Last updated 5 October 2026. This policy covers the Scorly app for Android and this website.
The short version
Scorly works without an account. Your scores, setlists, annotations and settings stay on your device. Three things can leave it, and you switch each on yourself: a backup, which goes to your own Google Drive; diagnostics, which carry no music, no titles, no file names and nothing you have typed; and, if you sign in to sync, who you are — your name and email address, held on Scorly's server in the EU. Signing in sends nothing from your library. There is no advertising, no tracking, no profile, and nothing is sold or shared for anyone else's purposes.
What Scorly keeps on your device
Everything the app is for: the score files you import, the pages it renders from them, your setlists, tags, annotations, and your settings. Imported files are copied into the app's own storage, so the library does not depend on where the original file was. This data is not sent anywhere, and uninstalling the app removes it.
Backup to Google Drive — optional
If you turn on backup, Scorly signs in to a Google account you choose, using Google's own account chooser. Scorly never asks for, sees, or stores your password.
- The permission asked for is the narrowest one that works — the
drive.filescope, which grants access only to files Scorly itself creates. Scorly cannot read, list, or alter anything else in your Drive. - Backups are visible in your own account, in a folder named
Scorly backup — DO NOT DELETE. They are yours: you can open the folder, count them, copy one to a computer, or delete them. - What is uploaded is one archive file containing your library — the score files, setlists, tags and annotations. It goes one way, from your device to your account. Nothing comes back unless you ask for a restore.
- Each backup is labelled with an identifier for the device and the installation that made it. These are generated by the app, identify a copy of the app rather than a person, mean nothing outside that folder, and are not sent anywhere else. They exist so that two tablets do not overwrite each other's backups, and so that a fresh installation cannot silently replace a backup it cannot account for.
- Signing out turns backup off and hands the Drive permission back. It leaves files already in your account alone — Scorly does not delete your files.
Once a backup is in your Drive, it is held under your own agreement with Google. Google's handling of it is described in the Google Privacy Policy.
Limited Use. Scorly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide and improve the feature you turned on — backup and restore, or signing in to sync; it is not transferred to anyone else, not used for advertising, and not read by a human except where you have asked for support with a specific problem, or where the law requires it.
Signing in to sync — optional
Sync will keep your library the same on every device you have. It is being built, and is in testing. Signing in is the only place Scorly asks who you are: it is never required, and nothing else in the app depends on it.
You sign in with Google, on Google's own screen. Scorly never asks for, sees, or stores your password. Google's screen says it will share your name, email address and profile picture — that is the fixed set Google shares for any app's Sign in with Google. Scorly keeps the name and the address. The link to the picture arrives inside Google's sign-in token; Scorly does not store it, show it, or use it.
What Scorly's server holds for your account
- An account identifier, random, made by the server.
- Your name, as Google gave it the first time you signed in.
- Your email address, as Google gave it the most recent time you signed in. It is shown back to you in the app and to nobody else, and it is never used to identify you.
- Google's identifier for your Google account, which is how the server recognises you the next time you sign in, and that the sign-in was with Google.
- When the account was made, and when each sign-in was first used.
- For each device signed in: a random identifier made by the app for that installation; the device's name as set in Android, or its model if it has none; when it signed in and was last used; and the keys that keep it signed in, stored only as one-way hashes that cannot be turned back into keys.
- Whether the account may use sync.
No part of your library is sent. Today the server holds no score, file, setlist, tag, annotation or setting. When sync starts to carry your library, this policy will say what it carries before that happens.
Where it is held, and for how long
The server runs on Cloudflare, acting as a processor for Scorly, and its database is restricted to Cloudflare's EU jurisdiction: it is stored in the European Union. Cloudflare is a US company. Requests reach the server through Cloudflare's network, which sees the IP address a request comes from in order to answer it; Scorly's server does not record it.
What the server holds is kept until you delete the account. A device that is not used for 90 days has to sign in again; its entry stays with the account until that device next reaches the server, or the account is deleted. Signing out removes that device's entry and no other — if the device is offline at the time, the entry lapses on its own after 90 days. The account stays.
Deleting your account
In Scorly, in Settings → Sync, choose Delete account. The account is deleted at once and for good — its name, address, Google identifier, devices and permission to sync — and every other device signed in to it is signed out the next time it is online. Nothing on any device is touched: your library stays where it is.
Two things outlast it, briefly. The one-way hashes of the deleted account's sign-in keys are kept, linked to nothing else, so that its other devices can be told the account was deleted; each is removed once the key it came from would have expired — at most 90 days after that device was last used. And Cloudflare's own recovery copies of the database hold earlier states for up to 30 days, after which the deletion is complete everywhere.
If you do not see a Sync section in Settings, or no longer have a device with Scorly on it, see Deleting your Scorly account.
Diagnostics — optional, and off until you say otherwise
Scorly can send anonymous usage and crash information, to find out which features are used and what breaks. It is off by default. Nothing is collected, queued, or held on the device before you consent. You are asked once, after a few reading sessions, and there is a switch in Settings. Declining costs you nothing — no feature is withheld, degraded, or nagged about.
What is never sent
This list is absolute. It applies to crash reports exactly as it applies to everything else, and there is no exception for shortening or hashing:
- No music and nothing from it — no page images, no thumbnails, no text taken from a score, no file contents, no content hashes.
- Nothing you typed or chose to name — no score title, alternative title, composer, key, tempo, instrument or notes; no setlist name; no tag name; no search text; no file name; no annotation, or where on a page it sits.
- No identity — no name, no email address, no Google account or cloud identity, no contacts, no advertising identifier.
- No location. Analytics services commonly derive a city or coordinates from the IP address a request arrives on; that enrichment is switched off. The only geography sent is a country code, asked of the device rather than inferred from an address.
- No free text of any kind. Every value sent is a member of a fixed list, a size bucket, or a true/false — there is no field a person could type into.
- A crash report carries the type of the failure and where in Scorly's own code it happened — never the error message, because a message is the one field that could contain the name of one of your files. A report that cannot be sent without such a fragment is dropped rather than trimmed.
What is sent
This is the complete list. Adding anything to it is a change to the app's published specification, not a setting that can drift.
| Event | When | What it carries |
|---|---|---|
app_opened | The app is opened | Phone or tablet; theme; country code |
library_summary | Once per opening | How many scores, setlists and tags, as size ranges |
score_imported | A file is imported | PDF or image; whether it succeeded; single or several |
score_opened | A score is opened | Whether it came from the library, a search, a setlist, or a file another app sent to Scorly |
reading_session_ended | You leave the reader | Pages turned and how long, as ranges; how pages were turned; whether zoom, rotation or full screen were used |
setlist_performed | A performance ends | How many pieces, as a range; whether it reached the end |
annotating_session_ended | You stop annotating | Pen, highlighter or both; whether anything was erased or undone; how many strokes, as a range |
search_performed | A search settles | Whether anything matched, and which field did — never what was typed |
feature_used | One of a fixed set of actions | Which action: pin, archive, lock, add to set, delete, rotate, and similar — never which score |
backup_run | A backup finishes | Manual or scheduled; whether it worked; the reason if not; size as a range |
restore_run | A restore finishes | Whether it worked, or was refused; the reason if not |
setting_changed | A setting is changed | Which setting, and which of its fixed values |
consent_granted | You turn diagnostics on | Where you turned it on |
error | A failure you were shown | A fixed error code, where it happened, and a fixed reason — whether it was our fault, your account, or your device |
deletion_requested | You turn diagnostics off | Nothing but the installation to delete |
| a crash | The app stops unexpectedly | The failure's type and where in Scorly's code it happened; app version, device model, OS version |
What every event also carries
Alongside the table above, each event carries nine facts about the app and the device it is running on. They are listed here rather than repeated in every row.
- The app's version and build number
- The device's make and model, and the version of Android on it
- The screen's width, height and pixel density
That is the complete list, and the app drops anything else the analytics library tries to attach — including its own session identifier, the device's name, and whether it has Wi-Fi or mobile data. The screen's size is there because Scorly decides how to lay out a page from it: whether two pages fit side by side is arithmetic on those numbers, and how many people have a screen that fits them is a question nothing else on this page can answer.
Where it goes, and for how long
Diagnostics go to PostHog, on its EU-hosted service, acting as a processor for Scorly. Events collected while you are offline wait on the device, for no longer than seven days, and are dropped if they cannot be sent.
Each installation of the app has a random identifier so that events from one device can be counted as one device. It is created by the app, is not derived from anything about you or your hardware, and is discarded when you turn diagnostics off.
Turning it off
The switch is in Settings, under Help improve Scorly. Turning it off stops collection immediately and permanently — you will not be asked again — and requests deletion of what was already sent for that installation. Reinstalling the app also starts you at off, with a new identifier.
This website
scorlyapp.com is a set of static pages served by GitHub Pages. It sets no cookies, embeds nothing from anywhere else, and runs no analytics. GitHub records server logs, including visitors' IP addresses, as part of serving the pages; see the GitHub Privacy Statement.
Your rights
Most of what you can ask for you can do yourself, immediately and without asking anyone:
- See or take your data — export your whole library to a file from Settings. If you signed in to sync, the Sync section shows the name and address the account holds; for a copy of everything listed above, ask us.
- Delete it — delete scores in the app, delete backup files in your own Drive, and uninstall to remove everything the app holds locally. If you signed in to sync, delete the account in Settings → Sync, or without the app.
- Withdraw consent — the diagnostics switch, which also requests deletion of what was sent.
- Ask us — for anything the above does not cover, write to support@scorlyapp.com.
Where the GDPR applies, the legal basis for diagnostics is your consent, which you may withdraw at any time; backup and sync are carried out to perform the features you asked for. You have the right to complain to your local data protection authority.
Children
Scorly is a tool for reading sheet music and is not directed at children. Without signing in to sync, it collects nothing that would identify anyone, of any age; signing in is never needed to use the app.
Changes
If this policy changes, the date at the top changes with it, and material changes to what leaves your device will be described in the app before they take effect.
Who this is, and how to reach them
Scorly is made by one independent developer, who is the controller of the little data described above. Everything — support, privacy questions, and any request under the rights listed here — goes to support@scorlyapp.com, and is read by the person who writes the app.