Partbook is operated by Ambroos Vaes ("we"), in Sweden. He is the data controller under the GDPR. Questions, requests, complaints: hello@partbook.app.
A practice app for choirs. Accounts are invite-only: you are here because your choir invited you.
Almost everything: because you asked us to, it is what makes the app work (in GDPR terms, performance of a contract). Operational logs and security measures: our legitimate interest in keeping the service running and abuse out. Nothing is processed for advertising, so there is nothing here that needs a consent banner.
Everything runs on Cloudflare. Our database and file storage are created under Cloudflare's EU jurisdiction, which restricts where the data may be stored as a guarantee, not a preference. Your data does not leave the EU at rest.
Requests themselves are processed on Cloudflare's worldwide network: the server code runs in the data center closest to wherever you are, which can be outside the EU. Voice-note transcription and the suggested note titles run on Cloudflare Workers AI, on GPU hardware somewhere on that same worldwide network. Transactional email goes out through Cloudflare's email service. Cloudflare, Inc. is a US company; its GDPR data processing addendum, which includes the EU standard contractual clauses, covers all of this.
Members of your choir see your name and your voice part. Your choir's leaders manage its member list, and your choir decides what it uploads and records; we host it for them. We can access data when needed for support, safety, or to keep the service running, and when we open a member's view of the app to help with a problem, that access is written to an audit log we keep.
Partbook is passwordless: we email you a sign-in link. Signing in stores a token on your device (in your browser's local storage, or the app's own storage), and it stays valid for 30 days of use.
On the web there is exactly one cookie. It contains the fixed text "1", nothing else: no identifier, no token, nothing about you. Its only job is to tell our server whether to answer partbook.app's front page with the marketing page or with the app, and it is deleted when you sign out. There are no tracking cookies and no third-party cookies, so there is still nothing here that needs a consent banner.
The complete list of email we send: your sign-in links, the invitation your choir sent you, and account-deletion confirmations. There is no marketing mail, and no code in Partbook that could send any.
Go to partbook.app/delete-account, enter your email, and confirm through the link we send you. Immediately: your sign-in identities, memberships, sessions, and personal track library are deleted, and your email address is scrubbed everywhere we can find it. Two honest details about what remains:
Content that already belongs to a choir stays with the choir: voice notes (which were never linked to your account) and published announcements, which keep the author name they were published with. If you are the only owner of a choir, transfer ownership first or write to hello@partbook.app.
We make no automated decisions about you and build no profiles. The usage counters cannot even tell two people apart, so there is nothing to profile with.
Under the GDPR you can ask for access, correction, erasure, a copy of your data, or object to processing: hello@partbook.app. You can also complain to your data protection authority (in Sweden: IMY, the Swedish Authority for Privacy Protection, imy.se).
We will update this page when something changes, and say so in the app when it matters.
Last updated: 18 August 2026.