KaraokeList

Privacy Policy

Last updated 17 August 2026 · Applies to KaraokeList 1.0 for iPhone

The short version

  • Your setlist lives on your iPhone. It works with no network at all.
  • There are no ads, no ad networks, no third-party trackers, and nothing is ever sold or shared with data brokers.
  • An account is required, so your songs are backed up and follow you to a new phone.
  • To write you a suggestion, the app sends your song titles and your profile answers to a large language model run by an outside provider. It does not send your name or your email.
  • The only thing another person ever sees is a public @handle you chose.
  • Venues you mark as private stay on your device, permanently.
  • You can delete your account, and everything in it, from inside the app.

1. Who this is from

KaraokeList is an iPhone app made by Michael Jones, an independent developer. For anything in this policy, including a request to see or delete your data, write to dev.michael.jones@gmail.com. I read that address myself.

This policy covers the KaraokeList iPhone app and this website. It does not cover anywhere else you might end up — if you tap a link to a venue's website or search for lyrics, you have left KaraokeList and that site's own policy applies.

2. What stays on your iPhone

KaraokeList is built local-first. Your songs and your logged nights are written to a database on the device, and reading them, searching them, adding to them and logging a sing all work with the network switched off.

Stored on the device:

A venue you mark as somewhere of your own — a friend's house, an office party — is permanently excluded from anything shared or synced. That flag is set by you and is never inferred.

3. Your account, and what syncs

KaraokeList requires an account. That is so your setlist survives a lost phone and follows you to a new one, and it is why sync is free in both directions.

You can sign in with Sign in with Apple, with Google, or with an email address and password. Accounts are handled by an outside authentication provider. What is held depends on which you pick: an account identifier always, an email address if you gave one, and whatever Sign in with Apple chose to return — if you used Apple's Hide My Email, I only ever see the relay address, never your real one.

Once you are signed in, your setlist, your sings and your nights out, your profile answers, and your public @handle are copied to a cloud database and attached to your account. Venue coordinates and private places are not. This is a backup of your own data for your own use — it is not published, not pooled, and not visible to anyone else.

4. What is sent to other companies

KaraokeList has no servers of its own. It relies on a small number of outside providers, each doing one job. They act as processors on my instructions: they may use what they receive to deliver that service to me, and not for their own purposes.

The categories, and what each one receives

Account and sign-inYour sign-in credential and account identifier, plus your email address if you signed in with one.
Cloud database and hostingThe synced copy of your setlist, sings, profile answers and public handle, described in section 3.
Large language modelA summary of your setlist, sent to an LLM to produce suggestions, name a song you described, or write your singer read. Exactly what is sent is set out below.
Abuse preventionA signal confirming the request came from a genuine copy of the app, so nobody else can run up the bill on your behalf. It identifies the app, not you.
Product analyticsA count of how often each AI feature is used, tied to your account identifier. See section 8.
Music recognition and catalogAn acoustic fingerprint when you identify a song, and your search text when you look one up.
Maps and place searchThe name you type when you are naming a bar, so real places can be offered back.

Who these are today: Google, through its Firebase platform, provides the first five. Apple provides the last two, and Sign in with Apple if you choose it. Their policies: Google, Firebase data handling, Apple. If a provider changes, this line changes with it and the date at the top moves — the categories above are what actually govern.

What actually goes to the model

When you ask for suggestions, ask "what's that song?", or open your singer read, the app sends the language model a summary of the material it needs to answer: song titles and artists from your setlist, your ratings, your Skill and Fun tags, your too-high/just-right/too-low answers, your profile answers, and the songs you have flagged Not again so it does not suggest one back to you.

It does not send your name, your email address, your account identifier, your location, the names of venues, or the contents of your notes. The result comes back, is saved on your device, and nothing about the exchange is stored by me. Your setlist is not used to train anybody's model.

Two that are worth spelling out

5. Location

KaraokeList asks for your location once, at one moment: when you tap the venue field while logging a sing. It does not track you, and it never reads your location in the background.

It asks for a precise fix, because the question it is answering is "which of these bars are you standing in," and a vague answer cannot answer it. But the precision is yours to give:

The reading is used to rank that one search. It is not sent to the language model, not attached to your account, and not stored as a trail. The only coordinate ever written down is the one belonging to a venue you picked — and, as above, that stays on the device.

6. Microphone

The microphone is used only while the identify screen is open and listening, and only to produce the acoustic fingerprint the recognition service matches against. Audio is not recorded, not saved, and not sent anywhere else. Closing the screen ends it. The app cannot listen when it is not in front of you.

7. Places, and the only thing other people see

KaraokeList has a shared map of bars that host karaoke, built from what singers contribute. Contributing is always a deliberate act — adding a venue, correcting one, confirming one, or reporting that it has stopped doing karaoke.

When you do contribute, what becomes public is the venue information itself — its name, address, and which nights it runs — alongside the public @handle you chose. Your handle is the only thing about you that another user of this app can ever see. Your email address, your real name, your setlist, your ratings, and your sings are never visible to anyone but you.

Nothing about a venue is published as a side effect of using the app. Logging that you sang somewhere does not put it on the map. Your habits are not mined into a listing, and a place you flagged as private can never become one however often you go.

8. Analytics

The app records one event each time you use an AI feature — a suggestion, a recall, a singer read — through a product-analytics service, tagged with your account identifier. That is the whole of it. It exists so I can tell whether the features people asked for are the features people use, and to keep an eye on what they cost to run.

There is no advertising identifier, no IDFA, no ad network, no attribution SDK, no session recording, no heatmapping, and no cross-app or cross-site tracking of any kind. The app's privacy manifest declares no tracking, and there is nothing in the binary that could do it.

9. What KaraokeList never does

10. How long it is kept, and deleting it

Your synced data is kept for as long as your account exists. It is your setlist — the point is that it is still there in two years.

You can delete your account from inside the app, in the profile screen. Deleting it removes your account, the synced copy of your setlist, sings and profile, and releases your @handle for someone else to take. It happens straight away and it cannot be undone.

Two things survive deletion, and you should know which:

You can also ask me to do any of this by email, at the address in section 1.

11. Children

KaraokeList is made for adults who go to bars, and it is not directed at children. It is not intended for anyone under 13, and I do not knowingly collect anything from a child under 13. If you believe a child has created an account, write to me and I will delete it.

12. Your rights

Wherever you live, you can ask me for a copy of what is held about you, ask me to correct it, or ask me to delete it. Most of that is a button in the app already, and I would rather you used it — but the email address works too, and I will answer within 30 days.

If you are in the EU or the UK

Under the GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection. The legal bases I rely on are: performance of a contract for your account and the syncing of your own data, since that is the service you signed up for; legitimate interests for the small AI-usage count and for the abuse-prevention check, which keep the app working and affordable; and consent for your location, your microphone, and your music account, each of which the system asks you for separately and each of which you can withdraw in iOS Settings at any time. You may complain to your local supervisory authority.

If you are in California

Under the CCPA and CPRA you have the right to know what is collected, to delete it, to correct it, and to opt out of sale or sharing. There is nothing to opt out of: KaraokeList does not sell or share personal information, and has not in the preceding twelve months. The categories collected are identifiers (an account identifier, and an email address if you gave one), your own user-generated content (your setlist and sings), coarse product-usage data, and — momentarily and only when you allow it — geolocation. I will not discriminate against you for exercising any of these rights.

13. Where it is held, and security

The data is stored on cloud infrastructure operated by the providers described in section 4, which for a US-based project means it is processed in the United States. If you are outside the US, using the app involves that transfer; those providers' terms carry the standard contractual clauses that cover it.

Everything is encrypted in transit and encrypted at rest by the hosting provider. Access is governed by server-side security rules that allow each account to read and write only its own documents, deployed and enforced on the server rather than trusted to the app. No method is perfect, and I am not going to pretend otherwise — but there is no advertising pipeline, no data warehouse, and nothing here of interest to anyone but you.

14. Changes

If this policy changes, the date at the top changes with it. If a change is a material one — a new kind of data, a new company involved, a new purpose — you will be told inside the app before it takes effect, not left to find it here.

15. Contact

Michael Jones · dev.michael.jones@gmail.com

Questions about this policy, requests about your data, or a correction to something above — all to the same address.