Privacy
Last updated: October 7, 2026
Accounts and Google sign-in
ScoreStarling uses Supabase to manage accounts. When you sign in with Google, we receive the Google identifier, email address and basic profile (such as your name and picture) used to identify your account. We only request basic identity permissions and never ask to read your Gmail, Google Drive or contacts. Signing in does not authorize us to access your other Google files.
Audio and scores
The audio you upload, the MIDI and scores generated from it, playback audio, exported files, revisions and notes are used to transcribe, edit, play, download and restore your work. Account ownership, job status, timestamps and usage records are used for access checks, processing jobs and usage limits.
Assistant connections
When you connect ScoreStarling to an assistant such as ChatGPT, Claude or Codex, we receive the requests it sends on your behalf, such as which score to open or which change to preview, and only the audio you ask it to transfer. We do not receive your conversation history. The assistant’s provider handles your conversation under its own policy.
Feedback
When you rate a transcription, we save your rating, any problems you tick and your comment, together with the score and revision you rated, so we can see which recordings our transcription handles poorly. If you tell an assistant what you think of a result, it may pass your words on to us; those entries are marked as relayed. Your comment and the problems you tick stay in our own database; our analytics only counts that a rating was given and whether it was good. Only if you tick “Let the ScoreStarling team listen to this recording and read the score” may our team play that one recording and read its score to improve transcription. An assistant cannot give this permission for you. We do not use shared recordings to train third-party models, and we would ask you separately before adding a recording to our test set.
Processing and storage
The app runs on Railway. Accounts and records are stored with Supabase, and your uploads, recordings and score files in a private Cloudflare R2 bucket. All three are placed in the eastern United States or eastern North America. Files may be cached temporarily on the application server while a job is processed. Private work requires your account’s authorization; anyone holding a temporary download link you obtained can access that file until the link expires.
Transcription with our built-in model runs on the application server. If you choose a band transcription, your audio is sent to our processor Mirelo, which uses the credits shown in the price you accept. Signing in with Google does not send your audio to Google.
Payments and billing messages
When you make a purchase, Stripe processes your payment details in its checkout, shown inside our Plans and credits page. We store your Stripe customer and purchase references, subscription status, credit grants of every kind (purchased, monthly, invitation and beta) with their expiry, task usage, the scores you unlocked and when, and payment adjustments to maintain your account balance. We do not store your card number. When billing email delivery is enabled, Resend sends payment confirmations and credit adjustments using your account email, purchase amount, credit allowance and expiry. Payment emails use our configured billing sender and replies reach our support inbox.
Invitations and beta codes
Every account has an invitation link made from a short code, and you can choose a display name to show with it. People who open your link, and a friend who joins with it, see that display name; if you leave it empty they see “a friend”. When someone joins with a link, we store the code, which account invited which, the invited account’s email address, when they joined, and, once they finish a first transcription, when the reward was granted, how many credits it gave and which score earned it. We use this to give each reward once, to keep to the limit of five rewarded friends per inviting account and to stop the same email address from joining by invitation twice. The inviting account sees how many friends joined and how many earned rewards, not who they are; when a friend’s first transcription earns the reward, we email the inviting account that both of you received credits, without naming the friend. When you redeem a beta code, we store which code, your account, your email address and the time, so that each account uses one code and the beta price is offered for 30 days. We also keep how many times each beta code has been redeemed, so we can tell which channels bring people. Our analytics also notes that a code was redeemed together with that channel label (a short name we chose, such as “discord”, or “referral” for a friend’s invitation link), never the code itself, your email address or who invited you.
Retention, trash and deletion requests
Your work and its revisions are kept so you can edit, restore and download it. Moving work to the trash hides it and revokes earlier download links, but does not permanently delete its files right away. There is currently no automatic retention cleanup or self-service permanent account deletion. To delete your account or work, contact the email below with enough information to confirm you own the account. We cannot recall copies you have already downloaded.
Browser and service logs
Your browser keeps you signed in with a secure session cookie that lasts up to an hour and a refresh cookie that renews it for up to seven days; short-lived cookies complete sign-in callbacks. Running the service requires processing network connections and error diagnostics. Please don’t share your account credentials or private download links in public.
Error reporting and usage analytics
We use Sentry to record exception types, code locations, app versions and job IDs without content, and PostHog to count public page visits, sign-ins, uploads, transcription results, score edits and previews, playback, recording, exports, meaningful assistant tool calls and feedback ratings (good or not, without tags or comments). We also count processing times, audio duration, output note counts and page counts. Accounts are counted with an identifier that does not reveal your email address; anonymous visits use a random visit cookie that lasts 30 days. A second 30-day cookie keeps two sources: how this browser first reached ScoreStarling and the latest site or campaign link that brought it back. A source is a public landing page and a coarse category, such as Google, Bing or an AI assistant; known sources use their domain only, and other referrers are grouped as other. From a campaign link we keep only its short source, medium, campaign and content labels (for example “youtube”, “video”, “october-launch”), never the rest of the address. When you create an account we save its first source with the account and keep it unchanged, together with the latest source, so sign-ups, scores, exports and confirmed payments can be counted by channel without creating person profiles. We do not send audio, score content, annotation text, email addresses, credentials, search terms, full referrer URLs or private download links to these services, and we do not enable session replay, automatic click capture or IP geolocation. An export event means a file was generated; a download-click event means the browser initiated saving it, not that the file was saved to disk.
Third-party services and contact
Google, Supabase, Railway, Stripe, Resend, Cloudflare, Webshare and any transcription provider you choose also handle the information their services need under their own policies. Resend delivers account and billing emails and processes the recipient address and message. Cloudflare stores your files and routes support messages to our support inbox. When a video site refuses our server, the download from a link you paste is tried again through Webshare’s proxies, which carry that connection and receive no account details. This page describes how ScoreStarling currently handles data and will be updated when features or providers change.
Account and privacy questions: support@scorestarling.com.