Effective date: [EFFECTIVE DATE]
Version: v1.0
Controller/handler: [DANCORA LEGAL ENTITY]
Privacy contact: [PRIVACY CONTACT]
This Privacy Policy explains how we process personal information in connection with Dancora. It does not replace the privacy notices of Apple, Google, Photos, Camera, an app store, or a destination you choose for sharing.
1. Information we process
| Category | Examples | Current purpose and location |
|---|---|---|
| Account and sign-in information | email, optional name, password hash, persistent Apple/Google identifier and verified contact email provided by them | account creation and management, authentication, and session protection; account-service database and device secure storage |
| Session and security information | server-side hash of a session token, expiry, and technical data necessary for login/rate limits | keep you signed in, detect abuse, and protect accounts |
| Practice content and state | media you select, recorded takes, selected ranges, speed, loops, timing, thumbnails, and practice names | stored locally on the device by default for playback, practice, recording, and history |
| Permission-related information | whether you grant Photos/files, Camera, or save-to-Photos permission | invoke the relevant system capability only when you ask to import, capture, or save |
| Support communications | messages, questions, and attachments you voluntarily send | respond, troubleshoot, and maintain the Service |
We should not upload your practice videos, recorded takes, or on-device practice state to the account service without a separate disclosure. The current build should not track you across apps or websites for advertising. If analytics, advertising, cloud sync, remote media processing, or another SDK/processor is introduced, the provider must first update this Policy, the data inventory, and any consent flow required by law.
2. How we use information and legal bases
We process information to provide, maintain, secure, and improve the Service you request, including signing you in, retaining local practice, responding to support, and preventing abuse. We rely on your system permission when a permission is needed. We will obtain consent where applicable law requires it for optional remote processing or non-essential processing. We may also process what is necessary to comply with law, resolve disputes, enforce these Terms, or protect the safety of users and the Service.
3. Sharing and disclosure
We do not sell personal information. We share only as necessary with:
- Apple or Google sign-in services you choose, to authenticate you;
- service providers bound to process data for us, but only where listed in the pre-release processor inventory;
- system sharing, Photos saving, or external services you intentionally select;
- authorities or others where law, legal process, rights protection, safety, fraud prevention, or security reasonably requires it; and
- others with your separate consent.
If a merger, financing, reorganisation, or asset transaction occurs, we will provide notice where required and use reasonable safeguards. Recipients must be required to provide protection appropriate to this Policy and applicable law.
4. International transfers
Account, authentication, or future processing services can involve a cross-border transfer. Before release, the provider must list the recipient, destination, categories, purpose, retention period, contact details, and transfer safeguards here: [CROSS-BORDER TRANSFER SCHEDULE]. We will obtain separate consent or use another lawful transfer mechanism where required.
5. Retention and deletion
- Local practice media, recordings, and history generally remain on your device until you delete them in the app, Photos/files, or uninstall the app, subject to operating-system backup and storage behaviour.
- Account information is retained while an account exists. The current implementation allows an active session for up to thirty days, and it becomes invalid on logout, revocation, expiry, or account deletion. Before release, the provider must state concrete log, backup, and legal-retention periods:
[RETENTION SCHEDULE]. - When you delete an account in the app, we delete or anonymise account personal information that is no longer needed, except the minimum information required by law, dispute handling, fraud prevention, or security. We do not remotely erase files that remain on your device or at a third-party destination.
6. Your choices and rights
Where applicable law provides them, you can request access, correction, deletion, copying, export, restriction, withdrawal of consent, or objection to certain processing. You can change permissions in device settings; withdrawal does not affect processing that was lawful before withdrawal. Send requests to [PRIVACY CONTACT]. We may verify identity to protect the account and respond within the time required by law. You may also complain to the competent data-protection authority.
7. Security
We use risk-appropriate technical and organisational measures such as password hashing, protected session storage, access controls, and transport protection. No system is perfectly secure. Use a device lock, protect credentials, and make careful choices before saving media to Photos or sharing it with a third party.
8. Children
Dancora is not directed to children below [MINIMUM AGE]. If we learn that we processed a child’s personal information without required guardian consent, we will take the action required by law, including deletion where appropriate. Before launch to Mainland China users under fourteen, the provider must establish a dedicated rule and obtain guardian consent where applicable.
9. Changes and contact
We will update this page and its effective date when this Policy changes, and give reasonable notice of material changes. Contact [PRIVACY CONTACT] or [ADDRESS] about privacy, data rights, or account deletion.