Privacy

Last updated: 26 September 2026

Woodshed keeps only what it needs to work. In short: what, why, where, and how to remove it.

Who is responsible

Your data is controlled by the private individual who runs Woodshed: Maciej Milewski

What we store

The email address and password you sign in with — the password is stored as a hash. Beyond that, everything you add in the app: library items, planned sessions, block ratings, tempos, practice time and notes.

Why

Only to make the app work (legal basis: GDPR Art. 6(1)(b) — providing the service you signed up for). No ads, no analytics, and your data is never sold to anyone.

Who else can access it

Supabase (database and sign-in; data is stored in the European Union, in Ireland), Vercel (hosting; a US company whose servers pages and requests pass through) and Cloudflare (bot protection at sign-in and sign-up; it checks signals from your browser). Technically, the person running the app can see it too.

Cookies

Only two: one keeps you signed in, the other remembers your language. No tracking or advertising cookies.

How long

For as long as your account exists. Deleting the account deletes everything stored in it.

Your rights

You can ask for a copy of your data, for it to be corrected, or for your account to be deleted with everything in it. There is no button for this in the app yet — just write to the address below. You can also complain to the data protection authority in your country.

Contact

Questions and requests about your data: woodshed.help@gmail.com