Privacy policy

Your songs live on your phone. This page says what leaves it, what a paid backup holds, and what never goes anywhere at all.

Last updated September 4, 2026

The short version

Songwriter's Drawer keeps your songs on your phone. You can write, record, film and search without an account, and nothing about that leaves the device.

Four things use the internet. Two of them only when you ask: reading a photographed page, and writing down a take you spoke. One is on for everyone: usage and crash reporting, as counts and short labels, never as anything you wrote. And one is a paid feature you switch on by subscribing: a backup of your songs, your takes and your videos, kept under an account you sign in to. All four are described in full below.

Without a subscription there is no copy of your work anywhere but your phone. With one, there is exactly one other copy, it is yours, and this page says what is in it.

Who this is from

Songwriter's Drawer is published by Baan Software PTE. LTD.. Questions about this policy, or about anything in the app, go to songwriters-drawer@baansoftware.com.

What the app stores on your device

All of it stays in the app's own storage on your phone, in a database and a folder of media files:

  • Songs, with their titles, stages and confidence.
  • Every lyric version you write, kept whole rather than overwritten, with the chords you placed over the words.
  • Audio recordings of your takes, and the waveform shape sampled while you recorded.
  • Videos you filmed, and a still frame taken from each one.
  • Photographs of pages you shot, and the transcripts made from them.
  • The words written down from a take you spoke.
  • Small settings: which capture the app opens by default, which tutorials you have already seen, and a randomly generated identifier that marks songs as belonging to this device. That identifier is created on the phone and is not tied to you.

The app also keeps a few copies of your words — the songs and the lyrics, not the audio — in its own storage, so that a file that will not open or a sync that goes wrong is not the end of a drawer. Those copies never leave the phone either.

An account, and what it is for

You can use the app without ever signing in. Signing in exists for one reason: a backup belongs to a person rather than to a phone, so that your songs come back after a phone is lost.

Signing in is handled by Firebase Authentication with Apple or Google. We receive the identifier that provider gives us, and an email address if the provider supplies one. We do not receive your password. Before you sign in the app still has an identity — an anonymous one, created on first use of a feature that needs our server, which exists so that the free monthly allowance for reading and listening can be counted. It is a random identifier and it is not you.

The backup, if you subscribe

A subscription buys one thing: a copy of your work on our servers, under your account. Turning it on is subscribing and signing in; there is no other way for your songs to reach us, and a free account never sends any of them.

What the backup holds:

  • The song rows — title, stage, confidence, whether it is archived or locked, and the dates.
  • Every lyric version, which is where the chords live.
  • Every moment's details: what kind it is, its label, how long it runs, its waveform, the language, and any transcript.
  • The audio of your takes and the video of your clips.

It is stored on Amazon Web Services in the United States (region us-east-1): the files in S3, the rows in DynamoDB. Media moves to colder storage after thirty days, which changes nothing about who can read it. The subscription itself is handled by RevenueCat and by Apple or Google — we never see a card number.

If a subscription lapses, the songs stay readable and the files are kept for twelve months. You can still bring everything back down to a phone in that time. After twelve months the files are deleted from our servers. Your phone's own copies are not touched by any of this, and neither is the free copy you can take of everything at any time.

Deleting your account from inside the app removes the backup and the account together. That is the one action here that really destroys something, and it does not touch the songs on your phone.

Reading a page, and writing down a take

When you photograph a page of lyrics and ask for it to be read, that image is sent to our own server, which passes it to Google's Gemini API and returns the words to your phone. Speaking your words works the same way: when you stop, that take is sent the same route and comes back as text for you to correct.

Our server is the one holding the model key, which is why the request goes through it rather than straight from your phone. It receives the image or the audio, forwards it, and returns the result. Google's handling of the request is governed by Google's privacy policy and the Gemini API terms; ours is this page.

The request carries the file, an instruction for reading it, and your identity — the anonymous one, or your account if you have signed in — because the free allowance has to be counted against somebody. Nothing else goes with it: not your other songs, not the title, not your drafts.

A take you make with the Record button is never sent for transcription, and neither is one already on a song. Anything visible in the photograph is part of what is sent, and anything audible in the room is part of what is sent when you speak. If there is something you would rather keep entirely local, do not photograph it and do not speak it — type it, or record it with the Record button. The image and the take stay on your phone whether or not the transcription succeeds.

What we collect about how the app is used

The app sends usage and crash reports to Google Firebase (Firebase Analytics and Crashlytics), so that we can see which parts of the app are used, what is ignored, and what is broken. There is no advertising SDK and no advertising identifier.

An event is a short label and a handful of values. A recording being saved arrives as recording_saved with how long the take was; a song being opened arrives as song_opened with how long it had been since you last touched it, banded rather than exact. That banding is deliberate: a precise number like “417 songs” identifies one person, and “over 50” answers the same question without doing so.

The following are never sent to Firebase, under any circumstances:

  • Any lyric, chord, note or title.
  • Any audio, any video, any photograph and any transcript — only how long a take ran, and how many words came back from it.
  • Anything you type into search — only how long it was and how many songs it found.
  • File names, and the names you give your takes: only whether a name matches a part of a song anyone would recognise, like a chorus or a bridge.
  • Song identifiers, or the identifier that marks songs as belonging to this device.

Alongside the events, Firebase records the ordinary things an analytics service records: an app-generated install identifier, your device model, operating system version, country and language. A crash report additionally carries the state of the app at the moment it failed — which line of our code it was running — and never the contents of your drawer. Google's handling of all of it is governed by Google's privacy policy and the Firebase privacy and security terms. Firebase's default retention applies; we set nothing longer.

There is no switch for this in the app. That is a deliberate choice and we would rather say so plainly than bury it: reporting is on for everyone, and the honest mitigation is that what is reported cannot describe you, only the app. If you would rather send nothing at all, both Apple and Google let you limit what apps may report from your phone's own settings, and deleting the app ends it completely.

The app stores

Downloading the app is a transaction between you and Apple or Google, not with us. The stores give developers aggregate statistics — how many people installed an app in a country in a week — which cannot identify anyone. If you have turned on sharing crash and usage data with developers in your phone's own settings, the store may pass on crash reports of its own, separately from ours; that is a setting you control on the device.

Children

The app is suitable for all ages. It has no chat, no social features and nothing public. It does have an optional account and an optional subscription, both of which are meant for whoever pays for the phone.

Your rights over your data

Your songs are files on a device you own. “Get a copy of everything” in the app's settings builds a single file holding every song, every word and every recording, and hands it to you — free, on any account, and without asking us for anything. That is the answer to a request for your data, and it is faster than writing to us.

If you have an account, deleting it from inside the app removes the backup and the account. Deleting the app removes everything it holds on the phone. For anything else — a question about what we hold, or a request to remove the usage counts described above — write to songwriters-drawer@baansoftware.com.

This site

This website runs no JavaScript, sets no cookies, embeds nothing from anyone else and loads no third-party fonts or scripts. Visiting it tells us nothing beyond what any web server necessarily handles in order to answer a request.

Changes

If this policy changes, the date at the top of the page changes with it, and a change that affects what leaves your phone will be described in the app's release notes rather than left to be discovered here.

A drawer nobody else can open

Yours on your phone, with no account. Backed up only if you ask for it.

Free. No account, no advertising, and nothing to sign up for.