1. Home
  2. Legal
  3. IQuantize Privacy Policy

IQuantize Privacy Policy

This document covers the iQuantize app and its sync backend. If you are just browsing this website, see the Website Privacy Policy and the Website Terms of Use.

Last updated: September 13, 2026

This Privacy Policy explains how IQuantize collects, uses, stores, and deletes information when you use the IQuantize app and related backend services. The app and its backend services are provided by Relato Garrido - Unipessoal Lda ("IQuantize"), VAT PT516683152, Rua das Palmeiras, Lote 5, 244, Quinta da Marinha, 2750-005 Cascais, Lisboa, Portugal, which is the controller responsible for the processing described in this policy. If the student is under the age of majority, a parent or guardian should review this policy and accept the startup agreement for the student.

1. When Sync Starts

The app shows a startup agreement with links to the EULA and this Privacy Policy before account-backed sync begins. The app does not register, fetch a server token, or upload synced rows until the agreement is accepted.

After acceptance, the app creates a guest account-backed sync identity and sync runs automatically when a network connection is available. No name, email address, username, or password is required for guest sync. A name and email address are required to start a website-billed Pro subscription. Email verification is optional for the initial Stripe Checkout and is required to create or join the durable web account used for browser access and recovery across installations. Practice data is stored locally first. Core local practice features remain available without a network connection, while sync, remote content, account verification, deletion confirmation, and cross-installation entitlement continuity require connectivity. Queued changes sync later.

2. Information We Collect

We collect information needed to operate the app, keep progress consistent, support teacher/student features, diagnose problems, and improve the learning experience.

Account and Installation Data

We collect backend user IDs, public codes, installation IDs, setup IDs, local database IDs, profile type, optional display name, platform, app version, build number, operating system version, coarse device model, legal-policy acceptance version, registration status, and timestamps. When you start website billing or request account recovery, the app stores the name and email address you entered locally and sends them with the authenticated request. The backend stores the unverified name and normalized email as a pending account claim so it can deliver confirmation, support resend or correction, and recover an eligible paid purchase after reinstall. A pending claim does not by itself create account membership or grant Pro. After verification and same-installation completion, we store the name and verified email address, account and installation membership IDs, and verification timestamps. We also store bounded linked-installation metadata, such as platform, coarse device model, app version, and last-seen time, so the account holder can identify, unlink, or revoke an installation. Personal Pro allows up to three active installations and up to five counted new-installation links in a rolling 30-day period. The first account installation is not counted as a new link. We record successful links, removals, revocations, limit denials, and audited support-recovery overrides so we can enforce those limits, notify the account holder, and review suspicious device churn. We retain first-seen and last-seen app-version history per installation and use local database IDs to identify reinstall or database-recreation attempts without hardware fingerprinting.

For first-party product analytics, the app also creates a random app-device ID independently of the installation and local database IDs. It stores this value in nonsynchronizing Keychain storage (device-only on iOS and the user Keychain on macOS) and sends it with registration and authenticated device metadata after the startup agreement is accepted. It helps us count active devices and distinguish repeated installations from additional devices. It is not derived from hardware, an Apple Account, IP address, or device fingerprint, and cannot sign you in or recover an account. Recreating the app database or reinstalling can preserve the value while that Keychain item survives; clearing the item changes it. On macOS it is scoped to the operating-system user, so it is not a guaranteed count of physical computers. A macOS backup, migration, or clone can carry the same ID to another Mac and combine their analytics; a new operating-system user or cleared Keychain can split one Mac into separate IDs. An installation's existing practice history may be grouped under its first reported app-device ID. Older installations that never report it remain unidentified.

Account Authentication and Billing Data

For purchase confirmation, email verification, passwordless sign-in, installation recovery, linked-installation use, and account security actions, we record bounded request, delivery, retry, confirmation, expiry, consumption, and security-event state. Delivery jobs store the destination email, timestamps, attempt state, and limited failure information needed to retry delivery; mail-provider response bodies are not retained. A successful installation link queues an email to the verified account with the coarse model/platform, link time, and a fixed Account Management link so the holder can review or revoke it.

When an authenticated installation is used, an email link is confirmed, or a browser account session is used, we record the IP address and a bounded user-agent string for security, abuse prevention, and session operation. For linked-installation use, we aggregate these data into at most one updated record per installation per hour. We also create a pseudonymous keyed correlation code from a coarse network prefix (IPv4 `/24` or IPv6 `/56`) and normalized browser/platform family. This code helps support correlate recent origins without storing an additional hardware identifier. It does not identify a person, and IP addresses, shared networks, VPNs, proxies, and user-agent spoofing can make it inaccurate. We do not use an IP address, user-agent, or this correlation code by itself to deny access automatically. We do not collect serial numbers, MAC addresses, Apple Account identifiers, canvas/font/audio probes, or similar covert fingerprint inputs for this purpose.

Single-use email-link, same-installation completion, and browser-session secrets are random values; the backend stores one-way hashes rather than the usable secrets. Opening a confirmation link proves control of the mailbox, not the identity of the human who clicked it, and creates a browser account session. The requesting installation is attached only after that installation presents the separate short-lived completion secret with its existing bearer. Browser account sessions last up to 120 days. We use a separate anti-forgery value and may require a new email link before a payment or security-sensitive action.

Website payments are hosted and processed by Stripe. IQuantize stores a Stripe customer reference and the minimum subscription status needed to grant Pro, such as plan, active status, current period end, cancellation-at-period-end state, and last verification time. For an installation without a verified account, IQuantize may send the entered display name when creating the Stripe customer but does not set the unverified app-entered email; Stripe Checkout collects the authoritative billing email. A verified account's name and email may be used for its Stripe customer. IQuantize does not receive or store full card numbers. Stripe collects the billing name, email, address, country, tax information, and payment details required for Checkout and the Billing Portal, and makes invoices and receipts available there.

Practice and Progress Data

We collect practice attempts and progress data, including song or groove references, attempt start/end times, duration, completion state, tempo, combined accuracy, matched/missed/extra counts, per-bar metrics, per-axis metrics, timing error metrics, velocity metrics, weak-bar training references, skill checkup results, learning plans, and current per-song practice state.

Settings and Library State

We collect latest app settings, practice preferences, calibration settings, MIDI pad maps, MIDI threshold settings, favorites, tombstones, content import/cache state, remote catalog cursor state, and library visibility state.

Hardware and Environment Data

We collect a redacted latest hardware configuration and capability summary, including MIDI source count, channel mask, velocity floor, calibration status, app session reference, and timestamps. We do not collect serial numbers, MAC addresses, Apple ID subjects, push tokens, exact persistent hardware identifiers, or private raw MIDI input captures.

Analytics and Diagnostics

We collect app analytics sessions and events such as app session start/end, screen names, practice started/completed/stopped events, subject references, event sequence, and redacted event properties. This includes categorical billing-funnel interactions such as showing or dismissing a paywall, selecting an upgrade, requesting or opening checkout, and the app later observing Pro activation. These client-observed events do not include card details, receipts, Stripe customer/session identifiers, checkout URLs, names, or email addresses. They are used for app functionality, diagnostics, analytics, and product improvement inside IQuantize.

macOS Update Checks

The macOS app downloaded directly from iqtz.app installs its own updates, so it asks iqtz.app for an update feed. It sends that request when you choose Check for Updates and, if you allow automatic checking when the app first asks, whenever you open the app and about once a day while it remains open. The request carries your IP address, the app version and build number, and the macOS version. It carries no device identifier, no account, installation, or setup identifier, and no practice data, and the website cannot link it to an IQuantize account. The website's server access log keeps these requests for up to 30 days, and we use them only to deliver updates and keep that service working, never for advertising or tracking. The App Store version of the app does not check for updates this way; Apple delivers its updates.

Teacher and Student Linking

Teacher/student linking is not available in the v1.0.3 release UI. The backend is capable of storing link requests, accepted/revoked link state, student public codes, teacher/student user identifiers, and teacher-visible progress summaries for controlled testing or a later enabled release. Automatic sync does not grant teacher access, and progress reads require an accepted link.

3. How We Use Information

We use collected information to:

We do not use collected data for third-party advertising or tracking.

4. Legal Bases

Where data-protection law requires a legal basis, IQuantize processes data needed to create and operate the guest or verified Pro account, deliver sync, provide and administer a requested subscription, preserve progress, provide requested features, and perform account deletion because that processing is necessary to provide the Service under the EULA. IQuantize processes limited IP address, user-agent, security, fraud-prevention, reliability, diagnostic, and product-improvement data where necessary for its legitimate interests and where those interests are not overridden by the user's rights. Payment, tax, invoice, and accounting records may also be processed to comply with legal obligations. Where consent is the required legal basis, IQuantize will request it separately, and it may be withdrawn without affecting processing already performed lawfully.

5. Linked Data

Synced data is linked to a guest backend account and installation because the Service needs stable identities to store progress, settings, teacher links, and account-deletion requests. A verified Pro account can link several installation-backed users to one email and Stripe entitlement without merging their practice histories. App Store privacy answers and privacy manifests treat these sync payloads as linked to the user.

6. Retention

Account-backed product projections, including practice attempts, progress, skill checkup results, learning plans, settings, MIDI maps, favorites, current library state, analytics, installation version history, and database-incarnation history, are retained until the account is deleted. Latest-value rows are replaced as newer values arrive except for the disclosed version and incarnation histories.

Verified account name, email, installation memberships, linked-installation metadata, and current billing references are retained while the account exists. Installation-link security events, minimal account-only rolling-limit entries, support-override records, hourly linked-installation usage-origin records, and browser-session origin metadata containing IP address, user-agent, or the pseudonymous correlation code are scheduled for deletion or clearing after 30 days. A link event keeps the bounded model and platform that were shown during linking so a queued owner notice and account-level churn evidence can still be delivered or reviewed if only that local installation is unlinked and deleted before email delivery. A rolling-limit entry contains only the account reference, internal link-source kind and row number, and time; it does not contain email, network, device, or practice data. These account-security records can remain after deletion of an already-unlinked local installation so that deleting that installation does not suppress the owner notice or reset the account security limit, and they are deleted with the verified account. The browser session itself may remain active after its older origin metadata is cleared. Superseded or canceled pending claims and dead delivery jobs are also scheduled for deletion after 30 days. A pending claim associated with a recoverable paid purchase may be retained while recovery or a billing-ownership conflict remains unresolved. Expired or consumed email-link records are scheduled for deletion after they have been inactive for more than 1 day; expired same-installation completion records follow the same short-lived retention policy. Expired or revoked web-session records are scheduled for deletion after 7 days. An active browser session expires after 120 days unless it is revoked earlier. Stripe and IQuantize may retain transaction, invoice, tax, refund, and accounting records for the period required by applicable law or dispute handling.

Operational records use shorter limits:

Successful account deletion removes the deleted installations and their app-device mappings on the server and clears the local app-device ID before creating fresh local state. It does not recover or combine the deleted account through that ID.

After account deletion, the Service keeps a one-way fingerprint of the deletion request token for up to 7 days so a retry can confirm that a request whose response was lost already succeeded. This receipt is not linked to a user or device and contains no synced payload. Non-identifying operational event counts and aggregate data-flow totals may remain after account-linked rows are removed.

Records required by law may be retained only for the period the law requires.

7. Sharing

We do not sell personal data or share it with third-party advertising networks. The current release does not expose teacher/student linking. If linking is enabled in a later release, teacher-visible progress will be shared only for an accepted link. Stripe processes customer, billing, payment, tax, invoice, and subscription data for website-billed Pro. ImprovMX processes the sender and recipient information and email content needed to deliver account verification and sign-in links from support@iqtz.app. Backend infrastructure providers may process data only to host, secure, monitor, and operate the Service. These providers may process data in countries outside your own under their applicable transfer safeguards. IQuantize requires service providers that process user data to provide the same or equivalent protection described in this policy and applicable law.

8. Security

Server tokens are stored in Keychain on Apple platforms and are bound to one backend installation. Web account authentication uses a Secure, HttpOnly browser cookie rather than browser local storage; usable email-link, installation-completion, and session secrets are not stored in the database. Account-changing forms use origin and anti-forgery checks, and payment details remain on Stripe-hosted pages. ImprovMX delivery requires authenticated STARTTLS. Sync payloads are allowlist-redacted before upload. Removing Pro from one Mac removes only its account membership; revoking an installation additionally invalidates its server token while preserving the other linked installations. The app is designed to keep local practice working if sync is paused, offline, or unavailable.

9. Children and Guardians

IQuantize is designed for student learners and may be used by minors with parent or guardian support. A parent or guardian should accept the startup agreement for a minor student and may delete the student's guest account-backed data in the app.

10. Your Choices and Privacy Rights

You may stop using the app at any time. Account-backed collection begins only after startup agreement acceptance. Teacher/student linking is not available in the v1.0.3 release UI. If a release kill switch or backend policy pauses sync, local practice data remains on the device and pending rows are not deleted solely because sync is paused.

You can update the name on a verified account and manage payment information, cancellation, invoices, and receipts through Stripe's hosted Billing Portal. The verified email is the account identifier and cannot be edited; contact support if it must be replaced. You can review the personal account's linked installations, remove Pro from one without deleting its independent practice history, revoke an installation so its existing server token can no longer be used, sign out one browser, or, after recent email authentication, sign out all browsers. If a legitimate recovery reaches the rolling new-link limit, support can review the opaque denial reference and may grant one target-bound attempt; support cannot override the three-active-installation limit.

Depending on where you live, you may ask to access, correct, delete, or receive a portable copy of personal data, and you may object to or restrict certain processing. Where processing relies on consent, you may withdraw consent at any time without affecting earlier lawful processing. You may also complain to your local data protection authority. Email privacy@iqtz.app to exercise a privacy right. IQuantize may need to verify the request before acting and may retain or continue processing data where applicable law permits or requires it.

11. Account and Data Deletion

Start deletion in Settings > About > Delete Account. A verified paid account shared by multiple installations requires a fresh email sign-in and explicit whole-account confirmation at cnc.iqtz.app; an installation credential alone cannot delete every linked device. Deletion expires open Checkout sessions, cancels non-terminal Stripe subscriptions, and then removes the verified account, its installation memberships, browser sessions, backend identifiers, installation records, synced practice/progress, settings, hardware snapshots, analytics, library/cache state, and teacher/student links as one customer account. If Stripe cancellation fails, deletion stops so the subscription is not orphaned. Returning to each linked app within 7 days completes its local practice-data purge and resets it to a fresh local identity; after that confirmation window, contact privacy@iqtz.app for help completing the local purge. Bundled or downloaded lesson content that is not account data remains available. Stripe or IQuantize may retain legally required transaction and invoice records. A nonidentifying deletion receipt may be retained for up to 7 days as described above.

Email privacy@iqtz.app for privacy questions or help with deletion.

12. Changes

We may update this Privacy Policy as the app and Service change. Material legal changes may require renewed acceptance before account-backed sync continues.

13. Contact

For privacy questions or help, contact privacy@iqtz.app, or write to Relato Garrido - Unipessoal Lda, Rua das Palmeiras, Lote 5, 244, Quinta da Marinha, 2750-005 Cascais, Lisboa, Portugal.

Requires an electronic drum kit or MIDI drum module.