Last updated: 28 August 2026
Your practice data never leaves your device. MIDIMIDI stores your songs, recordings, practice history, profiles and settings in your own browser — not on our servers. We hold only what a paid account strictly requires: your email address, a hashed password, and your subscription status.
Running a subscription service requires an account, so our server stores exactly this and nothing more:
That is the complete list. Our user database contains no practice data, no songs, no recordings, no statistics, and no usage or behavioural history of any kind.
Everything you actually create or import lives in your browser's local storage and IndexedDB, on your own computer:
None of this is transmitted to us, and we have no copy of it. That also means we cannot recover it for you — see the backup note in our Terms of Use.
Payments are processed by Stripe. Your card details are entered on Stripe's own checkout page and are never sent to, seen by, or stored on our servers. Stripe processes your payment information as an independent controller under its own privacy policy, available at stripe.com/privacy. Stripe tells our server only whether your subscription is currently valid.
We set a single cookie: a signed session token that keeps you logged in for 30 days. It is httpOnly (unreadable by scripts), sent only over HTTPS, and used solely to recognise your login. We use no advertising, analytics or tracking cookies. Logging out deletes it.
The app makes no third-party requests while you use it. Fonts, piano samples and all code are served from our own domain — including the typeface, which is self-hosted specifically so that loading MIDIMIDI does not disclose your IP address to a font provider. The only third parties involved in the service at all are:
We have never sold or shared personal data, and we do not use it for advertising or profiling.
We keep your account record for as long as your account exists. Ask us to delete it and we remove it from our database; Stripe separately retains payment records for the period its own legal and accounting obligations require.
You can ask us to access, correct, export or delete your account data at any time by emailing us. Depending on where you live, you may have these rights under the GDPR, the UK GDPR, the CCPA, or Mexico's Ley Federal de Protección de Datos Personales. We will respond within any period the applicable law requires. Your practice data needs no request — it is already on your device, and clearing the site's browser data erases it completely.
MIDIMIDI is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has created an account, contact us and we will delete it.
If we change how we handle your data, we will update this page and change the date above before the change takes effect. If a future version ever stores practice data on our servers — optional cloud backup, for instance — it will be opt-in and disclosed here first.
Questions about privacy or your data: support@midimidi.app