Skip to content

Privacy You Can Understand

This policy explains what Virtu processes on your device, what reaches our service providers, and the controls available to you.

Last updated: September 10, 2026

The Short Version

  • Your scores, MIDI practice results, review history, and saved recordings are generally handled on your device. Optional cloud and sharing features send the data needed for those features to our services.
  • Remote services handle account sign-in, subscriptions, notifications, diagnostics, attribution, and communications as described below.
  • Google Analytics and Microsoft Clarity run on this marketing site only after you allow analytics cookies.
  • Virtu does not sell personal information. We disclose the service providers that receive data to operate and improve the product.

This policy is provided by Forty Two LLC (상원12길 34, 13층, 성동구, 서울특별시, 대한민국 / 13th Floor, 34 Sangwon 12-gil, Seongdong-gu, Seoul, Republic of Korea). Forty Two LLC is the controller responsible for personal information processed by Virtu. References to “Virtu,” “we,” “us,” or “our” mean Forty Two LLC.

Information We Process

Local Practice & Recording Data

Imported scores, score metadata, MIDI notes, timing, velocity, session results, review schedules, practice settings, and saved recording files. Virtu evaluates and stores this information through the app's local service. Supported MIDI practice attempts can be retained automatically as local recordings; microphone/audio recordings are created only when you explicitly start and save one. Core practice data is not automatically uploaded just by signing in; if you enable Plus Cloud Continuity, the selected repertoire, canonical practice evidence, recording markers, active practice state, and approved settings are synchronized for backup and restore. When you use sharing or feedback features, the practice excerpts, recording details, and messages you choose to submit are uploaded. Their audience depends on the sharing option you choose; a link may be accessible to anyone who has it, and a public post may be visible to other users.

Account & Authentication Data

Name, email address, profile image, and information about your Virtu account and sign-in method. Google or Apple signs you in; Virtu does not receive your Google or Apple password. The app keeps the sign-in information it needs on your device so you can stay signed in. If you used Apple, we keep the information needed to disconnect Apple when you delete your account.

Subscriptions, Messages & Notifications

Store transaction or receipt identifiers, product and entitlement status, subscription dates, weekly practice recap settings, newsletter email submissions, feedback and support messages, notification preferences, and push-notification device tokens. In-app feedback also includes your account, locale, app release, platform, environment, and the app route where you opened the form. Payment card details are handled by the relevant app store and are not provided to Virtu.

Diagnostics & Product Events

Crash reports, stack traces, app release, device or browser details, URLs and navigation traces, event names and properties, network metadata such as IP address, and—when signed in—an account or customer identifier. Sampled Sentry browser replays may be collected to diagnose failures; text is masked and media is blocked in the current configuration. Public recording-share URLs are suppressed from optional analytics and diagnostics so their bearer tokens are not sent to those providers. Diagnostic events can still contain technical or user-linked context, so we do not describe them as anonymous.

Website Analytics & Download Attribution

If you allow analytics cookies, Google Analytics and Microsoft Clarity process page views, traffic sources, interactions, device/browser information, cookies or similar identifiers, and Clarity session replay data. Public recording-share URLs are excluded from this optional collection. Download links also carry campaign, placement, platform, page, and selected-plan parameters. On Android and iOS, AppsFlyer processes installation attribution and selected in-app events, a hashed customer identifier when signed in, SDK installation identifiers, and technical metadata such as app/device information and IP addresses. Android disables advertising identifiers and SDK network-data collection. iOS disables IDFA, IDFV, device-name collection, Apple Ads attribution, SKAdNetwork management, and sharing with integrated partners; it does not request ATT authorization. These identifiers are pseudonymous, not anonymous.

Why We Process It

  • Provide the service: authenticate your account, evaluate MIDI practice, maintain review schedules, save requested recordings, restore entitlements, and deliver notifications.
  • Operate and improve Virtu: investigate failures, secure the service, understand feature use, and measure whether downloads and campaigns work.
  • Communicate with you: answer support requests and send newsletters or product updates you requested.
  • Meet legal obligations: keep records or respond to valid legal requests where applicable.

Where the GDPR applies, our legal bases may include performance of a contract, our legitimate interests in operating and securing Virtu, your consent for optional marketing-site analytics and requested communications, and compliance with legal obligations. You can withdraw consent without affecting processing already carried out lawfully.

Service Providers & Disclosures

We disclose information to providers only for the functions below, subject to their terms and privacy practices. The data each provider receives depends on the feature and platform you use.

Sign-In

Google Sign-In and Apple Sign-In provide identity and profile details you authorize. See Google's Privacy Policy and Apple's Privacy Policy.

Purchases & Entitlements

Apple App Store, Google Play, and RevenueCat process purchases, receipts, subscription status, and customer identifiers. See RevenueCat's Privacy Policy.

Diagnostics & Product Events

Sentry processes the diagnostic, tracing, event-breadcrumb, user-identifier, and sampled replay data described above. See Sentry's Privacy Policy.

Attribution

AppsFlyer processes Android and iOS install attribution, SDK installation identifiers, a hashed customer identifier when signed in, technical metadata, and selected product events. Website download links may pass campaign parameters to AppsFlyer OneLink. See AppsFlyer's Privacy Policy.

Notifications

Firebase Cloud Messaging and Apple Push Notification service process device tokens and delivery information needed to send enabled notifications. See Firebase Privacy and Apple's APNs privacy information.

Hosting & Email

Amazon Web Services, including Amazon SES hosts supporting services and sends automatic practice recaps and requested emails. See the AWS Privacy Notice.

Marketing-Site Analytics

Google Analytics and Microsoft Clarity run only after analytics consent on virtu-oso.com. See Google's Privacy Policy and Microsoft's Privacy Statement.

We may also disclose information when required by law, to protect users or the service, or as part of a corporate transaction with appropriate notice and safeguards. Virtu does not sell personal information.

Cookies & Local Storage

Essential Local Storage

Virtu stores sign-in information, profile details, theme and other preferences, consent choices, and basic session information on your device. Keep your device secure and sign out on shared devices.

Optional Marketing-Site Analytics

Google Analytics and Microsoft Clarity load only after you allow analytics. You can change that choice at any time through . Withdrawing consent stops future optional collection on this site but does not delete data already held by a provider.

Storage, Retention & International Processing

  • Practice data stays in the installed app on your device until you use “Delete data from this device,” finish account deletion in the app, clear app data, or uninstall the app. Operating-system backups may keep copies for a while.
  • Account and subscription records are kept while needed to provide the service. After account deletion, personal account details and Google or Apple sign-in connections are removed. We may keep limited purchase, refund, security, legal, or support records when needed to complete a transaction, respond to a support request, prevent fraud, protect the service, or follow the law; these records may still include details that identify you.
  • Feedback and support messages are kept while needed to review and respond to them. Limited support records may remain after account deletion when needed to document or complete a request, and may still include details that identify you; temporary protected backups or legal obligations may also apply.
  • Newsletter data is kept until you unsubscribe, ask us to remove it, or the requested communication is no longer offered.
  • Diagnostics, attribution, and website analytics are retained according to our configured provider settings and only as long as reasonably needed for reliability, security, and measurement.

When you delete your Virtu account, we remove your personal account details and sign-in connections. Some limited records may remain temporarily in protected backups or where the law requires us to keep them. See the account-deletion page for details about deleting in the app or by email.

Providers may process information in Korea, the United States, and other countries where they operate. Where applicable law requires a transfer safeguard, we use a legally recognized mechanism or another lawful basis available for the transfer. Local privacy protections may differ by country.

Your Choices & Rights

  • Change analytics consent at any time through Cookie settings.
  • Unsubscribe from the newsletter through its unsubscribe link or by contacting privacy@virtu-oso.com.
  • Disable notifications in Virtu or in your device settings.
  • Choose “Delete data from this device” in the app settings; this does not delete your Virtu account.
  • Delete your Virtu account or request deletion by email through the account-deletion page.
  • Ask about access, correction, deletion, portability, or other rights by contacting privacy@virtu-oso.com.

We may need to verify your identity before completing a request. We respond within the period required by applicable law and may retain a minimal record of the request and response for accountability.

If you have a concern, contact privacy@virtu-oso.com. Korea's Personal Information Protection Commission or the California Attorney General.

Security & Children

Security

We use access controls, encryption in transit, protected secrets, least-privilege service identities, monitoring, and provider security controls appropriate to the data and feature. No service is perfectly secure, so protect your device and contact us promptly if you suspect unauthorized access.

Children

Virtu is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can investigate and remove it where appropriate.

Contact & Policy Changes

For privacy questions or requests, email privacy@virtu-oso.com . We review requests on business days and may need to verify your identity.

We may update this policy as Virtu changes. Material changes will be announced through an appropriate channel and with any notice required by applicable law.