Загрузка…
← Home

Legal documents

Personal Data Processing PolicyUser Agreement and Subscription TermsConsent to Personal Data ProcessingConsent to Advertising MessagesConsent to Data Distribution When Publishing a RecordingConsent to distribution of open profile data
Contents
1. Operator and scope2. Data, purposes and grounds for processing3. Cookies, local storage and analytics4. Microphone, MIDI and performance recordings5. Recipients and processing locations6. Retention and deletion7. Rights and enquiries8. Minors and security9. Changes to this policyOperator details and contact

VIBE PIANO

Personal Data Processing Policy

Version 2026-09-13.1-draft
View current versionVersion 2026-09-20.1-draftArchived versionVersion 2026-09-13.1-draftArchived versionVersion 2026-08-21.1-draft
Updated September 13, 2026
Archived versionView current version
⚠️ Draft. This document must be reviewed by a lawyer and is not final.

This version applies to the Russian Vibe Piano web service at https://vibepiano.ru. Changing the interface language does not change the operator or the applicable rules. The English and Chinese texts are translations of this version. The standalone iOS application has separate terms.

1. Operator and scope

Индивидуальный предприниматель Соболев Дмитрий Павлович, ОГРНИП 326508100266477, ИНН 501502113878 determines the purposes and methods of processing data concerning users, website visitors, people who contact us and participants in partner programmes. Contact: privacy@vibepiano.ru. This policy describes data processing; it does not in itself constitute consent to advertising, publication of a recording or automatic charges.

2. Data, purposes and grounds for processing

  • Account: name or display name, email if provided, avatar URL, the identifier and name of the chosen sign-in provider, an internal account identifier and session information. These are needed for sign-in, access management and saving preferences. The external account password and its OAuth tokens are not stored in the Vibe Piano database. The grounds are performance of the agreement and separately requested consent where applicable.
  • Learning: selected pieces, exercise results, questions, answers and response times, mistakes, streaks, achievements and practice history. These are used to track progress, provide feedback and adapt exercise selection. The principal ground is provision of the requested service features.
  • Subscription and access codes, if these features are enabled: plan, payment amounts, currencies, statuses and identifiers, access period, saved payment method token, promo code and information about credited amounts. These are needed for access, payments and settlements, refunds and compliance with legal obligations. The service does not receive the full card number or CVV; these are processed by the payment organisation.
  • Consent and abuse prevention: document type and version, the action and time of consent or withdrawal, source, account or consent-correlation identifier, IP address and browser information in the consent log. Certain evidence records use cryptographic derivatives instead of the original request details. These are needed to demonstrate the person's expressed choice, maintain security and protect legitimate interests.
  • Feedback: text of up to 2,000 characters, enquiry type, page path without parameters, application version and technical information shown before submission: window size, browser and operating system, language, MIDI devices and the current piece or lesson. An account identifier or a permitted analytics identifier is added where available. The feedback record does not include the IP address, full User-Agent, cookies or the contents of other screens. The purpose is to respond and resolve problems. An email enquiry also includes the sender's address and the information they provide.
  • Technical security: the connection IP address, time, HTTP request method and path, response code and processing duration may appear in server logs. These are needed for diagnostics, attack prevention and website operation; they are not advertising analytics.

Do not provide health information, biometric data or third-party data unless needed for your enquiry. The service does not use voice or performance to establish identity.

3. Cookies, local storage and analytics

Necessary cookies support sessions, remembering choices and evidence of consent. A random consent-correlation identifier in an HttpOnly cookie is not used for advertising and is valid for no more than 180 days. You can change your analytics choice in “Cookie settings”. Declining does not block the core features.

Language, theme, sound, metronome and some learning results are stored locally in your browser. These preferences have no automatic deletion period; you can delete them using your browser's controls. Deleting a web account does not clear local storage on your devices.

Without analytics permission, the service maintains aggregate counters using a predefined, limited set of metrics. To estimate daily visitor numbers, network data is processed in memory using a key that changes daily; the individual result is not stored as a visit record. This does not mean that technical server logs do not exist.

After separate permission, processing may include an analytics identifier, referral source and UTM tags, permitted interaction events and, for signed-in users, a link to their account. Yandex Metrica is connected only after this choice. Withdrawal disables further optional analytics; deletion of previously collected data is considered separately upon request. Aggregate counters are not used for personalised advertising.

4. Microphone, MIDI and performance recordings

The microphone is enabled at your request for local note recognition. Its stream is not uploaded to the server as an audio recording. MIDI transmits note events; device information may be included in an error report shown to you.

The recording feature captures the application's synthesised audio. Until publication, the recording stays on your device. Uploading and creating a public link occur only after a separate command. Publication requires separate consent to distribution.

The performance page contains audio, the piece title, composer and publication date. It does not display the account name, avatar or email. Anyone with the link can listen to, download and forward the recording; blocking search engine indexing does not make the link private.

5. Recipients and processing locations

The operator and persons authorised by the operator receive access to the extent needed for their tasks. Sign-in involves your chosen service: VK ID, Одноклассники, Mail.ru or Yandex ID. Loading an external avatar sends a request to the provider's infrastructure. Yandex Metrica is involved when analytics is permitted, and YooKassa when payments are enabled. These organisations have their own processing rules. Disclosure to public authorities is possible where there is a lawful ground.

When collecting Russian citizens' personal data over the Internet, the operator must comply with requirements for recording and storage in databases located in the Russian Federation. Cross-border transfers require a separate lawful ground and compliance with the statutory procedure. This policy does not declare all external services to be Russian and does not replace verification of the locations of hosting, backups, email and engaged processors. The actual list and processing locations must be confirmed by the operator before this version is approved.

6. Retention and deletion

  • The main profile, linked progress, enquiries and recordings are retained to operate the account; when it is deleted, associated user data is deleted subject to statutory exceptions.
  • Unlinked trainer history is deleted after 180 days; unlinked enquiries and old recordings without an owner after 365 days; aggregate counters and statistical structures after 400 days. Periodic deletion requires a functioning server job.
  • Unlinked request details in the consent log are cleared after 180 days. The event, choice, time and document version may be retained as evidence of lawful processing.
  • Payment documents, evidence of the accepted offer, obligations concerning partner settlements and cryptographic identifiers used to prevent repeated use of benefits may remain after account deletion if an independent lawful ground still exists. Pseudonymisation and unlinking from the account are not equivalent to complete destruction.
  • Detailed analytics events, retained anti-fraud registers, server logs and backups require separately approved retention periods and deletion procedures. A single rule that “everything is deleted with the account” does not apply to them; these periods must be agreed before this version is approved.

Deletion from the live system does not mean that previously created backups disappear immediately. Backups must have limited retention, protected access and a procedure for repeating deletions after restoration. Policy wording cannot replace these organisational measures.

7. Rights and enquiries

You may request information about processing, correction, blocking or destruction of data where statutory grounds apply, withdraw consent and challenge the operator's actions before Roskomnadzor or a court. Account settings provide server-data export, account deletion, management of published recordings and withdrawal of advertising consent. Export does not include files that remain only on your device.

Send your enquiry to privacy@vibepiano.ru, identify your account and describe your request. To protect against unauthorised requests, proportionate verification of identity or a representative's authority may be required; do not send a passport in advance. For enquiries without an account, provide enough information to locate your record.

Information requested is provided within 10 working days; the law permits a reasoned extension of no more than 5 working days. Requests to cease processing, correct or destroy data are fulfilled within the periods specified for the relevant ground in Articles 20 and 21 of Federal Law No. 152-FZ. Withdrawal of consent does not stop processing necessary under a contract or expressly required by law; the ground for retaining data is explained to the applicant.

8. Minors and security

An adult user, including a student's legal representative, sets up the account, gives consent and arranges payment. A separate verified system of child accounts is not provided. Acting as a representative does not grant the right to publish any other person's personal data without checking the necessary grounds.

Access restrictions, a secure connection, sign-in verification, data minimisation and logging of significant actions are used. Absolute security is not guaranteed; in the event of an incident, the operator fulfils response and notification duties within the statutory periods.

9. Changes to this policy

The version and date appear above the text. The archive provides access to previous texts. A new publication does not turn an old consent into consent to new purposes; a new expression of consent is requested where needed.

Operator details and contact

Индивидуальный предприниматель Соболев Дмитрий Павлович, ОГРНИП 326508100266477, ИНН 501502113878.

Address for written correspondence: 143180, Московская обл., г. Звенигород, Шиховский проезд, д. 1. Sole proprietor registration date: 29.04.2026.

For enquiries about data, access, payments and rights to materials: privacy@vibepiano.ru. Do not send your full card number, CVV, passwords or sign-in codes.

CreditsHome ↑