Chopinly

Privacy Policy

Effective September 5, 2026 · LaLa Solutions LLC (the data controller)

1. Who we are

Chopinly (chopinly.com and the installable app) is operated by LaLa Solutions LLC, a Delaware limited liability company ("we", "us"). For the purposes of the EU and UK General Data Protection Regulation (GDPR) we are the data controller for the personal data described here.

Contact: leif@lalalimited.com · Postal: LaLa Solutions LLC, c/o ZenBusiness Inc., 611 South DuPont Highway, Suite 102, Dover, DE 19901, USA. We have not appointed a Data Protection Officer because the law does not require one for a service of this size and kind; the email above reaches the person responsible.

2. Two ways to use Chopinly

Without an account

Everything — your goals, practice segments, notes, preferences, the sheet music you import — is stored in your browser on your device (localStorage, IndexedDB and the browser's cache). It is never sent to us. The only thing that reaches our servers is what any website receives when you open it: your browser asks for the app's files (HTML, scripts, styles, fonts, icons). Those requests pass through Cloudflare, which processes your IP address and request headers to deliver and protect the site (see §6 and §7). We run no analytics of any kind.

With an account

If you sign in, we store the items in §3 so that your practice is backed up and available on your other devices. Signing in is optional and reversible: sign out keeps your data on the device, delete account removes it from our servers. Score files are the one thing that is not uploaded by signing in alone: they go up only when you choose upload in Scores.

3. What we hold when you have an account

DataWhat exactlyWhyKept
Email addressThe address you sign in with.To identify your account and send you sign-in codes.Until you delete your account.
Practice dataGoals (name, optional composer, type, status), practice segments (start and end times, optional tempo), notes you write, the list of takes you record (which goal, when, how long, a 48-number loudness outline, whether you starred it), the list of your scores (title, composer, tags, page count, size, a hash of the file, when you last opened it), your bookmarks and the ink you draw on pages (as vector strokes), and deletion markers so devices agree.Backup and sync — the service you asked for.Until you delete the item or your account.
Take audioNever sent. The recordings themselves are stored only in the browser storage of the device that made them (IndexedDB). We cannot hear them; no server ever receives them. Removing them is a device setting in the account sheet, and clearing the device removes them all.—Until you remove them on that device.
Score files you uploadThe PDF of a score, exactly as you imported it, when — and only when — you choose upload in Scores. Stored in a private object store (Cloudflare R2) under your account, never shared, listed or published. Each account has a storage allowance shown in the account sheet (100 MB while the feature is promotional; the limit is a setting on your account, not a promise).To open the same score on your other devices.Until you remove it from the cloud, delete the score, or delete your account.
Session recordsOne per signed-in device: a random token stored only as a SHA-256 hash, created / renewed / expiry timestamps, and the browser's user-agent string (cut to 200 characters).To keep you signed in and let you see and end sessions.180 days from last use, or until you sign out.
Sign-in codesA salted hash of the six-digit code, the email it was sent to, an attempt counter.To verify it is you.10 minutes, or until used.
Rate-limit countersA count of recent requests keyed by your email address and by the IP address of the request.To stop abuse — someone hammering the sign-in or sync endpoints.One hour.

There are no passwords: Chopinly signs you in with a one-time code sent to your email. We hold no payment details because there is nothing to pay for; an account's plan (which sets its storage allowance) is a single word on the account record. We do not ask for your name, age, location, or anything about you beyond the email address.

4. What we never do

5. Why we process your data, and the legal bases

We do not rely on consent for anything today. If we ever add an optional feature that needs it, we will ask you clearly first and you can say no.

6. Who else sees your data

Two service providers ("processors") handle data on our behalf, under contracts that limit them to providing their service to us:

We disclose personal data to no one else, except if compelled by a valid legal process — and then only what is required, and we will tell you unless the law forbids it. If LaLa Solutions LLC were ever acquired, this policy would still bind the data, and you would be told before anything changed.

7. Where your data is processed

We are a US company and our processors are US companies. Account data is stored on Cloudflare's infrastructure, primarily in the United States; Cloudflare's global network may handle your requests at the data center nearest you. If you are in the EEA, the UK or Switzerland, transfers to the US rely on the EU–US Data Privacy Framework (and its UK and Swiss extensions) where the recipient is certified, and otherwise on Standard Contractual Clauses in our processors' data-processing terms. By using an account you understand that your data is processed in the United States.

8. How long we keep it

Each item's retention is in the table in §3. In addition: our database keeps a rolling 30-day history for disaster recovery, so deleted data leaves that history within 30 days. Cloudflare's server logs are kept for its own short operational window. When you delete your account we delete your uploaded score files, your practice data, sessions, codes and the account record immediately in one operation.

9. Your rights, and where the buttons are

Whether or not GDPR applies to you, you have these rights over your data, and most of them are a tap away in the app (the account button in the header):

For anything you can't do in the app, email leif@lalalimited.com. We answer within 30 days, free of charge. We verify requests through the email address on the account.

10. Security

All traffic is encrypted in transit (TLS). Session tokens are stored only as hashes; sign-in codes are salted and hashed, expire in ten minutes, and allow five attempts. There are no passwords to leak. The session cookie is HttpOnly, Secure and SameSite, and every state-changing request checks its origin. Requests are rate-limited. We collect as little as the service needs, which is the best security measure of all. No system is perfect: if we learn of a breach affecting your personal data we will notify you and, where required, the relevant authority without undue delay.

11. Children

Chopinly is not directed at children under 13, and an account requires you to be 16 or older, or to have a parent's or guardian's permission. We do not knowingly collect personal data from children; if you believe a child has created an account, email us and we will delete it.

12. California and other US state privacy laws

We do not sell personal information, do not "share" it for cross-context behavioral advertising, and do not collect sensitive personal information. We honor requests to know, delete and correct as described in §9, and we will never treat you differently for exercising a right. We do not respond to "Do Not Track" signals because we do not track.

13. Changes to this policy

If we change this policy we will post the new version here with a new effective date. If a change materially affects account holders, we will tell you by email or in the app at least 14 days before it takes effect.

14. Contact

LaLa Solutions LLC · leif@lalalimited.com · LaLa Solutions LLC, c/o ZenBusiness Inc., 611 South DuPont Highway, Suite 102, Dover, DE 19901, USA