LEGAL
Effective date: April 21, 2026 · Last updated: April 21, 2026
CymaTones LLC ("CymaTones," "we," "us," or "our") values your privacy. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have regarding your personal information when you use CymaTones.
| Category | Examples |
|---|---|
| Account information | Name, email address, password (hashed), profile preferences |
| Birth data (optional) | Birth date, time, location for Cosmos personalized readings |
| Payment information | Processed by SamCart — we receive transaction metadata (amount, product, status) but not full card numbers |
| Scan data | Voice recordings (processed in-browser, see below), spectrum analysis, harmony scores, scan results |
| Symptom selections | Symptom checker inputs, duration, intensity (stored to your account) |
| User content | Playlists you create, favorites, public comments or reviews |
| Support communication | Messages you send us, support request attachments |
| Category | Examples |
|---|---|
| Usage data | Which tracks you play, duration listened, features used, scan count, pages visited |
| Device & browser data | IP address, browser type, device type, operating system, user agent |
| Technical logs | Error reports, API request logs, security audit events |
| Cookies & similar tech | Session cookies, anonymous scan identifiers, preferences (see Cookies section) |
We use your information to:
We do not use your information to train external AI models, nor do we sell or rent your personal information to third parties for their marketing.
We share information only as follows:
We do not sell your personal information.
We work with the following trusted partners to operate CymaTones:
| Partner | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, auth, file storage | Account, scan, playlist, and session data |
| SamCart | Payment processing, subscription billing | Name, email, billing address, payment details |
| Vercel | Web hosting and edge functions | Request logs, deployment data |
| Anthropic | AI-enhanced report generation | Scan spectrum data and Symptoms picker inputs (processed but not retained for training by Anthropic per its enterprise terms) |
| Google (Gmail) | Transactional and support emails | Email address, message content |
| Daily.co (future) | Video meeting room for community calls | Display name, email, meeting metadata |
Each partner is bound by a data processing agreement or equivalent contractual protection. We review partners periodically to ensure they meet our privacy and security standards.
What we do store:
What we do not store:
The same principle applies to other scanners (Vision, Tongue, Face, Nails): where scans involve camera input, images are processed in your browser when possible. When server-side AI analysis is required, images are sent securely for analysis and retained only to the extent necessary to generate your report. You may request deletion of this data at any time.
CymaTones uses AI (currently Anthropic Claude) to enhance scan reports and generate personalized interpretations. When you complete a scan:
You may opt out of AI-enhanced analysis by contacting us; in that case, you will receive the local (non-AI) version of your report.
We use cookies and similar technologies to operate the Service. Types we use:
You can control cookies through your browser settings. Disabling essential cookies will break Service functionality.
Local storage: On public pages, we use your browser's local storage to save your scan history so you can return and review past results. This data stays on your device and is not transmitted to us unless you create an account.
We use Vercel Analytics and may use similar privacy-respecting analytics tools to understand aggregate usage patterns. These tools collect anonymized or de-identified data about page visits, conversion events, and performance metrics.
We do not use Google Analytics, Facebook Pixel, or advertising trackers on the Service.
| Data Type | Retention Period |
|---|---|
| Account data | While your account is active + 90 days after deletion |
| Scan results | While your account is active (unless deleted by you) |
| Playback/session logs | 24 months, then aggregated/anonymized |
| Payment records | 7 years (tax and accounting law) |
| Support communications | 3 years |
| Anonymous scan data (public) | 6 months, then deleted |
| Security audit logs | 12 months |
We take security seriously:
No method of transmission or storage is 100% secure. If we become aware of a data breach affecting your information, we will notify you as required by law.
You have the right to:
To exercise any of these rights, email privacy@cymatones.com. We'll respond within 30 days.
If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act give you additional rights:
To exercise California rights, contact privacy@cymatones.com. We may need to verify your identity before fulfilling the request.
California Civil Code § 1798.83 allows California residents to request certain information about our disclosure of personal information to third parties for direct marketing. We do not disclose personal information to third parties for their direct marketing.
If you are in the European Economic Area or United Kingdom, the GDPR gives you rights including access, correction, deletion, restriction, portability, and objection to processing of your personal information.
Legal bases for processing:
You may contact a supervisory authority in your country if you believe we have violated data protection law. We would appreciate the opportunity to resolve your concern first — please contact privacy@cymatones.com.
Our servers are primarily located in the United States. By using the Service, you consent to the transfer of your information to the United States and other countries where our service providers operate. We use standard contractual clauses or equivalent safeguards for transfers from the EEA/UK where required.
CymaTones is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, please contact privacy@cymatones.com and we will take steps to delete it.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. For material changes, we will notify you via email and/or an in-app notice at least 30 days before the changes take effect where required by law.
Questions about this Privacy Policy or how we handle your information?