1. What we collect
The complete list of personal data Guitar Buddha collects, across the website and the app:
- Standard server logs — when you visit this website, our host (Cloudflare) logs the request: IP address, user agent, requested URL, timestamp. These logs are retained by Cloudflare per their own policy and used only for security and abuse prevention. We do not access them for analytics.
- Website tip-jar payments — if you send a tip through this website (not the app), your email address, name, and card/billing details are collected by Stripe, our payment processor, to complete the charge. We never see or store your card number ourselves. See In-app & website purchases and Third parties.
- Pseudonymous app analytics — only if you opt in inside the app (off by default). Product-interaction events tagged with a random ID generated for your install, plus standard device context (app version, device model, OS, screen size, locale, timezone, network type) — never your songs, audio, notes, or anything that identifies you personally. See The app.
- Android launch notifications — if you choose to leave your email on the one-email signup, it's stored on a server we run (Cloudflare) and used for exactly one thing — that notification. Email hello@guitar-buddha.com any time to be removed.
That's the whole list.
2. What we don't collect
To be explicit:
- We don't have user accounts. We don't know who you are.
- On this website, we don't use Google Analytics, Mixpanel, Segment, Amplitude, or any analytics service. In the app, analytics are off by default; if you turn them on, they're pseudonymous, not tied to your identity (see The app).
- We don't have advertising trackers, conversion pixels, or third-party cookies.
- We don't collect your songs, takes, lyrics, chord charts, ideas, or any audio you record — ever, opted in or not.
- We never know what songs you've added or what you actually play. (If you opt in to analytics, we see which screens and tools get used, tagged to a random per-install ID — never their contents.)
- We don't have a "feedback" or "crash report" auto-uploader. Bug reports happen only if you choose to email us.
3. The website (this page)
This site is hosted on Cloudflare Workers. Cloudflare receives standard HTTP request logs when you visit. Those logs are governed by Cloudflare's privacy policy.
The site loads fonts from local files only — no external font CDN is contacted, and simply reading a page never contacts a third party. The one exception: if you use the tip jar on the Support page, clicking a tip amount takes your browser to checkout.stripe.com to complete the payment — see In-app & website purchases.
We do not set any analytics or marketing cookies. The only client-side storage we use is a single localStorage entry (gb-theme) that remembers your chosen visual theme. Nothing about you is in that value — just "strata", "terra", "obsidian", or "sand".
4. The app
The Guitar Buddha app is local-first. This means:
- All your songs, takes (audio recordings), ideas, settings, and library data are stored in the app's local sandbox on your device.
- None of this data is synced to a server. There is no Guitar Buddha server.
- The app does not require an account, login, or internet connection to function.
- Songs come from a built-in catalog, anything you type in yourself, or — on iPhone and iPad — chord sheets you scan with the camera (processed entirely on-device; on Mac, chord sheets are pasted in instead). The app does not contact any server to look up songs, lyrics, or chords.
- Optional analytics are off by default. If you turn them on (Settings → Privacy → "Help improve Guitar Buddha"), the app sends pseudonymous usage events — which screens and tools you open — to PostHog (US Cloud). Each event carries a random ID generated for your install (not for you) plus standard device context: app version, device model, OS, screen size, locale, timezone, network type. No accounts, no session recording, no name or email, and never your songs, audio, notes, or lyrics. Leave analytics off and none of this is sent. Separately, and regardless of this setting, the iOS and iPadOS app periodically asks the App Store whether a newer version has shipped — that request carries only the app's bundle ID and your store region. (The Mac app doesn't perform this check; it relies on the Mac App Store's own automatic-update mechanism.)
- Audio you record stays in app storage. It is not uploaded anywhere. You can export takes as audio files to share them yourself.
- On iPhone and iPad, deleting the app deletes all of its data automatically — that's how iOS's uninstall process works. On Mac, dragging the app to the Trash does not delete its stored data: your songs, takes, and settings remain in your user Library folder until you remove them yourself.
5. In-app & website purchases
Guitar Buddha is free. There are two separate, optional ways to tip:
In the app — three consumable in-app purchases ($0.99, $4.99, $9.99), processed entirely by Apple's App Store (iOS, iPadOS & Mac App Store alike; Google Play once the Android app ships). We never see your payment method, card number, name, or billing address for these. Apple and Google share with us only aggregate, anonymized transaction counts so we can see how much support comes in. Their handling of your purchase data is governed by their own privacy policies, not ours.
On this website (the Support page) — three one-time tip amounts ($3, $5, $10), processed by Stripe. Unlike the in-app tips, Stripe does share the tipper's email, name, and billing details with us so we know who to thank and can issue a refund if you ask. Your card number is handled entirely by Stripe and never touches our servers. See Third parties.
6. Third parties
The third parties involved in operating Guitar Buddha:
- Cloudflare — hosts this website. Cloudflare privacy policy.
- Apple App Store (iOS, iPadOS & Mac App Store) & Google Play (when the Android app ships) — distribute the app and handle in-app purchases. Their own privacy policies apply to that interaction.
- Stripe — processes website tip-jar payments (see In-app & website purchases). Stripe receives the tipper's email, name, and card/billing details to complete the charge. Stripe's privacy policy.
- PostHog — product analytics, only if you opt in inside the app (off by default; US Cloud host). No name, email, or account is ever sent. PostHog does generate a random ID for your install so repeat events can be grouped together; it's never linked to your identity. Its SDK also attaches standard context to each event — app version, device model, OS, screen size, locale, timezone, network type. See PostHog's privacy policy.
7. Your rights
Because we collect so little, most data-rights requests resolve quickly:
- Right to access — email us and we'll tell you what we hold. For most people that's nothing. If you've tipped through this website, Stripe holds the payment record with the email and name attached to it. If you left your address for the Android launch notification, we hold that address.
- Right to deletion — ask and we'll delete your Android-notify entry and any email correspondence. Stripe payment records are a different story: Stripe retains those for at least five years from your last transaction (their retention obligation, for tax, accounting, and fraud-prevention purposes — see Stripe's Privacy Center), so we can't delete them early even on request.
- Right to correction — email us with the update.
- Right to portability — your in-app data already lives entirely on your device; you can export takes as standard audio files at any time.
- Right to object — we don't do marketing, profiling, or automated decision-making, so there's nothing to object to. Email us with any concern.
If you are a resident of the EU (GDPR), the UK, California (CCPA/CPRA), or another jurisdiction with formal data-rights laws, these rights apply to you under those laws.
8. Children's privacy
Guitar Buddha is not directed at children under 13, and we do not knowingly collect personal information from children under 13. The app asks for no name, email, or account from anyone. Analytics are off by default; if switched on, the app sends usage events tagged with a random per-install identifier, not a name or account. If you believe a child under 13 has enabled analytics, turn it off in Settings → Privacy and email us — we'll purge the associated events.
9. Changes to this policy
If we change this policy in a material way, we will update the "last updated" date at the top of this page. There is no other notification channel.
10. Contact
Questions, complaints, or data requests:
We aim to respond within 7 days.