Last updated: June 2026
GraceNote is a chord chart app for worship leaders. This policy explains what data we collect, how we use it, and your rights.
Data we collect
- Your Google account name, email address, and profile photo URL (only when you choose to sign in with Google)
- Songs and sets you create
- App preferences
Google user data
GraceNote uses Google Sign-In (OAuth 2.0) to let you create an account and sync your data across devices. We access only the minimum information required.
When you sign in with Google, we receive and store:
- Your display name
- Your email address
- Your Google profile photo URL
How we use this information:
- Your name is displayed in the app to identify your account
- Your email address links your songs, sets, and preferences to your account, and may be used for product updates if you opt in
- Your profile photo is shown as your avatar in the app
How we protect this data:
- Stored securely in Supabase (EU servers, encrypted at rest)
- Never shared with any third parties
- Never used for advertising or marketing
- Never used to train AI or machine learning models
Retention and deletion:
- Your Google account data is kept for as long as your GraceNote account exists
- Deleting your GraceNote account permanently removes all associated Google data within 30 days
Your rights:
- Revoke GraceNote's Google access at any time: myaccount.google.com/permissions
- Delete your GraceNote account at any time: Settings → Delete account
OAuth scopes we request (minimum required):
- openid — to verify your identity
- email — to retrieve your email address
- profile — to retrieve your name and photo
We do not access your Google Drive, Gmail, Google Calendar, or any other Google service.
Data we do NOT collect
- We never sell your data
- We never share your data with third parties
- Songs stay private to your account
Data storage
- Your data is stored securely in Supabase (EU servers)
- You can delete all your data at any time via Settings → Delete account. Deletion is permanent and completed within 30 days.
Third-party services
- Google Sign-In (OAuth 2.0) — used for authentication only. Google's Privacy Policy
- Supabase — used for secure data storage (EU servers).
Product updates
With your permission, we may send you occasional product updates and feature announcements. You can change this preference at any time in Settings.