Privacy Policy

Last updated: 9 September 2026

On-device by default

Handpan is built so Pan Health Check, the scale explorer, lessons, tabs, sessions, and local progress can work on your device without an account.

Microphone

The microphone is used when you start Pan Health Check, scale detection, or practice grading. That microphone audio is analyzed on your device and is not saved as a recording or sent to us. The separate Record control on the Play screen records the virtual handpan’s own sound, not the microphone. Those recordings are saved on your device; you can listen, rename, or delete them in Recordings.

Coach

Session plans are created on your device from the goal, experience level, scale, and session length you choose. You do not need to sign in. The current release does not send these choices to our service, DeepSeek, or another AI provider.

Purchases and accounts

Subscriptions and restoration are handled by Apple StoreKit. Optional Sign in with Apple links an account to server-verified purchases. We store Apple’s app-specific account identifier, a name if supplied, and account session records. Apple authorization tokens are encrypted before server storage so we can remove Apple access during account deletion. The app stores its session in the device Keychain. Signing in does not upload your tabs, tuning history, or recordings.

To prevent reuse of an Apple sign-in credential, we keep a one-use fingerprint of its signed contents separately from your account. This record contains neither the raw credential nor your Apple account identifier. The fingerprint blocks reuse for the credential’s accepted lifetime, at most 10 minutes. Account deletion does not remove it early. Scheduled cleanup removes expired fingerprints; physical removal can happen after expiry.

No ads or trackers

We do not add advertising SDKs or third-party tracking SDKs.

Saved data and deletion

The current app has no recording-upload or recording-sync control. Its saved recordings, tabs, and practice history stay on your device. Our service retains any account data or recordings previously sent through its authenticated sync and upload endpoints until you delete that account.

Delete account in You removes the account’s synced data and uploaded recordings. When we hold an Apple authorization token, we revoke it before completing deletion. If an older account has no saved Apple token, we still delete its data and show how to remove Handpan from Sign in with Apple in your Apple Account settings. A failed deletion remains available to retry.

For accounts that used cloud uploads, or whose earlier upload use is unknown, we finish removing uploaded recordings before confirming deletion. If recording storage is unavailable, deletion remains available to retry. New accounts that have never used cloud recordings can be deleted without accessing recording storage.

Deletion does not remove local recordings, tabs, or practice history from your device, and it does not cancel an App Store subscription. We retain minimal transaction identifiers, product, status, and purchase environment for purchase records; they are separated from the deleted account and have no automatic deletion deadline. A deletion receipt and revoked session records are kept briefly so a lost server response can be retried. Scheduled cleanup removes them once they are at least 24 hours old.

Small account-linked usage counters enforce service and abuse limits. New counters expire within 24 hours of creation and are scheduled for automatic removal at expiry; removal can be delayed by service availability. This schedule does not establish that older counters have been removed. Account deletion does not reset that brief limit window.

Contact

Contact us through Handpan support.