← Back to Jamistry

Privacy Policy

Last updated: July 2026 · Controller: Bluepeak Works Ltd (trading as Jamistry) · hello@jamistry.com

1. What we collect and why

DataPurposeLegal basis (UK GDPR)
Email addressAuthentication (magic-link login)Contract performance
Skill level, genres, goalsPersonalise your practice contentContract performance
Activity logs (tab played, duration, score)Show your progress historyContract performance
Tabs you uploadStore and optionally share your contentContract performance
Ratings you give to community tabsCommunity quality rankingContract performance
Video/audio recordings you choose to shareCreate a private link to your recording (see §3)Contract performance
Jam Wall submissions (video clip, caption, credit, track name)Public showcase on the Jam Wall after review, and featuring in other Jamistry content (see §3)Consent
Social media handles (Instagram, YouTube, TikTok) you addCredit and tag you when your jam is featuredConsent
Feedback / bug reports you submitImprove the ServiceLegitimate interest
Usage events (feature used, duration, device type, a random device identifier, and an approximate country derived from your IP address)Understand how features are used, where they fail, and which countries players come from, so we can improve them (see §1a)Legitimate interest

We do not use tracking pixels, advertising networks, or third-party analytics. We do not sell your data, and we do not use your recordings to train machine-learning models.

1a. First-party usage analytics

To understand how the Service is used, we record basic usage events on our own servers — for example that a backing track was played, for how long, or that a recording was started. Each event carries a randomly generated device identifier stored on your device — in the browser's localStorage on the web, or the app's on-device storage in the Jamistry app — whether the device is mobile or desktop, and the platform (iOS/Android/desktop). This identifier is random — it is not derived from your device, does not identify you personally, and is not shared with anyone.

Approximate location. From the IP address your device sends when it contacts our servers, we derive an approximate location — the country only. The IP address is used solely for this lookup, which runs against an offline database on our own servers; it is then discarded. We store only the two-letter country code — never your IP address — and your IP is never sent to any third party for this purpose. The offline database is DB-IP Lite (© DB-IP, CC BY 4.0).

Recognising a returning device. Once you have signed in on a browser, we associate that browser's random device identifier with your account. This lets us recognise your activity on that browser in our analytics even during visits when you are not logged in. The association is derived only from your own past sign-ins on that browser, uses no cookies, and is deleted when you delete your account.

We do not use any third-party analytics service, advertising cookies, or fingerprinting, and events never include the content of your recordings. You can reset the identifier — and break the account association above — at any time by clearing your browser data for jamistry.com, or, in the Jamistry app, by deleting the app or your account.

2. Microphone

When you use chord detection or the tuner, the app (or your browser, on the web) asks for microphone access. Audio for those features is analysed entirely on your device using WebAssembly and is never transmitted to our servers. Recording yourself in JamLab is different — see §3.

3. Recordings & sharing (JamLab)

JamLab lets you record yourself playing; this captures your camera and microphone together with the backing track. By default these recordings stay on your device — you can play them back, download them, save them to your device's photo library, or share them directly from your device, and nothing is uploaded.

Phone share links. A recording is uploaded to our backend only when you choose "Get a phone share link" or submit it to the Jam Wall (below). For share links, the recording is converted to MP4 and stored on Amazon S3 in Stockholm, Sweden (within the EEA), so we can give you a private link and QR code to open it on another device. The link is unguessable, and the recording is deleted automatically about 24 hours after upload unless you also submitted it to the Jam Wall. Recordings shared this way are used solely to provide the share-link feature — never for analytics, advertising, or training machine-learning models. Recordings you submit to the Jam Wall are used as described below; we never use any recording to train machine-learning models. You can ask us to delete a shared recording sooner by emailing hello@jamistry.com.

Jam Wall. You can also submit a recording to the Jam Wall, Jamistry's public showcase. Submitting is always an explicit choice, confirmed in the submission dialog. Submitted clips are reviewed before anything is published: clips that are not approved are deleted automatically after about 5 days. Approved clips are displayed publicly on the Jam Wall — together with the caption, credit, and any social media handles you chose to add — and may also be featured in other Jamistry content, such as our official social media profiles (@PlayJamistry), promotional material, and educational content. Approved clips are kept until you ask us to remove them or we take them down; email hello@jamistry.com at any time and we will remove your clip.

4. Where data is stored

Your account, profile, and usage-analytics data (including the approximate country derived from your IP, and the device-to-account association described in §1a) is stored on a self-hosted Supabase instance running on a Hetzner server in Nuremberg, Germany. Recordings you choose to share (see §3) are stored on Amazon S3 in Stockholm, Sweden. Both locations are within the EEA; data transfers from the UK to the EEA are permitted under the UK adequacy regulations. No data is transferred outside the UK/EEA except as part of email delivery (see §5) and, where you have consented, Jam Wall clips featured in Jamistry content on external platforms such as social media (see §3).

4a. Purchases

In the iOS app, Premium is purchased through Apple's in-app purchase system. Payment is handled entirely by Apple: we never receive or store your card details, billing address, or Apple ID. What we do receive from Apple is a signed record of the transaction — transaction identifiers, the product purchased, the purchase date, and the store environment — which we store (see §4) linked to the Jamistry account it unlocks. We use this record solely to activate Premium on your account, to restore your purchase on a new device or account, and to process Apple-initiated refunds. Refunds themselves are requested from and decided by Apple, not us. If you delete your Jamistry account, the purchase record is kept but detached from any account — it contains no personal details beyond Apple's transaction identifiers, and keeping it is what allows the same purchase to be re-attached if you sign up again and use Restore Purchases.

On the web, purchases are processed by Lemon Squeezy as merchant of record: the checkout runs on their site, they handle payment, taxes, and invoicing, and we never see your card details. Lemon Squeezy notifies us of a completed order — the product purchased, an order reference, and the checkout email address — which we use to activate Premium on the matching Jamistry account (or to hold it for you until you sign in with that email). See Lemon Squeezy's privacy policy for how they handle payment data. Order history stays with Lemon Squeezy; we keep only the entitlement and order reference.

5. Email delivery

Login magic-links and OTP codes are sent via Brevo (formerly Sendinblue), whose servers are located in the EU. Brevo processes your email address solely to deliver authentication emails on our behalf. See Brevo's privacy policy.

6. Cookies and local storage

We store your session token on your device — in the browser's localStorage on the web, or the app's on-device storage in the Jamistry app — so you stay logged in, along with a random device identifier used for first-party usage analytics, which, once you sign in, we associate with your account on our servers so we can recognise your device between visits (see §1a). On the web we also use IndexedDB to cache the ONNX machine-learning model locally, avoiding repeated downloads. No third-party cookies are set.

7. How long we keep data

8. Your rights (UK GDPR)

You have the right to access, rectify, erase, or export your personal data, and to object to or restrict processing. To exercise any of these rights, email hello@jamistry.com. We will respond within 30 days. You also have the right to lodge a complaint with the UK supervisory authority: the Information Commissioner's Office (ICO).

Deleting your account. You do not have to email us to erase your data. Open the account menu — in the app or on the website — and choose Delete account. Your account, profile, activity and any Jam Wall clips you posted are erased immediately, while you wait. Full detail: Delete your account.

9. Children

The Service is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to this policy

We may update this policy. Material changes will be notified by email. The date at the top of this page always reflects the most recent version.

11. Contact

Jamistry is operated by Bluepeak Works Ltd, registered in England and Wales, company no. 17289177.
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
hello@jamistry.com
See also our Terms of Service.