In this policy, “we” means the operator of Ye Xiaoquan® Growth Plan, and “App” means Ye Xiaoquan Piano Companion for iPhone and iPad. Please read this policy before using the App.
We process only the information needed for sign-in, MIDI piano companionship, practice statistics, history, device synchronization and support. The current version contains no advertising, performs no cross-app tracking and includes no third-party behavioural analytics SDK.
01Scope
This policy applies to the Ye Xiaoquan Piano Companion iOS/iPadOS App, its supporting server APIs, this support website, and support information you voluntarily send by email.
It does not govern your digital piano, Apple, network operator or other third-party products and services. Their own policies apply.
02Information we handle
2.1 Account and authentication
- Account name: used to create, identify and sign in to your account.
- Password and credentials: the password is sent over an encrypted connection and the server stores only a one-way password hash. If you save login information, credentials are kept in Apple Keychain.
- Account status and timestamps: creation, update, credential issue, use, expiry and revocation times.
2.2 Device and app information
- An app-generated device identifier, device name, platform, operating-system version and app version.
- Your selected server region, recent device activity and the local identifier used for sync.
- These identifiers support security, device recognition, synchronization and troubleshooting; they are not used for advertising.
2.3 Practice and MIDI information
- Session summaries: target BPM and tolerance, start/end times, effective duration, key/beat/chord counts, average BPM and offset, stability, velocity and pitch range.
- Per-key detail: sequence and time, MIDI pitch, note name, velocity, interval, normalised beat count, BPM and rhythm deviation.
- Local state: pending uploads, retry progress, target BPM and display settings.
2.4 Diagnostics and support
- API request time, endpoint, status, latency, response size and error details may appear in the in-app debug view of development builds.
- Messages and attachments you choose to email to support.
- Please remove passwords, access tokens and information unrelated to your request.
03How we use information
- Create accounts, authenticate requests, maintain sessions and protect account security.
- Receive MIDI input and calculate tempo, rhythm deviation, stability, effective practice time and session summaries.
- Store sessions locally first, then synchronize summaries and detail in resumable batches.
- Provide history across devices signed into the same account and server region.
- Diagnose failures, prevent abuse, maintain reliability and respond to support requests.
- Comply with applicable law and protect users, services and legal rights.
We do not sell personal information and do not use practice data for personalised advertising.
04Device permissions and capabilities
The App does not need microphone or precise-location access for MIDI analysis.
05Storage and server regions
Practice data is written to the device first. If you sign in and a network is available, records are uploaded to your selected server region in stages. This design helps preserve a session during interruption or a temporary connection failure.
Changing regions does not migrate data
Existing records are not automatically moved and are not deleted from the previous server. New data is stored on the newly selected server. You will be signed out and must sign in again. We recommend staying with one region.
Transmission uses HTTPS. Server location and applicable data rules may vary by region. Choose the region suitable for you.
07Retention
- Local sessions: remain until synchronized, deleted in the App, removed with the App, or cleared by the operating system.
- Cloud sessions: remain while your account is active unless you delete the account or request deletion.
- Credentials: expire or are revoked under server security rules; saved credentials can be removed by signing out.
- Support correspondence: is retained only as long as reasonably needed to resolve the request and meet legal obligations.
Backups may retain deleted information for a limited cycle before secure expiration, unless longer retention is legally required.
08Your privacy choices
Access
View session summaries and synchronized history inside the App.
Correct settings
Change server region and local practice settings in Settings.
Stop sync
Practise offline or sign out; pending local data will not upload until conditions allow.
Delete the account
Use the small permanent-deletion option at the bottom of Settings. Two confirmations and current-password verification are required.
Account deletion permanently removes the account and associated cloud data from the current server and cannot be undone. Local records on other devices may require removal on those devices. For an access or deletion request you cannot complete in the App, contact us below.
09Children
Children should use the App with a parent or guardian. The guardian should help the child understand this policy and decide whether to create an account and synchronize practice data. A guardian who believes a child's information was handled improperly may contact us to request review or deletion.
10Security
Our safeguards include HTTPS transport, server-side password and token hashing, Apple Keychain, account-level isolation, authenticated requests, batch integrity checks and transactional deletion. Each account is restricted to its associated resources.
No transmission or storage method is absolutely secure. If an incident may affect your rights, we will take remedial action and notify affected users when required by applicable law.
11Policy updates
We may update this policy when the App, data handling, server regions or legal requirements change. The revised version will appear on this page with an updated date. We will provide additional notice when a change materially affects your rights.
12Contact us
For questions about this policy, personal information or account deletion, contact:
Include your account name, request type and information needed for verification, but never send your password or access token.