Sessionist Beta
How it works Session-ready Instruments
Download free

Privacy Policy

Last updated: 23 September 2026

This policy explains what information Sessionist handles and the rights you have. It covers the Sessionist app (Windows, Android and iOS) and this website at sessionist.ie.

Your audio never leaves your device without your say-so

Sessionist never uploads audio from your device without you specifically approving it, each and every time. There is no background upload, no diagnostic that carries audio, and no setting that switches it on. The only three occasions on which you can approve an upload are:

  • offering a recording of yours as a guide track for other users;
  • entering a recording in a competition;
  • sending an audio clip to a friend.

Each is a separate approval for that one recording. Everything else — practice scoring, pitch detection, diagnostics — happens on your device or as numbers only (sections 3 and 4).

1. Who we are

Sessionist is operated by Niall Kelleher, a sole trader in Ireland, trading as “Sessionist”, who is the data controller under the GDPR.

  • Address: 13 Vesey Place, Dublin, A96 R3H2, Ireland
  • Contact: privacy@sessionist.ie

2. Your account

You can try Sessionist as a guest, with no account, on a small set of demo tunes. Guest play is not saved: nothing about a guest is stored on our servers, and the app keeps nothing between guest visits. The only records a guest adds to are the anonymous tune play counts in section 3. If you register from a guest score screen, that one run carries into your new account; nothing else from guest play is kept.

Listen and Repeat and Practice Mode runs beyond the demo tunes need an account: you register with an email address, a password and a year of birth, or sign in with Google or Apple. The information below describes what we process for your account. Social and community features are a separate, explicit opt-in, available only where the declared year of birth is 16 or older — section 5 explains how we treat under-16s.

3. Information we collect

  • Email address — sign-in, account recovery and essential service messages.
  • Password — handled by Firebase and stored only in hashed form; we never see it.
  • Sign in with Google or Apple — if you choose it, we receive your email address from the provider (Apple may give a private relay address) and a sign-in token; no password is involved.
  • Display name, a system-generated player name, and a player ID.
  • Year of birth — to confirm eligibility and apply age-appropriate protections.
  • Learning data — tunes played and practised, scores and practice history, repertoire, instruments, recently-played tunes, playlists (and likes/dislikes), level and points, and your settings.
  • Community data (adults who opt in) — leaderboard entries (display name, score, speed, instrument), friends list, and in-app notifications.
  • Technical — a device latency calibration value (kept on your device) and, if you choose “remember me”, a sign-in token on your device.
  • Tune play counts (anonymous) — each time a tune plays in the app we record one line: the tune and setting, how it played (guide recording, notation playback, practice, listen and repeat, preview or competition), the speed, the instruments sounding, how many seconds of the tune sounded, and a random code for that launch of the app so one sitting’s plays can be counted together. The line holds nothing about you — no account, player ID, email, device identifier or location — and we do not link it to your account. It is recorded whether or not you are signed in. We keep these counts to know how often each tune is actually played, for rights holders and for deciding what music to offer.
  • Diagnostics (opt-in) — two switches on your Profile page. Run diagnostics: after a Listen and Repeat or Practice run the app uploads that run’s summary, the app’s console log and the run’s pitch-detection figures — sheets of numbers, never microphone audio — tagged with your player ID and a device code. Scoring reports: marking a note as wrongly scored on the score screen sends the figures for the notes you selected. During the beta both switches start on for adult accounts and you can turn either off; after the beta both are off unless you turn them on. Uploads happen only while we have collection switched on at our end. Guests send run diagnostics only while we have switched that on, with no account or device identity. Separately, if a leaderboard-bound run looks machine-played, an anonymised copy of that run’s scoring figures — no account, device or audio — is uploaded for review.

We use no third-party analytics, advertising or tracking.

4. Microphone and recordings

Sessionist scores your playing by listening to your instrument and detecting pitches in real time, so we ask for microphone permission at runtime — the core features will not work without it. You can change that permission at any time in your device settings.

For everyday practice, pitch detection runs on your device, and recordings are saved on your device and never modified. The one v1 exception is competition mode, which is opt-in and adults-only: audio is sent to our competition server for server-side scoring rather than processed locally, and the recording is uploaded as your entry only when you approve it after the performance ends. Community-guide contributions are also opt-in and adult-only, and are reviewed by a human moderator before publication.

Under-16s cannot upload audio in the launch version of the app (July 2026) — no competition entry, no community guides, and no recordings leaving the device. In later versions we plan to open opt-in competition entry to under-16s, behind a dedicated under-16 moderation team whose moderators must complete real-world identity verification and child-protection validation before reviewing any under-16 entry. At no stage will any moderator of under-16 audio entries be able to identify or communicate directly with any child. Their work is only to judge quality and vote for winners. All communications back to entrants are standardised and automated. We also plan on enabling an under-16s teacher mode, whereby the under-16 registered user can nominate another Sessionist user as their real-world music-class teacher. Teachers will be able to assign tunes, or sections of tunes, for student practice and see how or if the student has done. Teachers will complete real-world identity verification and must demonstrate pre-existing child-protection verification. Again, there is no free-form communication back from teacher to child — all of that must take place at real-world locations.

5. Children under 16

Users under 16 can register an account, and we process the same account and learning data for them as for any other user. What under-16s cannot do is social: they cannot turn on any social or community feature, and no recording ever leaves their device. Ireland’s age of digital consent is 16, so we offer no consent-based features to under-16s — their data is processed only as needed to run the account itself (see section 6). Year of birth is self-declared at registration and we cannot verify it; giving a false age breaches the Terms of Service. Parents or guardians can contact us at privacy@sessionist.ie about a child’s account, including to have it deleted.

6. How and why we use your data

  • Running your account and syncing your progress — to perform our contract with you.
  • Leaderboards and opt-in adult features such as competitions — with your consent.
  • Reviewing reported or submitted content for safety — our legitimate interest in a safe community.
  • Unlocking a purchase, handling refunds and keeping required records — contract and legal obligation.
  • Keeping the service secure and improving it — our legitimate interest.
  • Counting how often each tune is played (anonymous, section 3) — our legitimate interest in keeping an accurate record for rights holders.
  • Run diagnostics and scoring reports (section 3) — with your consent, to tune note scoring and pitch detection.
  • Sending essential messages such as email verification and password reset — to perform our contract.

We do not sell your data, advertise to you, or profile you for marketing. Where we rely on consent, you can withdraw it at any time.

7. Purchases

The one-time purchase that removes the daily run limit (see Terms, section 7) is sold by Paddle on sessionist.ie and Windows, by Apple in the App Store, and through Google Play on Android. Each takes the payment under its own privacy policy (Paddle, Apple, Google). We never receive or store your card or bank details. We keep a purchase record: your account ID, where you bought, the seller's transaction ID and the date. We use it to unlock your account on every device, to handle refunds and to keep the records the law requires.

8. Who we share data with

We share data only with the providers that run the service, acting as our processors: Firebase (Google) (sign-in and transactional email), Google and Apple (sign-in providers, if you choose them), Unity Gaming Services (cloud backup, leaderboards, friends, content delivery, anonymous tune play counts), and Firebase Hosting (Google) (this website and app downloads). See the Firebase and Unity privacy policies. Paddle, Apple and Google handle purchases as sellers in their own right (section 7). We do not sell or rent your data.

9. International transfers

Some providers process data outside the European Economic Area (for example in the United States), protected by appropriate safeguards such as Standard Contractual Clauses.

10. How long we keep it

  • Account and learning data — until you delete your account.
  • On-device data — until you delete it or uninstall the app.
  • Purchase records — as long as the law requires (typically up to six years).
  • Backups — purged within 30 days of account deletion.
  • Tune play counts — kept indefinitely; they contain no personal data, so deleting your account does not affect them.

11. Your rights

You can access, correct, delete, restrict, port or object to the processing of your personal data, and withdraw consent where we rely on it. Use the in-app account controls or email privacy@sessionist.ie; we respond within one month. You can also complain to the Irish Data Protection Commission — dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2, D02 RD28.

12. Deleting your account and data

You can delete your account at any time in the app, or by emailing privacy@sessionist.ie. This removes it from Firebase and Unity Gaming Services, and any content you published is removed or anonymised. Data on your device is removed when you delete it or uninstall the app. For the full procedure — what is removed, what is kept, the Contribution Manifest, timings and the email fallback — see Deleting your account and data.

13. Security

We use encrypted transmission (HTTPS/TLS), authentication through Firebase, and access controls limiting who can view user data. No method of storage or transmission is completely secure.

14. This website

sessionist.ie is a static site with no analytics or advertising cookies and no tracking. The host keeps brief server logs (such as IP address and browser type) to operate and secure the site. If you only visit the website, the account-related processing above does not apply to you.

15. Changes and contact

We may update this policy; we change the “Last updated” date above and flag significant changes in the app or by email. Questions or requests: privacy@sessionist.ie — Niall Kelleher, 13 Vesey Place, Dublin, A96 R3H2, Ireland.

Sessionist
Privacy Terms Refunds Deletion Open data Tune copyright
No ads No data selling Generous free tier
© 2026 Sessionist · sessionist.ie