Legal
Privacy Policy
Your music never leaves your device.
VocalOut separates vocals from music entirely on your phone. There is no account, no upload, and no server that receives your audio. We cannot hear, store, or access the files you process, because they never reach us.
What the app does send is anonymous diagnostic data — timings, error codes, and numbers about how your device performed. Never audio, and never anything taken from your files.
01What we never collect
The app does not transmit, and we never receive:
- Audio, or any part of the content of a file
- File names, file paths, song titles, artist names, or any other metadata read from your files
- Your name, email address, phone number, or contacts
- Precise location
- Advertising identifiers. Ad identifier collection and ad personalization signals are explicitly disabled in the app's build configuration
- A list of your music library or media collection
VocalOut shows no advertising and contains no advertising SDK. We do not set a user ID, so the diagnostics described below are not tied to you as a person.
02What the app sends
Diagnostics are on by default, and the app has no switch to turn them off. We rely on them to find the failures we cannot reproduce — a phone running out of memory on a long song, a model failing on a particular chip. Section 6 describes how you can stop the collection.
App and device context
- App version and build number, and the app version you first installed
- Operating system version
- Device hardware model (for example
iPhone16,1), total memory, and processor count - A performance tier derived from the above, used to group results
- Language, and an approximate region derived by our processor from your IP address. We do not receive or store your IP address itself
- An installation identifier generated by Firebase. It is not linked to you, is not shared with other apps, and is removed when you uninstall the app
Usage and processing events
- Which separation mode was run, whether it succeeded, failed, or was cancelled, and how long each stage took
- The length of the source file as a range, never an exact value: for example "4–6 minutes"
- Error codes and the pipeline stage a failure happened in
- Whether a result was played and for how long, whether stems were switched, and whether a result was deleted and how long after it was made
- Whether the purchase screen was shown, what led to it, and whether a purchase was made
- Identifiers for the song and the job. These are generated on your device, are not derived from the file or its contents, and mean nothing outside your installation. We use them only to connect the events of one job to each other
Stability and performance
- Crash reports, including stack traces
- The state of the app when something went wrong: which processing stage was running, how far it had gone, how much memory the app was using, how much free storage was left, and the device's thermal state
- Start-up time and the duration of each processing stage
Crash logs are written by us and contain stage names and numbers only. No file name, path, or song title is ever placed in them.
03Who processes this data
The data in Section 2 is processed on our behalf by Google LLC through Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, and Firebase Remote Config. Remote Config also lets us change certain settings — such as switching off the purchase screen if the store has a problem — without shipping a new build.
Google's handling of this data is described in the Firebase Privacy and Security documentation and in Google's Privacy Policy. We share this data with no one else, and we do not sell data.
04Files on your device
When you choose a song, the system grants VocalOut access to that specific file and the app copies it into its own private storage. It has to: the original may live in a location the app cannot reach again later, and the copy is what lets you run a second mode on the same song without picking the file all over again.
That copy, and every separated result, stays in the app's private storage on your device until you delete it. You can delete an imported copy while keeping its results, from the song's screen in your library. Uninstalling the app removes all of it.
Working files left behind by an interrupted job are cleaned up the next time you open the app. Exported files go wherever you send them with the system share sheet — after that they are outside the app and outside this policy.
05Purchases
VocalOut Pro is a one-time purchase handled by the App Store or Google Play. We never receive or store your payment details. The store tells the app only whether a purchase exists for your store account. Refunds are handled by the store under its own policies, not by us.
06Your choices
| What you want | How |
|---|---|
| Stop the collection | Uninstall the app. This deletes the installation identifier permanently and nothing further is sent. On iOS, Settings → Privacy & Security → Analytics & Improvements and on Android Settings → Google → Ads also limit what apps may collect and share. |
| Delete what was already collected | Write to grayforge.dev+vocalout@gmail.com. We will delete the diagnostic data associated with your installation. Because we hold no account, please send the message from a device that still has the app installed, or tell us the approximate dates you used it, so we can find the right records. |
| Ask what is held about you | Write to grayforge.dev+vocalout@gmail.com. The same limitation applies: without an account there may be no way for us to connect a request to a specific installation. |
| Delete your audio and results | Do it in the app, from your library. Nothing needs to reach us, because we never had it. |
Diagnostics never gate a feature. Everything in the app behaves the same regardless of what we receive.
Where you live changes what you may ask for
The rights above are given to everyone, but some places grant more.
- European Economic Area, United Kingdom, Switzerland. You may ask for access, correction, erasure, restriction, portability, and you may object to processing. You may also complain to your national data protection authority.
- South Korea. The Personal Information Protection Act (개인정보 보호법) gives you rights of access, correction, deletion and suspension of processing, and you may report a concern to the Personal Information Protection Commission (개인정보보호위원회, pipc.go.kr). Write to us in Korean if that is easier — 한국어로 문의하셔도 됩니다.
- California. You may ask what categories of data we collect and request deletion. We do not sell or share personal information, and we never have.
07How long data is kept
Diagnostic events are retained for up to 14 months and are then deleted automatically. Crash reports are retained for up to 90 days, following Firebase Crashlytics defaults.
Your audio and your results are never retained by us for any length of time, because we never receive them.
08International transfers
The diagnostic data described above may be processed on servers outside your country, including in the United States, by our processor. Your audio files are never transferred anywhere.
09Children
VocalOut is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has provided us with information, write to grayforge.dev+vocalout@gmail.com and we will delete it.
10Changes to this policy
If this policy changes we will update the dates at the top of this page. For a change that meaningfully affects what we collect or why, we will say so inside the app before it takes effect.
11Contact
Questions about this policy, or any request in section 6:
GrayForge —
grayforge.dev+vocalout@gmail.com