Vocalify
Back to home Open app

Privacy Policy

Last updated: 24 July 2026

Vocalify (“we”, “us”) is a browser-based singing trainer. This policy explains what data the service processes and the choices you have. Vocalify is local-first by default: without an account your practice data and settings stay in your browser. An account is optional — if you create one and sign in, your data is also stored on our server so it syncs across your devices (see “If you sign in” below).

1. Data we process

Stored on your device

To make the app work, Vocalify saves the following in your browser’s local storage and IndexedDB. Without an account this data stays on your device, and you can erase it at any time by clearing your browser data:

  • Settings and preferences (vocal range, scoring, instrument, audio latency, theme, language).
  • Practice sessions, scores and statistics.
  • Melodies you create and any backing tracks you add.
  • Voice recordings you make during practice.
  • Your cookie/analytics consent choice.

If you sign in (optional account)

You can use Vocalify fully without an account. If you choose to create one, we process and store the following on our server so your practice syncs across devices:

  • Your email address, and a securely hashed password if you set one. If you sign in with Google, we receive and store a Google account identifier and your email from Google instead.
  • Your synced settings, practice sessions and statistics, melodies and backing tracks.
  • Your voice recordings. While you are signed in, recordings you make during practice are uploaded to and stored on our server (in our own object storage) so you can play them back on any device. This happens automatically as part of syncing; it does not happen while you are signed out.
  • Login/session records needed to keep you signed in securely.
  • Where your account came from — the campaign tag or link that first brought your browser here (see 2b), or the site that linked to us, recorded once when the account is created so we can tell which of our efforts actually help people find Vocalify. It is never updated afterwards and is not used to target you.

Microphone & audio

When you grant microphone access, audio is analysed for pitch on your device, in real time — that pitch analysis never leaves your device. Any recordings you make are stored locally; if you are signed in, those recordings are also uploaded to and stored on our server (see “If you sign in”). While you are signed out, recordings stay on your device and we do not receive them.

Usage analytics — only with your consent

If — and only if — you accept analytics, we load Microsoft Clarity to understand how the app is used and to improve it. Clarity may collect information such as pages viewed, clicks, scrolling and interaction events (session replay), approximate location derived from your IP address, and device, browser and operating-system details. Clarity sets cookies to do this. Microsoft acts as a processor and may use the data per its own terms.

Analytics are off by default. Nothing is loaded and no analytics cookies are set until you choose “Accept”. You can withdraw consent at any time (see “Your choices”).

2. Cookies & local storage

PurposeTypeSet when
App preferences, sessions, melodies, recordingslocalStorage / IndexedDBAlways (required to run the app)
Account, synced data & recordings on our serverServer-side (database + object storage)Only when you create an account and sign in
Login session (keeps you signed in)CookieOnly when you sign in
Consent choice (vocalify_consent)Cookie on .vocalify.me (so you are asked once across the site and the app), mirrored in localStorageWhen you accept or decline
Colour theme (vocalify_theme)Cookie on .vocalify.me (so the site and the app match), mirrored in localStorageWhen you switch light/dark
Campaign attribution (vocalify_attr) — which advertising campaign or link brought you here (see 2b)Cookie on .vocalify.me, mirrored in localStorageOnly after you accept analytics
Analytics browser id (vocalify-anon-id) — a random value that separates “20 steps by one person” from “20 people”localStorageOnly after you accept analytics
Microsoft Clarity analyticsCookiesOnly after you accept analytics

2b. Usage analytics and error reports (our own server)

Besides Microsoft Clarity, Vocalify records a small stream of events on our own server — no third party is involved. There are two kinds, and they are treated differently on purpose:

  • Usage events — “app opened”, “microphone granted”, “exercise started”, “plan page viewed”, and the like: the name of the step, the page path, a timestamp, the app version, and a small payload such as the exercise type. These are recorded only if you accept analytics. They carry a random identifier kept in your browser's storage so we can tell “20 steps by one person” from “20 people”; it is not linked to anything outside Vocalify. If you are signed in, your account id is attached as well.
  • Performance reports — when a practice run finishes, and once when the app loads, we record how smoothly it ran: the frame rate, how many visible stutters there were, how long the page took to load, and a coarse description of the device — processor core count, a memory tier, browser family, operating system and a screen size bucket such as “phone”. Individual frame timings never leave your device and no full user-agent string is stored; the point is to find out whose devices the app runs badly on, so it can be made faster for them. Recorded only if you accept analytics, and carrying the same random identifier as the usage events above.
  • Error reports — when something in the app throws, we record the error message, the technical stack trace, the page path and your browser's user-agent string. These are recorded whether or not you accept analytics, because knowing the app is broken for someone is how it gets fixed. They carry no random identifier, and they never include audio, recordings, melodies or anything you typed.

The marketing pages (this site) record the same two streams: a page view with the campaign parameters in the link you arrived through (utm_source and similar), whether you scrolled to the pricing section, and which button took you into the app. With analytics accepted, those campaign parameters are also stored in a first-party cookie (vocalify_attr, 180 days) so that if you later create an account we can tell which campaign paid for the visit. It contains no name, no email and nothing about what you do inside the app.

Both are kept for at most 180 days and then deleted automatically. Neither is sold, shared, or used to build a profile of you.

3. Third parties

  • Hosting — our server (which stores account data, synced practice data and recordings) runs on infrastructure provided by Hetzner in the EU.
  • Google Sign-In — used only if you choose to sign in with Google. Google issues a token that we verify, giving us your email and a Google account identifier. See the Google Privacy Policy.
  • Resend — if you sign in by email code, we send that email through Resend, which processes your email address to deliver the message.
  • Microsoft Clarity — analytics, loaded only with consent. See the Microsoft Privacy Statement.
  • Google Fonts — fonts are requested from Google’s CDN when a page loads, which involves your IP address. See the Google Privacy Policy.

4. Legal basis

Where the GDPR applies: functional local storage relies on it being strictly necessary to provide the service you requested; account and sync data (including recordings) are processed to perform the service you request by signing in (Art. 6(1)(b)); analytics rely on your consent (Art. 6(1)(a)), which you can withdraw at any time.

For the events described in section 2b: consent for usage events (you can withdraw it at any time via “Cookie settings”), and legitimate interest for error reports — keeping the service working, with no identifier attached and the narrowest content that still makes a bug findable.

5. Data retention

Data stored on your device persists until you clear it. If you have an account, the data synced to our server (including recordings) is kept for as long as your account exists and is deleted when you delete your account (see “Your choices”); individual practice sessions can also be deleted from within the app. Analytics data collected by Microsoft Clarity is retained according to Microsoft’s policies.

Usage events and error reports (section 2b) are deleted automatically 180 days after they are received.

6. Your choices & rights

  • Analytics consent — accept or decline in the banner; change it anytime via “Cookie settings” in the footer, or in the app under Settings → Privacy & analytics. Declining stops both Microsoft Clarity and the usage events in section 2b; error reports, which carry no identifier, continue.
  • Erase local data — clear your browser’s site data for Vocalify to delete everything stored locally.
  • Account & server data — you can sign out at any time. To delete your account and the data synced to our server, email privacy@vocalify.me and we will remove it.
  • Microphone — revoke access at any time in your browser’s site permissions.
  • Where the GDPR or similar laws apply, you may have rights to access, rectify, erase or restrict processing, and to lodge a complaint with a supervisory authority.

7. Children

Vocalify is not directed to children under 13, and we do not knowingly collect their data.

8. Changes

We may update this policy; the “Last updated” date above will change. Material changes will be reflected here.

9. Credits

Instrument sounds use the “MusyngKite” soundfont, packaged by midi-js-soundfonts, redistributed unmodified under CC BY-SA 3.0.

10. Contact

Questions about privacy: privacy@vocalify.me.

Vocalify

Browser-based vocal training. Pitch you can see.

Home Open app Terms Refunds

© Vocalify

Vocalify stores data locally to run the app and uses analytics cookies to understand usage and improve it. You choose whether analytics is on.

Privacy policy