Privacy Policy
Last updated September 29, 2026
sheddex (sheddex.com) is a free collection of browser-based music practice tools, built and operated by Jack Mechem as a personal, non-commercial project. This page explains what data sheddex collects, why, and what your options are. It isn't written in dense legal boilerplate on purpose — if anything here is unclear, use the contact method at the bottom and ask.
The short version
Recorder and Slow Downer's actual recordings and loaded audio files always stay in your own browser and are never sent anywhere, account or not. Every other tool's data (tune lists, settings, chord charts, practice history and stats) works the same way when you're signed out — but if you create an account, that data syncs to sheddex's servers instead, so it follows you to another device signed into the same account. Signing in is entirely optional; every tool works fully without one. There's also an entirely separate, opt-in public profile (a username, picture, instruments, and your tunes) that only becomes visible to anyone — including people without an account — if you explicitly turn it on; see "Public profiles" below. There are no ads, no analytics, and no trackers anywhere on this site.
Data that stays on your device
Signed out, every tool on sheddex — the trainers, the metronome, Chord Charts, Slow Downer, the Recorder — stores its data (settings, tune lists, imported chord charts, practice history, recordings, and any audio files you load) directly in your browser's own local storage, using standard browser technology (localStorage and IndexedDB). None of it is uploaded to sheddex's servers or seen by Jack Mechem. It stays on your device until you clear it yourself (through your browser's own settings, or a tool's own reset controls where available) — clearing your browser's site data for sheddex.com will delete it.
Recorder's and Slow Downer's actual audio (recordings and loaded files) always works this way, signed in or not — see "Data collected if you create an account" below for what does sync.
Data collected if you create an account
Creating an account is entirely optional — every tool works fully without one.
If you sign up with email and password, sheddex collects and stores:
- Your email address.
- Your password, but never in a readable form — it's run through a one-way hashing function before it's stored, and can't be recovered from the stored value, by sheddex or anyone else.
If you sign in with Google instead, Google shares with sheddex:
- The email address and name associated with your Google account.
- Whatever else Google's own sign-in screen tells you it's sharing at the time you sign in — sheddex only requests the minimum needed to create an account (your email), nothing broader.
Confirming an action by email (creating an account, changing a password, deleting an account) briefly stores a one-time confirmation code, hashed the same way a password is, which expires automatically after 15 minutes whether or not it's used.
If you're signed in, sheddex also stores your tool data on its servers instead of only in your browser — tune lists, each tool's settings, imported chord charts, and the trainers' practice history/stats. Signing in doesn't merge what was already in your browser with your account — it switches over to whatever's already saved to the account, so anything only saved locally before you signed in stays only in that browser's local storage unless you re-add it while signed in. Recorder's recordings and Slow Downer's loaded audio files are the one exception — those stay local-only regardless of sign-in state (see "Data that stays on your device" above).
Public profiles
Separate from the account data above, sheddex lets you optionally set up a public profile — a username (unrelated to how you sign in), a picture, and the instruments you play — from the Public Profile tab of the account page. None of this is visible to anyone else, and it doesn't appear in the Community search page, until you explicitly turn "Make profile public" on there.
Once public, your username, picture, instruments, and every tune in your Tunes and Tunes to Learn lists (name, tempos, keys, and time signature — never any notes you've written on a tune) can be viewed by anyone at its own page (sheddex.com/u/your-username) and found via the Community search page — both reachable without an account. There's no way to show only some of your tunes; making your profile public shows all of them. A public profile also shows who you follow and who follows you (see "Follows" below) to anyone who can view the profile at all, under that same rule. Turning a profile back to private, or deleting it entirely, removes this visibility immediately — the account page lets you do either any time.
Tunes to Learn. Separate from your own Jam Practice tune list, sheddex also lets you keep a personal "Tunes to Learn" list — built by copying tunes you see on other people's public profiles onto your own list, from the account page's Tunes to Learn tab. This list is stored on sheddex's servers the same way your other synced tool data is, and is shown on your own public profile under the same public/private rule as everything else described here.
Follows. If you follow another public profile, that's stored as a simple record of who follows whom. Your own Following and Followers lists are always visible to you on the account page; on a public profile, both lists are visible to anyone who can view that profile, the same as the rest of it. Following requires being signed in; there's no notification sent to the account you follow.
Profile pictures are uploaded files, stored via Convex's file storage (see "Who else sees your data" below) — resized in your own browser before uploading, so only the resized version ever reaches sheddex's servers.
Cookies and browser storage
sheddex doesn't use advertising or tracking cookies. Browser storage is used only for the site to function: remembering your theme/display preferences, each tool's own settings, and — if you're signed in — keeping you signed in between visits.
Who else sees your data
sheddex doesn't sell data, and doesn't share it for advertising. A small number of service providers handle the account/email infrastructure on sheddex's behalf, only for the specific purpose named:
- Convex — stores account data (email, hashed password, session tokens), synced tool data, and (if you set one) your public profile — including uploaded profile pictures, via Convex's file storage — and runs the server-side code that handles all of it.
- Resend — sends the confirmation emails sheddex emails you (account creation, password changes, account deletion). Your email address is shared with Resend only to deliver these.
- Google — handles the "Sign in with Google" option, if you choose to use it, per Google's own privacy practices.
- Vercel — hosts and serves the sheddex.com site itself, and so processes standard technical information (like IP addresses) as part of serving web pages, the same as any web host.
- GitHub Pages — the Piano and Rhodes tones (used across several tools — see Credits) are real recordings your browser fetches directly from two GitHub Pages-hosted sample libraries the first time you pick one of those tones, not through sheddex's own servers, so GitHub sees that request the same way it would for any page it hosts.
These providers may process data on servers located outside your own country, including in the United States.
How long data is kept
Account data is kept for as long as your account exists. You can delete your account yourself, at any time, from the account page — this permanently removes your email, password, and sign-in history from sheddex's servers. Data stored in your own browser is kept until you clear it yourself and isn't affected by deleting your account.
Your choices
- Use sheddex without ever creating an account.
- View, change, or delete your account yourself, any time, from the account page — change or set a password, connect or disconnect Google sign-in, or permanently delete the account and everything tied to it.
- Turn a public profile back to private, or remove it entirely, any time from the Public Profile tab — either immediately stops anyone from being able to view it.
- Clear your browser's local storage for sheddex.com at any time to remove everything stored on your device.
Security
Passwords are stored hashed, never in plain text. Traffic to sheddex.com is encrypted (HTTPS). No online service can guarantee perfect security, but sheddex doesn't collect more than it needs to in the first place, which limits what there is to protect.
Children's privacy
sheddex isn't directed at children under 13, and doesn't knowingly collect personal information from anyone under 13. If you believe a child has created an account, contact us using the method below and it will be removed.
Changes to this policy
If this policy changes, this page will be updated and the date at the top will change. There's no mailing list or other notification beyond that.
Contact
Questions about this policy, or requests about your data (including deleting it, beyond what the account page already lets you do yourself), can be sent via GitHub issues.