fluidentity.cc is a small set of web apps for music practice, notes, money and planning. This policy explains what we collect when you use them, why, where it's kept, who else sees it, and how to have it deleted. It's written to be read, not skimmed past — if anything is unclear, write to support@fluidentity.cc.
Who we are
fluidentity.cc is run by Aman Sangal, an individual in Pune, Maharashtra, India. "We" and "us" in this policy mean him. Under India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data described here.
- Contact: support@fluidentity.cc
- Postal address: Blue Ridge, Pune, Maharashtra, India
- Grievance officer: Aman Sangal, grievance@fluidentity.cc
The short version
- Most apps work without an account. Those collect nothing about you beyond what every website sees.
- With an account we keep your email, a username, and what you create in the apps. We never store your password.
- We don't sell your data, and we don't share it with anyone except the services listed under Other companies that see your data.
- Everything is kept on our own server in India.
- You can have your account and everything in it deleted by emailing us. It's done within 30 days.
What we collect
Your account
When you sign up we keep your email address, your username, and a salted hash of your password — a one-way scramble we can check a password against, never the password itself. If you sign in with Google, we keep your email and Google's ID for your account instead of a password, and we don't receive your Google password or anything else from your Google account.
You can add more email addresses to your account. We keep each one and whether you've confirmed it, and a confirmed address can sign you in and receive a password reset. One address is your primary: account emails go there, and it's the only one other people see, on support tickets and replies. If you change your primary address, we email the old one to tell you.
We also keep a record of each device you're signed in on, so you stay signed in for 7 days, and whether you've confirmed your email.
Your profile
Every account has a profile picture: a mandala drawn from a random number, or a photo you upload instead. A photo is cropped and shrunk in your browser before it's sent, which also removes the location and camera details phones store in photos; we keep only that small copy. Your picture and username appear next to what you write — for example on support tickets. You can change both on your account page, and removing a photo deletes it.
Each account also has a role: user, or contributor if we've asked you to help with support. The site owner is the admin.
What you create
Notes, files, saved loops, beats, expenses, tasks, support tickets — whatever you put into an app that needs an account is stored so the app can show it back to you. Only your account can open it; support tickets work a little differently, as explained below. Details per app are below.
"Online now" counts
The home page shows how many people and devices are online. To count them, most pages check in with our server every 5 minutes, sending an anonymous device ID, your IP address, which app is open, and your account if you're signed in. Each record is deleted about an hour after your last check-in. We use these records only to show the counts.
Server logs
Like almost every website, our web server logs each request: your IP address, the time, the page asked for, and your browser's name. We use the logs to fix problems and stop abuse. They're deleted after 14 days.
Support tickets
When you file a ticket on the Support page, we keep what you wrote, your username and email so we can reply, and your browser's name to help reproduce the problem. A copy is emailed to our support mailbox. Everyone can see a ticket's title, app and status, and the replies to it. What you wrote is visible only to you, to us and to our contributors; your email stays with us.
Replies on tickets are written by us and by contributors. They're public, with the writer's username, picture and role, and every earlier version of an edited reply stays visible. Anyone signed in can also see the writer's email address by hovering over their name.
What we don't collect
No payment details (nothing is sold yet), no location, no contacts, no microphone or camera recordings. The apps that use your microphone or a browser tab's audio — Spectrum Visualiser — process the sound in your browser, and when you choose to share it to a room, pass it through live without recording it.
App by app
What each app keeps, and where. "On your device" means your browser's own storage — it never reaches us, and clearing your browser's data for fluidentity.cc removes it.
Drum Metronome
- Account
-
Optional — only to save beats
- Your data
-
- On our server — your saved beats
- On your device — your Custom pattern, settings, and a draft of the beat you're editing
- Works with
-
None
Fretboard Quiz
- Account
-
Not needed
- Your data
-
- On our server — nothing
- On your device — quiz settings, streak and best time, in a browser cookie
- Works with
-
None
Ear Training
- Account
-
Not needed
- Your data
-
- On our server — nothing
- On your device — your settings and your accuracy scores
- Works with
-
None
Transcribe A–B Player
- Account
-
Required
- Your data
-
- On our server — your saved loops, beat-sync settings and where you left Transcribe-Flow, per song, and your Spotify sign-in if you connect Spotify
- On your device — nothing
- Works with
-
Spotify (Premium), YouTube, GetSongBPM, MusicBrainz
Markdown Editor
- Account
-
Required
- Your data
-
- On our server — your files and images, their history and trash. With encryption on, file contents are encrypted in your browser before they reach us; file and folder names are not.
- On your device — which folders you left open and your text size, kept in this browser only
- Works with
-
None
Cashcade
- Account
-
Required
- Your data
-
- On our server — your accounts, categories and transactions
- On your device — nothing
- Works with
-
None — nothing connects to your bank
TaskQueue
- Account
-
Required
- Your data
-
- On our server — your tasks in all four sections. Tasks are not encrypted. Text you paste into Add from a list is read to build the preview and is not kept — only the tasks you add are saved.
- On your device — which of Finished or DNF you left open
- Works with
-
None
Spectrum Visualiser
- Account
-
Not needed
- Your data
-
- On our server — nothing; shared audio is passed through live and never recorded
- On your device — nothing
- Works with
-
None
Visual Time
- Account
-
Required to connect your calendar — not for the demo
- Your data
-
- On our server — which Google account you connected, and Google's access token for it, encrypted. Kept until you disconnect or delete your fluidentity.cc account. Your events and tasks are read from Google each time the clock draws, and never stored
- On your device — nothing
- Works with
-
Google Calendar and Google Tasks (read-only)
Cookies and browser storage
We use a small number of cookies, all needed for the site to work:
- Sign-in — keeps you signed in for 7 days. Removed when you sign out.
- Device — a random ID kept for 1 year, used only for the "online now" counts. It isn't linked to you unless you sign in.
- Security — short-lived cookies that protect sign-in forms, "Sign in with Google", "Connect Spotify" and Visual Time's "Connect your Google Calendar" from forgery. They last 10 minutes or less, except Visual Time's, which is removed when connecting finishes, or when you close your browser.
- Fretboard Quiz — your quiz settings, streak and best time.
Some apps also remember preferences in your browser's local storage, such as text size, the last tab you had open, or a draft of a drum pattern. That data stays on your device.
We don't use cookies to track you across other websites. Google's services described below set their own cookies, which Google's own policy covers.
Advertising
The home page loads Google AdSense's code so Google can check the site. Ads aren't shown yet. Before they are, this section will be updated to say which pages carry them.
Visitors in the European Economic Area, the UK and Switzerland see Google's consent message on the home page, where they can consent, not consent, or choose what to allow. Google uses their data for ads only as they choose.
Once ads are shown:
- Google, as a third party, uses cookies to show ads based on your visits to this and other websites. You can turn off personalised ads at Google's Ads Settings, and learn how Google uses data from sites that show its ads at policies.google.com/technologies/partner-sites.
- Pages made for young learners will only request non-personalised ads, and we never use ads to profile children.
Other companies that see your data
We use these services. Each sees only what it needs for its part, and each has its own privacy policy.
- Google — Sign in with Google (your email and Google account ID); Google Calendar and Google Tasks for Visual Time, read-only, when you connect them; YouTube videos and search in the Transcribe A–B Player; the fonts on some pages; AdSense on the home page. See the Google Privacy Policy.
- Google API data (Visual Time): when you connect your Google account to Visual Time, it reads, read-only: the list of your calendars (their names and colours), the title, time and colour of the events on them, your tasks that have a due date, and your Google email address, so you can see which account is connected. It uses them only to draw your clock, which only you can see. We keep your Google email address and Google's access token, encrypted, so the clock keeps working; the events and tasks themselves are fetched from Google each time and never stored. None of it is shared with anyone, sold, or used for ads, and no person reads it. Disconnect Google in Visual Time removes our access at Google and deletes the token at once; you can also remove it from your Google Account's third-party connections. fluidentity.cc's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- YouTube — when you play a video in the Transcribe A–B Player, you're using YouTube's player and agree to the YouTube Terms of Service.
- Spotify — if you connect Spotify to the Transcribe A–B Player, Spotify tells us your Spotify account's ID and lets us control playback on your devices. We keep Spotify's sign-in token until you delete your account; you can also remove our access at any time from your Spotify account's Apps page. See Spotify's Privacy Policy.
- GetSongBPM and MusicBrainz — we look up a song's tempo, key and details by its title and artist. Nothing about you is sent.
- Namecheap Private Email — hosts our mailbox. Support tickets, account emails (confirming your email, resetting a password) and anything you write to us pass through and are stored on its servers.
Where your data is kept, and how it's protected
Everything is stored on our own server in India. If we ever move it to a cloud provider, or to another country, we'll update this policy and tell account holders by email first.
- In transit: every page and app is served only over HTTPS. Sign-in cookies can't be read by page scripts and are only sent over HTTPS.
- Passwords are never stored — only a salted hash made with scrypt.
- Markdown Editor encryption is your choice. Turn it on from your account page and pick how you'll unlock your files: this device (a passkey — your fingerprint, face or screen lock), a storage password, or a recovery key. Any one of them is enough, and you can add more later.
- With it on, we can't read your files. Your browser makes the key, encrypts each file before it's sent to us and decrypts it after it arrives. We only ever hold copies of the key that are themselves locked by your device, storage password or recovery key, and we can't unlock any of them. Your storage password and recovery key are never sent to us.
- What we keep for each way in: the locked copy of your key, the random values needed to unlock it, and for a device, the passkey's ID and the name you gave it.
- What isn't encrypted: file and folder names, file sizes and when you saved them. Files saved before you turned encryption on stay unencrypted until you save them again.
- It relies on the code we send you. Like any web app that encrypts in your browser, this is only as trustworthy as the page your browser loads from fluidentity.cc.
- If you lose every way in — your devices, storage password and recovery key — your encrypted files can't be read by you or by us. There's no way to recover them. Resetting your sign-in password doesn't affect them, because encryption has its own ways in.
- Everything else is stored unencrypted on a server that only we can access. That includes TaskQueue tasks, and Markdown Editor files if you haven't turned encryption on.
If a breach ever affects your personal data, we'll tell you and the Data Protection Board of India as the law requires.
How long we keep it
- Your account and what you've created: until you delete it or ask us to delete your account.
- Markdown Editor: the last 20 saved versions of each file, and deleted files in the trash until you empty it.
- TaskQueue: tasks stay in their section — Up next, In progress, Finished or DNF — until you delete them, and a deleted task is gone at once. Text pasted into Add from a list is used only to show the preview and isn't stored.
- Visual Time: your Google email address and encrypted access token until you disconnect, delete your account, or remove our access at Google. Events and tasks aren't stored.
- Signed-in devices: 7 days, or until you sign out.
- "Online now" records: about an hour.
- Server logs: 14 days.
- Support tickets: as long as the site runs, so fixed problems stay on record. If you delete your account, your name and email are removed from them.
Your rights
Wherever you live, you can ask us to:
- show you what personal data we hold about you and who we've shared it with
- correct or update it
- delete your account and everything in it
- export what you've created, where the app doesn't already offer an export
- stop using your data for anything you've agreed to
Write to support@fluidentity.cc from the email address on your account, so we know it's you. We'll reply within 30 days — usually much sooner.
Deleting your account: there's no delete button yet. Email us and we'll delete your account, everything you've created in every app, your profile picture, your connected Spotify, Google Calendar and Google Tasks access, your encryption keys and registered devices, and your "online now" records, within 30 days, then confirm by email. Support tickets are kept with your name and email removed.
Under India's DPDP Act you can also nominate someone to exercise these rights if you die or can't, and complain to the Data Protection Board of India if we don't resolve a grievance. In the EU or UK, you can complain to your local data protection authority.
Children
Anyone can use the apps that don't need an account — several are made for learning music, including for young players. They collect nothing about you beyond the "online now" counts and server logs above.
To create an account, you need to be 18 or have a parent or guardian's consent. If you're under 18, ask a parent or guardian to read this policy and the Terms and agree before you sign up. We don't knowingly track children's behaviour or show them ads based on it. If you think a child has an account without consent, write to us and we'll delete it.
Grievances
If you have a complaint about how we handle your data or anything on the site, write to our grievance officer:
- Name: Aman Sangal
- Email: grievance@fluidentity.cc
We acknowledge complaints within 24 hours and resolve them within 15 days.
Changes to this policy
When this policy changes, the date at the top changes. If a change affects what we do with data you've already given us, we'll email account holders before it takes effect.