← CoLabRoom

Privacy Policy

Last updated September 15, 2026

CoLabRoom is published by Decibel Zero LLC ("we", "us"). This describes what the app actually collects and where it actually goes — not a generic template. If anything here stops matching what the app does, tell us at support@colabroom.com.

What we collect

Account

Your email address, a display name, and an optional profile picture.

What you write and record

Song lyrics and chord annotations, comments, room and song names, and any voice notes or reference recordings you attach to a song. All of it is stored so the people in your room can see and hear it — that's the point of the app.

What you import

Lyric sheets you import (PDF, Word, Excel, and the other formats CoLabRoom reads) are parsed on your own device before anything is saved. A public Google Sheet link is fetched only from the link you supply.

Invitations

The email address of anyone you invite to a room, or anyone you ask to play on a song before they have an account.

What you say about yourself

If you list yourself in the Open Mic: the city you type, what you play, and a few words about the kind of music you make. All three are optional, all three are editable, and all three stop being visible to anyone the moment you take yourself off the list.

Who you have worked with

When somebody asks you to play on a song, when you answer either way, and when a take you recorded lands on somebody else's song, we record that it happened — who, when, and which part. It exists for one purpose: making the people the app suggests to you better than a list of strangers. It is shown to nobody, there is no score anywhere in it, and it is deleted with your account.

What you say to people

Messages you send to one person, lines you write in a room's thread, replies on an ask, the note you can leave with “heard it”, and the questions you ask the app about a song are all stored, so the people they are for can read them. Each is yours to take back from inside the app. Who can see each one is under “Who can see what” below.

Looking for people

A note that you would like to meet somebody who plays a particular part is stored for a month and shown to musicians who play it. Sending or answering a connection request is stored so the app knows who your people are.

Whether you are here right now

While the app is open it tells our realtime service that you are, so your people — connections, and everybody you share a room with — can see a mark beside your name. It is not written down: closing the app ends it, and there is no record of when you were here.

Notifications on your phone

If you turn notifications on, your phone hands us a delivery token. We store it against your account and give it to Google's Firebase Cloud Messaging, which is what actually reaches the device. The token identifies an installation rather than a person: signing into a different account on the same phone moves it, uninstalling makes it stop working and we drop it the next time we try, and deleting your account deletes it. The notification itself carries only what you would see in the app.

The app also tells us when a notification reached your phone — with the app open, with it closed, or because you tapped it — so we can see for ourselves that delivery works rather than guess. That is stored on the notification itself and goes when it goes.

Reports and blocks

If you report something, we store what you reported, which kind of thing it was, anything you typed, and who put it there — and a person reads it. If you block somebody, we store that you did, so the app can keep the two of you apart.

Feedback and diagnostics

If you send feedback, we store its category, your message, the screen you were on, and your app version and platform. If the app crashes or hits an unexpected error, the same version/platform information and an error message are recorded automatically so we can find and fix it — this doesn't include your song content. Each time the app is opened it records that a session started, with the version and platform, so an error count has something to be divided by.

Analysis: where a recording actually goes

Analysing a recording is something you ask for, per song — it isn't automatic. When you do:

SupabaseStores the recording, your account data, and every song in the app. Our database and file storage provider.
RunPodRuns our own instrument-separation code on their GPUs, to split the recording into stems.
Google Cloud RunRuns our own chord-detection code, to work out what's being played.
RunPodAlso transcribes the words for a song sheet. That runs on the same worker as the separation, on our own code — the vocal does not leave that machine.
OpenAIUsed for the shorter path only: voice notes, and recordings you transcribe from Takes. The isolated vocal — not the full mix — goes to OpenAI's transcription API. Governed by OpenAI's own API data terms.
RunPodAlso works out the tune of the isolated vocal. That is where the sung range shown on a song sheet — and on your Open Mic profile, if you have listed yourself — comes from. Same worker, our own code.
Anthropic or OpenAIOnly when you ask the app a question about a song. Your question and what the app has already worked out — the title, key, chords, sections, up to sixty lines of the words, and which parts people have played on it — go to a language model that writes the answer. The recording never does. Which model depends on how we have configured it: Anthropic's API when a key for it is set, otherwise OpenAI's. Both publish API terms under which what is sent is not used to train their models. We keep your question and the answer too.
Apple or GoogleIf you dictate lyrics rather than type them, the phone's own speech recogniser is used, and on iOS that may send what you say to Apple. It's the system feature, not ours, and it only runs while you're dictating.

RunPod and Google Cloud Run are infrastructure we run our own code on — they don't process your recording for their own purposes. Making a song sheet no longer sends anything to OpenAI: transcription moved onto the analysis worker, where it is both more accurate and ours. OpenAI still receives the isolated vocal on the shorter path — a voice note, or a Studio recording you ask for words from — and never the full mix.

Analyses are cached by the recording's fingerprint: the exact same audio file, analysed again by anyone, reuses the first result instead of being reprocessed. Nobody can reach an analysis without already having the recording it came from.

Who can see what

A room and everything in it — songs, lyrics, comments, recordings — is visible only to that room's members. Nothing you write or record is public by default, and nothing becomes public because you finished it.

Three separate, deliberate acts can make something public, and each one is yours to take and yours to undo:

One more thing you can hand to one person: asking a particular musician to play on a song lets that person — and nobody else — hear that song while the ask is open. Withdrawing it, their answering no, or blocking them ends it.

Talking

A notification about any of these carries the sender's name and the first part of what they said, and nothing more.

The chord tool on this website

The chord tool takes an audio file, works out the chords, and sends them back. It does not require an account and does not create one.

The recording is never stored. It is held in memory for as long as the analysis takes, passed to the chord detector, and dropped. There is no upload folder, no database row, and no copy afterwards — so there is nothing to delete, and nothing for us to hand over if anybody ever asked.

One thing is kept, and only to stop the tool being used to run up a bill: a salted hash of the network address the request came from, with a count of how many songs it has sent today. Not the address itself, and not anything about the music. Those rows are deleted after a day. They can answer exactly one question — whether this requester has had its five songs today — and no other.

How long we keep it

Until you delete it or delete your account. There's currently no automatic expiry on feedback or diagnostic records — we're telling you that plainly rather than implying a cleanup schedule that doesn't exist yet.

Messages and threads stay until whoever wrote a line takes it back, the room is deleted, or the account is. A note looking for somebody expires after a month. Questions you asked the app, and its answers, stay with your account. A delivery receipt lives and dies with the notification it belongs to.

Your controls

Children

CoLabRoom isn't directed at children under 13, and we don't knowingly collect information from anyone under 13. If you believe a child has created an account, contact support@colabroom.com and we'll remove it.

Changes

If this policy changes in a way that matters — a new third party in the analysis chain, a change to what we keep — we'll update the date at the top and, for anything material, say so inside the app.

Contact

Decibel Zero LLC — support@colabroom.com