Piano Sight Reading Privacy Policy
Updated: September 17, 2026
Effective: September 17, 2026
Lumen Labs Studio, China (“Lumen Labs”, “we”, “us”, or “our”) operates Piano Sight Reading (the “App”). We value your privacy and explain in this Policy what personal information we process, why we process it, how long we retain it, when we share it, and the choices available to you.
Please read this Policy before using the App. If you do not agree with necessary processing described here, do not use the relevant service. Optional permissions remain under your control and can be changed in your device settings.
Questions, privacy requests, or complaints may be sent to support@lumen-labs.app.
I. How We Collect and Use Your Personal Information
(A) Device permissions that may be used by Piano Sight Reading
1. Microphone
If you enable microphone-based practice, the App uses microphone input on your device to detect pitch in real time. Raw microphone audio is not uploaded to our servers or retained by us. You may deny or revoke this permission and instead use a compatible MIDI keyboard or features that do not require audio input.
2. Camera, photos, and files
The App accesses a camera, photo, PDF, MIDI, or other supported file only when you actively select it for score import. We do not browse content you did not select. If you save or export a result, the operating system may request permission to write the file to a destination you choose.
3. Bluetooth and MIDI
Bluetooth or MIDI access is used to discover and connect a compatible digital piano or keyboard. On Android 11 and earlier, the operating system may categorize Bluetooth discovery as a location permission; the App does not use it to determine or track your location.
4. Network access
Network access is used for sign-in, synchronization, score-import processing, purchase verification, updates, support, and security. Basic on-device functions may remain available offline, but cloud-dependent functions require a connection.
5. Notifications
If you permit notifications, the App may show practice reminders, service notices, or task-status updates. You can disable notifications in the App or device settings.
6. Device and application information
To maintain compatibility and security, we may process device type, operating-system version, App version, language, time zone, network type, IP address, crash details, and a limited device or installation identifier. We do not use these details to obtain precise location.
(B) Personal information we collect and use directly
1. Operating and securing the App
We process request timestamps, service logs, error and crash information, security events, IP address, and limited device information to deliver requests, diagnose failures, prevent abuse, protect accounts, and maintain the service.
2. Registration, authentication, and login
A guest profile uses a random account identifier and a device-held security credential. If you choose Google Sign-In, we receive the identity token and the email address, display name, and profile image that Google makes available under your settings. We use that information to create or locate your account, display your profile, and keep it secure.
3. Practice, score import, and synchronization
We process practice type, selected exercise or score, progress, accuracy, duration, history, preferences, unlock state, and synchronization status so that you can continue learning and view your records. When you import a score, we process the selected image, PDF, MIDI file, filename, score title, composer information, recognition result, and your corrections to perform the requested import and manage your personal score library.
We do not use private scores or microphone content to train a public generative-AI model. If you send feedback or a support request, we process the message, selected diagnostics or attachment, and any optional contact information you provide.
4. Membership, orders, and fraud prevention
For a purchase, we process the platform, product identifier, order or transaction identifier, purchase time, receipt or verification data, currency, status, and membership term. Apple or Google processes payment details; we do not receive your full bank-card number. We use transaction data to verify entitlement, restore a purchase, respond to a refund, resolve disputes, and prevent fraud.
(C) Changes to the purpose of collection or use
We will not use personal information for a materially incompatible new purpose without giving notice and obtaining consent where required. If a new purpose is reasonably compatible with the original purpose and law permits it, we will still update this Policy when the change is material.
(D) Processing without consent where permitted by law
Applicable law may allow or require processing without consent, for example to perform a contract you requested, comply with law, protect life or significant property interests in an emergency, respond to lawful authorities, conduct news or public-interest activities within legal limits, process information you lawfully made public, or maintain safe and stable operation. We rely on these grounds only to the extent the law permits.
II. How We Use Cookies and Similar Technologies
(A) Keeping products and services secure and efficient
The mobile App does not rely on browser cookies for its core practice functions. It may use secure local storage for authentication, consent, settings, and a guest credential. Server-side security logs may associate a request with an account or installation to prevent abuse and maintain sessions.
(B) Providing a simpler access experience
These legal webpages use the lang URL parameter to display English or Chinese. They do not use a cookie or local-storage preference for language. If we later introduce non-essential cookies or similar tracking, we will provide notice and a choice where required.
III. How We Store Your Personal Information
(A) Storage locations
Information is processed on systems operated by us and our contracted service providers in locations needed to deliver the App. Information may therefore be processed outside your country or region. Where law requires a transfer mechanism, contractual protection, security assessment, certification, or separate consent, we will use the applicable safeguard.
(B) Retention periods
We retain information only for the shortest period reasonably necessary for the stated purpose, subject to legal obligations and backup rotation:
(1) Account and cloud practice data are generally retained while the account is active and are deleted or de-identified after final account deletion.
(2) Original score-import images, PDFs, and MIDI files are normally retained for no more than seven days after the task ends for confirmation, retry, and recovery, then enter deletion. A personal score you choose to keep remains until you delete it or the account is finally deleted.
(3) Support, security, and technical logs are retained for a limited period based on troubleshooting, security, and legal needs, then deleted or de-identified.
(4) We retain only the minimum order records needed for accounting, tax, payment disputes, refund administration, and fraud prevention for the legally required or permitted period. Unneeded raw payment parameters and callback bodies are deleted.
IV. How We Share, Transfer, or Publicly Disclose Personal Information
(A) Sharing and transfer
We do not sell personal information. We do not share it for cross-context behavioral advertising. We share only the minimum information necessary with the providers below, under appropriate contractual, technical, and organizational controls.
1. Third-party SDKs
Google Sign-In
- When used
- Used only when you choose Google authentication.
- Information provided
- It provides an identity token and account information authorized by you.
- Privacy policy
- Google Privacy Policy
Umeng analytics
- Purpose and conditions
- Used in released versions only after applicable privacy consent to understand feature use, stability, and crashes.
- Information processed
- Data is limited to what is needed for analytics and diagnostics.
- Privacy policy
- Umeng Privacy Policy
2. Third-party services
Apple App Store and Google Play
- Purpose
- Distribute the App and process purchases, payment, restoration, and refunds.
- Information received
- We receive transaction and entitlement information, not full card details.
- Privacy policies
- Apple Privacy Policy
Google Privacy Policy
Alibaba Cloud OSS
- Purpose
- To complete import and synchronization.
- Information stored
- Selected score source files and larger structured score content.
- Storage
- Controlled private object storage.
- Privacy policy
- Alibaba Cloud Privacy Policy
3. Assessment and control of recipients
Before sharing personal information, we assess whether the recipient has a lawful purpose, limit the data and retention period, require confidentiality and security, and prohibit unauthorized use. A provider may act independently where the law or its platform terms make it a separate controller, such as an application store.
4. Transfer in a merger or reorganization
If our business is involved in a merger, acquisition, financing, asset transfer, insolvency, or reorganization, personal information may be transferred as part of that transaction. We will require the recipient to continue protecting it under this Policy or provide legally required notice and choices.
(B) Public disclosure
We do not publicly disclose your personal information or private scores unless you direct us to do so, disclosure is necessary to protect vital interests in an emergency, or law requires it. Where consent is legally required, we will obtain it separately.
(C) Sharing, transfer, or disclosure without consent where permitted
We may disclose information without consent only where applicable law permits or requires it, such as a valid court order, lawful government request, emergency protection of life or property, investigation of fraud or security incidents, or establishment and defense of legal claims.
V. How We Protect Personal Information
We use access controls, authentication, encrypted transmission where appropriate, private object storage, least-privilege permissions, monitoring, backup controls, and incident-response procedures intended to protect information. Access is limited to personnel and providers who need it for authorized duties.
No internet transmission or storage system is completely secure. If a personal-data incident is likely to create a legally relevant risk, we will investigate, contain, remediate, document, and notify affected users or authorities as required by law.
VI. Managing Your Personal Information
1. Accessing, correcting, or obtaining a copy
You can view or update available account settings, practice history, preferences, and personal scores in the App. You may contact us to request access, correction, or a portable copy where applicable. We may verify identity before fulfilling a request.
2. Deleting information and withdrawing choices
You may delete supported practice records or personal scores through available App controls and revoke device permissions in system settings. Withdrawal does not make earlier lawful processing unlawful, and a feature may stop working if its required permission is withdrawn. You may also ask us to delete information where the law provides that right.
3. Deleting your account
Use the deletion option in the App’s account page. The account is locked and signed out immediately, followed by a 30-day revocation period before final deletion. If you cannot access the App, contact support for identity verification and assistance. Details appear in the Account Deletion Guide.
4. Complaints and regional privacy rights
Depending on your location, you may have rights to know, access, correct, delete, restrict or object to processing, withdraw consent, obtain portability, and complain to a data-protection authority. EEA and United Kingdom users may consult the GDPR. California users may consult the California Attorney General’s CCPA page. We will not discriminate against you for exercising an applicable privacy right.
5. Accessing this Privacy Policy
This Policy is available from the App’s privacy and legal links and at its current public URL. You may switch between English and Chinese with the control at the top of this page. English is the default version.
VII. Minors
The App serves a general music-learning audience and is not directed specifically to children. If you are below the digital-consent age applicable where you live, use the App only with consent and guidance from a parent or legal guardian. Guardians should supervise permissions, uploads, purchases, and account choices.
If we learn that we processed a child’s personal information without consent required by applicable law, we will take reasonable steps to restrict or delete it. A guardian may contact us to exercise the child’s applicable rights.
VIII. Changes and Notices
We may update this Policy to reflect changes in law, security, technology, or App functions. We will post the revised date and provide additional notice for a material change. Where law requires consent, the new processing will not begin until valid consent is obtained.
IX. Other
This Policy should be read with the User Agreement, Membership Agreement, and Account Deletion Guide. If a provision is invalid, the remaining provisions remain effective. This English version controls if it conflicts with a translation, without limiting mandatory privacy or consumer rights under applicable law.
X. How to Contact Us
Data controller: Lumen Labs Studio.
Privacy and support email:
support@lumen-labs.app.
Please describe your request and the account concerned without sending passwords or full payment-card details. We may ask for information reasonably necessary to verify identity and protect the account. We will respond within the period required by applicable law.