Last updated: August 2026
This Privacy Policy explains how PitchHighway (“we,” “us,” or “our”) collects, uses, stores, and protects your personal data when you use our web application and iOS application (collectively, the “Service”).
We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Romanian data protection law. Please also review our Terms of Service.
The data controller responsible for your personal data is:
When you create an account, we collect:
When you use pitch training features, we process:
Classification: Voice and audio data is personal data under the GDPR, but it is not biometric special-category data under Article 9. We use voice data for pitch training, scoring, and progress tracking — not for uniquely identifying you as a person. Therefore, processing is based on Article 6 (not Article 9) of the GDPR.
If you subscribe in the iOS app, we receive from Apple:
If you subscribe on the website, we receive from Stripe:
We do not receive or store your payment card details. All payment processing is handled by Apple or Stripe.
If you sign up to be notified about PitchHighway’s app launch, we collect:
This email address is stored in our database to send you a notification when the PitchHighway app is available, along with launch-related updates, early-access offers, and occasional promotional communications about PitchHighway. We do not share this email with third parties for their own marketing purposes. Email delivery is handled via Resend. You may unsubscribe or request deletion of your email at any time by emailing [email protected] with the subject line “Unsubscribe.”
If you upload your own songs for processing into Highway exercises, we collect and process:
Uploaded songs are stored in Cloudflare R2 (EU-preferred regions) and are associated with your user account. You retain full ownership of the songs you upload.
If you explicitly choose to share a performance on social media from the web app, we collect and store:
The recording is uploaded only after you confirm the sharing prompt — nothing is uploaded automatically. It is stored in Cloudflare R2 (EU-preferred regions) and is reachable by anyone who has the share link. Shared performances are automatically deleted 30 days after sharing.
If you connect an AI assistant (for example Claude or ChatGPT) to PitchHighway through our Model Context Protocol (MCP) server, we store:
We receive only the name of the tool the assistant calls — never your conversation with the assistant. See Section 7.1 for what a connected assistant can read.
If you request access to our affiliate program through the form at pitchhighway.com/affiliate, we collect:
We use this only to review your application and reply to you. Each application is stored in our database and a copy is emailed to our support inbox; email delivery is handled via Resend. We do not share it with third parties for their own purposes. You may request deletion of your application at any time by emailing [email protected].
We collect personal data through three channels:
We process your personal data for the following purposes, each with a corresponding legal basis under GDPR Article 6(1):
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account creation & authentication | Account data, OAuth data, auth tokens | Art. 6(1)(b) — Performance of contract |
| Providing pitch training features | Voice & audio data, usage data | Art. 6(1)(b) — Performance of contract |
| Tracking progress, scores & streaks | Usage & progress data | Art. 6(1)(b) — Performance of contract |
| Vocal range tracking | Voice data (pitch samples, MIDI range) | Art. 6(1)(b) — Performance of contract |
| Subscription management | Subscription data, Apple transaction IDs | Art. 6(1)(b) — Performance of contract |
| Security (fraud prevention, token management) | IP address, device info, auth tokens | Art. 6(1)(f) — Legitimate interest |
| Preventing free-tier abuse (e.g. resetting upload limits by deleting and re-creating an account) | One-way hashed identifier derived from your email, Apple ID, and/or Google account identifier | Art. 6(1)(f) — Legitimate interest |
| Service email communications | Email address | Art. 6(1)(b) — Performance of contract |
| App launch notification & promotional communications | Email address (from launch signup) | Art. 6(1)(a) — Consent |
| Reviewing affiliate program applications | Email address, name, and sharing plans (from the affiliate form) | Art. 6(1)(b) — Steps taken at your request prior to entering into a contract |
| Error monitoring & debugging | Technical/device data (no user PII) | Art. 6(1)(f) — Legitimate interest |
| Future anonymised ML training | Anonymised/aggregated voice data | Art. 6(1)(f) — Legitimate interest (with anonymisation) |
| Processing user-uploaded songs into Highway exercises | Uploaded song audio, processed outputs | Art. 6(1)(b) — Performance of contract |
| Hosting performances you explicitly choose to share | Shared performance recordings, song title | Art. 6(1)(a) — Consent |
| Creating My Covers videos; diagnosing & improving pitch detection and exercises | Pitch diagnostics telemetry (per-frame pitch values); and, while the “Practice recordings” setting is enabled, the raw microphone recording of a practice run | Art. 6(1)(f) — Legitimate interest (telemetry); Art. 6(1)(a) — Consent, via the “Practice recordings” setting, withdrawable at any time in Account settings (practice-run recordings and the cover videos created from them). Processed under Article 6, not Article 9 — see the Classification note in Section 3.2 |
| Advertising-conversion measurement (Reddit Pixel) | Cookie/pixel identifiers, IP address, pages viewed, sign-up events | Art. 6(1)(a) — Consent (EEA/UK, via our cookie banner). Outside the EEA/UK the pixel loads by default and you may opt out (see Section 11). |
| Serving your training data to an AI assistant you have connected (MCP) | Voice profile, usage & progress data, uploaded song metadata, MCP connection tokens | Art. 6(1)(a) — Consent, given when you approve the connection on our sign-in screen or generate and paste a personal access token yourself, and withdrawable at any time by disconnecting the assistant or replacing the token (see Section 7.1) |
Given the sensitive nature of voice data, we want to be fully transparent about how it is handled:
We share personal data only with the following third-party service providers, strictly for the purposes described:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Apple | Authentication (Sign-In with Apple) & subscription/payment processing (IAP) | Apple ID, transaction IDs, subscription status | USA (EU-US Data Privacy Framework) |
| Authentication (Sign in with Google) | Google account identifier, email, name | USA (EU-US Data Privacy Framework) | |
| Stripe | Subscription and one-time payment processing for purchases made on the website | Email address, our internal user identifier, and purchase details (amount, currency, plan). Card details are entered directly with Stripe and never reach our servers. | USA (EU-US Data Privacy Framework) |
| Cloudflare R2 | Storage of AI-generated song tracks, user-uploaded songs used in exercises, performances you explicitly choose to share, and practice-run voice recordings and generated cover videos collected under the practice recordings setting | Song audio files; user-uploaded audio files and their processed outputs (linked to user account); shared performance recordings; raw microphone recordings of practice runs (linked to user account, never public) | EU-preferred regions |
| Resend | Transactional email delivery | Email address, email content | USA |
| Telegram | Error alerts & in-app support chat | Error data, user email, chat messages | Global |
| OpenAI | AI-powered chat support | Chat messages, user questions | USA |
| Simple Analytics | Privacy-first website analytics (page views, referrers) | No personal data — no IP addresses, no cookies, no tracking | Netherlands (EU) |
| Advertising-conversion measurement for our ad campaigns on Reddit, via the Reddit Pixel (see Section 11) | Pixel events (pages visited on our site, and whether you create an account) together with the technical data Reddit’s pixel collects automatically: cookie identifiers, IP address, and browser/User-Agent information. We do not send Reddit your email address, name, or other directly identifying account details. | USA |
We do not sell your personal data for money. We use the Reddit Pixel on our website to measure how effective our advertising on Reddit is (see Section 11). For visitors in the European Economic Area and the United Kingdom, this pixel loads only if you consent through our cookie banner; for visitors elsewhere it loads by default and you can opt out as described in Section 11. Under some U.S. state privacy laws (such as the California CPRA), the information shared with Reddit for advertising may be considered a “sale” or “sharing” of personal information. Apart from this advertising-measurement pixel, we do not share data with advertisers or ad networks, and we do not engage in profiling for marketing purposes.
PitchHighway offers a Model Context Protocol (MCP) server so that you can let an AI assistant of your choice — for example Claude (Anthropic) or ChatGPT (OpenAI) — read your PitchHighway data. This only happens if you connect the assistant yourself: you add PitchHighway inside the assistant, sign in to your PitchHighway account on our authorisation screen, and approve the connection. Alternatively, you can generate a personal access token in the web app (Home → Connect → Advanced) and paste it into the assistant yourself; creating and using that token is your authorisation for the same access. Nothing is shared until you do one of these.
A connected assistant can read, for your own account only: your measured vocal range and Sing in Original Key setting; your practice progress, streak, scores and weekly activity; the list of songs you have uploaded (titles and processing status — never the audio); the note-level pitch results of your most recent song run; your latest “Check my voice” report; and your upload allowance. Every MCP tool is read-only: an assistant cannot change your account, upload, rename or delete songs, or hear you sing. We receive only the name of the tool the assistant calls — never your conversation with it.
Once an assistant has read your data, that data is processed by the assistant’s provider under their own privacy policy, which you should review. The provider acts as an independent controller of that data; we do not control what they retain.
You can end a connection at any time by removing PitchHighway from the assistant’s connector settings. Access tokens expire after 24 hours and refresh tokens after 90 days; expired token records are kept for a period after expiry to detect reuse of a replaced token (see Section 9), and all MCP tokens are deleted with your account. A personal access token is invalidated by generating a new one in the web app (Home → Connect → Advanced), or can be revoked on request via the contact details in Section 15.
Your personal data is primarily stored on servers within the European Union. Where data is transferred to service providers outside the EU (specifically Apple, Google, and Stripe, in the USA), such transfers are protected by:
Resend, OpenAI, and Reddit process data in the USA.
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy:
| Data Category | Retention Period |
|---|---|
| Guest account data | Automatically deleted after 30 days of inactivity |
| Registered account data | Until you delete your account |
| Voice data (pitch samples, vocal range) | Until you delete your account (server-side). Audio recordings stay on your device except as described in Section 3.2. |
| Practice-run recordings (the “Practice recordings” setting) | Until you delete your account |
| Usage & progress data | Until you delete your account |
| Subscription data | Until you delete your account (Apple and Stripe retain their own records independently) |
| Launch notification email | Until the user requests deletion or unsubscribes, or 12 months after the app launch (whichever comes first) |
| Affiliate applications | Until we have replied and, for accepted affiliates, for the duration of the partnership — or earlier on request |
| Refresh tokens | 7 days from issuance (or until revoked) |
| Password reset tokens | Until used or expired |
| Apple and Stripe webhook logs | Retained for operational integrity and debugging |
| Uploaded song data (original audio & processed outputs) | Until you delete the song or delete your account (whichever comes first) |
| Shared performance recordings | 30 days from sharing (or earlier on request, or when you delete your account) |
| Pitch diagnostics telemetry | Until pruned by periodic retention sweeps, or when you delete your account |
| Free-tier abuse-prevention identifier (hashed) | Retained after account deletion under our legitimate interest in preventing abuse, for no longer than necessary for that purpose |
| AI-assistant (MCP) OAuth tokens | Access tokens expire after 24 hours and refresh tokens after 90 days from issuance (each refresh replaces the previous one). Expired token records (hashed values only) are kept after the refresh token expires so that reuse of a replaced token can be detected, and are removed by routine cleanup once 30 days have passed since that expiry — or immediately when you delete your account |
| AI-assistant (MCP) personal access token | Until you generate a replacement, ask us to revoke it (see Section 15), or delete your account |
When you delete your account, all associated personal data is deleted via cascading database deletion, including any songs you have uploaded and their processed outputs stored in Cloudflare R2. Any practice-run recordings and generated cover videos collected under the practice recordings setting are deleted along with the rest of your server-side data. Audio recordings stored on your device are not affected by account deletion and remain under your control. The one exception is a one-way hashed identifier (derived from your email, Apple ID, and/or Google account identifier, containing no plaintext email or name) that we retain to enforce free-tier upload limits across re-registration; it is used solely to prevent abuse and is kept for no longer than necessary for that purpose.
Under the GDPR, you have the following rights regarding your personal data:
How to exercise your rights: You may exercise your rights by emailing [email protected] with the subject line “GDPR Request.” You may also delete your account and all associated data directly within the Service. We will respond to all requests within 30 days.
PitchHighway uses a JWT-based authentication system, not traditional browser cookies for session management.
?ref=), we set a first-party cookie holding only that partner’s public promo code, for 30 days. We use it to credit the partner if you subscribe and to apply their discount to your first payment automatically. It contains no identifier and is not used to track you across other websites.The Service is not directed at children under the age of 16 (the GDPR age threshold for consent to data processing). We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that data promptly. If you believe a child under 16 has provided us with personal data, please contact us at [email protected].
We implement appropriate technical and organisational measures to protect your personal data, including:
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will be revised accordingly. For material changes that affect how we process your personal data, we will notify registered users by email. Previous versions of this policy are available upon request.
For privacy-related inquiries or to exercise your GDPR rights, please contact us:
We will respond to all GDPR requests within 30 days of receipt.