Privacy Policy
This Privacy Policy explains what information TuneLocator ("the Service", "we", "us") collects, how it is used, and the choices you have. The short version:
1. Information we collect
- Account information. When you sign in with Google we receive your name, email address, and profile photo from Google. When you create an account with email and password, we store your email address; your password is handled and stored by Google Firebase Authentication — we never see it. We may send a verification email to confirm your address.
- Your uploaded files. PDF books you upload are stored in your private storage area so the Service can display them back to you. We also store basic metadata about each upload (file name, page count, size, upload date).
- Payment information. Subscriptions are processed by Stripe. Your card details go directly to Stripe and never touch our systems. We store only your subscription status and plan tier.
- Technical data. Our infrastructure provider (Google Firebase) automatically logs standard technical information such as IP addresses and request timestamps to operate and secure the Service.
- Local device storage. To avoid re-downloading, the Service caches your own books in your browser's local storage (IndexedDB) on devices you use. This data stays on your device and can be cleared at any time with the "Clear device cache" button in My Books.
2. How we use your information
- To operate the Service: authenticate you, store and display your books, and remember which books you've uploaded.
- To process subscription payments and apply your plan's limits.
- To secure the Service, prevent abuse, and debug problems.
- To respond when you contact us for support.
We do not sell or rent your personal information, use your uploaded files for anything other than serving them back to you, or share your files with other users.
3. Who can see your files
Your uploaded books are private to your account, enforced by server-side security rules: only a request authenticated as you can read, replace, or delete your files. Other users of the Service cannot access them.
4. Service providers
We rely on the following processors to run the Service:
- Google Firebase (Google LLC) — authentication, file storage, database, and hosting. Firebase privacy
- Stripe — subscription payments. Stripe privacy
5. Data retention and deletion
- You can delete any uploaded book at any time from My Books; deletion removes the file from our storage.
- You can clear locally cached copies from your own devices at any time.
- You can permanently delete your entire account and all associated data yourself at any time from Settings → Delete account. This immediately removes your uploaded files, your stored metadata, and your sign-in account. Some records may be retained where required for legal or accounting reasons (e.g. payment records held by Stripe).
6. Security
All traffic is encrypted in transit (HTTPS). Files and data are stored on Google Cloud infrastructure with per-user access rules. No method of storage is 100% secure, but we limit access strictly to your own authenticated requests.
7. Children
The Service is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
8. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the effective date above. Continued use of the Service after a change means you accept the updated policy.
9. Contact
Questions or requests: ias@statsias.com