Privacy Policy
How PitchTimePro handles account, practice, microphone, camera, analytics, and billing data during the AWS rebuild.
Last updated: July 12, 2026
Data we collect
- Account details you provide when account services are enabled.
- Practice settings, range selections, lesson progress, and scores when progress sync is enabled.
- Billing events from Stripe when subscriptions are enabled.
- A versioned keyed-HMAC fingerprint of the normalized account email, product trial redemption, a three-year deletion receipt, and non-promotional communication-suppression status after deletion. These records do not contain the raw email address.
- Basic device and diagnostic signals used to operate the service. If you choose “Allow analytics,” Google Analytics also measures page visits and account or checkout funnel events without receiving the account fields you enter. The Google tag remains off when you choose “Only essential,” and your versioned choice is stored in a first-party cookie for 180 days.
Microphone and camera processing
Browser lessons process microphone audio on the device for pitch detection. The camera starts only when you run the device-local gesture readiness check or enter a lesson with an authored syncopation gesture line; MediaPipe hand landmarks are processed on the device. The readiness check verifies stable capture-timed evidence and never shifts lesson scoring. Raw microphone audio, camera video, and camera recordings are not uploaded or retained by PitchTimePro.
Analytics choices
PitchTimePro asks before loading Google Analytics. You can change that choice at any time using the button on this privacy page. This choice is independent from the choice made on another Scale Mode Tools product domain.
Account deletion and retention
After all Stripe subscriptions have ended, you can permanently delete the account shared by PitchTimePro and ScaleModePro. We delete product profiles, settings, progress, account mappings, Cognito access, linked Google identity information held by Cognito, and saved Stripe customer payment details. The three-year deletion receipt contains only a keyed-HMAC email fingerprint and deletion timestamp. Separate purpose-limited trial and suppression facts remain as described below. The HMAC key is kept separately in AWS Secrets Manager with restricted access.
Retention schedule
- Account and product data are kept while the account is active and deleted when an eligible deletion request completes.
- The keyed-HMAC deletion receipt and deletion timestamp are retained for three years after deletion under the South Carolina legal-claims period, then scheduled for automatic deletion.
- Invoices, payments, refunds, tax calculations, and related accounting evidence are retained for at least four years after the related South Carolina return is filed or due. A specific record may be retained for six or seven years when an applicable federal tax period, audit, refund, bad-debt treatment, or other legal requirement calls for it.
- Support, chargeback, fraud, security, and contract evidence relevant to a dispute or claim is generally retained for three years after the matter closes or the claim accrues, and longer only while a legal hold or proceeding requires it.
- Deleted DynamoDB data may remain in encrypted production recovery copies for up to 35 days. Recovery copies are isolated for disaster recovery and are not used to recreate a deleted live account.
- The keyed-HMAC communication-suppression fact remains until you affirmatively opt back in or it is no longer needed to honor the opt-out. Commercial-email opt-outs are applied within ten business days.
- The keyed-HMAC email fingerprint and product trial-redemption facts remain indefinitely for the non-statutory purpose of preventing repeat-trial abuse. They are not used to recreate an account or send promotional email.
- Stripe independently retains transaction information under its payment-services, fraud-prevention, financial-crime, legal, and operational requirements and states that Business User-provided personal data is generally retained for five or more years after the relationship or last transaction, whichever is later.
- A legal hold, active audit, dispute, refund request, chargeback, court order, or different applicable law can extend the period for the affected record. We restrict retained records to their stated purpose and delete or de-identify them when the controlling period ends.
Infrastructure direction
PitchTimePro is being moved to AWS-native backend ownership for auth, database, storage, email, secrets, and entitlement records. Browser and mobile code must not hold privileged provider credentials.
Contact
Privacy requests can be sent to legal@scalemode.tools. Product support can be sent to support@scalemode.tools.