erased, to receive it in a portable format, and to object to certain processing. To exercise any of these rights, email privacy@cantoralis.com; we will respond within the time the law allows. Deleting your account deletes your personal data as described in Section 9.

11. Security

We protect your data with encryption in transit (TLS), row-level security in our database so accounts can only reach their own data, and least-privilege access to our infrastructure. No system is perfectly secure, but we design for the smallest possible exposure — starting by collecting little in the first place.

12. Children

The Service is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.

13. Complaints

If you believe we have mishandled your data, please contact us first — we want to put it right. You also have the right to lodge a complaint with a supervisory authority, in our case Persónuvernd, the Icelandic Data Protection Authority, or with the authority in your own country.

14. Changes to this policy

If we change this policy in any material way, we will post the updated version here and, where the change matters to you, notify you by email or through the Service before it takes effect.

15. Contact

Privacy questions and rights requests: privacy@cantoralis.com. General questions: hello@cantoralis.com.

Home Pricing Free Tools The App Terms Privacy Refunds

© 2026 Cantoralis — the classical training room.