Privacy Policy
Last updated 17 August 2026 · Applies to KaraokeList 1.0 for iPhone
The short version
- Your setlist lives on your iPhone. It works with no network at all.
- There are no ads, no ad networks, no third-party trackers, and nothing is ever sold or shared with data brokers.
- An account is required, so your songs are backed up and follow you to a new phone.
- To write you a suggestion, the app sends your song titles and your profile answers to a large language model run by an outside provider. It does not send your name or your email.
- The only thing another person ever sees is a public @handle you chose.
- Venues you mark as private stay on your device, permanently.
- You can delete your account, and everything in it, from inside the app.
1. Who this is from
KaraokeList is an iPhone app made by Michael Jones, an independent developer. For anything in this policy, including a request to see or delete your data, write to dev.michael.jones@gmail.com. I read that address myself.
This policy covers the KaraokeList iPhone app and this website. It does not cover anywhere else you might end up — if you tap a link to a venue's website or search for lyrics, you have left KaraokeList and that site's own policy applies.
2. What stays on your iPhone
KaraokeList is built local-first. Your songs and your logged nights are written to a database on the device, and reading them, searching them, adding to them and logging a sing all work with the network switched off.
Stored on the device:
- Your setlist — song titles, artists, the Skill and Fun tags, your star rating, notes, and the "Not again" flag.
- Your sings — what you sang, when, where, how you rated it, and whether it sat too high, just right, or too low in your voice.
- Your profile answers — the ones you gave when you set the app up, all of them skippable.
- Venue coordinates — the map position of a bar you logged a sing at. These never leave the device. They are excluded from every sync, by design, because they were gathered to fill in a text field and publishing them would be a different purpose.
- Your last batch of suggestions, so it is still readable offline.
A venue you mark as somewhere of your own — a friend's house, an office party — is permanently excluded from anything shared or synced. That flag is set by you and is never inferred.
3. Your account, and what syncs
KaraokeList requires an account. That is so your setlist survives a lost phone and follows you to a new one, and it is why sync is free in both directions.
You can sign in with Sign in with Apple, with Google, or with an email address and password. Accounts are handled by an outside authentication provider. What is held depends on which you pick: an account identifier always, an email address if you gave one, and whatever Sign in with Apple chose to return — if you used Apple's Hide My Email, I only ever see the relay address, never your real one.
Once you are signed in, your setlist, your sings and your nights out, your profile answers, and your public @handle are copied to a cloud database and attached to your account. Venue coordinates and private places are not. This is a backup of your own data for your own use — it is not published, not pooled, and not visible to anyone else.
4. What is sent to other companies
KaraokeList has no servers of its own. It relies on a small number of outside providers, each doing one job. They act as processors on my instructions: they may use what they receive to deliver that service to me, and not for their own purposes.
The categories, and what each one receives
| Account and sign-in | Your sign-in credential and account identifier, plus your email address if you signed in with one. |
|---|---|
| Cloud database and hosting | The synced copy of your setlist, sings, profile answers and public handle, described in section 3. |
| Large language model | A summary of your setlist, sent to an LLM to produce suggestions, name a song you described, or write your singer read. Exactly what is sent is set out below. |
| Abuse prevention | A signal confirming the request came from a genuine copy of the app, so nobody else can run up the bill on your behalf. It identifies the app, not you. |
| Product analytics | A count of how often each AI feature is used, tied to your account identifier. See section 8. |
| Music recognition and catalog | An acoustic fingerprint when you identify a song, and your search text when you look one up. |
| Maps and place search | The name you type when you are naming a bar, so real places can be offered back. |
Who these are today: Google, through its Firebase platform, provides the first five. Apple provides the last two, and Sign in with Apple if you choose it. Their policies: Google, Firebase data handling, Apple. If a provider changes, this line changes with it and the date at the top moves — the categories above are what actually govern.
What actually goes to the model
When you ask for suggestions, ask "what's that song?", or open your singer read, the app sends the language model a summary of the material it needs to answer: song titles and artists from your setlist, your ratings, your Skill and Fun tags, your too-high/just-right/too-low answers, your profile answers, and the songs you have flagged Not again so it does not suggest one back to you.
It does not send your name, your email address, your account identifier, your location, the names of venues, or the contents of your notes. The result comes back, is saved on your device, and nothing about the exchange is stored by me. Your setlist is not used to train anybody's model.
Two that are worth spelling out
- Identifying a song by listening — a digital signature of the audio is sent to be matched. It is a fingerprint, not a recording, and no audio is stored by the app or by the service.
- Searching the music catalog — this needs your permission, because it uses your music account to pick a storefront. Declining leaves the add form completely usable; you just type the title yourself.
5. Location
KaraokeList asks for your location once, at one moment: when you tap the venue field while logging a sing. It does not track you, and it never reads your location in the background.
It asks for a precise fix, because the question it is answering is "which of these bars are you standing in," and a vague answer cannot answer it. But the precision is yours to give:
- Precise — the app lists the bars right around you.
- Approximate — it lists the neighbourhood, with a wider net, and says so.
- Denied — nothing is lost. The search still runs, ranked from a venue you have already logged, and whatever you type always saves.
The reading is used to rank that one search. It is not sent to the language model, not attached to your account, and not stored as a trail. The only coordinate ever written down is the one belonging to a venue you picked — and, as above, that stays on the device.
6. Microphone
The microphone is used only while the identify screen is open and listening, and only to produce the acoustic fingerprint the recognition service matches against. Audio is not recorded, not saved, and not sent anywhere else. Closing the screen ends it. The app cannot listen when it is not in front of you.
7. Places, and the only thing other people see
KaraokeList has a shared map of bars that host karaoke, built from what singers contribute. Contributing is always a deliberate act — adding a venue, correcting one, confirming one, or reporting that it has stopped doing karaoke.
When you do contribute, what becomes public is the venue information itself — its name, address, and which nights it runs — alongside the public @handle you chose. Your handle is the only thing about you that another user of this app can ever see. Your email address, your real name, your setlist, your ratings, and your sings are never visible to anyone but you.
Nothing about a venue is published as a side effect of using the app. Logging that you sang somewhere does not put it on the map. Your habits are not mined into a listing, and a place you flagged as private can never become one however often you go.
8. Analytics
The app records one event each time you use an AI feature — a suggestion, a recall, a singer read — through a product-analytics service, tagged with your account identifier. That is the whole of it. It exists so I can tell whether the features people asked for are the features people use, and to keep an eye on what they cost to run.
There is no advertising identifier, no IDFA, no ad network, no attribution SDK, no session recording, no heatmapping, and no cross-app or cross-site tracking of any kind. The app's privacy manifest declares no tracking, and there is nothing in the binary that could do it.
9. What KaraokeList never does
- No selling or sharing of personal information, as those words are defined by California law or any other. There is no arrangement under which anyone could buy this data, and there never will be.
- No advertising, and no ad networks or data brokers in the app.
- No tracking you across other apps or websites.
- No profile sold to a label, a venue, or a music service.
- No lyrics. Lyrics are licensed by publishers, so the app stores none and shows none. It links out to your browser, where the licensed text is on the publisher's own page.
- No publishing anything you wrote without you doing it yourself.
10. How long it is kept, and deleting it
Your synced data is kept for as long as your account exists. It is your setlist — the point is that it is still there in two years.
You can delete your account from inside the app, in the profile screen. Deleting it removes your account, the synced copy of your setlist, sings and profile, and releases your @handle for someone else to take. It happens straight away and it cannot be undone.
Two things survive deletion, and you should know which:
- Data on your own device is removed when you delete the app. Deleting your account signs you out; removing the app removes the local copy.
- Venue information you contributed to the shared map stays on the map, because other people are relying on it — but it stops being connected to you, since the handle it was filed under is gone. This is the same principle any shared map runs on: the bar's Thursday karaoke night is a fact about the bar, not about you.
You can also ask me to do any of this by email, at the address in section 1.
11. Children
KaraokeList is made for adults who go to bars, and it is not directed at children. It is not intended for anyone under 13, and I do not knowingly collect anything from a child under 13. If you believe a child has created an account, write to me and I will delete it.
12. Your rights
Wherever you live, you can ask me for a copy of what is held about you, ask me to correct it, or ask me to delete it. Most of that is a button in the app already, and I would rather you used it — but the email address works too, and I will answer within 30 days.
If you are in the EU or the UK
Under the GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection. The legal bases I rely on are: performance of a contract for your account and the syncing of your own data, since that is the service you signed up for; legitimate interests for the small AI-usage count and for the abuse-prevention check, which keep the app working and affordable; and consent for your location, your microphone, and your music account, each of which the system asks you for separately and each of which you can withdraw in iOS Settings at any time. You may complain to your local supervisory authority.
If you are in California
Under the CCPA and CPRA you have the right to know what is collected, to delete it, to correct it, and to opt out of sale or sharing. There is nothing to opt out of: KaraokeList does not sell or share personal information, and has not in the preceding twelve months. The categories collected are identifiers (an account identifier, and an email address if you gave one), your own user-generated content (your setlist and sings), coarse product-usage data, and — momentarily and only when you allow it — geolocation. I will not discriminate against you for exercising any of these rights.
13. Where it is held, and security
The data is stored on cloud infrastructure operated by the providers described in section 4, which for a US-based project means it is processed in the United States. If you are outside the US, using the app involves that transfer; those providers' terms carry the standard contractual clauses that cover it.
Everything is encrypted in transit and encrypted at rest by the hosting provider. Access is governed by server-side security rules that allow each account to read and write only its own documents, deployed and enforced on the server rather than trusted to the app. No method is perfect, and I am not going to pretend otherwise — but there is no advertising pipeline, no data warehouse, and nothing here of interest to anyone but you.
14. Changes
If this policy changes, the date at the top changes with it. If a change is a material one — a new kind of data, a new company involved, a new purpose — you will be told inside the app before it takes effect, not left to find it here.
15. Contact
Michael Jones · dev.michael.jones@gmail.com
Questions about this policy, requests about your data, or a correction to something above — all to the same address.