Basso Privacy Policy
Effective date: August 22, 2026
Basso is a voice-training app published by Tiki Studios ("Tiki Studios", "we", "us"). This Privacy Policy explains what information Basso handles, where it goes, and — just as important — what never leaves your device.
The short version
- Your voice never leaves your device. Microphone audio is analyzed on-device in real time and is never uploaded to us or anyone else.
- No accounts. We never ask for your name, email address, or password.
- Your training data stays local. Voice measurements, progress, and settings live only in a database on your device. Deleting the app deletes them.
- Two processors, both anonymous: Firebase (Google) for usage analytics and crash reporting; RevenueCat for subscription management under an anonymous ID.
- No ads, no tracking. Basso contains no advertising and does not track you across other apps or websites.
- Minors are protected: analytics is disabled for users who self-report as minors.
1. Who is responsible for your data
The data controller is Tiki Studios. You can reach us at support@vitola.my.
2. Information processed on your device (never uploaded)
The following data is created and stored only on your device, in a local database or as temporary files. It is not transmitted to us — there is no Basso server.
- Voice audio. When you take a voice test or do a guided exercise, microphone audio is captured as a raw PCM stream and fed directly into Basso's on-device pitch-analysis engine. The audio is discarded as it is analyzed. The one exception is the optional Record & compare feature: it saves a single temporary WAV file (up to about 10 seconds) so you can play your take back against the coach's reference take. That file stays on your device and is deleted automatically when you close the feature.
- Voice measurements. Metrics derived from voice tests: median pitch (Hz), pitch percentiles, pitch stability, lowest comfortable pitch, voiced ratio, ambient noise floor, a measurement-quality flag, your device model, and the local hour of the test.
- Profile and preferences. Your birth year (used only to apply the minor protections described in Section 6), your training goal, your daily practice-minutes choice, and your locale.
- Training progress. Your program assignment, session and exercise completions, settings, and a local cache of your subscription status.
- Practice reminders. If you enable reminders, notifications are scheduled on your device by the operating system. No server is involved.
- Share cards. If you choose to share a progress card, the image is rendered on your device and leaves it only through the destination you pick in the system share sheet.
3. Information collected by third-party services
3.1 Firebase Analytics (Google)
Basso logs usage events to Firebase Analytics to understand how the app is used and where to improve it. Events include:
- app opens;
- onboarding start and steps (goal selection, daily practice-time choice, age confirmation);
- microphone-permission result (granted/denied), and whether the ambient-noise check passed before a test;
- voice-test completions, which carry numeric pitch values (median pitch and low-range pitch in Hz) and a measurement-quality flag; skipping the low-range test;
- viewing your result and your revealed plan, and which training track you were assigned (track name and routing-config version);
- weekly re-test results (pitch and change versus your baseline);
- paywall views, trial start, purchase completion (product identifier only), and purchase restore;
- practice-session starts and completions (session identifier and duration), exercise-block completions;
- share-card creation, notification opens, settings changes, and whether the speech-language-pathologist referral notice was shown to you.
Events are linked to a Firebase app-instance ID — a random identifier generated when you install the app — plus standard automatically-collected device and app metadata (device model, OS version, app version, coarse country/region). Event parameters carry only identifiers, numbers, and enum values: never audio, free text, names, or contact details.
3.2 Firebase Crashlytics (Google)
If the app crashes, Firebase Crashlytics receives a crash report: the stack trace, device model, OS version, app version, and device state at the time of the crash, tied to a Crashlytics installation identifier. Crash reporting is disabled in debug builds.
3.3 RevenueCat
RevenueCat manages your subscription status. Purchases are associated with an anonymous app-user ID generated by RevenueCat — Basso never identifies or logs you in to RevenueCat, so these records are not linked to your identity by us. The payment itself is processed entirely by the Apple App Store or Google Play; we never see your card details or your store-account identity.
We do not sell personal data, and we do not share your data with anyone other than the processors listed above.
4. What Basso does not collect
- Your audio — it is processed on your device and never uploaded (Section 2).
- No accounts or identity data — no names, email addresses, phone numbers, or passwords (if you email us for support, we obviously receive that email).
- No advertising data — no ad networks, no advertising identifiers (no IDFA, no Android Advertising ID), and no cross-app or cross-website tracking. Basso never shows the App Tracking Transparency prompt because it does not track you.
- No precise location, contacts, photos, or similar device data beyond what Section 3 describes.
5. Microphone access
Basso requests microphone access for one purpose only: analyzing your voice pitch during voice tests and exercises, on-device, as described in Section 2. You can revoke the permission at any time in your device's system settings; measurement features will stop working until it is granted again, but the rest of the app is unaffected.
6. Children and minors
Basso is not directed to children under 13, and you must be at least 13 years old to use it.
During onboarding, Basso asks for your birth year. The birth year and the resulting minor flag are stored only on your device. For users who self-report as minors (under 18), analytics is disabled — no usage events are collected as described in Section 3.1.
If you are a parent or guardian and believe a child under 13 is using Basso, please contact us at support@vitola.my.
7. How we use information
We use the information in Section 3 to operate and improve Basso: understanding which features are used, measuring program engagement, diagnosing crashes, and managing subscriptions. We do not use your information for advertising, ad targeting, or profiling.
8. International transfers
Firebase (Google) and RevenueCat, Inc. process the Section 3 data on our behalf, including in the United States. If you use Basso outside the United States, that data will be transferred to and processed in the United States under those providers' data-processing terms:
- Google Firebase: firebase.google.com/support/privacy and policies.google.com/privacy
- RevenueCat: revenuecat.com/privacy
9. Data retention and deletion
- On-device data (voice measurements, profile, progress, settings) is retained until you delete the app. Deleting Basso from your device deletes all of it.
- Temporary files (the record-compare WAV, share-card images) are deleted automatically by the app or the operating system.
- Analytics and crash data are retained by Google according to our Firebase project configuration and Google's data-processing terms, tied only to the anonymous app-instance ID.
- Purchase records are retained by RevenueCat so that your subscription status stays restorable, tied only to the anonymous app-user ID.
- Support correspondence is kept only as long as needed to handle your request.
To request deletion of the service-side data described above, email support@vitola.my and we will delete what can be tied to your app-instance or purchase identifier.
10. Your rights
Depending on where you live (for example the EEA, UK, Switzerland, or California), you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Because Basso has no accounts and holds no data that identifies you, the practical route for most requests is: on-device data → delete the app; anonymous service-side data → contact us at support@vitola.my. You may also lodge a complaint with your local data-protection authority.
11. Security
Your training data never leaves your device, which removes the largest risk by design. On the device it sits inside the app's private storage, protected by the operating system's app sandboxing and device-level encryption. The limited data handled by Firebase and RevenueCat is protected under their respective security and data-processing terms. No method of transmission or storage is 100% secure, but we collect as little as possible precisely so there is little to protect.
12. Changes to this policy
If we change this policy, we will post the new version at vitola.my/basso/privacy and update the effective date above. Material changes will be highlighted in the app or on that page before they take effect.
13. Contact
Tiki Studios
Email: support@vitola.my