Last updated September 15, 2026
CoLabRoom is published by Decibel Zero LLC ("we", "us"). This describes what the app actually collects and where it actually goes — not a generic template. If anything here stops matching what the app does, tell us at support@colabroom.com.
Your email address, a display name, and an optional profile picture.
Song lyrics and chord annotations, comments, room and song names, and any voice notes or reference recordings you attach to a song. All of it is stored so the people in your room can see and hear it — that's the point of the app.
Lyric sheets you import (PDF, Word, Excel, and the other formats CoLabRoom reads) are parsed on your own device before anything is saved. A public Google Sheet link is fetched only from the link you supply.
The email address of anyone you invite to a room, or anyone you ask to play on a song before they have an account.
If you list yourself in the Open Mic: the city you type, what you play, and a few words about the kind of music you make. All three are optional, all three are editable, and all three stop being visible to anyone the moment you take yourself off the list.
When somebody asks you to play on a song, when you answer either way, and when a take you recorded lands on somebody else's song, we record that it happened — who, when, and which part. It exists for one purpose: making the people the app suggests to you better than a list of strangers. It is shown to nobody, there is no score anywhere in it, and it is deleted with your account.
Messages you send to one person, lines you write in a room's thread, replies on an ask, the note you can leave with “heard it”, and the questions you ask the app about a song are all stored, so the people they are for can read them. Each is yours to take back from inside the app. Who can see each one is under “Who can see what” below.
A note that you would like to meet somebody who plays a particular part is stored for a month and shown to musicians who play it. Sending or answering a connection request is stored so the app knows who your people are.
While the app is open it tells our realtime service that you are, so your people — connections, and everybody you share a room with — can see a mark beside your name. It is not written down: closing the app ends it, and there is no record of when you were here.
If you turn notifications on, your phone hands us a delivery token. We store it against your account and give it to Google's Firebase Cloud Messaging, which is what actually reaches the device. The token identifies an installation rather than a person: signing into a different account on the same phone moves it, uninstalling makes it stop working and we drop it the next time we try, and deleting your account deletes it. The notification itself carries only what you would see in the app.
The app also tells us when a notification reached your phone — with the app open, with it closed, or because you tapped it — so we can see for ourselves that delivery works rather than guess. That is stored on the notification itself and goes when it goes.
If you report something, we store what you reported, which kind of thing it was, anything you typed, and who put it there — and a person reads it. If you block somebody, we store that you did, so the app can keep the two of you apart.
If you send feedback, we store its category, your message, the screen you were on, and your app version and platform. If the app crashes or hits an unexpected error, the same version/platform information and an error message are recorded automatically so we can find and fix it — this doesn't include your song content. Each time the app is opened it records that a session started, with the version and platform, so an error count has something to be divided by.
Analysing a recording is something you ask for, per song — it isn't automatic. When you do:
RunPod and Google Cloud Run are infrastructure we run our own code on — they don't process your recording for their own purposes. Making a song sheet no longer sends anything to OpenAI: transcription moved onto the analysis worker, where it is both more accurate and ours. OpenAI still receives the isolated vocal on the shorter path — a voice note, or a Studio recording you ask for words from — and never the full mix.
Analyses are cached by the recording's fingerprint: the exact same audio file, analysed again by anyone, reuses the first result instead of being reprocessed. Nobody can reach an analysis without already having the recording it came from.
A room and everything in it — songs, lyrics, comments, recordings — is visible only to that room's members. Nothing you write or record is public by default, and nothing becomes public because you finished it.
Three separate, deliberate acts can make something public, and each one is yours to take and yours to undo:
One more thing you can hand to one person: asking a particular musician to play on a song lets that person — and nobody else — hear that song while the ask is open. Withdrawing it, their answering no, or blocking them ends it.
A notification about any of these carries the sender's name and the first part of what they said, and nothing more.
The chord tool takes an audio file, works out the chords, and sends them back. It does not require an account and does not create one.
The recording is never stored. It is held in memory for as long as the analysis takes, passed to the chord detector, and dropped. There is no upload folder, no database row, and no copy afterwards — so there is nothing to delete, and nothing for us to hand over if anybody ever asked.
One thing is kept, and only to stop the tool being used to run up a bill: a salted hash of the network address the request came from, with a count of how many songs it has sent today. Not the address itself, and not anything about the music. Those rows are deleted after a day. They can answer exactly one question — whether this requester has had its five songs today — and no other.
Until you delete it or delete your account. There's currently no automatic expiry on feedback or diagnostic records — we're telling you that plainly rather than implying a cleanup schedule that doesn't exist yet.
Messages and threads stay until whoever wrote a line takes it back, the room is deleted, or the account is. A note looking for somebody expires after a month. Questions you asked the app, and its answers, stay with your account. A delivery receipt lives and dies with the notification it belongs to.
CoLabRoom isn't directed at children under 13, and we don't knowingly collect information from anyone under 13. If you believe a child has created an account, contact support@colabroom.com and we'll remove it.
If this policy changes in a way that matters — a new third party in the analysis chain, a change to what we keep — we'll update the date at the top and, for anything material, say so inside the app.
Decibel Zero LLC — support@colabroom.com