Match Play: Practice Studio
Match Play: Practice Studio ("Match Play") is a music practice app for iPhone, iPad, Android and the web, provided under the Acantivo brand ("Acantivo", "we", "our", or "us"). This policy explains what data we collect, how we use it, who we share it with, and the choices and rights you have.
1. Who We Are
Match Play is provided under the Acantivo brand. Acantivo is a brand name, not a registered company. We are responsible for the personal data described in this policy.
Contact: support_matchplay@acantivo.com
Postal address: Nishi-Shinjuku Mizuma Building 2F, Nishi-Shinjuku 3-3-13,
Shinjuku-ku, Tokyo 160-0023, Japan
2. Services Used By The App
Match Play is built on Google Firebase: Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase, Cloud Functions, Firebase Analytics, Firebase Crashlytics, Firebase Cloud Messaging, Firebase Remote Config, and Firebase App Check (which uses Google Play Integrity on Android, Apple App Attest on iOS, and Google reCAPTCHA Enterprise on the web). The app also works with:
- Google Drive, Dropbox, and Microsoft OneDrive, when you choose to import a file;
- YouTube, for searching and playing reference performances;
- Google AdMob (mobile) and Google AdSense (web), for ads on the free plan;
- RevenueCat together with the Apple App Store or Google Play, and Paddle for web purchases, for the optional Match Play Plus subscription;
- Cloudflare, which delivers and caches media;
- Google's email service, which delivers feedback you send in the app to our support inbox.
3. Information We Collect
Depending on how you use the app, we may collect or store the following categories of data:
- Account information such as your email address, display name, username, the sign-in provider you use (email, Google, or Apple), and your Firebase account identifier.
- Content you create or upload, including pieces, PDF scores, score annotations and markups, highlights, comments, to-dos, cards, and audio and video recordings of your own performances and of reference performances you record or upload.
- Files you choose to import from your device, your photo library, or connected cloud services (Google Drive, Dropbox, OneDrive), and search queries you run to find scores or reference media.
- YouTube search result metadata used for reference-performance search, preview, selection, cache, and ranking features, such as video IDs, titles, channel names, URLs, embed URLs, thumbnail URLs, duration, and search/preview/selection counters.
- Collaboration data when you share a piece, including the usernames or email addresses you add, the access role you grant, the content you share, and who saved each version.
- Feedback you submit in the app, including the subject, message details, your user ID, display name, email address if available, and timestamps.
- Usage analytics collected through Firebase Analytics.
- Technical crash and diagnostic information, including crash traces, app version, device model, operating system version, and installation identifiers.
- Security and integrity signals from Firebase App Check, such as attestation results from Google Play Integrity or Apple App Attest, and device, browser and interaction signals evaluated by Google reCAPTCHA Enterprise on the web.
- A push-notification token if you allow notifications.
- Subscription and purchase data if you buy a paid plan, such as your subscription status (active or expired), plan, renewal and expiration dates, and store transaction and product identifiers. We do not receive or store your full payment card number or bank details.
- Advertising data if you use the free plan, such as a device or advertising identifier, coarse location, and ad-interaction signals used by our advertising providers to serve, frequency-cap, and measure non-personalized ads and to prevent fraud. This is not used to build a cross-app advertising profile of you.
- Training archives of annotation data, only if you opt in to ML training (see Section 10).
4. Accounts And Authentication
The app supports email/password authentication as well as sign-in with Google and Sign in with Apple through Firebase Authentication. We use this information to create accounts, sign you in, link sign-in methods you choose to connect, send password-reset and email-verification messages where required, and secure your data.
5. Your Content, Recordings And Cloud Sync
When you are signed in, your pieces, scores, annotations, comments, to-dos, cards, and recordings are stored in our Firebase project (Cloud Firestore and Cloud Storage) so they persist with your account and sync across your devices. This content is private to your account unless you choose to share it (see Section 6).
Recording uses your device's microphone and, for video, its camera. The app asks for these permissions through your device or browser and uses them only while you record. Photo library access is used only to import the files you pick. You can change these permissions at any time in your device or browser settings. Recordings you keep are uploaded to cloud storage with your account.
If you save a recording to your device or share it to another app, that copy is handled by your device and that app, outside Match Play.
6. Usernames, Finding People And Sharing
Your display name and username are listed in a user directory so other signed-in Match Play users can find you to share a piece with you. Search results show your display name and username, never your email address. Someone who already knows your email address can also add you by email.
When you share a piece, the people you share it with can see it and your contributions to it, including your display name or username (for example, next to a version you saved). Viewers can see the shared content; editors can also change it. If you add an email address that does not have a Match Play account yet, we store it so that person gets access when they sign up with that address. Only share with people you intend to give access to that content.
7. Importing Files From Cloud Services
If you choose to import a file from Google Drive, Dropbox, or OneDrive, the app uses that provider's official picker and your authorization to access only the file you select. We use that access to bring the chosen file into your Match Play workspace. Your use of those services is also governed by their respective privacy policies. You can disconnect or revoke access from within each provider's account settings.
8. Reference Media And YouTube
The app can search for and embed reference media, including videos played through YouTube. When embedded content loads, the content provider (for example, Google/YouTube) may collect data in accordance with its own privacy policy. Search queries you run are processed by our Cloud Functions to return matching results.
For YouTube reference-performance search, Match Play uses YouTube Data API v3
from Firebase Cloud Functions. The YouTube API key is stored on the server and is
not included in the app client. Match Play may call YouTube API endpoints such as
youtube.search.list and youtube.videos.list to retrieve
video metadata needed to show results and confirm that a video can be
embedded.
Match Play may cache YouTube metadata so repeated searches can be served with fewer API calls. Match Play does not download, copy, extract, or rehost YouTube audio or video content. Playback remains hosted by YouTube and is shown through YouTube's embedded player or a hosted player page loaded in the app.
Your use of YouTube features is also governed by the YouTube Terms of Service, the YouTube API Services Terms of Service, and the Google Privacy Policy.
9. Security Checks
To protect our backend and your account from abuse, Match Play uses Firebase App Check to confirm that requests come from a genuine copy of the app. App Check relies on Google Play Integrity on Android, Apple App Attest on iOS, and Google reCAPTCHA Enterprise on the web. These services evaluate device, app, browser, and interaction signals under the Google Privacy Policy and Google Terms of Service or Apple's privacy policy. We use the results only for security and abuse prevention.
10. Optional ML Training
Using your annotation data to train machine-learning models is optional and opt-in. It is off by default, and normal app use does not require it.
If you turn it on, Match Play may create a separate training archive containing annotation export data such as annotation cards, timeline areas, PDF areas, comments, to-dos, file metadata, and relationships derived from time and PDF position. Training archives are stored separately from normal app data and use a pseudonymous user identifier. They do not currently include your audio or video recordings or the full contents of your PDF files; we will ask for your consent before using those for training.
You can turn ML training off at any time in the app's Privacy settings. When you do, we stop creating training archives and remove pending or unprocessed archives where possible. If your data has already been used to train or improve a model, it may not be technically possible to remove its influence from that model, but we will not use your data for future training.
11. Cookies And Similar Technologies
The app and its service providers store small amounts of data on your device using cookies or similar technologies:
- Local preferences and device storage. Settings such as workspace layout, list sort order, and diagnostics choices are stored in on-device or browser storage and are not uploaded.
- Firebase identifiers. Firebase services (Authentication, Firestore, Storage, Messaging, Analytics, Crashlytics, Remote Config, App Check) create and store identifiers — such as installation, session, authentication, and App Check tokens — using device storage, browser local storage, or similar technologies.
- reCAPTCHA Enterprise (web). On the web, Google reCAPTCHA Enterprise may place or read cookies and similar technologies to tell people and automated abuse apart, under the Google Privacy Policy.
- YouTube embedded player. When you load or play an embedded YouTube video, the YouTube player (provided by Google) may place or read cookies, local storage, device or browser identifiers, or similar technologies, and may collect usage data in accordance with the Google Privacy Policy.
- Advertising (Google AdMob and AdSense). To show and measure non-personalized ads on the free plan, Google AdMob (mobile) and Google AdSense (web) may store or read device or browser identifiers, cookies, or similar technologies, subject to the consent you provide (see Section 17) and the Google Privacy Policy.
You can clear locally stored data by clearing the app's data or your browser storage. Cookies from embedded players and Google services are controlled through your browser or device settings and Google's privacy tools.
12. Analytics
The app uses Firebase Analytics to understand how features are used so we can improve the product. Analytics data is used in aggregate to measure engagement and reliability and is not used to serve advertising.
13. Crash Reports And Diagnostics
The app sends limited crash and stability diagnostics to Firebase Crashlytics. This essential diagnostic collection helps us detect failures, maintain app reliability, and fix bugs. Crash diagnostics are used only for app security, stability, and debugging. They are not used for advertising or profiling. Crash reports are associated with your account identifier (your Firebase user ID) so we can diagnose issues affecting your account; we do not intentionally attach your name, email address, or your content to crash reports.
14. Push Notifications
If you allow notifications, the app registers a push token with Firebase Cloud Messaging so we can deliver notifications relevant to your account and activity, such as sharing activity. You can turn notifications off at any time in your device settings.
15. Feedback And Support
If you send feedback through the app, we store the message you submit together with account identifiers available to us at that time, such as your user ID, display name, and email address, and deliver it to our support inbox by email. We use this information to respond to issues, review feature requests, and improve the app.
16. Payments, Subscriptions, And Media Delivery
Match Play offers an optional paid subscription (Match Play Plus). To offer, verify, and manage subscriptions and to unlock Match Play Plus, Match Play uses RevenueCat as a subscription-management processor, together with the app store you purchase through (Apple App Store or Google Play) and — for web purchases — Paddle.com Market Ltd as the merchant of record and web payment processor.
Match Play does not receive or store your full payment card number or bank details; those are handled by the app store or the payment processor.
The subscription data Match Play and RevenueCat process includes your Match Play account identifier (Firebase user ID), used as the subscription app user id; your subscription and purchase status; store transaction and product identifiers; and the device platform and store environment (production or sandbox). RevenueCat receives these purchase events to determine your entitlement and to notify our servers, which set your plan accordingly. This data is used to provide, restore, sync, and support your subscription and to prevent abuse.
Media you access (such as recordings and reference audio) may be delivered and cached through Cloudflare, a content-delivery provider, so shared and repeated playback is faster. Cached copies are not stored permanently and refresh periodically; in some cases cached media is actively purged, for example after a subscription refund. When you delete a file, it is removed from our storage and any remaining cached copy stops being served once it expires. The app stores, RevenueCat, Paddle, and Cloudflare each process this data under their own privacy policies.
17. Advertising And Your Choices
Match Play shows advertising to free-plan users to help fund the free service; Match Play Plus subscribers see no ads. On mobile the app uses Google AdMob, and on the web it uses Google AdSense. All ads are non-personalized (contextual): they are not based on a cross-app or cross-site profile of you and are not used to track you across other apps or websites.
To serve, frequency-cap, measure, and protect these ads from fraud, Google may process a device or advertising identifier, coarse location, and ad-interaction data under the Google Privacy Policy and Google's advertising terms. Where required — for example in the European Economic Area, the UK, and Switzerland, and under applicable US state privacy laws — Match Play presents a Google-certified consent message (Google's User Messaging Platform in the app, or a consent management platform on the web) before ads load. You can change your choices through the app's or site's privacy controls, reset your advertising identifier or limit ad tracking in your device settings, and remove ads entirely by subscribing to Match Play Plus.
18. How We Use Information And Our Legal Bases
We use the information described above to:
- provide Match Play — accounts, storing and syncing your content, recordings, sharing and collaboration, file imports, reference-media search, subscriptions, and support — because it is necessary to provide the service you asked for;
- keep Match Play secure and reliable — App Check, abuse and quota protection, crash diagnostics, and analytics to improve the app — based on our legitimate interest in running a safe, working service;
- show and measure non-personalized ads on the free plan, based on our legitimate interest in funding the free plan, or on your consent where the law requires it;
- send push notifications and create ML training archives, based on your consent, which you can withdraw at any time;
- keep records we are legally required to keep, such as for billing and tax.
19. International Data Transfers
Your data may be processed in countries other than the one you live in, including the United States, where service providers such as Google Firebase, RevenueCat, Paddle, and Cloudflare process data. Those countries' data protection laws may differ from yours. Where the law requires it, these transfers rely on safeguards offered by our providers, such as the European Commission's Standard Contractual Clauses.
20. Account Deletion And Data Retention
We keep your account information and content for as long as your account is active. Deleting a piece removes the app data for that piece and its files where possible.
You can delete your account in the app (Settings → Account & profile → Delete account) or by email; see how to delete your Match Play account. Deleting your account removes your Firebase Authentication account, your profile and username (so you no longer appear in user search), every piece you own — including pieces you shared with others, who lose access — with its scores, recordings and other files, your access to pieces others shared with you, and your ML training consent records and training archives that have not been used. For security, you may be asked to sign in again first.
Some data may remain: comments, recordings, or other contributions you added to pieces owned by other people stay part of those pieces; feedback you sent may be kept to support past requests; subscription and purchase records are kept by the app stores, Paddle, and RevenueCat as billing and tax rules require; and limited diagnostic, cached, and log data may be retained for a limited period for security, reliability, and quota protection. Match Play cannot delete data held independently by third-party providers such as Google or YouTube. Deleting your account does not cancel a subscription.
21. Your Rights And Choices
Depending on where you live — including under the EU and UK GDPR and Japan's Act on the Protection of Personal Information — you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its use, receive a copy of it, and withdraw consent you have given. Withdrawing consent does not affect processing that already took place.
You can delete your account, turn ML training off, and change notification, permission, and ad-consent choices yourself in the app or on your device. For any other request, including a copy of your data, contact support_matchplay@acantivo.com. We may need to verify your identity before acting on a request, and we will respond within the time required by applicable law. If you are unhappy with how we handle your data, you can also complain to the data protection authority where you live.
22. Children's Privacy
Match Play is intended for general audiences and is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at support_matchplay@acantivo.com and we will take steps to remove it.
23. Changes To This Policy
We may update this policy as the app changes. The current version will always be posted at this page with a revised "Last updated" date.