Privacy Policy
Version 1.5 · Last updated August 26, 2026
Account data
When you sign in with Apple or Google, we store your name, email, and a pseudonymous account ID so your library and settings stay attached to your account. This is required to use Paginote and is not affected by your analytics consent choice.
Feedback you send us
If you use Help & feedback, we store your name, email, and message, plus your app version, OS version, and device model, so we can read and reply to it. This is sent regardless of your analytics consent choice.
Analytics & crash reports
When you allow analytics, Firebase Analytics and Crashlytics collect:
- A Firebase Installation ID — a pseudonymous device identifier
- App usage events: screens visited, features used, scores opened
- Crash and error reports, to help us fix bugs
- Device metadata: OS version, app version, device model, language
- IP address — used briefly to derive approximate country, then discarded by Google
We never collect your score contents through analytics.
Signing out or deleting your account turns this collection off immediately, until you — or the next account on this device — make a new choice.
Your scores
Your imported PDF files are stored on your device, and a copy also syncs to your own private iCloud account (via CloudKit) so it's available on your other devices — individual files must be under 250 MB. Score details, annotations, and setlists sync the same way. We never upload your files to Paginote's servers and never see their contents: all of this sync happens directly between your device and Apple, and we don't have access to any of it.
Camera & document scanning
If you use the scanner to import printed sheet music, Paginote uses your device's back camera to photograph pages and turn them into a PDF, entirely on your device — the photos themselves are never stored or transmitted, only the resulting PDF becomes part of your score library.
If you enable eye-blink page turning, Paginote uses your device's front camera and Apple's on-device face-tracking (ARKit) to detect blinks during a performance. This processing happens entirely on your device — no image, video, or face data ever leaves it, and none of it is stored or sent to Paginote or anyone else.
Calendar
If you use "Add to Calendar" on a scheduled setlist, Paginote writes that setlist's name, performance date, time, duration, location, and notes as an event into a calendar you choose, using Apple's EventKit framework — entirely on your device.
Paginote never reads, collects, or transmits anything else from your calendar, to us or to anyone else. You can revoke calendar access at any time in iOS Settings → Privacy & Security → Calendars.
Data security
We use encryption to protect your information. Data exchanged with Firebase Authentication and Firestore, and files transferred from the Google Drive or Dropbox APIs, is sent over encrypted (TLS/HTTPS) connections; files you import from iCloud Drive are accessed through Apple's own secure file-provider framework. Data stored in Firebase Authentication and Firestore is encrypted at rest by Google Cloud's infrastructure.
Security procedures are in place to protect the confidentiality of your data: access to the systems where account and feedback data is stored is restricted, and protected by two-factor authentication. Files you choose to import from Google Drive, iCloud Drive, or Dropbox are downloaded directly from those services to your device — they are never uploaded to, or stored on, Paginote's own servers.
Connecting Google Drive or Dropbox opens their sign-in page in your device's shared system browser session rather than a private in-app one, so you don't have to sign in again every time you import. This means Google's or Dropbox's own session cookies may be kept in that shared browser session, under their privacy policies rather than Paginote's — Paginote doesn't access, read, or control that data.
Paginote's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Purpose
This data is used to run your account, respond to feedback, and — where you've allowed it — understand how Paginote is used so we can improve it. It is not sold or shared with third parties for advertising.
Data controller
Thomas Løjmann Jørgensen
thomas@paginote.app
Retention
Google retains raw analytics events for up to 14 months (Firebase Analytics default). Account and feedback data is kept until you delete your account or ask us to remove it.
Your rights
You have the right to:
- Withdraw analytics consent at any time (Profile → Privacy, data & terms of service)
- Delete your account in the app at any time, or ask us to delete your account, feedback, and analytics data
- Access information about what data is held about you
To exercise your rights, contact thomas@paginote.app.