Scope
This policy applies to the Tabla Focus iOS app, website, feedback and waitlist forms, and related support channels.
Account and sign-in
You can choose Continue without an account and use the full Taal Metronome, including Lay Automation, plus the Tabla Tuner and Tanpura. Guest use does not create a Supabase account. Guest metronome sessions are not saved, synced or later uploaded. Sign in with Apple is required for membership features, purchases, restore, and features that read or write account-backed data.
The Terms of Use and this policy are linked before any account is created and again under Settings → Help & About → About Tabla Focus; both links open the published pages on tablafocus.com. When you sign in, we receive your Apple account identifier and the name and email you choose to share through Apple's sign-in flow (Apple lets you keep your email private with a relay address).
Account-backed app data is stored in our Supabase backend so it can sync across your devices. It includes your profile details — the name you share, your time zone, which side you play the dayan on, and your reminder and notification preferences; practice sessions, with their length in seconds and a server-side tempo trace of each session; skill, mastery and progress data; your personal activity records (described below); your onboarding answers; your tabla look; and the names you give Lehra presets. Favorites and routines, and the notes on catalog items and custom skills saved by earlier versions of the app, are also held for as long as they exist. When the same item is changed on two devices before they sync, a copy of each version is kept so neither change is lost.
If you start deleting your account, an encrypted Apple sign-in token is held briefly so the deletion can revoke Sign in with Apple. If you abandon that attempt, the token is cleared within 7 days. Explicit columns are read and written; we do not run open-ended queries against your data.
Your private iCloud content
Compositions, Custom Lists, Scan Notes, practice recordings, and the lehras you write in the Lehra Composer are stored on your device and, when iCloud is available, in your own iCloud account using Apple's CloudKit private database, each in its own private store. None of this content is stored in Supabase, published, or shared with other Tabla Focus users, and we cannot read it.
Composition notation includes your compositions and phrases, and Custom Lists hold the lists you make of them. Scan Notes keeps scanned notebook pages, note titles, dates, tags, and recognized text. A composed lehra holds its melody, taal, key, instrument, and the name you give it.
When you compose a lehra, the app records details such as its taal, key, instrument, and note count as an activity event in your account. Its name and its notes are never sent.
Your practice analytics
Analytics in Tabla Focus means your own practice statistics. We record in-app activity — practice sessions, feature opens, reminders, and related events — for signed-in accounts in our Supabase backend so the app can show your own history, streaks, and progress. A guest metronome session is not recorded. This history is personal: it powers your own progress view inside the app, not comparisons against other users, and it is never used for advertising.
You can export a copy of this data from Settings → Account & Data → Export → Account Data, as a zip of plain CSV files, once a day on each device.
Onboarding questions
When you first use the app, it asks a short, skippable set of questions about your tabla background and goals, so it can introduce the features that suit you before you decide whether to sign in. Answers given before sign-in stay on that device. If you later sign in and the account has not completed onboarding elsewhere, those selections are saved to your Supabase account so they can carry across your devices. If that account already completed onboarding, its existing account record wins. We store selections only, never free text, because the questions have none. Skipping keeps any answers you have already given. If you take the tour again after sign-in, the answers you change replace the stored ones.
Activity from permission prompts or a membership screen is recorded only after sign-in. The device keeps a small onboarding receipt and the local answers needed to avoid replaying the tour. After account onboarding is confirmed or durably queued, the guest receipt is no longer needed. Once signed in, you can review or change your answers from Settings → Help & About → Help → Take the tour again; they are included in your data export and deleted with your account.
Activity recording
When you are signed in, Tabla Focus records in-app activity — practice sessions, feature opens, and related events — in your own account on our backend (Supabase) so the app can build your history: charts, streaks, the monthly Analytics read-back, the Activity log, and the lifetime Progress Report. These records identify items by bundled catalog identifiers or by the identifiers of items you created, and record session length in seconds. They never include notation, note contents, recordings, audio, images, titles, filenames, or raw error messages. Guest metronome sessions do not create practice records.
No third-party analytics service receives this activity. The PostHog product-telemetry integration was removed on August 27, 2026, and there is no session recording, autocapture, or automatic screen tracking. Information handled for subscriptions, including by earlier app builds, is explained under Subscriptions below.
The Activity Recording switch in Settings → Account & Data → Account is on by default. It is on by default because it is how the app keeps your own history — part of the service you sign in for, not a separate consent. The switch applies to the device you set it on. Turning it off stops new activity being recorded from that device immediately. It does not erase history already recorded, and it never stops your practice sessions saving — those remain the record your streaks and statistics are built from.
We do not collect the IDFA (Apple's advertising identifier), sell any data, or track you across other apps or websites.
The website uses Google Analytics 4, and only after you grant consent in the banner. You can change that choice at any time from Cookie settings in the site footer. For details, see the Cookie Policy.
We also receive data you intentionally provide through the website. A feedback submission is stored with your browser type, language, time zone, and, when sent from the app, the app version, build, operating system version and device model. A waitlist sign-up is stored with your email address, the source and campaign (UTM) details of the link that brought you, and the time you gave consent. If you contact support directly, we receive your message and email address.
Microphone: three uses, one rule
The microphone is used for exactly three features. Audio never reaches our servers from any of them.
The Tabla Tuner uses the microphone only for live pitch detection on your device so it can show the note and cents your drum is sounding. It listens while its screen or pane is showing, and stops when that closes or the app goes to the background. It does not record, store, upload, transcribe, or grade your audio.
Practice recordings are audio takes you deliberately record. They are saved on your device and, when iCloud is available, in your own iCloud account using Apple's CloudKit private database — the same arrangement as Compositions and Scan Notes. We do not store recordings in Supabase, we cannot listen to them, and they are never published or shared with other Tabla Focus users. While you record, the app runs an on-device check that tabla is audible, so it can tell you when it cannot hear the drum; nothing from that check is stored. You can export your recordings from the app as audio files at any time, and delete any recording inside the app.
Lehra Composer can record one cycle while you hum with its click. The source take and unfinished edits are kept in a protected, account-scoped draft on that device while you work. They are excluded from backup, never synced to CloudKit or Supabase, never included in exports, and removed when you save or discard the draft, the next time you open the Composer, when you sign out, or when you delete your account. The saved lehra contains notes and timing, not the source recording.
Camera: one use
The camera is used for one feature you start yourself, and it is never used in the background.
Scan Notes photographs notebook pages. The pages, their titles, dates, tags, and recognized text stay on your device and, when iCloud is available, in your own iCloud account — exactly as described above. They never reach our backend.
Your tabla look. Settings → Your Tabla lets you choose the materials the app draws your tabla from — a wood and a lacing colour for the dayan, a metal and a lacing colour for the bayan. Those material names are saved to your account in our Supabase backend so the look follows you to your other devices; no photograph is taken or stored, and they are deleted with your account.
Notifications
Practice reminders and other notifications are scheduled on your device by the app. Your reminder times and notification preferences are saved to your account so they follow you to your other devices. Permission to show notifications is asked for, and given, separately on each device.
Widgets and Siri
Widgets, Live Activities, and Siri answers are built on your device from data the app already holds; nothing extra is sent to us for them. Widgets and Live Activities can show information such as your streak and practice minutes on the Lock Screen.
Subscriptions
Memberships are bought and billed through Apple's App Store. Apple does not share your payment details with us. Starting with Tabla Focus 1.0 (build 12), the app uses Apple's StoreKit 2 directly to purchase and restore memberships and check Apple-verified subscription information. These builds do not include the Superwall SDK and make no direct SDK requests to Superwall. When you make a purchase, the app sends Apple an app-specific account identifier to associate that purchase with your Tabla Focus account. Your membership remains owned by the Apple Account that bought it.
We removed Apple's direct production and sandbox subscription notification destinations for Superwall on September 18, 2026. Both direct destinations are now unconfigured. This does not confirm retirement of queued deliveries, separate forwarding or retained App Store Server API access. Any remaining paths may still deliver or retrieve subscription transaction and renewal data, including the app-specific account identifier and purchases from native builds. This information supports subscription management and revenue reporting; it does not include practice content. Clearing the direct destinations does not erase records already received.
Earlier builds use Superwall for subscription management, starting when the app opens and before sign-in. Those builds send no usage events or install-attribution match. Superwall receives the IP address, app-specific and SDK device identifiers, device model, operating system and app version, language, region, currency, time zone, installation date, active products and subscription status. After sign-in it also receives the Tabla Focus account identifier, and after a purchase it receives the App Store transaction record. Superwall derives an approximate country, region and city from the IP address for subscription management and subscription and revenue reporting. It receives no practice content, notation, recordings or onboarding answers. This is never precise location, and the app never asks for location permission.
Updating the app does not automatically erase records previously sent to Superwall, including through Apple server integrations. Deleting your Tabla Focus account also does not automatically erase those records or cancel your Apple subscription. Superwall may retain records under its applicable retention terms. Contact hello@tablafocus.com for requests about records previously sent through Tabla Focus.
Authorizing audio downloads
Starting with Tabla Focus 1.0 (build 12), a request for a new paid audio download sends an Apple-signed subscription transaction to our Supabase authorization service. Supabase sends that signed transaction to our separate Google Cloud Run verifier, which verifies it and checks current subscription status with Apple. Supabase checks the signed-in session and installation proof before issuing a download link. This check can process purchase and renewal information, transaction identifiers and the app-specific account identifier supplied to Apple. The app does not upload subscription proof merely because you launch it or sign in.
We use Apple's App Attest to verify an app installation and bind download requests to that installation and your signed-in session. Registration happens only when a new download needs authorization, not on launch or sign-in. We register an installation-specific public key and key identifier in our private Supabase tables, linked to your account. This is a security identifier, not an advertising identifier. Apple processes the attestation request. We use short-lived, single-use challenges to prevent a captured authorization request from being reused.
Registration challenges expire after five minutes and download-authorization challenges after two minutes and are removed during subsequent authorization requests. Expired challenges cannot authorize a request. Registered public keys and key identifiers remain until your account is deleted; deleting the account also removes its challenges. Our Supabase and Google Cloud Run service code does not persist or log the Apple-signed transaction payload. Hosting providers process operational request metadata and security logs under their service terms; this is separate from our application's transaction handling. A signed download link can remain valid for seven days to let a download finish. Cloudflare delivers the audio and processes the network request, including its IP address. Existing verified audio files on your device remain available offline; a new authorization check does not erase those files or revoke an already-issued download link.
Listening and reference content
Some catalog features fetch public reference data directly from third parties, which — like any web request — exposes your IP address to that provider: album and track details from Apple's iTunes catalog service, artist portraits and summaries from Wikipedia and Wikimedia Commons. None of these requests carry your identity or any of your practice data. The app also downloads its starter compositions from tablafocus.com; that download carries no account identity or practice data either.
The Listening Room plays 30-second previews inside Tabla Focus, and links each record to Apple Music with the official “Listen on Apple Music” button. Full recordings play in the Apple Music app, under Apple's terms: Tabla Focus never receives your Apple Music account, your authorisation, or your listening history.
Roadmap ideas and voting
You can suggest ideas and vote on the public roadmap without creating an account. To remember a browser's votes and reduce repeated voting, we set a necessary signed anonymous browser cookie that lasts for up to one year. The cookie is not used for advertising or cross-site tracking.
We store pseudonymous vote records created from that anonymous browser identifier. We do not store the raw identifier in those records. Idea requests are checked with Cloudflare Turnstile to distinguish people from automated abuse; Cloudflare receives the technical information needed to perform that check under its own privacy terms.
We also use one-way keyed hashes (HMACs) derived from browser and network identifiers to enforce submission and voting limits. We do not store the raw identifiers in these rate-limit records, and the records expire after 48 hours. The text, Area, moderation state, and related review information for submitted ideas are kept as needed to review, publish, reject, or merge the request and maintain the public roadmap.
Composition editor and library
You can write a piece or open a .tabla file in the composition editor without an account. The piece is kept in your browser's local storage and is not sent to us unless you choose to add it to the library. Downloading a piece saves a file on your device and sends nothing.
When you add a piece to the library, we store its notation and the optional name you enter under “Credit as”. Both are published on the piece's public page, marked unverified until someone checks it, and are kept as needed to review, publish or reject the piece and maintain the public library. That step is checked with Cloudflare Turnstile, which loads only when you open it. To limit repeated submissions we set a necessary signed anonymous browser cookie for up to one year and store keyed hashes (HMACs) derived from that cookie and your network address with the submission — not the raw identifiers.
How we use information
Account-backed app data is used to run app features, sync your own practice content, show your own practice history, and support account deletion. Provided website and support information is used to respond to requests, improve product quality, and maintain service security and reliability.
Launch and product update emails, and replies to support messages, are sent through our email provider. Launch and product update emails include an unsubscribe option so you can opt out at any time.
Legal bases we rely on
Where the UK or EU GDPR applies, we rely on performance of a contract to create your account, run the core features you sign in for, manage your subscription, and keep the in-app activity record that builds your own history; consent for website analytics and launch or product-update emails, each of which you can withdraw at any time; and legitimate interests in keeping the service secure and reliable and preventing automated abuse — you can object to either. We do not process special categories of personal data.
Automated decisions
We do not use automated decision-making or profiling that produces legal or similarly significant effects. Your practice analytics describe your own activity to you and are never used to judge, rank, or gate you against other players.
Data sharing
We do not sell personal data and we do not share it with third-party advertisers. Data is processed through the providers used to run Tabla Focus, each named here: Apple (Sign in with Apple, private iCloud/CloudKit storage for Compositions, Custom Lists, Scan Notes, practice recordings, and composed lehras, App Store purchases and billing, Apple Music links and catalog lookups, notifications, subscription verification and App Attest), Supabase (account data, sync, subscription verification and download-authorization security records), Superwall (possible queued notification deliveries or separate forwarding, any retained subscription API access, earlier-build subscription management, and retained records, as described above), Google (Google Analytics 4 on the website, only after consent), Cloudflare (automated-abuse checks, delivery of downloadable Sangat audio, and the network that serves the tablafocus.com domain), our email provider (launch and product update emails and support replies), Wikipedia and Wikimedia Commons (public reference content), and Firebase/Google Cloud (website hosting, form storage, and the separate Cloud Run service that verifies Apple subscription evidence for new audio downloads).
Retention
Download-authorization key records remain until account deletion; challenge lifetimes and signed-link validity are described under Authorizing audio downloads above. We keep account-backed data for as long as your account is active, so your practice history and progress stay available across devices. Raw app activity events are rolled into your personal totals and then deleted, about 13 to 14 months after they are recorded, so your own long-term totals and progress keep working without the raw event stream. An abandoned account-deletion attempt, and the encrypted Apple token held for it, are cleared within 7 days. Superwall may retain subscription records received through Apple server integrations and earlier builds under its retention terms, as described under Subscriptions above.
On the website, support and feedback submissions are deleted 12 months after they were sent or last changed, whether or not the request was resolved. The moderation log is kept for 12 months and holds no email addresses. Waitlist sign-ups are kept until you ask us to delete them. If you unsubscribe, we stop emailing you and keep only the record that you unsubscribed, so you are not emailed again. Rate-limit records are keyed hashes and expire after 48 hours; the anonymous voting cookie expires after up to one year. Roadmap ideas and associated pseudonymous votes may remain while needed to operate and preserve the accuracy of the roadmap. Other operational records are retained only as long as needed for reliability, security, and compliance.
Deleting your account
You can delete your account inside the app from Settings → Account & Data → Account → Delete Account. Deleting your account:
- Removes your Tabla Focus profile, account-backed content, favorites, practice sessions, analytics history, onboarding answers, progress, and download-authorization keys and challenges from our backend
- Revokes your Sign in with Apple credential, so the app no longer has access to sign you in
- Removes the account's data from the device you delete it on, including the onboarding answers held there, your tabla look, and unfinished Lehra Composer drafts and source takes
Compositions, Custom Lists, Scan Notes, practice recordings, and composed lehras are stored separately in your own iCloud account, so deleting your Tabla Focus account does not remove them on its own. The delete-account screen offers three separate choices to erase them from iCloud and this device, all off by default: Compositions (which also erases your Custom Lists and composed lehras), Scan Notes, and Recordings.
If you choose any of those erases, they happen first. If a later step fails, your account is not deleted and you can try again, but the iCloud content you chose to erase is not restored.
When you confirm deletion with Apple, the app keeps only a retired identifier for that account in your device's Keychain, for this device only. It stops an old local backup or recovery file on that device from bringing the deleted data back. It is not a profile or a credential, and signing out does not create one.
Copies of your data on your other devices stay there until the app is next used on them. Deleting your account does not automatically erase records previously sent to Superwall; see Subscriptions above for retained records and contact details. If you start a deletion and do not finish it, the attempt and the encrypted Apple token held for it are cleared within 7 days. Deleting your account does not cancel a subscription; cancel it in your Apple Account settings.
Contact: hello@tablafocus.com.
Your rights over your data
If you are in the United Kingdom, the European Economic Area, India, or another region with comparable data-protection law, you have the right to ask for a copy of the personal data held about you, to have inaccurate data corrected, to have your data deleted, to object to or restrict how it is used, and to receive it in a portable form. Where processing rests on your consent, you can withdraw that consent at any time. In India these rights arise under the Digital Personal Data Protection Act; grievances are handled through the same contact below, and you may escalate to the Data Protection Board of India if unsatisfied.
The fastest portable copy is self-service: Settings → Account & Data → Export → Account Data exports your account and practice data as a zip of CSV files, including every profile field, the copies kept when a change conflicted, and whether each item was deleted. The lehras you wrote are exported separately as MIDI. You can make the account data export once a day on each device, whether or not you hold a membership. For requests about download-authorization security records, contact us using the address below.
Activity recording in the app is part of the service you sign in for, and the Activity Recording switch in Settings → Account & Data → Account stops it on that device at any time. Website analytics run only on your consent, which you can change at any time from Cookie settings in the site footer. Account data is processed to provide the service you signed in for. Automated-abuse checks rest on legitimate interests, and you can object to them.
To exercise any of these rights, write to hello@tablafocus.com. Requests are answered within one month. You can delete your account, and everything attached to it, from inside the app at any time without asking.
Tabla Focus is run by Sreeram Kongeseri, who is the data controller, based in Portugal in the European Union, and is reachable at the address above. If you believe your data has been handled wrongly, raise it with us first at the same address and we will look into it directly. You may also complain to a data-protection authority — your own national authority where you live, or our lead supervisory authority in Portugal, the Comissão Nacional de Proteção de Dados (CNPD). In the United Kingdom that authority is the Information Commissioner's Office, and in India the Data Protection Board of India.
US state privacy rights
If you live in California or another US state with a comprehensive privacy law, you have the right to know what personal information we hold, to access, correct, or delete it, and to appeal our decision. We do not sell your personal information and do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act. We will not discriminate against you for exercising these rights. Tabla Focus is currently below the revenue and volume thresholds that make that Act binding on a business; we honour these rights for every US user regardless. To make a request, use the same contact as above.
Where your data is processed
Some providers process data outside your country. Compositions, Custom Lists, Scan Notes, practice recordings, and composed lehras stay in your own iCloud under Apple's terms. Account data is held by Supabase; subscription data from earlier builds or any remaining delivery, forwarding or API-access paths, and retained subscription records, are processed by Superwall in the United States; automated-abuse checks, Sangat audio delivery, and the tablafocus.com domain network by Cloudflare; website analytics by Google Analytics, in the United States; website hosting, forms and the separate subscription-verification service by Firebase/Google Cloud; and emails by our email provider. For every transfer outside the United Kingdom and the European Economic Area we rely on the data processing terms each of these providers applies to its customers, including the European Commission's standard contractual clauses or an equivalent transfer mechanism, and those terms govern our use of each service.
Children
Tabla Focus is not directed at children under 13, and the minimum age of digital consent varies by country — 13 in the United Kingdom and the United States, and between 13 and 16 across the European Economic Area depending on the member state. Signing in requires an Apple ID used in accordance with Apple's age terms for your region. We do not knowingly collect personal data from children; if you believe a child has created an account, contact us and it will be deleted.
Security and breach notification
Data is protected through application controls, access restrictions, and routine security practices. If a breach ever affects your personal data, we will notify you and the relevant authorities within the timelines required by the law that applies to you, with a plain-language description of what happened and what you can do.
Policy changes
We may update this policy when product or legal requirements change. Material updates will be reflected by the date on this page.