Privacy Policy
1. Introduction
QuickStave ("we", "our", "us") is a browser-based music notation application. This Privacy Policy explains how we collect, use, and protect your personal information when you use our service at quickstave.com and quickstave.app.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your email address, display name, and profile picture (if provided via OAuth sign-in with Google or Facebook). We do not store your OAuth provider password.
2.2 Score Data
Your musical scores are stored in our cloud infrastructure when you are signed in. Scores marked as Private are accessible only to you. Scores marked as Unlisted or Public are accessible to others as described in our Terms of Service and in §6.2 below.
2.3 Usage Data
We use Vercel Analytics to collect anonymous, aggregated usage data (page views, performance metrics). This does not include personally identifiable information and does not use cookies for tracking.
2.4 Payment Information
Payment processing is handled entirely by Stripe. We do not store your credit card number or banking details. We receive only a reference to your Stripe customer record.
3. How We Use Your Information
- To provide and maintain the QuickStave service
- To sync your scores across devices
- To process subscription payments
- To send transactional emails (magic links, account notifications)
- To respond to support requests
We do not sell your personal information. We do not send marketing emails unless you explicitly opt in.
4. Data Storage & Security
Your data is stored on secure infrastructure (Fly.io for application servers, PostgreSQL for relational data, Cloudflare R2 for file storage). All data is transmitted over HTTPS. Access to production systems is restricted to authorised personnel.
5. Third-Party Services
We share data with the following services only as necessary:
- Google / Facebook — OAuth authentication
- Stripe — payment processing
- Resend — transactional email
- Vercel — website hosting and anonymous analytics
- Cloudflare — CDN and file storage
- Fly.io — API server and database hosting
The full list, including what each provider handles and where, is on our sub-processors page. Note that music scanning uses no third party at all — it runs entirely in your browser, and the sheet music you scan is never uploaded.
6. Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Delete your account and all associated data directly from the app
- Receive a copy of your scores in a structured, machine-readable format — free of charge, on any plan
- Withdraw consent for optional data processing
You can delete your account from Edit Profile within the app. For other requests, contact us at [email protected].
6.1 Requesting a copy of your data
Email [email protected] from the address on your account and ask for a copy of your data. We will send you your scores as MusicXML files, together with the account details we hold, within 30 days and at no cost. This applies on every plan, including Free, and after a subscription has ended.
This is separate from the in-app export tool. The export button inside the editor — which saves a score directly to MusicXML, MXL or MIDI whenever you want it — is a convenience feature included with Pro. Your right to obtain a copy of your own work is free and always available, regardless of plan.
6.2 Who can see your scores
Scores you keep Private are visible only to you. Scores you set to Unlisted or Public are reachable by anyone holding the link, which is the point of those settings.
As the people who operate the service, we are technically able to access stored scores. As a matter of policy we do so only to operate and troubleshoot the service, to provide support you have asked us for, or where the law requires it. We do not read your scores for product research, analytics, or marketing, and we do not use your scores to train machine-learning models.
7. Data Retention
We retain your account data for as long as your account is active. When you delete your account, your personal data, scores, and storage objects are permanently removed from our live systems straight away. Anonymised, aggregated analytics data may be retained indefinitely.
Two things outlive that deletion, and we would rather say so than claim otherwise:
- Database backups. Our database is backed up automatically each day and those backups are kept for a short rolling period before being overwritten. Deleted data therefore persists in backups for a few days after deletion. We do not restore backups in order to recover deleted accounts.
- Payment and accounting records. If you have ever bought anything, the record of that transaction is held by our payment processor and retained for as long as accounting and tax law requires, which in Norway is currently five years. This is a legal obligation and is not affected by deleting your account. It covers the transaction — not your scores.
If you own a Team, you will need to dissolve it or hand it over to another member before you can delete your account. Deleting it outright would remove the team from everyone else on it.
8. Children's Privacy
QuickStave is not directed at children under 13. If you are a school or educator using QuickStave's Team plan for students, you are responsible for obtaining any required parental consent.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we post the new policy on this page, raise the version number and effective date shown at the top, and list what changed on our change history page.
For material changes we do not rely on you noticing. The next time you sign in, QuickStave asks you to read and accept the new version before you carry on.
10. Contact
For privacy-related questions, contact us at [email protected].
Questions about this document? [email protected]. See also our Terms of Service, Acceptable Use Policy, Refund & Cancellation Policy, Copyright & Takedown Policy, Sub-processors, and Privacy Policy.