Privacy Policy
This policy explains what fluent.dance collects when you use the app, why, who processes it, how long it is kept, and what you can ask us to do about it. It is written from the app's own data inventory and describes exactly what the app does, nothing more.
The short version: the app works without an account. Anonymous use produces only pseudonymous identifiers. If you choose to sign in, we additionally keep your account record and the practice history you sync. We never see your name from a payment, your email address, or your payment details, we do not sell personal data, and there is no advertising.
Who we are
fluent.dance is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY] (“we”). We are the controller of the personal data described in this policy.
For privacy requests write to privacy@fluent.dance. For everything else, support@fluent.dance.
What we collect and why
When you use the app without signing in
- An app-user identifier. A random identifier created on first launch. It attaches your subscription to your device so purchases can be verified and restored, and it is what you quote to us when you exercise your rights. It is held by us and by RevenueCat, our subscription processor.
- An install identifier. A second random identifier sent with requests to our servers. It enforces the limit on how many devices can use one subscription at the same time, rate-limits abuse, and lets us trace misuse.
- Your IP address. Received by our servers and by the video delivery network whenever the app fetches content. Used for delivery and security only, and kept transiently in server logs.
- Your screen's aspect ratio. Sent when the app asks for a video so we can serve the edit that fits your display. It is a coarse device characteristic and identifies nobody.
- Playback positions, downloads and the media cache. Stored on your device only. They never leave it while you are anonymous, and deleting the app deletes them.
When you subscribe
Purchases are made through Apple's App Store or Google Play. The store handles payment and holds your purchase history under its own privacy policy. We receive, through RevenueCat, only confirmation of which plans your app-user identifier holds and when they renew or expire. We never receive your name, email address or payment details from a purchase.
When you choose to sign in
Signing in with Apple or Google is optional. If you do, we keep:
- An account record. Our own account identifier, the pseudonymous subject identifier your sign-in provider issues for our app, your display name as the provider supplies it, and, for Google accounts, the address of the profile photo Google already publishes, so the app can show it. We do not read or store your email address.
- Your synced practice state. Course picks, progress, practice-day streak and challenge state, so that they follow you to another device. On an anonymous device the same data stays local.
- Session credentials. A refresh token, stored hashed, so you stay signed in. It expires 180 days after last use.
The sign-in token your provider issues is verified once and discarded. Only the subject identifier, your display name and the photo address are kept.
When the app shows your Google profile photo it fetches the image from Google's servers, which reveals your IP address to Google, a processor we already rely on. Nothing of ours travels with that request.
Casting to a TV
On Android the app uses the Google Cast SDK to find and play on TVs on your local network; on iOS it uses AirPlay, which is part of the operating system. The name of the TV is shown on your phone and never sent to us. The Cast SDK reports its own pseudonymous telemetry to Google under Google's policy.
Crash reports
If the app crashes, a report containing the device model, operating system version and the install identifier is sent to Firebase Crashlytics so we can fix the problem. This is on by default because a working app depends on it. You can turn it off in Settings.
Usage analytics
To understand which features are used and to test changes, the app sends events such as “lesson opened” to PostHog, hosted in the European Union. Events carry only identifiers, categories and numbers, never free text, and are linked to the install identifier and, if you are signed in, to your account identifier. In the European Economic Area, the United Kingdom and Switzerland this is off until you turn it on; elsewhere it is on until you turn it off, in Settings.
We use no advertising identifiers, no cross-app tracking, no precise location, no contacts, and we collect no content you create.
Who processes it for us
- Apple and Google — payments, subscription management and, if you choose it, sign-in.
- RevenueCat — subscription status linked to your app-user identifier.
- bunny.net — video delivery; receives your IP address when streaming.
- Google — the Cast SDK's telemetry and the profile photo fetch described above.
- Google Firebase — crash reports.
- PostHog — usage analytics, hosted in the European Union.
- Render and MongoDB Atlas — hosting for our servers and database, in [HOSTING REGION].
Each processor acts under a data processing agreement with us and processes data only for the purposes above.
The legal bases we rely on
- Performing our contract with you for the subscription, entitlement and account data.
- Our legitimate interest in running a secure, working service for the install identifier, IP addresses, the device limit, and crash reports.
- Your consent for usage analytics where the law requires it. You can withdraw it at any time in Settings.
How long we keep it
- Device records used for the device limit are deleted after 90 days of inactivity.
- Server logs, including IP addresses, are kept for 30 days.
- Your account record and synced practice state are kept until you delete your account.
- Refresh tokens expire 180 days after last use.
- Crash reports are kept by Firebase for 90 days.
- Analytics data is kept for the shortest period that still answers our product questions, configured at the vendor.
- Subscription records are kept by RevenueCat and the stores under their own policies.
Your rights
Depending on where you live you can ask us to access, correct, delete or export the personal data we hold about you, and object to or restrict some processing. You also have the right to complain to your data protection authority.
- Delete your account yourself in Settings. This removes your account record and synced practice state from our servers and unlinks your subscription from the account. Your subscription itself continues through the store.
- Anonymous data is keyed by your app-user identifier, which you can find under Settings, About This App. Quote it when you write to privacy@fluent.dance so we can find and delete or export the records that belong to your device.
- Export is provided as a machine-readable file of the records above.
We answer within one month. Data held by the stores is requested from them directly.
International transfers
Our servers and database are hosted in [HOSTING REGION]. Where a processor handles data outside the European Economic Area we rely on [TRANSFER MECHANISM].
Children
The app is not directed at children. You must be at least 13 years old to use it, or 16 where the law of your country sets that age. We do not knowingly collect data from anyone younger; if you believe we have, write to us and we will delete it.
Changes to this policy
When this policy changes we update the version and date at the top and, for material changes, tell you in the app before they take effect. Previous versions stay available from this page.
Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY]. Privacy requests: privacy@fluent.dance. Support: support@fluent.dance.