Privacy Policy
Last updated: July 9, 2026
This Privacy Policy explains how Choreographic Pte. Ltd. (UEN 202415326W) (“Choreographic”, “we”, “us”, or “our”) collects, uses, discloses, stores, and protects personal data when you use Choreographic, including our mobile applications, websites, cloud services, account features, subscriptions, support, sharing, and realtime collaboration features (together, the “Service”).
If you have questions about this Privacy Policy or want to exercise a privacy right, contact us at privacy@choreographic.app. For general support, contact help@choreographic.app.
1. Scope
This Privacy Policy applies to the Service. It covers Choreographic apps for iOS and, where available, Android versions distributed through Google Play or other approved channels. It also covers our website pages, including Terms, Privacy, support, and product pages.
This Privacy Policy does not replace privacy notices from Apple, Google, RevenueCat, Supabase, Cloudflare, Mixpanel, Firebase, Framer, SMTP2GO, or other providers that process data under their own terms when you interact with their services, platforms, websites, app stores, payment systems, identity systems, or SDKs.
2. Summary
Choreographic is a choreography planning and collaboration service. Depending on how you use it, we may process account information, choreography files, crew and dancer information, audio and media files, collaboration records, access requests, local sync metadata, analytics, crash reports, subscription status, support messages, and transactional email data.
We use this data to provide the Service, keep your work synced, support sharing and collaboration, manage subscriptions, send transactional messages, troubleshoot issues, protect users and systems, comply with law, and improve Choreographic.
We do not sell your private choreographies, crews, audio, or choreography content. We do not use your private User Content in marketing materials without your separate permission. We do not send marketing emails unless we have a lawful basis to do so, such as your opt-in consent where required.
3. Personal Data We Collect
The personal data we collect depends on your device, account status, app version, platform, settings, subscription status, and the features you use.
Account And Authentication Data
We may collect and process:
- email address;
- name or display name, if provided or returned by an identity provider;
- user ID, account ID, Supabase Auth ID, and internal identifiers;
- authentication method, such as email one-time passcode, Sign in with Apple, or Google sign-in;
- session, token, and account-security metadata;
- email verification, sign-in, change-email, and account-recovery information;
- locale, country or region signals, time zone, platform, and app version; and
- account preferences and user settings.
Choreography, Crew, And Library Data
When you create, import, store, sync, or share content, we may process User Content and related metadata, including:
- choreography titles, folders, library items, thumbnails, access settings, and recently deleted status;
- formations, dancer positions, prop positions, stage layouts, paths, timing, notes, and editor state;
- crew names, dancer names, roster information, and assignments;
- media, audio files, trim settings, waveform data, file metadata, upload metadata, and storage keys;
- import data from supported legacy files;
- PDF or other export metadata;
- offline-sync metadata, pending operations, conflict data, sync checkpoints, outbox records, and change history needed to keep devices and cloud state coordinated; and
- records needed to preserve undo, offline edits, cloud sync, realtime coordination, and recovery from connection failures.
You are responsible for making sure you have permission to upload or share personal data about dancers, students, collaborators, crew members, or other people.
Sharing, Access, And Collaboration Data
When you share content or collaborate with others, we may process:
- collaborator user IDs, email addresses, display names, roles, and access levels;
- invitations, direct access grants, inherited access, share links, access requests, approval or rejection records, and access-change history;
- information about who owns an item, who can view or edit it, and who requested access;
- realtime collaboration session data, presence, connection state, edit coordination events, and sync notifications;
- records showing when content was created, updated, shared, accessed, or modified; and
- messages or transactional emails related to collaboration, such as requests for editing access.
Other users with access to shared content may see information necessary for collaboration, such as your name, email address, profile information, access level, edits, presence, or activity related to the shared item.
Device, App, And Local Storage Data
We may collect or process device and app data, including:
- device type, operating system, app version, build number, language, region, and device identifiers made available by the platform or SDKs;
- local database, cache, media, import/export, and offline-sync records stored on your device;
- network status and connectivity signals used for sync and recovery;
- push notification tokens or similar identifiers, if notification features are enabled in the future; and
- information needed to diagnose errors, crashes, performance issues, and sync problems.
The App may store data locally on your device so it can work offline and recover from network interruptions. Local data may include copies of account data, choreography data, media, pending edits, cached content, and files you import or export.
Subscription, Purchase, And Entitlement Data
If you use paid features, trials, subscriptions, promotional entitlements, or in-app purchases, we may process:
- product IDs, subscription status, entitlement status, trial status, renewal status, expiration date, cancellation status, and restore status;
- platform purchase metadata from Apple, Google Play where available, RevenueCat, and related platform systems;
- app account token, receipt, transaction, or subscription identifiers where made available by platform rules;
- subscription management links and records needed to maintain or restore access; and
- limited purchase-use or consumption information shared with Apple if you request an Apple refund and Apple asks for it after you provide required consent.
Apple, Google, and RevenueCat may process purchase, payment, tax, receipt, and subscription data under their own terms and privacy notices. We generally do not receive your full payment card details from app stores.
Analytics And Product Usage Data
We use analytics tools, including Mixpanel and RevenueCat, to understand how the Service is used, improve product quality, measure subscription flows, and diagnose product issues. We do not use advertising or attribution SDKs, and we do not use advertising identifiers to track you across other companies’ apps or websites.
Depending on your platform, permissions, and settings, analytics data may include:
- app opens, sign-ins, onboarding steps, paywall views, purchase attempts, subscription status changes, feature usage, export usage, and collaboration events;
- account identifiers, user IDs, email address after sign-in, app version, platform, country or region, language, and device signals; and
- product metadata such as counts or categories needed to understand feature use, for example choreography, formation, stage, dancer, or folder counts.
We do not need to inspect the creative substance of your private choreographies to operate normal analytics. Analytics events are limited to product and operational signals unless needed for support, security, or a feature you use.
Crash, Diagnostic, And Security Data
We may use Firebase Crashlytics and related diagnostic tools to collect crash reports, error logs, performance diagnostics, custom keys, device information, app state, and events leading up to a crash or failure.
We may also collect security logs, audit logs, rate-limit signals, abuse-prevention records, access-control records, and backend operational logs to protect accounts, content, collaborators, and systems.
Support And Communications Data
If you contact us or interact with support, we may process:
- your name, email address, account ID, app version, device details, and support history;
- the contents of your message and any attachments, screenshots, diagnostics, files, or logs you provide;
- records of abuse, privacy, intellectual-property, access, subscription, or data-rights requests; and
- replies and internal notes needed to resolve the request.
We also send transactional and service emails, such as one-time passcodes, sign-in messages, change-email notifications, access-request notices, collaboration notifications, account notices, and support replies. SMTP2GO may process transactional email data for delivery.
Website Data
When you visit our website or Framer-hosted pages, Framer and its hosting infrastructure may process basic technical data such as browser type, device type, IP address, request logs, and strictly necessary cookies in order to serve the pages, keep them secure, and prevent abuse. We do not run our own advertising or analytics tracking on the marketing website. If we add website analytics or non-essential cookies in the future, we will provide a cookie notice and obtain consent where required by law.
Profile Images
Profile image upload is not currently implemented in the app. If we make this feature available and you choose to upload a profile image, we may process that image, related metadata, thumbnails, and storage records so your profile can be displayed in supported account or collaboration features.
4. How We Collect Personal Data
We collect personal data:
- directly from you when you create an account, use the App, upload content, collaborate, subscribe, contact support, or use website forms;
- automatically from your device, app, browser, app store, operating system, and SDKs;
- from collaborators and other users who invite you, request access, share content, or add information about you;
- from Platform Providers and identity providers such as Apple and Google;
- from subscription and entitlement providers such as RevenueCat;
- from infrastructure, analytics, diagnostics, email, and security providers; and
- from logs and records generated when the Service operates.
5. How We Use Personal Data
We use personal data to:
- provide, operate, maintain, and secure the Service;
- create and manage accounts;
- authenticate users and protect account access;
- store, sync, back up, and recover choreography, crew, media, folder, access, and collaboration data;
- support offline editing, realtime collaboration, sharing, access requests, and permission controls;
- process imports, exports, audio playback, thumbnails, previews, and file operations;
- manage subscriptions, trials, entitlements, renewals, restores, refunds, and platform compliance;
- send transactional and service messages;
- provide support, troubleshoot bugs, investigate reports, and respond to requests;
- analyze feature usage, improve app quality, understand subscription flows, and plan product improvements;
- detect, prevent, and respond to fraud, abuse, security incidents, unlawful conduct, and policy violations;
- comply with legal obligations, platform rules, court orders, regulatory requests, and valid government requests;
- enforce our Terms of Use and protect the rights, safety, and property of Choreographic, users, collaborators, providers, and the public; and
- handle business administration, accounting, audits, disputes, and corporate transactions.
6. Legal Bases And Lawful Grounds
Where a lawful basis is required, we rely on one or more of the following:
- contract, to provide the Service and features you request;
- legitimate interests, such as securing the Service, improving product quality, preventing abuse, supporting users, and operating our business, where those interests are not overridden by your rights;
- consent, such as for certain tracking, marketing, permissions, or optional features where consent is required;
- legal obligation, where we must comply with law, tax, accounting, platform, consumer-protection, privacy, or regulatory requirements; and
- vital interests or public interest in rare cases where necessary for safety, security, or legal compliance.
If you are in Singapore, this includes collection, use, disclosure, and retention of personal data under the Personal Data Protection Act 2012 and related rules. If you are in the European Economic Area, United Kingdom, Switzerland, California, or another jurisdiction with specific privacy rights, additional rights may apply as described below.
7. How We Share Personal Data
We share personal data only as needed for the purposes described in this Privacy Policy, the Terms of Use, or as permitted or required by law.
Service Providers And Platforms
We use providers that help us operate the Service, including:
- Supabase for authentication, database, storage-related metadata, edge functions, realtime features, and backend services. Our current Supabase project region is us-west-1.
- Cloudflare Workers and Cloudflare R2 for API infrastructure, media and object storage, routing, security, and edge services.
- RevenueCat for subscriptions, entitlements, app-store purchase state, and subscription management.
- Apple for App Store distribution, StoreKit purchases, Sign in with Apple, platform services, app review, refunds, and Apple-related account or device services.
- Google for Google sign-in and, for Android versions distributed through Google Play, Google Play distribution, billing, subscription, platform, and Play services.
- Mixpanel for product analytics and usage measurement.
- Firebase Crashlytics for crash reporting and diagnostics.
- SMTP2GO for transactional email delivery.
- Framer for website hosting and related web infrastructure.
- Other infrastructure, security, support, legal, accounting, and professional providers needed to operate our business.
These providers may process personal data under our instructions, their own terms, or both, depending on the provider and the context.
Collaborators And People You Share With
If you share content, invite someone, request access, accept access, use a Share Link, collaborate, or participate in a shared choreography or crew, we disclose information needed to make that feature work. This may include your name, email address, profile details, access level, edits, shared content, activity, and collaboration state.
People with access to shared content may copy, export, screenshot, download, or further disclose information outside the Service. We cannot fully control data once another user has received it or exported it.
Legal, Safety, And Compliance
We may disclose personal data if we believe it is reasonably necessary to:
- comply with law, court order, subpoena, government request, regulator request, platform request, or legal process;
- enforce our Terms of Use or other agreements;
- detect, prevent, or address fraud, abuse, security incidents, payment disputes, technical issues, or unlawful conduct;
- protect the rights, property, privacy, or safety of Choreographic, users, collaborators, providers, Platform Providers, or the public; or
- establish, exercise, or defend legal claims.
Business Transfers
If we are involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar corporate transaction, personal data may be disclosed or transferred as part of that transaction, subject to appropriate protections where required by law.
8. Collaboration Visibility And Shared Content
Collaboration features require some information to be visible to other users. For example, a collaborator may see the choreography, crew, access level, edits, update history, presence or activity signals, and account information needed to identify participants.
Owners are responsible for granting appropriate access. Collaborators are responsible for respecting the access granted to them. If you remove yourself from shared content, or if an Owner removes you, your future access may stop, but previous copies, exports, screenshots, cached data, or downloads may remain outside our control.
If you believe shared content violates your rights, contains personal data that should not have been shared, or is being misused, contact help@choreographic.app or privacy@choreographic.app.
9. Marketing, Tracking, And Your Choices
We currently send transactional and service messages needed to operate the Service. We do not currently send marketing emails to users who have not consented. If we introduce newsletters, promotional emails, or promotional push notifications, we will provide notice and obtain consent where required by law.
You may be able to control analytics, notifications, and app permissions through your device settings, app settings, browser settings, or platform privacy controls.
We do not sell your personal data, and we do not share it for cross-context behavioral advertising or targeted advertising. We do not use advertising or attribution SDKs. If we introduce any advertising, attribution, or data-sharing that could be considered a “sale”, “sharing”, or “targeted advertising” under applicable privacy laws, we will update this Privacy Policy and provide the required opt-out or consent mechanism, including honoring recognized opt-out preference signals where the law requires it.
10. Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law, platform rules, accounting rules, tax rules, security needs, dispute resolution, or legitimate business requirements.
Current retention practices include:
- Account data is generally kept while your account is active and for as long as needed to provide the Service.
- Choreography, crew, folder, access, media, and collaboration data is generally kept while you or authorized collaborators maintain it in the Service.
- Individual library items deleted through the App may first be retained in a recently deleted or scheduled deletion state, currently for approximately 30 days, unless restored or deleted sooner through available features.
- Account deletion currently removes the Supabase Auth user through Supabase Admin APIs and causes related app database records tied to that user to be removed through cascading database relationships where configured.
- Media and object storage deletion may occur asynchronously, including through storage deletion queues and Cloudflare R2 cleanup processes. Failed or delayed deletion jobs may remain until retried or investigated.
- Certain sync and diagnostic records may be retained for limited operational windows. For example, sync-applied operation records are currently pruned after approximately 90 days, and some offline scope registration records expire after approximately 30 days.
- Support communications are generally retained for up to 24 months after the last interaction, unless we need to keep them longer for legal, security, accounting, dispute, abuse-prevention, or business-continuity reasons.
- Transactional email records, security logs, audit logs, crash reports, analytics data, and backend logs are retained for periods that depend on provider settings, operational needs, security needs, and legal requirements.
- Subscription, payment, refund, receipt, tax, and entitlement records may be retained by Apple, Google, RevenueCat, and other providers under their own policies. We may retain subscription-management records as needed for account support, entitlement verification, refunds, disputes, accounting, fraud prevention, and legal compliance.
- Backups may retain deleted data until the backup expires, is overwritten, or is no longer needed.
We cannot delete copies that are outside our control, such as files you exported, screenshots, downloads, device backups, copies held by collaborators, records held by Platform Providers, or records another user independently owns.
11. Account Deletion, Content Deletion, And Data Export
You may delete your account through the App where account deletion is available. Account deletion is intended to remove your account and associated app data that we are not legally required or otherwise permitted to retain.
Deleting your Choreographic account does not automatically cancel subscriptions managed by Apple, Google, or another Platform Provider. You must cancel those subscriptions through the relevant platform or subscription management flow.
You may delete individual content where the App supports deletion. Some content may remain temporarily in recently deleted, backup, cache, offline, sync, provider, support, security, or legal records as described in this Privacy Policy.
Choreographic does not currently offer a self-service full-account data export flow. You may export supported content through existing app export features, such as PDF or file export where available. You may also request a copy of your personal data by contacting privacy@choreographic.app, and we will respond where required by applicable law.
12. Your Privacy Rights
Depending on where you live and how you use the Service, you may have rights to:
- access personal data we hold about you;
- correct inaccurate or incomplete personal data;
- delete personal data;
- receive a copy of personal data or request portability;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- opt out of marketing;
- opt out of sale, sharing, or targeted advertising where applicable;
- appeal a privacy-rights decision where required by law; and
- complain to a privacy regulator or data protection authority.
To exercise a right, contact privacy@choreographic.app. We may need to verify your identity and account relationship before responding. If your request concerns shared content, collaborator data, school or studio data, payment records, app-store records, or provider-held data, we may need to coordinate with relevant users or providers, and some limits may apply.
13. Children And Minors
Choreographic content may be suitable for younger audiences, and app-store content ratings reflect that content suitability. Content suitability is separate from the legal capacity to create an account or agree to our Terms.
You must be at least 13 years old to create an account and use the Service. The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13 as account holders. If we learn that we have collected personal data from a child under 13 as an account holder without required parental consent, we will delete it. If you are between 13 and the age of majority (or the age of digital consent) in your country, you may use the Service only where a parent or legal guardian consents on your behalf where required by law.
A dancer, student, or other person named or described in choreography, crew, or roster data is a subject of that data but is not necessarily a user of the Service. If you are an account holder — including a choreographer, teacher, coach, studio, or organization — entering, uploading, sharing, or syncing personal data about another person, including a child or minor, you are responsible for having any permissions or consents required by law before you do so.
If you believe a child under 13 has created an account or provided personal data without required consent, contact privacy@choreographic.app so we can review and take appropriate action.
14. Security
We use technical, organizational, and administrative measures designed to protect personal data. These measures may include authentication, access controls, row-level access policies, encryption in transit, provider security controls, audit logs, monitoring, backups, and operational safeguards.
No app, network, storage system, or transmission method is completely secure. You are responsible for keeping your device, account, email address, and identity provider secure, and for sharing content only with people who are authorized to receive it.
15. International Transfers
Choreographic is operated from Singapore and uses service providers in other countries. Your personal data may be stored or processed in Singapore, the United States, and other countries where we or our providers operate.
Our current Supabase project region is us-west-1. Cloudflare, Apple, Google, RevenueCat, Mixpanel, Firebase, Framer, SMTP2GO, and other providers may process data in multiple countries according to their infrastructure and terms.
Where required by law, we use appropriate safeguards for international transfers, such as contractual protections, provider data-processing terms, and other lawful transfer mechanisms.
16. Third-Party Links And Services
The Service may link to third-party websites, app stores, identity providers, subscription management pages, support tools, or platform services. We are not responsible for the privacy practices of third parties that we do not control. Review their privacy notices before providing personal data to them.
17. Changes To This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice where required by law or platform rules, such as through the App, website, email, or another reasonable method.
The “Last updated” date shows when this Privacy Policy was last revised. Your continued use of the Service after an updated Privacy Policy takes effect means the updated Privacy Policy applies, subject to any rights you have under applicable law.
18. Contact
For privacy questions, requests, or complaints, contact:
Choreographic Pte. Ltd.
UEN: 202415326W
Registered address: Blk 374 Clementi Ave 4, #10-160, Singapore 120374
Privacy: privacy@choreographic.app
Support: help@choreographic.app