Privacy policy
This policy explains what ChordBento collects, why, and what you can do about it. It is written to meet the Protection of Privacy Law, 5741-1981, as amended by Amendment 13.
Who is responsible
ChordBento operates this service and is the controller of the database behind it. You can reach us at [email protected] about anything in this policy.
What we collect
- Account details: your email address, and — if you sign in with Google — the display name and avatar image Google returns.
- Your content: the chord sheets, setlists, performance notes, tags and version history you create.
- Your preferences: interface language, sheet layout defaults, accessibility settings and pedal shortcuts.
- Consent records: which optional categories you accepted or rejected, when, and under which version of this policy.
- Error reports, only if you consent: the page address and a technical stack trace when something crashes.
Why we collect it and on what basis
- To provide the service you signed up for — storing and displaying your sheets and setlists. Basis: performance of a contract.
- To keep you signed in and remember your settings. Basis: performance of a contract.
- To prove that consent was given or withdrawn. Basis: legal obligation.
- To diagnose crashes and measure feature usage. Basis: your consent, which you can withdraw at any time.
We do not
- Sell or rent your personal data, or disclose it to third parties as a business.
- Send marketing email.
- Use your chord sheets or setlists for any purpose other than showing them back to you.
- Run advertising or profiling.
Who else processes your data
- Supabase — database, authentication and storage for your account and content.
- Netlify — hosting and content delivery for the application itself.
- Google — only if you choose to sign in with Google. Nothing else on the page contacts Google: the web fonts are served from our own domain.
- Lovable — receives crash reports, and only when you have consented to error monitoring.
Transfers outside Israel
Our processors operate infrastructure outside Israel, so your data may be stored and processed abroad. Israel and the European Union recognise each other as providing adequate protection, and transfers are made under the contractual terms of each processor. If you would rather your data were not processed abroad, this service is not able to accommodate that.
How long we keep it
Your account details and content are kept for as long as your account exists. When you delete your account, the content is erased immediately. Consent records and the privacy audit trail are deliberately kept afterwards, because they are the evidence that consent was given and that the erasure happened; they contain no chord sheets, setlists or profile details.
Your rights
Under the Protection of Privacy Law you may inspect the data held about you (zchut iyun), ask for it to be corrected (zchut tikun), ask for your account to be deleted, and object to direct marketing. You can exercise all of these yourself from the Privacy centre inside the app. We respond to any request that needs manual handling within 30 days.
If you are not satisfied with how we handle a request, you may complain to the Privacy Protection Authority at the Ministry of Justice.
How we protect your data
- Every table enforces row-level security, so one account cannot read or modify another account's rows.
- All traffic is served over HTTPS, and the application sends a strict Content-Security-Policy.
- Passwords are handled by Supabase Auth and are never stored by this application.
- Server functions verify your session on every request and validate all input against a strict schema.
Cookies and local storage
The service stores a small amount of data in your browser, most of it essential to signing in and remembering your settings. The cookie and storage policy lists every item and what it is for.
Changes to this policy
If we change what we collect or why, we will update this page and ask for consent again where the change affects an optional category.
Last updated: