Skip to content

Privacy You Can Understand

This policy explains what Virtu processes on your device, what reaches our service providers, and the controls available to you.

Last updated: July 31, 2026

The Short Version

  • Your scores, MIDI practice results, review history, and saved recordings are generally handled by Virtu's local app service on your device.
  • Remote services handle account sign-in, subscriptions, notifications, diagnostics, attribution, and communications as described below.
  • Google Analytics and Microsoft Clarity run on this marketing site only after you allow analytics cookies.
  • Virtu does not sell personal information. We disclose the service providers that receive data to operate and improve the product.

This policy is provided by Forty Two LLC (상원12길 34, 13층, 성동구, 서울특별시, 대한민국 / 13th Floor, 34 Sangwon 12-gil, Seongdong-gu, Seoul, Republic of Korea). Forty Two LLC is the controller responsible for personal information processed by Virtu. References to “Virtu,” “we,” “us,” or “our” mean Forty Two LLC.

Information We Process

Local Practice & Recording Data

Imported scores, score metadata, MIDI notes, timing, velocity, session results, review schedules, practice settings, and saved recording files. Virtu evaluates and stores this information through the app's local service. A recording is created only when you start and save one. Core practice data is not automatically uploaded as part of account sign-in.

Account & Authentication Data

Name, email address, profile image, sign-in provider identifier, Virtu account identifier, and authentication tokens. Google or Apple authenticates you; Virtu does not receive your Google or Apple password. The client stores access and refresh tokens and a cached profile in local application or web-view storage so you can remain signed in. For Apple accounts, Virtu also stores an encrypted Apple authorization refresh credential on the backend so that Apple authorization can be revoked when the account is deleted.

Subscriptions, Messages & Notifications

Store transaction or receipt identifiers, product and entitlement status, subscription dates, weekly practice recap settings, newsletter or waitlist email submissions, feedback and support messages, notification preferences, and push-notification device tokens. In-app feedback also includes your account, locale, app release, platform, environment, and the app route where you opened the form. Payment card details are handled by the relevant app store and are not provided to Virtu.

Diagnostics & Product Events

Crash reports, stack traces, app release, device or browser details, URLs and navigation traces, event names and properties, network metadata such as IP address, and—when signed in—an account or customer identifier. Sampled Sentry browser replays may be collected to diagnose failures; text is masked and media is blocked in the current configuration. Diagnostic events can still contain technical or user-linked context, so we do not describe them as anonymous.

Website Analytics & Download Attribution

If you allow analytics cookies, Google Analytics and Microsoft Clarity process page views, traffic sources, interactions, device/browser information, cookies or similar identifiers, and Clarity session replay data. Download links also carry campaign, placement, platform, page, and selected-plan parameters. On Android, AppsFlyer receives install attribution and selected in-app events with a customer identifier; Virtu's current Android configuration disables advertising identifiers and network-data collection.

Why We Process It

  • Provide the service: authenticate your account, evaluate MIDI practice, maintain review schedules, save requested recordings, restore entitlements, and deliver notifications.
  • Operate and improve Virtu: investigate failures, secure the service, understand feature use, and measure whether downloads and campaigns work.
  • Communicate with you: answer support requests and send newsletters or waitlist updates you requested.
  • Meet legal obligations: keep records or respond to valid legal requests where applicable.

Where the GDPR applies, our legal bases may include performance of a contract, our legitimate interests in operating and securing Virtu, your consent for optional marketing-site analytics and requested communications, and compliance with legal obligations. You can withdraw consent without affecting processing already carried out lawfully.

Service Providers & Disclosures

We disclose information to providers only for the functions below, subject to their terms and privacy practices. The data each provider receives depends on the feature and platform you use.

Sign-In

Google Sign-In and Apple Sign-In provide identity and profile details you authorize. See Google's Privacy Policy and Apple's Privacy Policy.

Purchases & Entitlements

Apple App Store, Google Play, and RevenueCat process purchases, receipts, subscription status, and customer identifiers. See RevenueCat's Privacy Policy.

Diagnostics

Sentry processes the diagnostic, tracing, event-breadcrumb, user-identifier, and sampled replay data described above. See Sentry's Privacy Policy.

Attribution

AppsFlyer processes Android install attribution, a customer identifier, and selected product events. Website download links may pass campaign parameters to AppsFlyer OneLink. See AppsFlyer's Privacy Policy.

Notifications

Firebase Cloud Messaging and Apple Push Notification service process device tokens and delivery information needed to send enabled notifications. See Firebase Privacy and Apple's APNs privacy information.

Hosting & Email

Amazon Web Services, including Amazon SES hosts supporting services and sends automatic practice recaps and requested emails. See the AWS Privacy Notice.

Marketing-Site Analytics

Google Analytics and Microsoft Clarity run only after analytics consent on virtu-oso.com. See Google's Privacy Policy and Microsoft's Privacy Statement.

We may also disclose information when required by law, to protect users or the service, or as part of a corporate transaction with appropriate notice and safeguards. Virtu does not sell personal information.

Cookies & Local Storage

Essential Local Storage

Virtu uses local storage for authentication tokens, cached profile information, theme and other preferences, consent choices, and basic session state. Authentication data is sensitive; protect access to your device and sign out on shared devices.

Optional Marketing-Site Analytics

Google Analytics and Microsoft Clarity load only after you allow analytics. You can change that choice at any time through . Withdrawing consent stops future optional collection on this site but does not delete data already held by a provider.

Storage, Retention & International Processing

  • Local practice data remains in the app's local database and recording storage until you use “Delete local practice data,” complete in-app cloud-account deletion, clear app data, or uninstall the app, subject to operating-system backups.
  • Account and subscription records are kept while needed to provide the account and maintain entitlements. When cloud-account deletion completes, personal profile fields and authentication links are removed, subscription access is revoked, and the profile row is anonymized into a tombstone so retained financial and audit relationships remain valid. Related retained records may still contain limited provider transaction or refund references, refund explanations, or operator audit details where required.
  • Feedback and support messages are kept while needed to review and respond to them. In-app feedback linked to your cloud account is deleted when that account is deleted, subject to temporary protected backups or legal obligations.
  • Newsletter and waitlist data is kept until you unsubscribe, ask us to remove it, or the requested communication is no longer offered.
  • Diagnostics, attribution, and website analytics are retained according to our configured provider settings and only as long as reasonably needed for reliability, security, and measurement.

“Delete local practice data” removes the current user's local database data and recording files from that device without deleting the Virtu cloud account. “Delete Virtu account” anonymizes the cloud profile, removes its sign-in identities, notifications and entitlements, then deletes that account's local data from the current device. We do not physically delete the backend user row because doing so would break relationships to records that must remain. The profile fields are replaced, but related financial or audit records may retain limited provider transaction or refund references, refund explanations, or operator audit details and therefore are not necessarily anonymous. Limited information may also remain where required by law, needed to establish or defend claims, or temporarily present in protected backups. See the account-deletion page for the in-app and login-independent request paths.

Providers may process information in Korea, the United States, and other countries where they operate. Where applicable law requires a transfer safeguard, we use a legally recognized mechanism or another lawful basis available for the transfer. Local privacy protections may differ by country.

Your Choices & Rights

  • Change marketing-site analytics through Cookie settings.
  • Turn off weekly practice recaps in Virtu settings, use the relevant unsubscribe link in an email, or contact us to stop email messages.
  • Change push-notification permissions through Virtu or your device settings.
  • Delete scores, recordings, and other device data with “Delete local practice data” while keeping the cloud account active.
  • Delete your Virtu cloud account in Settings, or use our login-independent account-deletion request if you no longer have the app.
  • Ask to access, correct, delete, restrict, object to, or receive a portable copy of personal information, as provided by applicable law.

Korean users may have rights to access, correct or erase personal information, and request suspension of processing under PIPA. People in the EEA or UK may have GDPR rights, and California residents may have rights under the CCPA if that law applies to Virtu. Legal exceptions can limit a request. We may verify your identity and will respond within the period required by the law that applies.

Send a request to privacy@virtu-oso.com. You may also contact the relevant privacy regulator, including Korea's Personal Information Protection Commission, an EEA/UK data protection authority, or the California Attorney General's privacy office.

Security & Children

Security

We use technical and organizational measures designed to protect personal information, including encrypted transport for remote services, access controls, and established service providers. No storage or transmission method is completely secure, so we cannot guarantee absolute security.

Children

Virtu is not directed to children under 13. We do not knowingly collect personal information from a child who cannot legally provide consent without a parent or guardian. If you believe a child provided information improperly, contact us so we can investigate and take appropriate action.

Contact & Policy Changes

Questions or privacy requests can be sent to privacy@virtu-oso.com or to Forty Two LLC at the address above.

We may update this policy as Virtu, its providers, or applicable requirements change. We will update the date above and provide additional notice when a change is material and notice is required.