Pianify

Privacy Policy

Version 1.0 · last updated 2026-08-26

This explains what Pianify stores about you, why, for how long, and what you can make us do about it. It is written to be read, not to be scrolled past.

1. Who is responsible

The controller of your personal data is a private individual resident in Hungary. Pianify is run by one person, not by a company, and it earns nothing — there is no advertising, no subscription and nothing for sale.

For anything in this document, write to info@pianify.net. That address is read by the person responsible, not by a support queue.

The operator's name and postal address are not printed here, and are given on request. Ask at the address above and you will be told, as will the supervisory authority named in section 12 if it asks. The reason is that publishing them means publishing a private individual's home identity on a public page — the site is a hobby, not a business, and there is nobody else's letterhead to put it on. If you are exercising a right under sections 8 to 11, you do not need the name first: write to the address above and the request is handled either way.

We have not appointed a Data Protection Officer. Article 37 of the GDPR requires one only where processing is large-scale and systematic, or where special categories of data are processed at scale. Pianify is a game with accounts and leaderboards; it is neither.

2. What we hold, and why

You can play every piece on this site without an account. Everything below exists only because you chose to create one.

DataWhyLegal basisKept for
UsernameIdentifies you, and is shown publicly on leaderboards Contract, Art. 6(1)(b)Until you delete your account
Email addressConfirming the account is yours, password resets, and messages about the service itselfContract, Art. 6(1)(b)Until you delete your account
Password, as a PBKDF2-SHA-256 hashSigning you in. We never hold the password itself and cannot recover itContract, Art. 6(1)(b)Until you delete your account
Chosen avatar and languageDrawing your profile and the site in your language Contract, Art. 6(1)(b)Until you delete your account
Six-digit verification codes, hashedConfirming an address or a password reset Contract, Art. 6(1)(b)20 minutes, then unusable
Session token in a cookieKeeping you signed in Contract, Art. 6(1)(b)30 days, or until you sign out
Leaderboard entries: song, hands, score, accuracy, rank, combo, judgement counts, time The leaderboards themselvesContract, Art. 6(1)(b)Until you delete your account
Rate-limit counters, keyed by IP address, by account, or by email address depending on what is being limitedRate limiting, so one machine cannot open thousands of accounts or guess passwordsLegitimate interests, Art. 6(1)(f) A counter is dead once its window passes — an hour at most. Rows are swept on a rolling basis and are never read again after their window
Cloudflare Turnstile tokenTelling a person from a script at sign-up and at password resetLegitimate interests, Art. 6(1)(f)Checked once and discarded
Rejected score submissions, with the reasonFinding leaderboard manipulation Legitimate interests, Art. 6(1)(f)12 months
A count of how many pieces your account opened per hourDetecting bulk downloading of the arrangementsLegitimate interests, Art. 6(1)(f)12 months
Moderation records: what action was taken on your account, when, by whom, and the reason for a suspensionSo a moderator decision can be explained, reviewed and appealed Legitimate interests, Art. 6(1)(f)12 months, or until the account is erased
Whether the account is a moderatorAccess to the moderation tools Contract, Art. 6(1)(b)Until you delete your account
Deletion timestamps, if you delete the accountRunning the 30-day recovery window in section 7Legitimate interests, Art. 6(1)(f)30 days, then overwritten

The first four rows above — username, email, password hash, avatar and language — are kept until you delete your account, and then for the 30 days described in section 7 before being overwritten.

The balancing test for the four legitimate-interest rows. Each exists to stop abuse that would otherwise fall on other users or on the people whose work the arrangements are. Each holds the least it can — a counter rather than a log, an hour rather than a year, a count of pieces rather than which pieces. None is used to build a picture of you, to advertise, or to make any decision about you. We consider that a person creating an account would reasonably expect a site to defend itself this way.

3. What we do not do

4. What other people can see

Your username, your avatar, the date you joined and your results are public — including on your player page, which anyone can open from a leaderboard. That is what a leaderboard is. Your email address, your password and everything else are not, and are never shown to another user.

Choose a username accordingly. You can change it at any time from your profile.

5. Who else processes it

ProcessorWhat it doesWhereSafeguard
Cloudflare, Inc.Hosting and CDN, the API, the account and leaderboard database (stored in the EU), the arrangements (stored in the EU), rate limiting and bot protection. Requests are processed at the Cloudflare location nearest the visitor, which may be outside the EEA.Database and files: EU. Request processing: global edge network.EU Standard Contractual Clauses; EU-US Data Privacy Framework
Resend (Plus Five Five, Inc.)Delivery of account verification, password-reset and email-change messages. Receives the address a message is sent to and the message itself, which is a six-digit code — never a password.United StatesEU Standard Contractual Clauses; EU-US Data Privacy Framework

Both act only on our instructions, under Article 28 contracts. Where data reaches a country outside the EEA, the transfer relies on the safeguard named above.

6. Your rights

You can exercise any of these by writing to info@pianify.net. We answer within one month, and will say so if we need longer, which the GDPR allows in limited cases.

If you think we have got this wrong, you can complain to the Hungarian supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11., Hungary. You may also complain to the authority where you live.

7. What deletion actually does

Immediately. You are signed out on every device, your leaderboard entries are deleted, any outstanding codes and usage counters go with them, and you can no longer sign in. The cached copies of any leaderboard you appeared on are dropped at once rather than left to expire, so your name stops being served straight away.

For the next 30 days. Your username, email address and password hash are still held, marked deleted and invisible to everyone except us. This is so a deletion made by mistake can be reversed — write to info@pianify.net and we can put the account back. We rely on Article 6(1)(f) for this delay: a person who deletes the wrong account has no other remedy, and 30 days of recoverability is worth more to them than 30 days of strictness when the data is already invisible to everybody else.

After 30 days. The username, email address and password hash are overwritten with values derived from an internal id, and the moderation records naming the account are deleted. At that point nothing can bring it back. If you want the erasure to happen at once rather than after the window, say so and we will do it.

One thing survives: a one-way fingerprint of your email address, so that an account closed for abuse cannot immediately be recreated on the same address. It carries no name, cannot be turned back into an address, and is not used for anything else. We rely on Article 6(1)(f) for it and are telling you about it here rather than doing it quietly.

8. Age

You must be at least 16 to create an account. Hungary sets the age of consent for online services at 16 under Article 8(1) of the GDPR, and we have no way to verify a guardian's permission. If we learn that an account belongs to someone younger, we delete it.

Playing the piano here needs no account and no age.

9. Security, honestly

Passwords are stored as PBKDF2-HMAC-SHA-256 hashes with a per-account salt, never in the clear. Verification codes are stored hashed too. The session cookie is HttpOnly, Secure and SameSite=Lax. Everything travels over HTTPS. Sign-in, code entry and registration are rate limited, and changing your password signs out every other device.

None of that makes a breach impossible. If one happens and it is likely to be a risk to you, we will tell you and the supervisory authority, as Articles 33 and 34 require.

10. Changes

This document has a version number and a date at the top. If we change it in a way that matters, we will say so in the app before you next play, and record which version you have seen.