Privacy Policy
What we collect, why we collect it, and how to get rid of it.
Last updated: July 23, 2026
ChordGrab turns a YouTube link into guitar chords you can play along to. This policy explains what data that involves. We keep collection to the minimum the product needs, we don't sell your data, and we don't use it to train AI models.
This policy covers the ChordGrab mobile app and the chordgrab.com website. If you have questions, email privacy@chordgrab.com.
1. What we collect
Information you give us
- Email address — used to sign you in (via a one-time code) and to sync your songbook across devices. We do not store a password; there isn't one.
- Profile details — a display name and, optionally, an avatar image you upload.
- Links you submit — the YouTube URLs you paste in to get chords.
- Content you create — songs saved to your songbook, chord corrections you make, and posts, photos, likes and comments in the community feed.
- Support messages — the name, email and message you send through the contact form.
Information collected automatically
- Product analytics — which screens and features get used, and whether a detection succeeded. Tied to a pseudonymous ID, not to your email.
- Crash and error reports — stack traces and device model/OS version when something breaks, so we can fix it.
- Basic web analytics — page views and referrers on this website.
We do not collect your contacts, precise location, photos beyond what you explicitly upload, or your microphone.
2. How we use it
- To detect chords from the links you submit and show you the result
- To sign you in and keep your songbook and profile in sync
- To run the community feed
- To diagnose crashes and understand which features are worth keeping
- To answer your support requests
Legal bases, if you're in the UK/EU: performing our contract with you (accounts, songbook, detection), and our legitimate interests (analytics, crash reporting, abuse prevention). You can object to the analytics processing at any time by emailing us.
3. How chord detection works
This is the part most people want to understand, so plainly: when you paste a link, we fetch the clip's audio from the source platform and analyse it to recognise chords. We then send the analysis result — plus the video title — to an AI model to name the song and tidy up the chord names. We do not upload anything from your device during this process beyond the link itself.
Detection results are cached in our database and shared: if someone else pastes a link you've already analysed, they get the cached result. The cached row records which account first submitted it, but that identity is never shown to other users.
ChordGrab does not host, store or redistribute the source video. We only process its audio transiently to produce a chord chart.
4. Who processes your data
We use a small number of subprocessors. Each only receives what it needs:
| Processor | What it handles |
|---|---|
| Supabase | Database, authentication, and file storage (avatars, post images) |
| Anthropic (Claude) | Naming the song and correcting chord labels. Receives the chord analysis and video title — not your account details. Anthropic does not train on this data. |
| Railway | Hosts the audio-analysis service that processes clip audio |
| PostHog | Product analytics (EU region) |
| Sentry | Crash and error reporting |
| Vercel | Hosts this website and its API routes |
We do not sell personal information, and we do not share it with advertisers. Some of these providers are based in the United States; transfers rely on Standard Contractual Clauses.
5. How long we keep it
- Account and content — kept while your account is active, deleted when you delete your account.
- Analytics — retained for up to 12 months in pseudonymous form.
- Crash reports — retained for up to 90 days.
- Support messages — retained for up to 24 months so we have context if you write in again.
- Cached detections — retained indefinitely, but detached from your account when you delete it (see below).
6. Deleting your account
You can delete your account at any time — from Profile → Delete account in the app, or from the account deletion page on this site. Deletion is permanent and immediate. It removes your profile, songbook, community posts, comments, likes, and uploaded images.
Two things survive deletion in anonymised form: chord corrections and cached detections. These are detached from your account (the link to you is set to null) rather than deleted, because other people's results depend on them. They contain no personal information once detached.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can do most of this yourself in the app; for anything else, email privacy@chordgrab.com and we'll respond within 30 days. You also have the right to complain to your local data protection authority.
8. Children
ChordGrab is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we'll remove it.
9. Security
Data is encrypted in transit (TLS) and at rest. Database access is restricted by row-level security, so one account cannot read another's data. Session tokens are stored in the device keychain. No system is perfectly secure, but we'll notify affected users promptly if a breach ever occurs.
10. Changes to this policy
If we make a material change, we'll update the date at the top of this page and, for significant changes, notify you in the app. Continuing to use ChordGrab after a change means you accept the updated policy.
11. Contact
Privacy questions: privacy@chordgrab.com
Everything else: support@chordgrab.com or the contact form.
