Privacy Policy
Effective: August 7, 2026
Tap Five, LLC (“Tap Five”, “we”, “us”) makes Subdivide, an iOS app for musicians: a metronome, multi-section click tracks, a chromatic tuner, and audio cue tracks. This policy explains, in plain English, what data the app and our servers handle, and what we don’t do with it.
If something here is unclear, email us at privacy@tapfive.dev.
TL;DR
- The app has no accounts. No email, no password, no Apple ID. Nothing you do in the app is tied to a name we hold. The website has an optional email newsletter; that is the only email address we hold, and only if you sign up.
- Your work stays on your iPhone. Tracks, presets, cue point tracks, and any audio you import live on your device, and sync through your own iCloud account if you have iCloud on. In normal use, none of it passes through our servers; sharing is the one exception, described next.
- Your music reaches our servers only when you share it. Sharing a track or an audio cue track uploads that track so the person you send the link to can open it. Nothing else in the app is uploaded to us.
- The tuner never records you. Microphone audio is analyzed on your device and never saved or sent anywhere.
- No ads, no cross-app tracking. The only third-party SDKs are usage analytics (TelemetryDeck, on by default, opt out anytime in Settings) and crash reporting (Sentry). Neither receives your tracks or your audio, and we don’t sell or share your data.
- Shared links expire. A shared track, and any audio uploaded with it, is deleted 30 days after the last time anyone opens the link.
- Purchases are Apple’s, not ours. Subdivide Pro is handled entirely by Apple’s App Store. We never receive your receipt, your payment details, or your Apple ID.
1. Who we are
Subdivide is built and operated by Tap Five, LLC, a US company. For any privacy question or request, reach us at privacy@tapfive.dev. Postal correspondence is available on request.
2. What stays on your device
Almost everything. The following is stored locally on your iPhone and, if you have iCloud enabled, synced through your own iCloud account using Apple’s CloudKit. It goes from your device to Apple and back to your other devices without passing through our servers, and Apple gives app developers no way to read the contents of a user’s private iCloud database. Sharing is separate, and is covered in Section 3.
- Tracks, sections, transitions, drill pages, count-offs, and presets, including every label you type.
- Audio cue tracks: the audio file you imported, its filename, and your cue point labels, timestamps, and colors.
- Metronome settings, sound profile choice, tuner preferences, theme and accent color.
- Your practice stats (beats played, seconds of track and cue playback), which sync between your devices through Apple’s iCloud key-value store.
MusicXML import runs entirely on your device. The file is parsed in the app and never uploaded.
3. What reaches our servers
Your music reaches our servers in two situations, both of which you start: when you share a track, and when you open a share link someone sent you. If you do neither, nothing about your music reaches us. Any request to our servers also carries the technical information listed below.
When you share a track
- The labels you’ve given the track and its sections and transitions, plus tempos, subdivisions, time signatures, the accent pattern of each bar, muted beats, bar counts, and drill pages.
- The random identifiers the app generated on your device for the track and each of its parts. They aren’t derived from you or your phone. The track’s identifier is the same each time you share it, which is how re-sharing reuses the same link rather than making a duplicate.
When you share an audio cue track
- The track label, your cue point labels, timestamps, colors and BPMs, the count-off pattern, your repeat and count-off settings, the original filename of the audio, and the track duration.
- The audio file itself, uploaded from your device to our object storage so your recipient can download it. It remains available for the life of the share link — 30 days after the link was last opened (Section 11).
Sent with every request to our servers
- Your app version, so we can return data in a format your version understands.
- Your IP address, which any web request necessarily reveals. We use it to rate-limit abuse. It is not written to our logs in full — the last part is dropped first, so a log line can’t be tied back to one person.
- A short-lived rate-limit key for requests from a web browser, made by hashing your IP address together with three standard browser headers. It exists only as a counter that expires with its time window, and it isn’t stored against anything you shared. Requests from the iOS app aren’t fingerprinted at all.
What we generate
- A short share code — the random string in the link you send.
- Operational logs: one line per request with the method, path, response status, truncated IP address, user agent, and app version, plus diagnostic messages when something on our side fails. We do not log request or response bodies, so your track contents never appear in logs. Our hosting provider holds these, and a copy is forwarded to Better Stack, our log provider, so we can search them when something breaks. Retention for both is in Section 11.
- A count of how many times each share has been opened, kept on the shared track itself and deleted along with it. It tells us whether sharing is working; it records nothing about who opened it.
- A daily internal summary posted to a private staff channel: how many links were created and opened, how many live shares exist, and error counts. It contains no track labels, no share codes, no IP addresses and no user agents — only numbers.
How share links behave
- A share link is unlisted, not secret. Anyone who has the link can open the track until it expires, and can see every label and the audio filename.
- Labels are screened for profanity. Before we store them, track, section, transition and cue point labels are checked against a profanity word list. A match replaces the whole label — a track label becomes “Track” and the others are cleared. Audio filenames are not screened. The filter can miss things, and can occasionally match an innocent label; renaming the track and sharing again produces a corrected link.
- Opening the share screen uploads the track, so the link is ready the moment you send it. For an audio cue track that includes the audio file. If you close the screen without sending the link, the uploaded copy remains until it expires on the normal schedule; you can request earlier deletion under Section 13.
- Re-sharing an identical track reuses the same link rather than creating a second copy.
- A preview image is generated when a link is created, so that pasting the link into a message shows a preview.
4. The tuner and your microphone
Subdivide asks for microphone access for one reason: to detect the pitch you’re playing so the tuner can show it. Audio is analyzed frame by frame on your device. Each short frame is held in memory only long enough to measure its pitch, then released. Nothing is recorded, written to disk, or sent anywhere, not to us and not to a third party. Nothing else in the app uses the microphone, so if you revoke access in iOS Settings, everything except the tuner keeps working.
5. Audio you didn’t record yourself
An audio cue track starts with an audio file you bring in from your device, and a recording can contain other people.
- Responsibility for shared audio rests with the person who shares it. We don’t choose, record, or review the audio; the sharer does. Recording-consent laws vary by jurisdiction, and some require everyone on a recording to agree to it.
- We don’t listen to it. We store the file so your recipient can download it, and delete it 30 days after the link was last opened. We don’t transcribe it, analyze it, index it, identify voices in it, or use it to train anything.
- If you appear on a shared recording and want it removed, email privacy@tapfive.dev with the share link. We will review the request and remove the track and its audio.
- Labels are not screened for personal information. Anything a sharer types into a track or cue point label is visible to everyone who has the link.
6. Analytics and crash reporting
These help us understand which features get used and fix crashes. Neither receives your tracks, your labels, or any audio.
- Usage analytics (TelemetryDeck). Pseudonymous events recording that a feature was used — a screen viewed, playback started, a setting changed — along with small technical details of the action, such as a tempo, a count, or the option chosen. Events describe actions, not content; they never include your tracks, labels, or audio. The SDK attaches technical context to each event automatically: app and build version, iOS version, device model and screen size, language, region and time zone, whether it’s a TestFlight or App Store build, the day and hour of the event, your color scheme, and your accessibility display settings (text size, reduce motion, bold text and similar). It also keeps per-install counters of how often the app is used. Events are attributed to a one-way hash of Apple’s vendor identifier for your device, which iOS resets when you remove all of our apps from that device. It tells us “same install”, not who you are. Per TelemetryDeck’s policy and our agreement with them, they do not store IP addresses, do not track you across other apps or websites, and process data in Germany. Analytics is on by default; you can turn it off anytime in Settings → Analytics.
- Crash and app-hang diagnostics (Sentry). When the app crashes or freezes we receive a diagnostic report: the stack trace, plus device model, iOS version, and app version. We’ve configured Sentry to attach no personally identifiable information, no IP address, and no network or request data. Sentry also records that the app was launched and for how long, so we can tell whether a release is crashing more than the last one. A stack trace can occasionally include a small fragment of in-memory data; we never intentionally send your content. Crash reporting has no opt-out. If we add one, we’ll say so here.
We sometimes run A/B tests, showing different versions of a screen to different installs. Which version you see is decided by a random identifier generated and stored on your device; if analytics is on, that assignment is included with related events so we can compare versions. It is not linked to anything else.
7. Purchases
Subdivide Pro is sold through Apple’s App Store. Apple handles the payment, the receipt, and the subscription; the app checks your entitlement with Apple on your device. Your purchase never touches our servers, and we never see your name, email, payment method, or Apple ID. Apple provides us aggregate sales reporting through App Store Connect, which we can’t use to identify individual buyers.
8. This website
subdivide.app is a static site hosted on Railway, the same provider that runs our backend. We use OpenPanel for site analytics: page views and outgoing link clicks, with basic browser and referrer information. Per OpenPanel’s policy, they set no tracking cookies and store no IP addresses — your IP is used transiently to derive a city-level location and an anonymous visitor identifier, then discarded. We run no advertising or remarketing tags.
If you sign up for our email list, your email address goes to Loops, our email provider. We use it to send occasional product updates and nothing else. We don’t sell or share it, and every email has an unsubscribe link. Unsubscribing removes you from the list; you can also email us and we will remove your email address.
9. Subprocessors
These are the third-party services that help us run Subdivide. Their links go to their own privacy policies.
| Provider | What it does | Data it sees | Region |
|---|---|---|---|
| Apple (policy) | App Store distribution and purchases, iCloud/CloudKit sync | Subscription transactions, and the tracks and audio you sync through your own iCloud | US |
| Railway (policy) | Hosting for subdivide.app and for our backend, plus its database, cache, object storage and server logs | Shared tracks, shared audio files, request logs with truncated IP addresses | US |
| Better Stack (policy) | Operational log storage and search | Request metadata with truncated IP addresses — no track contents, no audio | EU |
| Loops (policy) | Our email newsletter | Your email address, if you sign up for it | US |
| TelemetryDeck (policy) | In-app usage analytics | Pseudonymous app-usage events and basic device/app info — no track contents, no audio, no stored IP | EU (Germany) |
| Sentry (policy) | Crash and app-hang diagnostics | Stack traces, app-launch and session information, device model, iOS/app version — no content, no stored IP | US |
| OpenPanel (policy) | Website analytics for subdivide.app | Page views and link clicks — no cookies, no stored IP | EU (Sweden) |
We’ll update this list before adding or replacing a provider that handles your content.
10. What we don’t do
- No advertising IDs, no IDFA, no ad networks, no advertising profiles. Subdivide never shows you an ad.
- No cross-app or cross-site tracking. We use usage analytics and crash reporting (Section 6), and neither is used to follow you anywhere else.
- No collection, by the app, of your Apple ID, name, email address, phone number, contacts, photos, calendar, or location. The only email address we ever hold is one you type into the newsletter form on our website.
- No recording, storing, or transmitting of microphone audio (Section 4).
- No biometrics. We don’t create voiceprints, don’t identify anyone by voice, and don’t derive any biometric identifier from the tuner’s microphone input or from audio you import — including as those terms are defined by the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and the CCPA.
- No sensitive personal information as the CPRA defines it — no government identifiers, no precise geolocation, no genetic or biometric data, and none of the statute’s other categories.
- No sale of personal information. No sharing for cross-context behavioral advertising (CCPA/CPRA “sharing”).
- No automated decision-making that produces legal effects or similarly significant effects on you, as described in GDPR Article 22.
11. Retention
| What | How long |
|---|---|
| Shared tracks and audio cue tracks | Deleted 30 days after the last time the link was opened. Opening a link resets its 30-day clock, at most once an hour, so a link in active use keeps working. Shared audio files are deleted from object storage at the same time. |
| Audio uploads that never completed | Removed by a daily sweep, and in any case on the 30-day schedule above. |
| Operational logs (with the IP address truncated) | Two copies, both deleted automatically: 3 days at Better Stack, where we search them, and 30 days at our hosting provider, which produces them. We keep no archive of our own beyond those. |
| Daily summary counters | Reset each day once the summary is sent. The summary is counts only and stays in our staff chat history. |
| Rate-limit counters | One hour, or 24 hours for share creation from a browser, then they expire automatically. |
| Web session tokens | Unusable after 10 minutes; the record is removed by an hourly cleanup job, so up to about 70 minutes. |
| Newsletter subscribers (Loops) | Until you unsubscribe, or ask us to remove you. |
| Copies in your own iCloud | Held by Apple under your iCloud account, not by us, until you delete them from iCloud. |
| Usage analytics (TelemetryDeck) | Retained by TelemetryDeck per their policy (linked in Section 9); pseudonymous events, never your content. |
| Crash & hang diagnostics (Sentry) | Retained by Sentry per their policy (linked in Section 9); their standard retention is 90 days, then deleted. |
If you ask us to delete a shared track sooner, we will (see Section 13).
12. Security
- All traffic between the app and our servers uses HTTPS (TLS).
- Data at rest is encrypted by our hosting provider.
- Audio uploads and downloads use short-lived, single-purpose signed URLs rather than public buckets.
- Share codes are generated with a cryptographically secure random number generator and validated for format before any lookup happens.
- Requests to create and to open shares are rate-limited, which makes it impractical to discover share links by guessing at volume.
- Credentials for our storage and database live on our backend only and are never sent to the app.
If we discover a breach affecting personal data, we’ll notify the relevant supervisory authority within 72 hours of becoming aware of it where the GDPR or UK GDPR requires it, and notify affected people without undue delay where the breach is likely to result in a high risk to their rights, or where US state law requires it. We hold no email addresses for app users, so individual notice by email is not possible; notice would be posted on subdivide.app, in the app, and on the page a share link resolves to if shared tracks were involved.
13. Your rights
We hold no account and no name for you, and no email address unless you signed up for our newsletter. What we do hold is whatever you shared, found by its share code, plus request logs containing a truncated form of your IP address.
You can ask us to:
- Delete a shared track or audio cue track. Send us the share link or the code from it and we’ll remove the track and any uploaded audio.
- Tell you what we hold for a given share code, or send you a copy of it.
- Correct anything inaccurate.
- Object to or limit specific processing, or withdraw consent you previously gave. Some processing can’t be separated from running the service — crash reporting, for example — and where that’s the case we’ll say so.
For analytics, you don’t need to email us. Turning off “Send usage data” in Settings → Analytics stops collection on that device. To delete everything the app holds about you, delete the app; to also remove the iCloud copy, delete it from iCloud in iOS Settings.
To exercise a right, email privacy@tapfive.dev. We respond within 30 days. We won’t refuse service or charge you for making a request.
If we say no, you can appeal. If we decline a request we’ll tell you why in writing. You can appeal by replying to that response, or by emailing privacy@tapfive.dev with “Appeal” in the subject line. We’ll review it and respond in writing with our decision and reasoning within 45 days. This right is required for residents of Virginia, Colorado, Connecticut, Texas, Montana, Oregon and a number of other states, and we extend it to everyone.
Authorized agents. Someone else can submit a request on your behalf, using the same email address and process. We hold no identity information about anyone, so an agent’s request is handled exactly like a direct one, keyed to whatever identifies the data — a share code, or a newsletter email address.
California (CCPA/CPRA). You have the rights to know, access, delete, correct and port your personal information, to opt out of its sale or sharing, and not to be discriminated against for exercising any of them. We do not sell personal information and we do not share it for cross-context behavioral advertising, and we haven’t in the preceding twelve months. We don’t collect sensitive personal information as § 1798.140(ae) defines it, so the right to limit its use doesn’t arise. We don’t knowingly sell or share the personal information of anyone under 16.
| Category | What, specifically | Source | Why |
|---|---|---|---|
| Identifiers | IP address; app version; the identifier your device generated for a track; a short-lived rate-limit key; an email address if you joined the newsletter; a pseudonymous device hash if analytics is on | Your device, when it contacts us; you, for the newsletter | Delivering the share you asked for; limiting abuse; counting installs |
| Internet or network activity | Request metadata (method, path, status, user agent); pseudonymous in-app usage events | Your device | Operating and debugging the service; understanding feature use |
| Audio, electronic, visual, or similar information | The audio file you chose to upload with a cue track; the labels you’ve given the track and its parts; the original filename of your audio | You, when you share | Letting your recipient open the track as you built it |
How long we keep each of these is in Section 11, and the third parties we disclose them to for business purposes are listed in Section 9. We use them for the purposes stated and for nothing else.
Do Not Sell or Share. We don’t sell or share personal information, so there is no opt-out link to provide and nothing for a Global Privacy Control signal to opt you out of. If that ever changes we’ll add the link, honor GPC, and update this policy first.
EU/EEA, UK, Switzerland (GDPR/UK GDPR). Here is the legal basis for each thing we do:
| What we do | Legal basis |
|---|---|
| Create a share link and serve the shared track to whoever opens it | Article 6(1)(b) — performing the service you asked for by tapping Share |
| Store audio you upload with a cue track, including anyone else audible on it | Article 6(1)(f) — our legitimate interest, and yours, in delivering the share you requested. We’ve weighed this against the interests of anyone else on the recording; see Section 5 |
| Log requests and rate-limit them | Article 6(1)(f) — keeping the service available and resisting abuse, which Recital 49 recognises as a legitimate interest |
| Screen labels against a profanity list | Article 6(1)(f) — not serving offensive content to the people who open share links |
| Send you the newsletter | Article 6(1)(a) — your consent, given by signing up and withdrawn by unsubscribing |
| Crash and hang diagnostics | Article 6(1)(f) — our legitimate interest in a stable app. The reports contain no account data and nothing we can attribute to you |
Your right to object. You have the right to object at any time, on grounds relating to your particular situation, to any processing we base on legitimate interests. Email privacy@tapfive.dev and tell us what you’d like us to stop. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims.
You can lodge a complaint with your national supervisory authority; a list of EEA authorities is at edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK that’s the Information Commissioner’s Office (ico.org.uk); in Switzerland, the FDPIC (edoeb.admin.ch).
Other US states: If your state grants additional rights (Virginia, Colorado, Connecticut, Utah, Texas, and similar), we honor equivalent requests through the same email above.
14. Children
Subdivide is not directed at children under 13 (US), or under the local digital-consent age in the EEA and UK (between 13 and 16). The app has no account, and no feature in it asks anyone for a name, an email address, or any other contact information. The newsletter form is on our website, not in the app.
Two things do reach us that US children’s privacy law treats as personal information because they are persistent identifiers: your IP address, which reaches our servers when you share or open a shared track and is truncated before logging, and a one-way hash of your device’s vendor identifier, which is sent with usage analytics if analytics is on. We use neither to contact anyone, to build a profile of an individual, or for advertising.
If we learn we’ve collected personal information from a child without verifiable parental consent, we delete it promptly. If a child shared a track and you’d like it removed, send us the link at privacy@tapfive.dev and we’ll delete it.
15. International transfers
Our backend runs in the United States. If you share a track from the EEA, UK, or Switzerland, that track is transferred to the US to be stored and served. Operational logs (request metadata only, with the IP address truncated) are stored by Better Stack in the European Union. In-app usage analytics (TelemetryDeck) are processed in Germany and website analytics (OpenPanel) in Sweden; crash diagnostics (Sentry) and our email list (Loops) are processed in the United States. The subprocessors we use offer GDPR-compliant transfer mechanisms in their data processing agreements, such as Standard Contractual Clauses or EU-US Data Privacy Framework certification. To confirm the safeguards for a particular provider, contact us.
16. Changes
We may update this policy as the app evolves. Changes take effect when posted here, and the date at the top reflects the current version. Where a change requires your consent under applicable law, we’ll ask before applying it to your data.
17. Contact
Tap Five, LLC
Privacy requests and questions: privacy@tapfive.dev