```
# Privacy Policy — Music Diary
**Last updated:** August 4, 2026
**Document version:** 1.6
**Developer:** Sergei Nenashev
**Contact:** snenashev@gmail.com
> This is the English version of the policy. The Russian original is available at
> [privacy.md](privacy.md); both describe the same practices.
---
Music Diary is an Android app that helps musicians track their practice: pieces, exercises, fragments, tempo, and session length. This document explains what data the app processes, why, and how you can control it.
## 1. What is stored locally on your device
All data about your practice is stored **only on your device**, in the app's protected folder, and is accessible only to you. The diary itself is never sent anywhere: the only case in which this data leaves your device is if **you yourself** create a backup to a destination you choose (see section 7). The contents of your diary are never shared with the ad network or with the install-attribution service (see sections 2 and 3).
This includes:
- the list of pieces and exercises, including titles, composers, key, tuning, target tempos, and notes;
- fragments of pieces and exercises, measure ranges, and numbering;
- practice session history: duration, selected blocks, BPM changes, mood, and notes;
- photos of scores that you take inside the app or import from your gallery;
- arbitrary files (PDF, MP3, images, Guitar Pro `.gp/.gp3-7/.gpx`) that you attach to pieces, exercises, or fragments;
- external links that you attach to pieces, exercises, or fragments;
- app settings (theme, BPM step, default tuning, and so on).
Uninstalling the app automatically deletes all of this data.
## 2. Advertising
Starting with version 0.5.0, the app **shows ads**. Ads are served by the **Yandex Advertising Network (YAN)** through the Yandex Mobile Ads SDK bundled into the app.
**Where ads appear:** on the History screen (inline in the list) and on the session summary screen. There are no ads during an active practice session or in the create/edit forms.
**What the ad network receives.** To select and display ads, the Yandex SDK contacts Yandex servers and transmits technical data:
- the **device advertising identifier** (Google Advertising ID);
- IP address — from it the recipient, like any server on the internet, can approximately determine the country and city; precise location is not transmitted, and the app requests no permission to access it;
- technical information about the device and app (model, OS version, language, screen parameters, app version);
- information about ad impressions, clicks, and loading errors.
**What is NOT sent to the ad network:** the contents of your diary — pieces, exercises, fragments, notes, session history, tempos, photos, and attached files. That data stays on your device (see section 1) and is never sent to the ad network.
**Consent and control.** On first launch the app asks for your consent to **personalized** advertising; the same choice governs install attribution (section 3), which the request itself states explicitly. The request is shown once: right after the intro tour, or — if the tour does not run (for example, you updated from an earlier version and had already taken it) — on the very first screen. Your answer is remembered — a refusal included — and the same question is not asked again. **The exception is a material change in what is collected:** if a new data recipient, a new purpose, or a new transmitted parameter appears, the text of the request is updated and consent is asked again — of everyone, including those who refused before. Until you answer the new text the new purpose does not operate, and your earlier choice keeps applying only to what you had already been asked about. That is exactly what happened with install attribution (section 3): consent given in version 0.5.0 to a question about advertising alone does not count for the tracker, so after updating the request appears once more — including for those who declined back then. Your choice is passed to the SDK. You can change it at any time: `Settings → Personalized ads`. If personalization is off, ads are still shown but are selected without using an advertising profile. **Ads cannot be switched off entirely in the current version.**
You can reset or delete your advertising identifier through the system: `Android Settings → Privacy → Ads`.
Yandex's processing of this data is governed by its own documents: .
The app uses no other ad networks. For the install-attribution service, see section 3.
## 3. Install attribution (MyTracker)
The app includes **MyTracker**, an install-attribution service operated by **VK** (my.com). It solves exactly one problem: it tells the developer which ad brought a user in, so it is clear which advertising campaign pays off and which does not. It is **not** analytics of your behaviour inside the app: MyTracker does not receive which screens you open, what you tap, or what you write in your diary.
**What is sent to MyTracker:**
- **resettable device identifiers** — the Google Advertising ID (GAID) and the App Set ID;
- **the install referrer** — the install-source tag that Google Play hands to the app after installation; this is what encodes which ad the user came from;
- **app launch events and session length** — how many times the app was opened and how long it was on screen; without screen contents and without in-app actions;
- **IP address** — transmitted by the very fact of a network request;
- **technical information about the device and app** — model, OS version, language, screen parameters, app version;
- **battery level and readings from a few sensors** (gyroscope, magnetometer, barometer) — MyTracker uses them as signs of a real device, to detect fraudulent installs;
- **an install identifier** — a random UUID generated on your device when the tracker first starts, kept until the app is uninstalled.
**What is NOT sent to MyTracker:** the contents of your diary — pieces, exercises, fragments, notes, session history, tempos, mood, photos, and attached files. All of it stays on your device (see section 1). Your location coordinates are not sent: geodata collection is explicitly disabled in the tracker's configuration, and the app requests no location permissions at all — so the system gives the tracker neither coordinates nor information about Wi-Fi networks and cell towers. **A clarification for accuracy:** from the IP address, which is transmitted by the very fact of a network request (it is in the list above), the recipient can approximately — at the level of country and city — determine where the request came from. This is not device geolocation and not a separately collected field, but Google Play rules require such approximate location to be disclosed on a par with real location, and we disclose it — both here and in the Data Safety form. Collection of device-environment data (those same Wi-Fi networks and cell towers) is disabled in the tracker's configuration by a separate switch, independently of permissions. Purchase tracking is likewise disabled (there are no in-app purchases, and the corresponding module is excluded from the build), as is the preinstall check.
**Consent and control.** MyTracker is governed by the **same** switch as ad personalization: `Settings → Personalized ads` (section 2). Specifically:
- while you **have not answered** the consent request — the tracker does not start and sends nothing;
- if you **declined** — the tracker does not start and sends nothing;
- if you **agreed** — the tracker starts and begins transmitting the data listed above;
- if you agreed **in version 0.5.0**, where the question was about advertising alone — the tracker does **not** start, even with the switch on, until you answer the updated request (see section 2).
A refusal is not final, but neither does it undo itself: while the switch is off, the tracker never comes up, on any app launch. If you later turn `Settings → Personalized ads` on **yourself** — having already answered the updated request — the tracker starts — and, unlike withdrawal (see below), that takes effect at once, without waiting for an app restart.
**A limitation we state honestly.** The bundled SDK version (MyTracker 3.6.0) offers no programmatic way to stop a tracker that has already started — it has no consent-revocation API. So if you withdraw consent **after** the tracker has started, collection stops not immediately but **from the next app launch**: on startup the app re-checks your choice and the tracker simply never comes up. This limitation does not apply to advertising — personalization there is switched off at once.
You can reset or delete your advertising identifier through the system: `Android Settings → Privacy → Ads`.
MyTracker's processing of this data is governed by its own documents: . In the terms of those documents MyTracker acts as a data processor and the app developer as the data controller.
The app connects no other standalone analytics systems or trackers: there is no analytics of your behaviour inside the app, and no data goes to any analytics service beyond those named in sections 2 and 3.
**A clarification for accuracy.** The Yandex Mobile Ads SDK (section 2) brings with it its own internal component, **AppMetrica** — it ships inside that ad SDK and serves the SDK's own operation (ad delivery, impression and ad-revenue accounting, diagnostics). It is not a service separate from the ad network, and it is not analytics of your practice: the app sets up no AppMetrica key of its own, writes no events into it, and sends it nothing about your diary. The technical data it handles is the same data listed in section 2 and falls under the same processing on Yandex's side.
## 4. Offline processing of attached files
Viewing and playing Guitar Pro tablature is implemented with the bundled open-source library **AlphaTab** (MPL-2.0). File parsing, notation/tablature rendering, and synthesizer audio all happen **locally on your device**; your `.gp` files are not sent to AlphaTab's servers or to any other service. All notation, fonts, and the bundled SoundFont ship with the app.
## 5. Donations
The home screen has a "Support the developer" button that opens the [CloudTips](https://pay.cloudtips.ru/p/7a26a718) page in an external browser or mobile app. Any donation transactions happen **entirely on CloudTips' side**; the app receives no information about the fact, amount, or status of a payment. CloudTips terms: .
## 6. Permissions the app requests
| Permission | Purpose |
|---|---|
| `POST_NOTIFICATIONS` (Android 13+) | Showing the active session status in the notification shade so the timer is not lost. |
| `FOREGROUND_SERVICE` / `FOREGROUND_SERVICE_SPECIAL_USE` | Keeps the session timer running while the app is minimized. |
| `WAKE_LOCK` | Keeps the screen awake during active practice (if enabled in settings). |
| Camera (requested on demand) | Photographing a score — only when you tap "Take photo" yourself. |
| Gallery and files (`PickVisualMedia`, `OpenDocument`) | Importing photos and attaching files — only at the moment you choose them. |
| `android.hardware.usb.host` (optional) | Sending MIDI Clock to a connected pedal/looper to synchronize tempo. |
| `INTERNET`, `ACCESS_NETWORK_STATE` | Loading ads (section 2), sending install-attribution data (section 3), and uploading backups to the storage you choose (section 7). |
| `com.google.android.gms.permission.AD_ID` | Access to the advertising identifier — for showing ads (section 2) and for install attribution (section 3). Added by the ad SDK; the attribution SDK requires the same permission and adds no new ones. |
| `RECEIVE_BOOT_COMPLETED` | Restoring the automatic backup schedule after the device restarts. |
## 7. Storage, backups, and data sharing
- Local data is stored on the device until you delete it manually or uninstall the app.
- **Backups.** On your command (or on a schedule, if you enable one) the app can save a full backup — database, photos, and attached files — to a location **you** choose: a folder on your device or in the cloud via the system folder picker, or a WebDAV server whose address and credentials you provide. The data goes **only where you send it**; the developer has no access to that storage and receives no copies. WebDAV credentials are stored encrypted on your device. Scheduled automatic backups can be turned off in settings.
- **Sharing with third parties.** Apart from the ad network (section 2 — technical data and the advertising identifier), the MyTracker install-attribution service (section 3 — only with your consent), and the backup storage you choose yourself, the app shares your data with no one. The contents of your diary are never sent to the developer and are not stored on the developer's servers — the app has no backend.
## 8. Your rights
You can at any time:
- **Export your data** — `Settings → Export JSON` saves all your local records to a file.
- **Delete your data** — uninstalling the app removes all local app data from your device.
- **Ask questions** — write to the developer at snenashev@gmail.com. Response within 30 days.
For users in the Russian Federation, these rights are provided in accordance with Federal Law No. 152-FZ "On Personal Data".
## 9. Changes to this policy
Material changes to this policy will be reflected in an app update, with the document version bumped in the header and in `Settings → Privacy → Privacy Policy`.
If the change is material — a new data recipient, a new purpose, or a new transmitted parameter appears — the document version is not the end of it: we **ask for consent again**. The text of the request is updated, answers given to the previous text no longer count for the new purpose, and until you answer, the new purpose does not operate (see section 2 for details). The rule also works the other way round: rewording alone, with no change to what is collected, does **not** trigger a new request — we do not think it right to interrupt you with a dialog when nothing has changed for you.
The current version is always available:
- inside the app (Account → Privacy Policy);
- at the permanent link: .
## 10. Contact
**Developer:** Sergei Nenashev
**E-mail for requests:** snenashev@gmail.com
**Response time:** up to 30 business days.
```