Piano Sight Reading Privacy Policy

Updated: September 17, 2026

Effective: September 17, 2026

Lumen Labs Studio, China (“Lumen Labs”, “we”, “us”, or “our”) operates Piano Sight Reading (the “App”). We value your privacy and explain in this Policy what personal information we process, why we process it, how long we retain it, when we share it, and the choices available to you.

Please read this Policy before using the App. If you do not agree with necessary processing described here, do not use the relevant service. Optional permissions remain under your control and can be changed in your device settings.

Questions, privacy requests, or complaints may be sent to support@lumen-labs.app.

I. How We Collect and Use Your Personal Information

(A) Device permissions that may be used by Piano Sight Reading

1. Microphone

If you enable microphone-based practice, the App uses microphone input on your device to detect pitch in real time. Raw microphone audio is not uploaded to our servers or retained by us. You may deny or revoke this permission and instead use a compatible MIDI keyboard or features that do not require audio input.

2. Camera, photos, and files

The App accesses a camera, photo, PDF, MIDI, or other supported file only when you actively select it for score import. We do not browse content you did not select. If you save or export a result, the operating system may request permission to write the file to a destination you choose.

3. Bluetooth and MIDI

Bluetooth or MIDI access is used to discover and connect a compatible digital piano or keyboard. On Android 11 and earlier, the operating system may categorize Bluetooth discovery as a location permission; the App does not use it to determine or track your location.

4. Network access

Network access is used for sign-in, synchronization, score-import processing, purchase verification, updates, support, and security. Basic on-device functions may remain available offline, but cloud-dependent functions require a connection.

5. Notifications

If you permit notifications, the App may show practice reminders, service notices, or task-status updates. You can disable notifications in the App or device settings.

6. Device and application information

To maintain compatibility and security, we may process device type, operating-system version, App version, language, time zone, network type, IP address, crash details, and a limited device or installation identifier. We do not use these details to obtain precise location.

(B) Personal information we collect and use directly

1. Operating and securing the App

We process request timestamps, service logs, error and crash information, security events, IP address, and limited device information to deliver requests, diagnose failures, prevent abuse, protect accounts, and maintain the service.

2. Registration, authentication, and login

A guest profile uses a random account identifier and a device-held security credential. If you choose Google Sign-In, we receive the identity token and the email address, display name, and profile image that Google makes available under your settings. We use that information to create or locate your account, display your profile, and keep it secure.

3. Practice, score import, and synchronization

We process practice type, selected exercise or score, progress, accuracy, duration, history, preferences, unlock state, and synchronization status so that you can continue learning and view your records. When you import a score, we process the selected image, PDF, MIDI file, filename, score title, composer information, recognition result, and your corrections to perform the requested import and manage your personal score library.

We do not use private scores or microphone content to train a public generative-AI model. If you send feedback or a support request, we process the message, selected diagnostics or attachment, and any optional contact information you provide.

4. Membership, orders, and fraud prevention

For a purchase, we process the platform, product identifier, order or transaction identifier, purchase time, receipt or verification data, currency, status, and membership term. Apple or Google processes payment details; we do not receive your full bank-card number. We use transaction data to verify entitlement, restore a purchase, respond to a refund, resolve disputes, and prevent fraud.

(C) Changes to the purpose of collection or use

We will not use personal information for a materially incompatible new purpose without giving notice and obtaining consent where required. If a new purpose is reasonably compatible with the original purpose and law permits it, we will still update this Policy when the change is material.

(D) Processing without consent where permitted by law

Applicable law may allow or require processing without consent, for example to perform a contract you requested, comply with law, protect life or significant property interests in an emergency, respond to lawful authorities, conduct news or public-interest activities within legal limits, process information you lawfully made public, or maintain safe and stable operation. We rely on these grounds only to the extent the law permits.

II. How We Use Cookies and Similar Technologies

(A) Keeping products and services secure and efficient

The mobile App does not rely on browser cookies for its core practice functions. It may use secure local storage for authentication, consent, settings, and a guest credential. Server-side security logs may associate a request with an account or installation to prevent abuse and maintain sessions.

(B) Providing a simpler access experience

These legal webpages use the lang URL parameter to display English or Chinese. They do not use a cookie or local-storage preference for language. If we later introduce non-essential cookies or similar tracking, we will provide notice and a choice where required.

III. How We Store Your Personal Information

(A) Storage locations

Information is processed on systems operated by us and our contracted service providers in locations needed to deliver the App. Information may therefore be processed outside your country or region. Where law requires a transfer mechanism, contractual protection, security assessment, certification, or separate consent, we will use the applicable safeguard.

(B) Retention periods

We retain information only for the shortest period reasonably necessary for the stated purpose, subject to legal obligations and backup rotation:

(1) Account and cloud practice data are generally retained while the account is active and are deleted or de-identified after final account deletion.

(2) Original score-import images, PDFs, and MIDI files are normally retained for no more than seven days after the task ends for confirmation, retry, and recovery, then enter deletion. A personal score you choose to keep remains until you delete it or the account is finally deleted.

(3) Support, security, and technical logs are retained for a limited period based on troubleshooting, security, and legal needs, then deleted or de-identified.

(4) We retain only the minimum order records needed for accounting, tax, payment disputes, refund administration, and fraud prevention for the legally required or permitted period. Unneeded raw payment parameters and callback bodies are deleted.

IV. How We Share, Transfer, or Publicly Disclose Personal Information

(A) Sharing and transfer

We do not sell personal information. We do not share it for cross-context behavioral advertising. We share only the minimum information necessary with the providers below, under appropriate contractual, technical, and organizational controls.

1. Third-party SDKs

Google Sign-In

When used
Used only when you choose Google authentication.
Information provided
It provides an identity token and account information authorized by you.
Privacy policy
Google Privacy Policy

Umeng analytics

Purpose and conditions
Used in released versions only after applicable privacy consent to understand feature use, stability, and crashes.
Information processed
Data is limited to what is needed for analytics and diagnostics.
Privacy policy
Umeng Privacy Policy

2. Third-party services

Apple App Store and Google Play

Purpose
Distribute the App and process purchases, payment, restoration, and refunds.
Information received
We receive transaction and entitlement information, not full card details.
Privacy policies
Apple Privacy Policy
Google Privacy Policy

Alibaba Cloud OSS

Purpose
To complete import and synchronization.
Information stored
Selected score source files and larger structured score content.
Storage
Controlled private object storage.
Privacy policy
Alibaba Cloud Privacy Policy

3. Assessment and control of recipients

Before sharing personal information, we assess whether the recipient has a lawful purpose, limit the data and retention period, require confidentiality and security, and prohibit unauthorized use. A provider may act independently where the law or its platform terms make it a separate controller, such as an application store.

4. Transfer in a merger or reorganization

If our business is involved in a merger, acquisition, financing, asset transfer, insolvency, or reorganization, personal information may be transferred as part of that transaction. We will require the recipient to continue protecting it under this Policy or provide legally required notice and choices.

(B) Public disclosure

We do not publicly disclose your personal information or private scores unless you direct us to do so, disclosure is necessary to protect vital interests in an emergency, or law requires it. Where consent is legally required, we will obtain it separately.

(C) Sharing, transfer, or disclosure without consent where permitted

We may disclose information without consent only where applicable law permits or requires it, such as a valid court order, lawful government request, emergency protection of life or property, investigation of fraud or security incidents, or establishment and defense of legal claims.

V. How We Protect Personal Information

We use access controls, authentication, encrypted transmission where appropriate, private object storage, least-privilege permissions, monitoring, backup controls, and incident-response procedures intended to protect information. Access is limited to personnel and providers who need it for authorized duties.

No internet transmission or storage system is completely secure. If a personal-data incident is likely to create a legally relevant risk, we will investigate, contain, remediate, document, and notify affected users or authorities as required by law.

VI. Managing Your Personal Information

1. Accessing, correcting, or obtaining a copy

You can view or update available account settings, practice history, preferences, and personal scores in the App. You may contact us to request access, correction, or a portable copy where applicable. We may verify identity before fulfilling a request.

2. Deleting information and withdrawing choices

You may delete supported practice records or personal scores through available App controls and revoke device permissions in system settings. Withdrawal does not make earlier lawful processing unlawful, and a feature may stop working if its required permission is withdrawn. You may also ask us to delete information where the law provides that right.

3. Deleting your account

Use the deletion option in the App’s account page. The account is locked and signed out immediately, followed by a 30-day revocation period before final deletion. If you cannot access the App, contact support for identity verification and assistance. Details appear in the Account Deletion Guide.

4. Complaints and regional privacy rights

Depending on your location, you may have rights to know, access, correct, delete, restrict or object to processing, withdraw consent, obtain portability, and complain to a data-protection authority. EEA and United Kingdom users may consult the GDPR. California users may consult the California Attorney General’s CCPA page. We will not discriminate against you for exercising an applicable privacy right.

5. Accessing this Privacy Policy

This Policy is available from the App’s privacy and legal links and at its current public URL. You may switch between English and Chinese with the control at the top of this page. English is the default version.

VII. Minors

The App serves a general music-learning audience and is not directed specifically to children. If you are below the digital-consent age applicable where you live, use the App only with consent and guidance from a parent or legal guardian. Guardians should supervise permissions, uploads, purchases, and account choices.

If we learn that we processed a child’s personal information without consent required by applicable law, we will take reasonable steps to restrict or delete it. A guardian may contact us to exercise the child’s applicable rights.

VIII. Changes and Notices

We may update this Policy to reflect changes in law, security, technology, or App functions. We will post the revised date and provide additional notice for a material change. Where law requires consent, the new processing will not begin until valid consent is obtained.

IX. Other

This Policy should be read with the User Agreement, Membership Agreement, and Account Deletion Guide. If a provision is invalid, the remaining provisions remain effective. This English version controls if it conflicts with a translation, without limiting mandatory privacy or consumer rights under applicable law.

X. How to Contact Us

Data controller: Lumen Labs Studio.
Privacy and support email: support@lumen-labs.app.

Please describe your request and the account concerned without sending passwords or full payment-card details. We may ask for information reasonably necessary to verify identity and protect the account. We will respond within the period required by applicable law.

“钢琴视奏”隐私政策

更新日期:2026年9月17日

生效日期:2026年9月17日

位于中国的 Lumen Labs Studio(以下简称“Lumen Labs”“我们”或“我方”)运营“钢琴视奏”(英文名称:Piano Sight Reading,以下简称“本应用”)。我们重视您的隐私,本政策说明我们处理哪些个人信息、处理目的、保存期限、共享情形以及您可以作出的选择。

请在使用本应用前阅读本政策。如果您不同意本政策所述的必要处理,请不要使用相关服务。可选设备权限始终由您控制,您可以在设备设置中进行调整。

如有隐私请求、疑问或投诉,请发送邮件至 support@lumen-labs.app。

一、我们如何收集和使用您的个人信息

(一)您在使用“钢琴视奏”相关功能时,可能使用以下设备权限

1. 麦克风权限

当您启用麦克风练习时,本应用在您的设备上使用麦克风输入进行实时音高识别。我们不会将原始麦克风音频上传至服务器,也不会保存该录音。您可以拒绝或撤回权限,改用兼容的 MIDI 键盘或无需音频输入的功能。

2. 相机、照片和文件权限

只有当您主动选择图片、PDF、MIDI 或其他支持的文件用于曲谱导入时,本应用才会访问对应相机、照片或文件。我们不会浏览您未选择的内容。当您保存或导出结果时,操作系统可能要求获得写入您所选位置的权限。

3. 蓝牙与 MIDI 权限

蓝牙或 MIDI 权限用于发现并连接兼容的电子琴。Android 11 及更早版本可能将蓝牙发现归类为位置权限;本应用不会使用该权限确定或追踪您的位置。

4. 网络访问权限

网络用于登录、同步、曲谱导入处理、购买验证、更新、支持和安全保障。部分设备端基础功能可以离线使用,但依赖云端的功能需要网络连接。

5. 通知权限

在您允许后,本应用可以显示练习提醒、服务通知或任务状态更新。您可以在本应用或设备设置中关闭通知。

6. 设备和应用信息

为维护兼容性和安全,我们可能处理设备类型、操作系统版本、应用版本、语言、时区、网络类型、IP 地址、崩溃信息以及有限的设备或安装标识。我们不会利用这些信息获取精确位置。

(二)我们直接收集与使用您的个人信息

1. 保障本应用和服务正常、安全运行

我们处理请求时间、服务日志、错误与崩溃信息、安全事件、IP 地址和有限设备信息,用于完成请求、诊断故障、防止滥用、保护账号和维护服务。

2. 注册、认证和登录

游客身份使用随机账号标识和设备保存的安全凭证。如果您选择 Google 登录,我们会接收身份令牌,以及 Google 根据您的设置提供的邮箱、显示名称和头像,用于创建或查找账号、展示资料并保护账号安全。

3. 练习、曲谱导入与同步

我们处理练习类型、所选练习或曲谱、进度、准确率、时长、历史记录、偏好、解锁状态和同步状态,使您能够继续学习并查看记录。当您导入曲谱时,我们处理您选择的图片、PDF、MIDI 文件、文件名、曲谱标题、作曲者信息、识别结果和修改内容,以完成导入并管理个人曲谱库。

我们不会使用私人曲谱或麦克风内容训练面向公众的生成式人工智能模型。您提交反馈或支持请求时,我们会处理消息、您选择的诊断信息或附件,以及您自愿提供的联系信息。

4. 会员、订单与反欺诈

发生购买时,我们处理平台、商品标识、订单或交易标识、购买时间、收据或验证数据、币种、状态和会员期限。支付信息由 Apple 或 Google 处理,我们不会获得完整银行卡号。交易数据用于验证权益、恢复购买、响应退款、处理争议和防止欺诈。

(三)收集、使用目的变更的处理

未经通知并在需要时取得同意,我们不会将个人信息用于实质上不相容的新目的。若新目的与原目的合理相容且法律允许,我们仍会在发生重大变化时更新本政策。

(四)依法无需同意的处理

适用法律可能允许或要求我们在无需同意的情况下处理信息,例如履行您请求的合同、履行法定义务、紧急保护生命或重大财产权益、响应有权机关、在法定范围内开展新闻或公共利益活动、处理您依法公开的信息,或维护服务安全稳定运行。我们仅在法律允许的范围内依赖这些依据。

二、我们如何使用 Cookies 和同类技术

(一)保障产品与服务安全、高效运转

移动应用的核心练习功能不依赖浏览器 Cookie。本应用可能使用设备安全存储保存认证信息、同意状态、设置和游客凭证。服务器安全日志可能把请求与账号或安装实例关联,用于防止滥用和维护会话。

(二)提供更便捷的访问体验

本法律页面通过网址中的 lang 参数显示英文或中文,不使用 Cookie 或本地存储保存语言偏好。若以后引入非必要 Cookie 或类似追踪技术,我们将依法提供说明和选择。

三、我们如何存储您的个人信息

(一)信息存储地点

信息由我们及受托服务商在提供本应用所需的地点处理,因此可能在您的国家或地区之外处理。适用法律要求跨境传输机制、合同保护、安全评估、认证或单独同意时,我们将采取相应保障措施。

(二)存储期限

除法定义务和受限备份轮换外,我们只在实现所述目的所需的最短合理期间内保存信息:

(1)账号和云端练习数据通常在账号有效期间保存,在账号最终注销后删除或去标识化。

(2)曲谱导入的原始图片、PDF 和 MIDI 通常在任务结束后最多保存 7 天,用于确认、重试和故障恢复,随后进入删除流程;您主动保存的个人曲谱保留到您删除或账号最终注销。

(3)支持、安全和技术日志根据排障、安全与法律需要在有限期间内保存,随后删除或去标识化。

(4)我们仅在会计、税务、支付争议、退款处理和反欺诈所需的法定或许可期限内保存最少订单记录,并删除不再需要的原始支付参数和回调正文。

四、我们如何共享、转让、公开披露您的个人信息

(一)个人信息的共享、转让

我们不出售个人信息,也不会为了跨情境行为广告共享个人信息。我们仅在适当的合同、技术和组织控制下,向下列服务商共享实现功能所必需的最少信息。

1. 第三方 SDK

Google Sign-In

使用场景
仅在您选择 Google 认证时使用。
提供的信息
向我们提供身份令牌及您授权的账号资料。
隐私政策
Google 隐私政策

友盟分析

使用目的与条件
仅在取得适用的隐私同意后,用于发布版本的功能使用、稳定性和崩溃分析。
处理的信息
处理范围限于分析和诊断所必需的信息。
隐私政策
友盟隐私政策

2. 第三方服务

Apple App Store 与 Google Play

使用目的
用于分发本应用并处理购买、支付、恢复和退款。
接收的信息
我们接收交易及权益信息,不会获得完整银行卡资料。
隐私政策
Apple 隐私政策
Google 隐私政策

阿里云 OSS

使用目的
用于完成导入和同步。
保存的信息
您选择的曲谱源文件和较大的结构化曲谱内容。
存储方式
受控的私有对象存储。
隐私政策
阿里云隐私政策

3. 对接收方的评估和约束

共享前,我们会评估接收方是否具有合法目的,限制信息范围和保存期限,要求保密与安全,并禁止未经授权的使用。若法律或平台规则使服务商成为独立个人信息处理者,例如应用商店,则其独立政策同时适用。

4. 合并、收购或重组时的转让

若我们的业务发生合并、收购、融资、资产转让、破产或重组,个人信息可能随交易转移。我们将要求接收方继续按照本政策保护信息,或依法向您提供通知和选择。

(二)个人信息的公开披露

除非您明确指示、紧急保护重大生命权益所必需或法律要求,我们不会公开披露您的个人信息或私人曲谱。依法需要同意时,我们会另行取得同意。

(三)依法无需同意的共享、转让或披露

我们仅在适用法律允许或要求时无需同意披露信息,例如执行有效法院命令或合法政府要求、紧急保护生命或财产、调查欺诈或安全事件,以及提出、行使或抗辩法律请求。

五、我们如何保护您的个人信息安全

我们采用访问控制、身份认证、适当的传输加密、私有对象存储、最小权限、监控、备份控制和事件响应流程保护信息。只有因授权职责确有需要的人员和服务商才能访问相关信息。

互联网传输和存储系统都无法保证绝对安全。若个人信息事件可能造成法律所关注的风险,我们将依法进行调查、控制、修复和记录,并通知受影响用户或主管机关。

六、管理您的个人信息

1. 查询、更正或取得副本

您可以在本应用中查看或更新可用的账号设置、练习历史、偏好和个人曲谱。您也可以联系我们依法请求访问、更正或取得可携带副本。为保护账号,我们可能在处理请求前核验身份。

2. 删除信息和撤回选择

您可以通过应用内可用功能删除支持的练习记录或个人曲谱,并在系统设置中撤回设备权限。撤回不会影响撤回前处理行为的合法性;若撤回必要权限,对应功能可能停止工作。适用法律赋予删除权时,您也可以联系我们提出请求。

3. 注销账号

您可以在应用内账号页面使用注销功能。账号会立即锁定并退出登录,随后进入 30 天撤销期,届满后最终删除。无法使用本应用时,请联系支持并完成身份核验。详见《账号注销说明》。

4. 投诉及属地隐私权

根据您所在地区,您可能享有知情、访问、更正、删除、限制或反对处理、撤回同意、数据可携以及向监管机关投诉的权利。欧洲经济区及英国用户可以查阅GDPR;加州用户可以查阅California Attorney General 的 CCPA 页面。我们不会因您依法行使隐私权而歧视您。

5. 访问隐私政策

您可以通过本应用的隐私和法律链接以及当前公开网址访问本政策,并使用页面顶部按钮切换英文和中文。页面默认显示英文。

七、未成年人条款

本应用面向一般音乐学习用户,并非专门面向儿童。若您未达到所在地适用的数字同意年龄,请仅在父母或其他法定监护人同意和指导下使用本应用。监护人应监督权限、上传、购买和账号选择。

若我们发现儿童个人信息在未取得适用法律要求的同意时被处理,我们将采取合理措施限制或删除相关信息。监护人可以联系我们行使儿童依法享有的权利。

八、隐私政策的修订和通知

我们可能因法律、安全、技术或应用功能变化更新本政策。我们会标明新的更新日期,并对重大变更提供额外通知。依法需要同意时,在取得有效同意前不会开始新的处理。

九、其他

本政策应与《用户协议》、《会员服务协议》和《账号注销说明》一并阅读。若某项条款无效,其他条款继续有效。中英文版本不一致时,以英文版本为准,但不限制适用法律赋予您的强制性隐私或消费者权利。

十、如何联系我们

个人信息处理者:Lumen Labs Studio。
隐私与支持邮箱:support@lumen-labs.app。

请说明您的请求和相关账号,但不要发送密码或完整银行卡信息。为保护账号,我们可能要求提供合理必要的信息核验身份,并将在适用法律要求的期限内回复。