Privacy
Good Ears is a small practice app. The short version: your playing never leaves your device, and nothing here is sold, shared, or used for advertising.
What never leaves your device
- Your microphone audio. When you play, the sound is analysed in your browser — pitch detection and grading run entirely on your machine. Your most recent graded attempt is held in the page’s memory so you can play it back and hear your own timing; it is replaced by your next run and gone the moment you leave the page, and it is never written to storage. Measuring your microphone’s timing in Settings opens it for about five seconds in the same way: the tones are analysed as they come back, nothing is recorded, and the single number it works out — how many milliseconds your device takes to hear you — is kept on this device only. It is deliberately not synced to your account, because it describes this machine rather than you.
- Saying answers out loud. The “Say it aloud” drill can listen and mark you, and that is the one place in this app where microphone audio may leave your device. Where your browser can recognise speech on the device — recent Chrome can — it does, and nothing leaves. Where it cannot, what you say during the drill is sent to your browser vendor’s speech service to be turned into words, under their privacy policy rather than this one. That never happens without you being asked first, in plain words, on the drill’s own page; say no, or use any other browser, and the drill runs on a timed gap with no microphone open at all. This app records none of it, keeps none of it, and never receives it — no route here accepts audio. It applies only to that drill: playing your instrument is still graded entirely on your own machine.
- Takes you record playing along. A take is different, because you asked for it: it is saved in this browser’s own storage beside the song, so that you can listen back to it and so that it shows up in your practice log. It stays on this device. It is never uploaded — there is no route in this application that accepts audio — and it does not follow you to another device, signed in or not. Deleting the song deletes its takes, and the practice log has a button that deletes every recording at once.
- Songs you add, and the loops on them. A song you add to slow down and play along with is stored in your browser’s own storage (IndexedDB) on that device, with the speed and loops you saved on it. It is never sent anywhere: not uploaded, not read by a model the way a photographed page is, and it does not follow you to another device, signed in or not.
- Your stars, when signed out. Practice progress is kept in your browser until you choose to sign in.
- Your practice log. How long you practised, on which days, and on what is recorded in this browser’s own storage first, always. Signed in, it is also kept with your account so that the same week reads the same on your phone and your computer: the length of each session, the day, and which level, sheet, song or drill it was. That is all — no audio, nothing you typed, and nothing about the device beyond a random id it gave itself so that two devices’ logs can be merged without double-counting. Signed out, none of it leaves the browser and there is nothing to send it to. The printable record you can hand a teacher is built from the local copy in your browser and goes no further than your own printer or PDF. You can erase the whole log — this browser and your account, on every device — at any time from the bottom of the practice log page.
- A log of what this device did. Levels opened, runs and their scores, and settings you changed — the last few hundred, kept in this browser’s own storage so that a problem can be described precisely instead of guessed at. It holds the shape of your practice and never its content: no audio, and nothing you typed. No route accepts it. The Copy button in Settings hands it to you, and what happens to it after that is entirely your decision; Clear erases it.
- Your guided practice. The automatic session is worked out in your browser from your stars, your library and your practice log — no request is made to plan it, and what it decided you should work on is not sent anywhere. The session you are part-way through is kept in this browser so it survives moving between pages, and it is forgotten when you finish or end it. Whether the end-of-block alarm is on is remembered here too, on this device only.
What does leave
- Pages you photograph. The image is sent to our own server, read into notes and chords there by our own model, and the result is returned to you. It is not sent to any AI provider — no Anthropic, no OpenAI, nobody: the reading is done on our machines with weights we trained ourselves. We do not store the file either; it is read and dropped, and the only lasting copy is the one in your browser — unless you correct the read, which is the corrections item below.
- PDFs are the one exception. A PDF cannot be read by our own model yet, so a PDF you upload — and only a PDF — is passed to Anthropic’s API to be read into notes and chords, and is not stored by us either way. Anthropic’s own handling of that request is governed by their policies. Upload a photograph or a screenshot instead and nothing leaves our servers.
- Corrections you make to a read — and only then, the page. Checking a page line by line teaches the reader: each line you mark right, fix or skip is sent to the trainer and kept, and the page image goes with the first of them, so the reader can learn the books and the camera it got wrong. The review says so on the page before you start. That is the one case in which a photographed page is stored — never the mic, never a recording — and it is kept to train our own model, not sent to anyone else. Ask and it is deleted.
- If you sign in with Google: your email address, name, and profile picture, held by our authentication provider (Supabase) so the account exists across your devices. We request only basic profile scopes — no access to your Gmail, your contacts, or your Drive. Drive is asked for separately and only if you press the button for it, and even then only for files this app created (see below).
- If you sign in: a record of each finished exercise — which level, your score, and when. That is what makes stars follow you between devices.
- If you sign in: your sheets. The title, the book you filed it under, and the music read off the page are kept with your account, so a page you photograph on one device is there to practise on the other. The photographs themselves are not: they stay in this browser unless you connect Google Drive, below. Nor is your choice of which bars to leave out when you play it — that stays on the device you chose it on and goes nowhere. Deleting a sheet deletes it from your account too, on every device, rather than having it reappear on the next one.
- If you connect Google Drive — and only if you do. The photographed page (the first one, where a song runs over several) and any backing track you attach are uploaded to a folder called Good Ears in your own Google Drive, so they can reach your other devices without us holding them. They are yours: your storage, your quota, and files you can open, back up or delete without asking us. We ask for the narrowest Drive permission Google offers (
drive.file), which can only ever see files this app itself created — never the rest of your Drive, which we cannot read or even list. Connecting is a separate button in Settings and signing in never asks for it; leave it alone and nothing of yours goes to Drive at all. - If you sign in: your player settings — instrument, timing strictness, backing style, whether levels are unlocked, which way the level map is drawn, and light or dark screen — stored with your account so they follow you to your next device. Nothing else about how you practise is kept, and signed out they never leave this browser.
- Anonymous usage counts. So the author can tell whether anyone is using the app: the type of thing that happened (a visit, a level opened, an exercise finished), the level, the score, and a shortened one-way hash. While the app is open and in front of you it also ticks “still here” about every five minutes — that tick is the only way anybody can tell whether people spend real time in here rather than bouncing, and it stops the moment you switch away. A visit that arrived from a shared link says that much and nothing about who shared it. Requests that identify themselves as crawlers or link previews are dropped rather than counted — the browser name is read to decide that and never kept. No IP address, browser, or device information is stored, and the titles of your sheets are never sent.
- Suggestions you send. The suggestion box requires you to be signed in, and files what you wrote to the project’s private issue tracker on GitHub along with your account email, the page you were on, and the app version — so that someone can actually reply to you. Nothing is sent unless you write a suggestion and press Send.
- Basic traffic analytics via Vercel, the host, for page-view counts.
Deleting things
Clearing your browser data removes the library — songs, takes and all — this browser’s copy of the practice log, any session in progress, and any signed-out progress. The practice log also has a delete button of its own, which deletes the account’s copy as well as this browser’s so it cannot come back on the next sign-in, and a second one for the recordings alone; deleting a song deletes the takes recorded against it. To have an account and its practice history deleted, contact the author and it will be removed.
Children
Good Ears is not directed at children under 13 and no account is knowingly created for one.
Changes
If what this app does with data changes, this page changes in the same commit — a rule the project holds itself to, so that this page and the code never disagree.