TYPE-02 Early access

LEGAL · PRIVACY

Privacy Policy

LAST UPDATED 2026-10-04 · REV 10

This policy covers TYPE-02, the music discovery app made by Type Studio. TYPE-02 shares its account system with the Type Studio app, so the account, credit, and run data described here is the same data that app uses.

What TYPE-02 collects

TYPE-02 only sees what a user gives it while using the app.

Account. A user signs in with an email address and password through Supabase Auth. Supabase stores the account (a user id, the email, and the password in hashed form) along with the version of the terms and this policy the user last accepted.

Runs. When a user starts a Mini or Max run, the backend stores a run record keyed to their user id: what they searched for, the song they picked, the run's status, and when it ran. That record is what lets their run history follow them across devices.

Results. A finished run's analysis and recommendations are stored per song, not per user, so a later run of the same song by anyone can reuse or update that stored result. The stored result describes the song and contains nothing that identifies a user. When a user refines a Max result in chat, the rebuilt batch of recommendations is saved into that song's result.

Credits and subscription. The user's credit balance, their credit transactions, and whether Type Pro is active are stored with their user id.

Logs and error reports. Google Cloud keeps standard request logs for the backend (IP address, user agent, time, and response status). Type Studio reads them only to debug and protect the service. When the app or the backend hits an error, an error report goes to Sentry with the error, the app version, and device and operating-system details. Error reports are configured to leave out personal details such as the user's email.

On the device. The app keeps the user's sign-in session in the platform's secure storage (the Keychain on iOS and macOS, the Keystore on Android) so they stay signed in. The Liked list and a note of which terms the user accepted are stored on the device. The Liked list is never sent to Type Studio's servers.

TYPE-02 runs no advertising and no analytics, advertising, or attribution SDKs, and it sets no cookies.

Who TYPE-02 shares data with

Google Cloud. Vertex AI (Gemini) writes the analysis and recommendations. For each run, the backend sends Gemini text: the song the user picked, candidate songs and tags gathered from music services, and any refinement note or Max chat message the user typed. TYPE-02 sends Gemini no audio and doesn't send it the user's name or email. Google Cloud also hosts the backend (Cloud Run), the run records and credit records (Firestore), and the stored results (Cloud Storage).

Music services. To search the catalog and fill in song details, the backend sends song and artist names to Apple Music, Last.fm, Deezer, iTunes Search, and Spotify. Spotify is reached only with Type Studio's own app credentials; the app never signs a user in to Spotify or Apple Music. These requests carry nothing that identifies the user.

Some requests go straight from the device to these services instead of through the backend. Playing a 30-second preview streams it from Apple's or Deezer's servers, and cover art loads from those services. When the backend has no preview for a song, the app asks iTunes Search for one, and when the backend's song search fails, the app searches Last.fm directly. Those requests show the service the device's IP address and the song being looked up. Opening a song on Spotify, Apple Music, or Last.fm leaves TYPE-02 for that service, and its own privacy policy applies.

Sign-in, payments, and error reporting. Supabase handles sign-in and stores the account. RevenueCat confirms whether Type Pro is active using the user's account id and the purchase token the store issues. The Apple App Store or Google Play processes payment. Sentry receives the error reports described above.

Type Studio never sends any of these providers a user's password.

What TYPE-02 doesn't do

Type Studio doesn't sell a user's data, share it for advertising, or show ads in the app, and it doesn't transfer data to anyone outside the providers named above. It doesn't train any model on a user's data. Google Vertex AI operates under its own retention policy for API traffic, which a user should review on Google's site if that matters to them. As of this date, Google Cloud's terms state that customer data sent through Vertex AI is not used to train Google's foundation models.

Where a user's data is processed

TYPE-02's backend, run records, and stored results are on Google Cloud in the United States. Supabase, RevenueCat, Sentry, and the music services process requests on their own infrastructure, which may be in the United States or elsewhere. If a user opens the app from the European Economic Area, the United Kingdom, or another region with cross-border transfer rules, their data is transferred to and processed in the United States. Type Studio relies on each provider's standard contractual clauses (or an equivalent transfer mechanism) for that transfer, and each provider's own privacy terms govern the data it receives.

Payments

Type Pro is sold and processed by the Apple App Store or Google Play, depending on the platform. Type Studio never sees or stores a user's card or payment details, because the store handles the entire transaction. RevenueCat sits between the store and Type Studio's backend to confirm whether a subscription is active; it receives a store-issued purchase token and the user's account id, not the payment method. Apple, Google, and RevenueCat each handle that data under their own privacy policies.

Retention

Run records stay until the user deletes the run or their account. Deleting a run removes the user's record of it, and also removes the song's stored result if no other user has a run of that song. A run that stops responding is marked as failed after a few minutes and stays in the user's history until they delete it.

Credit and subscription records stay as long as the account exists.

Delete Account (under Settings, Manage Account) removes the user's run records, credit and subscription records, and profile, and deletes the sign-in account from Supabase, for TYPE-02 and the Type Studio app alike. Stored per-song results that other users' runs also rely on are kept, since they contain nothing that identifies the user. Backend logs and error reports expire on Google Cloud's and Sentry's standard retention schedules.

The Liked list and other on-device data stay on the device until the user removes them or deletes the app.

A user's rights

A user in Canada has the right under PIPEDA to ask what personal data Type Studio holds about them, to correct it, and to have it deleted. A user in the EU or UK has the same rights under the GDPR, plus data portability and the right to object to processing. A user in California has the right under the CCPA to know, to delete, and to opt out of sale, which is moot here because Type Studio doesn't sell data.

To exercise any of these, a user emails [email protected] from the address they signed in with. Type Studio responds within a reasonable time, which usually means within the same week.

Children

TYPE-02 is not directed at children. It doesn't knowingly collect data from anyone under 13, or under 16 in the European Economic Area. If someone believes a child has signed up, they contact Type Studio and it deletes the account.

Changes to this policy

When this policy changes, the "Last updated" date at the top of this page changes, and for a material change the app asks the user to review and accept the updated policy before they continue.

Contact

Email [email protected] with any privacy question, a data-export request, a deletion request, or anything else covered here. See also the terms of use.