Local Personal data
Songs, setlists, practice logs, calendar events, contacts, and charts in signed-out Personal use are stored on this device and are not collected by Locked In.
Account and sync data
Signing in uses email OTP authentication. Band workspaces sync shared records to Supabase for active members. Personal cloud sync uploads Personal workspace records for signed-in users. Free and Personal Pro plans have different Personal song and chart-storage limits.
Purchases and subscriptions
Apple processes iOS purchases and payment credentials. Locked In sends Apple an app account token and stores verified product, transaction, original-transaction, environment, subscription-status, renewal, expiration, grace, refund, revocation, account/workspace-link, and reconciliation facts needed to verify access, prevent account mismatches, and recover entitlement state. Locked In does not retain raw signed StoreKit payloads or receive payment-card details.
Google Drive import
Google Drive import runs only when a user chooses Google Drive. Locked In opens Google Picker with the non-sensitive drive.file permission, lets the user select one PDF, and downloads only that selected file as a chart. Locked In does not list the user's whole Drive, access Drive in the background, or retain a Google refresh token. The imported PDF is stored on the device and, depending on the active workspace and sync state, may be stored in the user's private Personal cloud storage or shared band workspace storage. Shared band charts may be available to active members of that workspace. Users can replace or delete imported charts in Locked In; deleting a chart in Locked In does not delete its source file from Google Drive. Google user data is used only to provide the visible chart-import and chart-storage features described here and is handled subject to the Google API Services User Data Policy, including its Limited Use requirements.
Charts and files
Chart PDFs upload through explicit chart actions or signed-in Personal cloud sync setup. Routine sync uses lightweight chart metadata, then Locked In may separately cache missing or updated charts from the active workspace so they remain available offline.
Diagnostics and support
User-shared diagnostics may include app/build environment, sync status, account/workspace scope, entitlement status, and safe error summaries. Songs, charts, credentials, raw StoreKit payloads, and private keys are not included unless a user deliberately shares relevant content outside the normal diagnostics flow.
Account deletion
Deleting an account removes account profile data, Personal cloud sync data, user-private band chart/preferences, and active non-owned memberships. Shared band workspace records remain with the workspace. Local Personal data on the current device is preserved by default. Deleting a Locked In account does not cancel an Apple subscription; billing must be managed through Apple.