1. Controller and contact
The controller is Yetly Jakub Kosiński, a sole trader entered in CEIDG, address: Brzozy-Brzeziny 13, 05-220 Zielonka, Polska, NIP 5272920562, REGON 385508094. Contact: [email protected], telephone: +48 782 785 669. The same address may be used for privacy requests and complaints.
No data protection officer has been appointed. Privacy matters are handled directly by the controller. This policy covers the Fretuno Android app, fretuno.com and related support communication.
2. Who may use Fretuno
Fretuno is offered to users in the European Union. It is not directed to children. Independent use is intended for persons aged 16 or over; a purchase must be made by an adult or with a parent or guardian’s involvement. If we learn that a younger child’s data was provided without a valid basis, we will delete it.
3. Data kept only on the device
The app may store an instrument and tuning, level, goals, settings, onboarding results, lesson progress, training sessions, answers, correctness, response time, mastery estimates, review dates and subscription projection. These records are stored in the app’s local Room database or Android DataStore and are not synchronized as training history to the Fretuno server.
- Local data remains until you delete it in Fretuno, clear the app’s storage or uninstall the app.
- Android backup and device-to-device transfer are disabled for Fretuno app data.
- Remote lesson bodies are held in memory and are not saved by the app.
4. Backend and subscription data
When the app connects to the Symfony API, the server creates a random pseudonymous UUID and session records. We process creation and last-activity times, hashed access/refresh credentials, session expiry and revocation times, a RevenueCat App User ID derived from the UUID, the current subscription projection and limited webhook metadata such as event ID, type, status and timestamps. Raw webhook bodies are not retained.
Google Play processes the Play account, payment method, order and statutory billing records under its own terms. Fretuno and RevenueCat receive purchase-history and entitlement information needed to activate Pro and produce operational subscription reports; they do not receive full payment-card details. This is not behavioural analytics of lessons or microphone use.
5. Microphone
Microphone access is requested only when you open the tuner or a pitch exercise. Short PCM frames are analysed in memory on the device to estimate pitch and stability, then discarded. Raw sound is not recorded, saved, sent to the server or supplied to RevenueCat, Google Play, Cloudflare or Contabo. A derived exercise result may be saved locally as part of training history.
6. Website and technical logs
Cloudflare proxies fretuno.com and provides cookieless Web Analytics. It may process IP address, request time, host and path, referrer, browser/device signals, response and security or performance signals to deliver and protect the site and prepare aggregate statistics. Web Analytics does not use advertising cookies, localStorage or fingerprinting. To prevent abuse, the API transiently uses the source network address passed through the proxy as a rate-limit key; an address may also occur in an origin security or error record. The regular origin access log stores only time, request ID, method, path without query string, status, response size and duration; it omits client IP, user agent and referrer.
The currently published Fretuno pages do not set Fretuno cookies or write Fretuno data to browser localStorage.
If you email us, we process your address, message, attachments and the correspondence metadata necessary to answer and document the matter. Do not send microphone recordings or unrelated sensitive data.
7. Purposes and legal bases
- Article 6(1)(b) GDPR - create and maintain the pseudonymous API session, deliver lessons, verify entitlement, provide export/deletion and perform the user agreement.
- Article 6(1)(c) GDPR - comply with accounting, tax, consumer, regulatory and lawful-authority obligations.
- Article 6(1)(f) GDPR - secure the service, prevent abuse, diagnose faults, establish or defend claims, prepare operational subscription reports and obtain aggregate, cookieless website statistics. These interests are balanced against users’ rights.
- Consent is not currently used for advertising, newsletters or optional app analytics. If such a feature is introduced, the policy and the relevant consent controls will be updated first.
8. Recipients and processors
Data is disclosed only as needed to: Contabo GmbH (EU server and infrastructure); Cloudflare, Inc. (proxy, security and Web Analytics); RevenueCat, Inc. (subscription entitlement and purchase history); Google, including Google Play (store, payment and subscription management); the provider operating the [email protected] mailbox; professional advisers and public authorities where legally required. Providers may not use processor data for their own unrelated advertising.
9. Transfers outside the EEA
Cloudflare, RevenueCat and Google may process data outside the EEA, including in the United States. Where an adequacy decision does not apply, transfers are based on the European Commission’s Standard Contractual Clauses and appropriate supplementary safeguards. Their own-controller processing is also governed by their published privacy information. A copy or explanation of the relevant safeguards may be requested at the contact address.
10. Retention
- API sessions: 30 days after expiry or revocation.
- Pseudonymous UUID and subscription projection: 400 days after last activity, unless a subscription is active or the record is needed for a dispute or legal duty.
- RevenueCat webhook receipts: 180 days.
- Origin access and security logs: 30 days.
- Rolling PostgreSQL backups: 14 days; deleted data disappears as protected copies expire.
- Cloudflare Web Analytics: raw, unsampled metrics are made available for 7 days; provider dashboard data may remain available for up to 6 months, in accordance with the enabled service.
- Privacy-right and complaint correspondence: 3 years after closure; tax, accounting and dispute records for the period required by law.
- Google Play and RevenueCat apply their own retention to records for which they act independently.
11. Security
Traffic uses HTTPS, production services are separated by internal networks, secrets are mounted separately from application images, tokens are stored only as hashes on the server, endpoints are rate-limited, database ports are not public and backups are access-restricted. No system is risk-free. Please report a suspected incident to the contact email without including secrets or tokens.
12. Your rights
Depending on the circumstances you may request access, a copy, rectification, erasure, restriction, portability and objection to processing based on legitimate interests. You may complain to the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, or to the competent supervisory authority in your EU country. Contact us at [email protected]. We may request proportionate information to verify that a request concerns your pseudonymous record.
13. Automated decisions
Fretuno may adapt exercises locally using training results. It does not make decisions producing legal or similarly significant effects, and it does not build advertising profiles.
14. Changes
We may update this policy when the service, providers or law changes. A new version and effective date will be published here; material changes will be communicated in the app or by another proportionate method before they take effect where required.