The short version
HalfStep stores what you log — your sessions, your pieces, and any recordings you make — so you can look back at them. Your recordings are private by default. We don't sell your data, we don't run ads, and we don't profile you for advertisers. You can delete your account and everything in it from inside the app, and it's really deleted.
This policy explains what HalfStep ("we", "us") collects, why, who else touches it, and how to get rid of it. HalfStep is an iPhone app for logging music practice.
What we collect
Things you give us
| Data | Why we have it |
|---|---|
| Email & password | To create and secure your account. Passwords are hashed by our auth provider — we never see or store the password itself. |
| Profile | Display name, username, avatar image, bio, and instruments. This is the part other people see. |
| Practice sessions | Start time, duration, instrument, piece, tempo, focus area, a rating, a title, and any notes you write. |
| Recordings | Audio and video you choose to capture. Stored in a private bucket and played back through short-lived signed links. |
| Social activity | Who you follow, whose Front Row you sit in, the Bravos you give, and comments you write. |
| Early-access email | If you signed up on this website, just your email address and the date. |
Things your device gives us
- A push token — an anonymous identifier for your install, so we can send the notifications you've turned on. Deleted with your account.
- Notification preferences — which categories you've enabled.
- Basic technical data — our providers log IP addresses and timestamps as part of normal operation and abuse prevention.
Things we deliberately don't collect
No advertising identifiers. No location data. No contacts. No third-party analytics or tracking SDKs. The microphone and camera are used only while you're recording a take, and what they capture goes nowhere except your own storage.
The metronome and tuner listen without recording. The tuner analyses pitch on your device in real time to show you a reading. That audio is never written to a file, never uploaded, and never leaves your phone.
Who can see what
Every table in our database uses row-level security, which means access rules are enforced by the database itself rather than by app code that could have a bug in it.
- Your recordings are private. They live in a non-public bucket and are only reachable through links that expire after an hour.
- Your profile and sessions are visible to people you're connected to — that's the point of the feed. Assume anything you write in a session note or title may be read by people who follow you.
- Your email address is never shown to other users. People find you by username.
- Your practice notes are not read by us as a matter of course, and are never used to train any machine-learning model.
HalfStep is in beta and the sharing model is still tightening — private accounts and follow approval are planned before the app opens up beyond people you know. Until then, treat what you post as visible to other HalfStep users.
Who we share it with
We don't sell your data and we don't share it for advertising. We use a small number of service providers who process data on our behalf:
| Provider | What they handle |
|---|---|
| Supabase | Database, authentication, and file storage. Where nearly all your data lives. |
| Expo | Push notification delivery. Receives a device token and the notification text. |
| Cloudflare | Hosting and DNS for this website, and forwarding for our contact address. |
| Apple | App distribution through the App Store and TestFlight. |
We'll also disclose data if we're legally required to, or if it's necessary to protect someone's safety. If we ever add a provider that materially changes this picture, we'll update this page and change the date at the top.
How long we keep it
Your data stays for as long as your account exists. When you delete your account, it goes — see below. Early-access emails are kept until we launch or until you ask us to remove yours, whichever comes first.
Deleting your account
In the app: Settings → Account → Delete account. There are two confirmation steps because it can't be undone.
This is a real deletion, not a deactivation. It removes your login, your profile, every session, every piece, every recording and avatar file, your push tokens, and your follows, Bravos, and comments. Backups taken before the deletion roll off on their own within 30 days.
To be removed from the early-access list without having an account, email hello@joinhalfstep.com.
Your rights
Depending on where you live — the UK, EU, California and several other US states among them — you may have the right to access your data, correct it, delete it, take a copy elsewhere, or object to certain processing. HalfStep honours these requests regardless of where you live, because drawing that line by geography seemed like the wrong instinct.
Deletion is self-service in the app. For anything else, email hello@joinhalfstep.com and we'll respond within 30 days. We won't charge you or make it difficult.
For the legally-minded: our basis for processing is performing the contract you entered when you created an account (storing your sessions), your consent (notifications, which you can withdraw in Settings), and our legitimate interest in keeping the service running and free of abuse.
Children
HalfStep isn't intended for children under 13, and we don't knowingly collect their data. Many music students are minors — if you're under 18, please get a parent or guardian's permission before signing up, and think twice before putting your full name or anything identifying in a public profile. If you believe a child has created an account, email us and we'll remove it.
Security
Data is encrypted in transit and at rest by our providers. Recordings sit in a private bucket behind expiring links. Access rules are enforced at the database level. Account deletion runs server-side with credentials that never reach the app.
That said: no service is perfectly secure, HalfStep is a beta built by one person, and we'd rather say so than imply otherwise. If you find a security problem, please email us before disclosing it publicly — we'll take it seriously and credit you if you'd like.
International transfers
Our providers operate globally, so your data may be stored or processed outside your country, including in the United States. Where required, transfers rely on standard contractual clauses or equivalent safeguards through those providers.
Changes
We'll update this page when things change and revise the date at the top. For anything significant, we'll tell you in the app or by email rather than quietly editing.
Contact
Questions, requests, or complaints: hello@joinhalfstep.com.
If you're in the UK or EU and you're unhappy with how we've handled something, you can complain to your national data protection authority.