Privacy Policy#
Leftoak Labs, LLC
Effective Date: August 23, 2026
1. Introduction#
Welcome to Leftoak Labs, LLC ("Leftoak Labs," "we," "us," or "our"). Leftoak Labs develops and operates web applications and digital services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our websites and applications (collectively, the "Services").
This Privacy Policy applies to all Services operated by Leftoak Labs. Certain Services may collect and process data in ways specific to their functionality. Where this is the case, we provide an Application-Specific Addendum at the end of this policy that describes those additional practices. The applicable addendum is incorporated into and forms part of this Privacy Policy.
Current addenda:
- Addendum A: fretengine (guitar instruction and practice tools)
We are committed to being transparent about the data we collect and how we use it, and to respecting the privacy rights of all our users regardless of location. Our Services are built and operated in the United States and are primarily intended for a US audience, though we do not restrict access based on geographic location.
By accessing or using any of our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy and any applicable addendum. If you do not agree, you must not use the Services and are prohibited from doing so.
2. Who Is Responsible for Your Data#
The entity responsible for your personal data is:
Leftoak Labs, LLC Email: support@leftoak.com
3. Personal Data We Collect#
The specific personal data we collect depends on which Service you use and how you interact with it. Across our Services, we may collect the following general categories. Refer to the applicable addendum for details on exactly which data a particular Service collects.
3.1 Data You Provide Directly#
- Account Information: When you create an account through a third-party authentication provider, we receive and store your user identifier, email address, display name, and email verification status. Authentication is passwordless (email link sign-in) and managed entirely by the third-party provider. No passwords are created or stored.
- User Content: Content you create or input within the Services, such as session names, configuration settings, chat messages, or other user-generated data as described in the applicable addendum.
- Payment Information: When you make a payment through our Services (such as a voluntary payment or subscription), you provide payment information directly to Stripe, our third-party payment processor. Stripe supports a variety of payment methods as described on their platform. We do not collect or store payment card details on our servers. We store limited subscription-related identifiers (such as customer and subscription IDs from the payment processor) to manage your account entitlements.
- Communications: If you contact us for support or provide feedback, we may collect the content of those communications.
3.2 Data Collected Automatically#
- Analytics and Usage Data: Page views, feature interactions, click events, and session behavior, collected via our analytics platform.
- Heatmaps: Where enabled, aggregated heatmaps of user interactions (click and scroll patterns) used to understand product usage.
- Session Recordings: With your consent, our analytics provider records your interactions with the Service, including pages viewed, mouse movements, clicks, scrolling, and navigation, so we can replay a session to find and fix usability and technical problems. Recordings are masked in your browser before they are sent: text you input, conversation history, billing information, and email are excluded and never reach our analytics provider.
- Approximate Geolocation Data: Country, region, and city derived from your IP address for analytics. Where applicable, precise IP addresses are excluded from stored analytics records.
- Cookies and Similar Technologies: Used for session management and analytics, subject to your cookie preferences.
- Device and Browser Information: Browser type, operating system, screen resolution, referring URLs, and language preferences.
- Application and Server Logs: Our application servers generate logs that may include timestamps, request metadata, IP addresses, and error information. These logs are used for debugging, security monitoring, and service reliability.
3.3 Data from Third Parties#
- Authentication Providers: When you sign in, we receive your user identifier, email address, display name, and email verification status from the authentication provider.
- Payment Processor: We receive limited data from Stripe related to your transactions and subscription status, used solely to manage your account and provide the Services.
4. How We Use Your Personal Data#
We use your personal data for the following purposes:
- Providing and operating our Services: Processing your requests, delivering content, maintaining functionality, and managing your account and subscription.
- Processing payments: Facilitating voluntary payments or subscriptions through Stripe.
- Managing entitlements: Determining your access level and available features based on your subscription status.
- AI-powered features: Processing your chat messages through third-party AI services to generate responses, where you have opted into AI-powered features through a Paid Subscription. Your chat messages are sent to AI service providers solely for the purpose of generating a response. See the applicable addendum for details on AI data handling.
- Product analytics and improvement: Understanding how users interact with our Services so we can improve them. Analytics data is collected only with your consent via cookie preferences.
- Debugging and service reliability: Identifying and resolving technical issues using server logs and error reports.
- Security and fraud prevention: Protecting our Services and users from unauthorized access, abuse, and fraudulent activity.
- Legal compliance: Meeting applicable legal or regulatory obligations.
5. Cookies and Tracking Technologies#
- Essential Cookies: Required for the Services to function, including authentication and security. These cannot be disabled.
- Analytics Cookies: Used by our analytics platform to collect usage data and to record your interactions with the Service as described in Section 3.2. Subject to your cookie preferences.
Cookie Consent and Control: Where a Service uses non-essential cookies, the Service provides a cookie consent mechanism giving you full control over analytics cookies. When you decline analytics cookies, cookie-based analytics tracking and session recording are disabled entirely. You may update your preferences at any time through the cookie settings within the applicable Service.
We do not use cookies for advertising or behavioral targeting purposes on any of our Services.
Global Privacy Control (GPC) and Do Not Track: We respect browser-based opt-out preference signals. Where we detect a Global Privacy Control (GPC) signal or similar universal opt-out mechanism, we treat it as a valid opt-out of any sale or sharing of personal information (though we do not currently sell or share personal information). We do not respond to general Do Not Track (DNT) browser signals, as there is no industry-standard protocol for interpreting them.
6. Third-Party Service Providers (Sub-Processors)#
We work with third-party service providers who process personal data on our behalf. The specific sub-processors used by each Service are listed in the applicable addendum.
We require all sub-processors to maintain appropriate security measures and handle personal data responsibly. We maintain data processing agreements with our sub-processors where appropriate.
We do not sell your personal data to any third party.
7. AI Data Processing#
Certain Services include AI-powered features that involve sending your data to third-party AI service providers. When you use AI features:
- What is sent: Your chat messages and application data necessary for the AI to respond (including user-specified configuration and settings) are sent to the AI provider. We send only the data necessary for the AI to respond to your query.
- What is stored: Full chat transcripts (your messages and AI responses) are stored in our database as part of your session data. AI providers may also temporarily process your data in accordance with their own data handling policies.
- What is not sent: Your account email, display name, payment information, and other personal identifiers are not sent to AI providers. Chat messages are associated with an anonymous session identifier.
- AI provider data usage: We use AI providers under terms that prohibit them from using your data to train their models. See the applicable addendum for the specific AI providers used and links to their data handling policies.
- Your control: You choose whether to use AI features by subscribing to a tier that includes them. You can stop using AI features at any time by downgrading your subscription or simply not engaging with the AI assistant.
8. International Data Transfers#
Our Services are built and operated in the United States. If you access our Services from outside the United States, your personal data will be transferred to and processed in the United States. We work with service providers who maintain appropriate safeguards for handling personal data.
9. Data Retention#
We retain personal data only as long as necessary to fulfill its purpose or as required by law. General retention principles:
- Account data: Retained for the duration of your account. Upon account deletion, we delete your personal data from our primary systems and instruct our sub-processors to do the same.
- Subscription data after cancellation: Session data, user content, and workspace configurations associated with a cancelled subscription are retained for ninety (90) days following the end of the subscription period, after which they may be permanently deleted. If you resubscribe within this retention period, your data is restored.
- Chat transcripts: Retained while your Navigator Plan Subscription is active. After your Navigator Plan Subscription ends (whether by cancellation, downgrade, or non-renewal), chat transcripts are retained for ninety (90) days, then permanently deleted.
- Payment data: Leftoak Labs does not independently store payment card details. Stripe retains payment data on their platform per Stripe's privacy policy and applicable financial regulations. We retain only transaction confirmation details (amount, date, transaction identifier) and subscription-related identifiers (customer ID, subscription ID) as necessary for our records and account management.
- Analytics data: We aim to retain analytics data for no longer than necessary for the purposes described in this policy. See the applicable addendum for specific retention details.
- Application and server logs: Retained for up to 30 days, then automatically deleted.
Service-specific retention details are in the applicable addendum.
When data is no longer needed, we securely delete or anonymize it. If immediate deletion is not possible (e.g., data in backup archives), we isolate it from further processing until deletion is feasible.
10. Your Rights#
Regardless of where you are located, you may contact us at support@leftoak.com to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Delete your personal data from our systems. When we receive a deletion request, we delete data from our primary systems and instruct our sub-processors to do the same. Application and server logs may contain personal data (such as IP addresses or request metadata) and are automatically deleted after 30 days. Data in backup archives will be isolated from further processing and deleted when the backup expires.
- Request a copy of your data in a common format.
- Withdraw consent for analytics cookies and session recording at any time via cookie settings within the applicable Service.
- Object to any processing you believe is not necessary for the Service.
We aim to respond to all privacy requests promptly. We may need to verify your identity before processing your request. If we are unable to fulfill a request, we will explain why and work with you to find a resolution.
You may also have additional rights under the laws of your jurisdiction. We are committed to working in good faith to honor applicable privacy rights.
11. Data Security#
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit using TLS/HTTPS.
- Encryption of data at rest where supported by our infrastructure providers.
- Access controls and authentication mechanisms.
- User data isolation — each user's data is scoped to their authenticated account and is not accessible by other users.
- Regular review of security practices.
- Use of sub-processors with industry-standard security certifications.
No method of transmission or storage is completely secure. In the event of a data breach that affects your personal data, we will notify affected users and applicable authorities as required by law.
12. Children's Privacy#
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have, we will promptly delete it. Contact us immediately if you believe we have inadvertently collected data from a child.
13. Marketing Communications#
Leftoak Labs does not currently engage in marketing, profiling, or targeted advertising. If marketing features are introduced in the future, we will update this policy and obtain consent where required by applicable law.
We will never sell your personal data to third parties for their marketing purposes.
14. Third-Party Links and Services#
Our Services may contain links to third-party websites or services not operated by us. We are not responsible for their privacy practices or use or disclosure of your personal data, and we encourage you to review their policies.
15. Changes to This Privacy Policy#
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be posted with a revised effective date, which shall constitute notice of such changes.
Your continued use of the Services after the effective date of an updated Privacy Policy constitutes your acceptance of the changes. If you do not agree to the updated Privacy Policy, you must stop using the Services.
16. Contact Us#
Leftoak Labs, LLC Email: support@leftoak.com
Addendum A: fretengine#
Application: fretengine — guitar instruction and practice tools URL: https://fretengine.com Addendum Effective Date: August 23, 2026
This addendum supplements the Leftoak Labs Privacy Policy with data practices specific to fretengine. Where this addendum conflicts with the general policy, this addendum governs for users of fretengine.
A.1 Description of the Service#
fretengine is a guitar instruction web application that provides music education through interactive lessons, chord and scale visualization, practice tools, and an AI-powered music theory assistant. fretengine offers free and paid functionality, with paid features requiring account registration and an active subscription.
A.2 Data Collected by fretengine#
Data You Provide#
| Data | Description | Applicable Tiers |
|---|---|---|
| Account information | User ID, email address, display name, and email verification status received from Firebase Authentication when you create an account | Solo Plan, Navigator Plan |
| Session names | User-provided names for saved sessions (max 50 characters) | Solo Plan, Navigator Plan |
| Chat messages | Messages you send to the AI music theory assistant | Navigator Plan |
| Payment information | Email (if provided), billing address, and transaction data collected by Stripe when you make a tip or subscribe | All (tips); Solo Plan, Navigator Plan (subscriptions) |
Data Generated Through Use#
| Data | Description | Applicable Tiers |
|---|---|---|
| Instrument selection | The pre-defined instrument selected for each session (including its tuning, fret count, and fret marker positions) | Solo Plan, Navigator Plan |
| Session workspace state | Tool configurations, display settings, and workspace preferences | Solo Plan, Navigator Plan |
| Session metadata | Session identifiers, creation and update timestamps, associated instrument | Solo Plan, Navigator Plan |
| AI responses | AI-generated music theory explanations, recommendations, and instructions stored as part of chat transcripts | Navigator Plan |
| Subscription identifiers | Stripe customer ID, subscription ID, and price ID linked to your user account | Solo Plan, Navigator Plan |
| Fretboard overlays | Chord and scale visualization data generated through session use | Solo Plan, Navigator Plan |
| Entitlement status | Your current subscription package level, stored as a custom claim on your authentication token | Solo Plan, Navigator Plan |
Data Collected Automatically#
| Data | Description | Applicable Tiers |
|---|---|---|
| Usage and interaction data | Page views, feature interactions, click events, session behavior (via PostHog) | All |
| Heatmap data | Aggregated click and scroll patterns (via PostHog) | All |
| Approximate geolocation | Country, region, and city derived from IP address. Precise IP addresses are excluded from stored analytics records. | All |
| Device/browser info | Browser type, OS, screen resolution, referring URLs, language preferences | All |
| Cookie identifiers | Analytics cookies set by PostHog, subject to your cookie preferences | All |
| Server logs | Request metadata, timestamps, IP addresses, error information (via Google Cloud Logging) | All |
A.3 How fretengine Uses Your Data#
In addition to the general purposes described in Section 4:
- Session persistence: Storing your instrument selections, workspace state, and session metadata so you can return to saved sessions across devices and over time.
- Subscription management: Using Stripe customer and subscription identifiers to manage your billing, determine your entitlement level, and provide access to paid features.
- Entitlement enforcement: Storing your subscription package level as a custom authentication claim for efficient access control without requiring a database lookup on every request.
- AI assistant responses: Sending your chat messages and relevant application data to third-party AI providers to generate music theory guidance and session configuration instructions. Personal identifiers such as email and display name are not transmitted to AI providers.
- Chat transcript storage: Storing the full text of your conversations with the AI assistant (both your messages and AI responses) as part of your session data, so you can review past conversations.
A.4 AI Data Processing (fretengine)#
When you use the AI music theory assistant in fretengine:
What Is Sent to AI Providers#
- Your chat messages (the text you type in the chat interface).
- Application data necessary for the AI to provide relevant responses, including user-specified configuration and settings associated with your session.
What Is Not Sent to AI Providers#
- Your email address, display name, or other personal identifiers.
- Your payment information or subscription details.
- Your analytics data, browsing history, or device information.
How AI Providers Handle Your Data#
We use the following AI service providers to power the fretengine AI assistant. We may use one or more of these providers at any time, and may change providers as described in our Terms of Service:
| Provider | Purpose | Data Handling |
|---|---|---|
| Google (Gemini) | AI response generation | Data processed under Google Cloud's data processing terms. Not used for model training. See Google's AI data handling policies. |
| Anthropic (Claude) | AI response generation | Data processed under Anthropic's API terms. Not used for model training. See Anthropic's privacy policy. |
We select AI providers that commit to not using API customer data for model training purposes. However, AI providers may temporarily store data for content safety monitoring, abuse prevention, or debugging in accordance with their own policies.
Content Guardrails#
The AI assistant includes prompt-level guardrails and default provider safety settings designed to keep conversations focused on guitar music theory. These guardrails are not infallible, and we do not guarantee that all AI responses will be perfectly on-topic or free from error.
A.5 fretengine Sub-Processors#
| Provider | Purpose | Data Shared | Data Location |
|---|---|---|---|
| Firebase Authentication (Google) | User authentication and identity management | User ID, email, display name, email verification status, custom entitlement claims | United States |
| Google Cloud Firestore | User data storage (sessions, instruments, workspace state, subscription records, chat transcripts) | All user-generated content, chat transcripts, and subscription identifiers | United States |
| Google Cloud Platform | Application hosting, compute, and logging | Request metadata, timestamps, IP addresses, error information | United States |
| Google (Gemini API) | AI response generation for chat assistant | Chat messages, application data (user configuration and settings) | United States |
| Anthropic (Claude API) | AI response generation for chat assistant | Chat messages, application data (user configuration and settings) | United States |
| PostHog | Product analytics, heatmaps, session replay | Usage data, heatmap data, session recordings, approximate geolocation, device/browser info, cookie identifiers | United States (PostHog Cloud US) |
| Stripe | Payment processing and subscription billing | Email (if provided by user to Stripe), billing address, payment card details, transaction data | United States, Ireland, and globally |
Privacy policies:
- Firebase / Google Cloud: https://cloud.google.com/terms/cloud-privacy-notice
- Google Gemini: https://cloud.google.com/gemini/docs/discover/data-governance
- Anthropic: https://www.anthropic.com/privacy
- PostHog: https://posthog.com/privacy
- Stripe: https://stripe.com/privacy
A.6 Data Retention (fretengine)#
| Data | Retention Period |
|---|---|
| Account data | Retained for the duration of your account. Deleted upon account deletion request. |
| Session data and workspace state | Retained while subscription is active. After cancellation, retained for 90 days, then permanently deleted. |
| Instrument configurations | Retained while subscription is active. After cancellation, retained for 90 days, then permanently deleted. |
| Chat transcripts | Retained while the Navigator Plan Subscription is active. After the Navigator Plan Subscription ends, retained for 90 days, then permanently deleted. |
| Subscription identifiers | Retained for the duration of your account, and for a reasonable period after account deletion as needed for financial records and dispute resolution. |
| Payment data | Leftoak Labs does not independently store payment data beyond transaction confirmation details (amount, date, and transaction identifier) and subscription-related identifiers. Stripe retains payment data on their platform per Stripe's privacy policy. |
| Analytics data (PostHog) | We aim to retain analytics data for no more than 12 months from collection. |
| Session recordings (PostHog) | 30 days from capture, then automatically deleted. |
| Server logs (Cloud Logging) | 30 days (auto-deleted) |
A.7 Data Deletion#
When you delete a session within fretengine, the session and its associated data (including chat transcripts, if applicable) are initially soft-deleted (marked as deleted and excluded from the application). Soft-deleted data is permanently removed from our database during routine maintenance. If you require immediate permanent deletion, contact us at support@fretengine.com.
When you request account deletion, all associated data — including sessions, instruments, workspace state, chat transcripts, and subscription records — is deleted from our primary database. Subscription identifiers may be retained for a reasonable period as needed for financial records.
A.8 Marketing (fretengine)#
fretengine does not currently engage in direct marketing, profiling, or targeted advertising. If marketing features are introduced, this addendum will be updated and consent obtained where required by applicable law.
— End of Privacy Policy and Addendum A —