The short version
HalfStep stores what you log: your sessions, your pieces, and any recordings you make, so you can look back at them. Your recordings are private by default. We don't sell your data, we don't run ads, and we don't profile you for advertisers. You can delete your account and everything in it from inside the app, and it's really deleted.
This policy explains what HalfStep ("we", "us") collects, why, who else touches it, and how to get rid of it. HalfStep is an iPhone app for logging music practice.
What we collect
Things you give us
| Data | Why we have it |
|---|---|
| Email & password | To create and secure your account. Passwords are hashed by our auth provider, so we never see or store the password itself. |
| Profile | Display name, username, avatar image, bio, and instruments. This is the part other people see. |
| Practice sessions | Start time, duration, instrument, piece, tempo, focus area, a rating, a title, and any notes you write. |
| Recordings | Audio and video you choose to capture. Stored in a private bucket and played back through short-lived signed links. |
| Social activity | Who you follow, whose Front Row you sit in, the Bravos you give, and comments you write. |
| Early-access email | If you signed up on this website, just your email address and the date. |
Things your device gives us
- A push token: an identifier for your install, stored against your account so we can send the notifications you've turned on. It isn't an advertising identifier and it isn't shared with anyone but Expo, who deliver the notification. Deleted with your account.
- Notification preferences: which categories you've enabled.
- Basic technical data: our providers log IP addresses and timestamps as part of normal operation and abuse prevention.
- When you last opened the app, and on which version: the time, whether the phone is an iPhone or an Android, and the app version it is running. One line per account, overwritten each time rather than added to, so there is no history of your visits. It is tied to your account. We use it to see whether people come back and to tell which version someone is on when they report a problem. Nobody else using HalfStep can see it, and it is deleted with your account.
- A crash report, when the app crashes: what broke and where, plus the device model, the iOS version and the app version. It goes to Sentry. It is not tied to your account. We deliberately don't attach your user ID, and session replay is switched off, so nothing about a crash tells us who you are or shows us what was on your screen. Sentry gets what crashed, not who.
- Whether you have an active subscription: handled by RevenueCat. Unlike the crash report, this one is tied to your account, because the whole job is knowing whether your account has HalfStep Pro. RevenueCat receives your HalfStep account ID and the purchase receipt Apple issues. It never receives a card number, because we never receive one either: Apple takes the payment and tells us only that it happened.
Things we deliberately don't collect
No advertising identifiers. No location data. No contacts. No analytics tool. Nothing records which screens you open, what you tap, or how long you spend anywhere in the app. The one thing we note is when you last opened it, described above, and that stays in our own database. The microphone and camera are used only while you're recording a take, and what they capture goes nowhere except your own storage.
Two third-party components do run inside the app, and neither one is an analytics or advertising tool. Sentry receives a report when the app crashes. RevenueCat handles subscription purchases. Both are described in the next section and again under who we share it with, because a policy that mentions a processor only in a table is hiding it in plain sight.
The metronome and tuner listen without recording. The tuner analyses pitch on your device in real time to show you a reading. That audio is never written to a file, never uploaded, and never leaves your phone.
Who can see what
Every table in our database uses row-level security, which means access rules are enforced by the database itself rather than by app code that could have a bug in it.
- Your recordings are private. They live in a non-public bucket and are only reachable through links that expire after an hour.
- Your profile and sessions are visible to people you're connected to. That's the point of the feed. Assume anything you write in a session note or title may be read by people who follow you.
- Your email address is never shown to other users. People find you by username.
- Your practice notes are not read by us as a matter of course, and are never used to train any machine-learning model.
- You can make your account private. In Settings → Privacy. New followers then need your approval before they can see anything, and the rule is enforced by the database, not by the app.
- You can block someone. Blocking is silent and works in both directions: neither of you can see the other's profile, sessions, or comments, and any existing follow between you is removed.
HalfStep is in beta. If we change how sharing works, we'll update this page and revise the date at the top rather than quietly widening what's visible.
Who we share it with
We don't sell your data and we don't share it for advertising. We use a small number of service providers who process data on our behalf:
| Provider | What they handle |
|---|---|
| Supabase | Database, authentication, and file storage. Where nearly all your data lives. |
| Expo | Push notification delivery. Receives a device token and the notification text. |
| Sentry | Crash reporting. Receives a stack trace, the device model and the app version when something breaks. Not linked to your account, and it records no screen content. Added September 2026. |
| RevenueCat | Subscription management. Receives your HalfStep account ID and the receipt Apple issues for a purchase, so the app knows whether Pro is active. No payment details, because Apple handles the money. Added September 2026. |
| Cloudflare | Hosting and DNS for this website, and forwarding for our contact address. |
| Apple | App distribution through the App Store and TestFlight, and all payment if you subscribe to HalfStep Pro. Apple takes the payment, holds the card details, and tells us only that a valid subscription exists. If you use Sign in with Apple, Apple also handles that sign-in and returns your email address (which may be a private relay address) and, the first time only, your name. |
| Only if you use Google sign-in. You authenticate with Google directly, in Google's own sign-in sheet, and your Google password never reaches HalfStep. Google hands the app a signed identity token, which our auth provider checks with Google before creating your session. What we receive from that token is your email address, name and profile picture. Nothing else in your Google account is requested, and the app is never given a key to it. |
We'll also disclose data if we're legally required to, or if it's necessary to protect someone's safety. If we ever add a provider that materially changes this picture, we'll update this page and change the date at the top.
How long we keep it
Your data stays for as long as your account exists. When you delete your account, it goes. See below. Early-access emails are kept until we launch or until you ask us to remove yours, whichever comes first.
Deleting your account
In the app: Settings → Account → Delete account. There are two confirmation steps because it can't be undone.
This is a real deletion, not a deactivation. It removes your login, your profile, every session, every piece, every recording and avatar file, your push tokens, and your follows, Bravos, and comments. Backups taken before the deletion roll off on their own within 30 days.
Two things sit outside that, and it would be misleading not to say so. Crash reports are not deleted with your account, because they were never attached to it in the first place and there is no way to find yours; they expire on Sentry's own retention schedule. A subscription is not canceled by deleting your account, because Apple runs the billing and we cannot reach it. Cancel it in App Store → your name → Subscriptions.
To be removed from the early-access list without having an account, email hello@joinhalfstep.com.
Your rights
Depending on where you live (the UK, EU, California and several other US states among them), you may have the right to access your data, correct it, delete it, take a copy elsewhere, or object to certain processing. HalfStep honors these requests regardless of where you live, because drawing that line by geography seemed like the wrong instinct.
Deletion is self-service in the app. For anything else, email hello@joinhalfstep.com and we'll respond within 30 days. We won't charge you or make it difficult.
For the legally-minded: our basis for processing is performing the contract you entered when you created an account (storing your sessions), your consent (notifications, which you can withdraw in Settings), and our legitimate interest in keeping the service running and free of abuse.
Children
HalfStep isn't intended for children under 13, and we don't knowingly collect their data. Many music students are minors. If you're under 18, please get a parent or guardian's permission before signing up, and think twice before putting your full name or anything identifying in a public profile. If you believe a child has created an account, email us and we'll remove it.
Security
Data is encrypted in transit and at rest by our providers. Recordings sit in a private bucket behind expiring links. Access rules are enforced at the database level. Account deletion runs server-side with credentials that never reach the app.
That said: no service is perfectly secure, HalfStep is a beta built by one person, and we'd rather say so than imply otherwise. If you find a security problem, please email us before disclosing it publicly. We'll take it seriously and credit you if you'd like.
International transfers
Our providers operate globally, so your data may be stored or processed outside your country, including in the United States. Where required, transfers rely on standard contractual clauses or equivalent safeguards through those providers.
Changes
We'll update this page when things change and revise the date at the top. For anything significant, we'll tell you in the app or by email rather than quietly editing.
Contact
Questions, requests, or complaints: hello@joinhalfstep.com.
If you're in the UK or EU and you're unhappy with how we've handled something, you can complain to your national data protection authority.