Privacy Policy
Last updated: September 26, 2026
This policy is issued by Pink Lumenade LLC, 3130 Balfour Rd, Suite D #1023, Brentwood, CA 94513, USA ("Pink Lumenade", "we", "our"). We make Upscore, a score tracking, fitness and AI coaching tool for Dance Dance Revolution (DDR) and Pump It Up players. This policy describes what data we collect, how we use it, who we share it with, and your rights. It applies to the Upscore iOS and Android apps, the Upscore watch apps for Apple Watch and Wear OS, the Upscore desktop companion, the app at edi.dance, and the website at upscore.dance.
What We Collect
Account information
Your email address and sign-in credentials, provided through Google, Apple, or an email and password. We use Supabase Auth to manage accounts. We never see or store your Google or Apple password.
Profile photo
By default your avatar is a cartoon face generated from your account, and no image is collected. If you choose to set a profile photo, the photo you select is cropped and resized on your device to a small square image, then uploaded to our storage and linked to your account.
Two things happen before it leaves your device. The image is re-encoded, which removes embedded metadata such as GPS location, camera model, and capture time from the original photo. Only the cropped square is uploaded; the rest of the original image is not.
Your profile photo is stored in a private bucket and served to you over an expiring link. It is visible only to you. Upscore does not currently show your avatar to other players. You can remove it at any time in the app under Profile, by tapping your avatar and choosing "Remove photo", which deletes the stored image and restores your generated face. It is also deleted when you delete your account. A link to your photo can stay valid for up to a year, so a copy you shared yourself could still load for that long after you remove it.
Upscore does not perform face recognition or any other biometric analysis on your photo. It is stored and displayed, nothing more.
Health and fitness data
During a session, with your permission, Upscore reads your heart rate from your Apple Watch, Wear OS watch or a Bluetooth heart rate monitor you pair, and reads steps and active energy from Apple Health or Health Connect. After a session it writes the workout, with steps, energy and heart rate, back to Apple Health or Health Connect so it counts in your health app. On Android, if you allow it, Upscore reads your weight and past weight entries from Health Connect to estimate calories. Your weight stays on your phone and is never uploaded.
Your heart rate readings from the session, along with your average and peak heart rate per song, calories and steps, are stored on our servers so we can show you live BPM, training zones and post-session analytics.
We use your health and fitness data only for those features. We do not use it for advertising or marketing, we do not sell it, and we do not share it with any third party, including our analytics, crash reporting or AI providers, for data mining or any purpose other than delivering Upscore's features to you. You can revoke Upscore's access at any time: on iOS under Settings > Privacy & Security > Health, and on Android in the Health Connect app. On iOS you can also stop Upscore from storing your heart rate on our servers under Profile > About and Privacy > Health. On Android, delete a session from its recap to remove its heart rate data, or contact us.
Body signals (optional)
If you turn on Train insights, Upscore can read sleep, resting heart rate, heart rate variability and other workouts from Apple Health on iPhone or Health Connect on Android to show how recovered you are; your steps, breathing rate, blood oxygen and skin temperature for Daily Health; your weight, body fat, lean mass, VO2 max, active calories, nutrition, water and mindful minutes for the charts you choose; and, only with a separate permission, your menstrual cycle. This data stays on your phone. It is never uploaded to our servers, never shared with anyone, never used for advertising, and is forgotten when you leave the tab. Turn it off at any time: on iPhone in Settings > Privacy & Security > Health, on Android in Health Connect. On Android, the system may also remove the permission itself if you don't use Upscore for months.
Score and gameplay data
Scores, grades, clear lamps, flare levels and related play data that you import from Sanbai, PhaseII, e-amusement, LIFE4 or Pump It Up (AM.PASS), from score files you upload (Dynasty, Grand Free, Eagle, CSV), from the Upscore desktop companion, or by photographing a results screen. This data comes from the services you connect and the files and photos you give us. It is stored in our database and used to power the app's features.
Connected service tokens
When you connect a score service, you sign in with that service directly. We never see or receive your password. We keep the sign-in token the service issues so we can fetch your own play data for you while the connection lasts. The e-amusement token is stored encrypted. Disconnecting a service deletes the token, and so does deleting your account.
Goals and preferences
Goals you create and app settings you configure.
Chat messages
Messages you send to Edi (the AI coach) are processed in real time to generate responses (see "AI Chat" below). Your conversation history is stored on your device. Our servers keep only usage counts such as tokens, the model used and response time. If you rate a reply with thumbs up or down, we also keep that message, your question and the few messages before it, so we can review what went wrong. We also store the short profile summary Edi writes about your play. Both are deleted with your account.
Photos of an arcade screen
If you have Upscore read a song or a score from a photo of the arcade screen, or use the desktop companion, the image is sent to OpenAI to read it and then discarded. We do not keep the photo. Do not include other people in it.
Subscription and purchase data
If you subscribe to a paid tier (Pro or League), purchases are processed by the app store you buy through: Apple (App Store) on iOS or Google (Google Play) on Android. We use RevenueCat to manage subscription status. We give RevenueCat your account id, email and display name so purchases can be matched to your account, and RevenueCat tells us your subscription state. We never receive or store your payment card details; the app store handles payment.
Usage analytics
We use PostHog to understand how the app is used so we can improve it. This includes product events such as pages visited, features used, session length, step counts and which heart rate device you connected, and, in the released app, recordings of how you move through screens. Sleep, heart rate variability and recovery screens are masked from recordings. Heart rate and calorie values are never sent as event data. When you are signed in, analytics are tied to your account id and email.
Diagnostics and crash data
We use Sentry to capture crashes and errors so we can fix bugs. A report includes your account id and email, your device type and operating system version, technical details of the error, and a replay of the screens you were on just before it, with text and images masked. Screens showing body signals are left out of these reports.
AI Chat (Edi)
Edi is powered by Anthropic's Claude. When you send a message, your question, your recent messages, and relevant score, goal and profile context are sent to Anthropic's API to generate a response. We never send your health data to Anthropic. Anthropic does not use your messages to train its models, and neither do we. Anthropic's data-usage policy also applies to this processing; see Anthropic's Privacy Policy.
How We Use Your Data
- Display your scores, track progress, and calculate statistics
- Show live heart rate, training zones, and post-session workout analytics
- Save your sessions to Apple Health or Health Connect (with your permission)
- Fetch your new plays from the score services you connect
- Power Edi's AI coaching using your score context
- Track your goal progress
- Manage your subscription and entitlements
- Diagnose crashes and improve the app based on usage patterns
Our Legal Basis
If you are in the UK, the EU or another place whose law asks us to name a legal basis for each use of your data, here it is:
- Running the app for you (your account, scores, goals, sessions apart from their heart rate parts, connected services, subscriptions, Edi's answers): performing our contract with you, our Terms of Use.
- Heart rate and other health data: your explicit consent. We ask on the screen shown before your first session with heart rate. You can withdraw it at any time under Profile > About and Privacy > Health on iOS, in your device's health settings, or by deleting your account.
- Body signals (sleep, resting heart rate, heart rate variability, vitals, body measurements, cycle): your explicit consent through the Apple Health or Health Connect permission, and the data never leaves your phone.
- Usage analytics and crash reports: our legitimate interest in understanding and fixing the app, balanced against your privacy: heart rate and calorie values are never sent as analytics events, and the screens showing your body signals are masked from recordings. You can object to analytics at any time by emailing us.
- Abuse and payment alerts, and limits on how fast Edi can be used: our legitimate interest in keeping the service running and paid for.
- Subscription and purchase records: our legitimate interest in keeping accurate accounts, handling refunds and disputes, and meeting the bookkeeping rules that apply to us.
You need an email address to have an account. Everything else is your choice: without health permissions there are no heart rate features, without a connected service you import scores another way, and without a photo you keep the generated face.
We do not make decisions about you by automated means that have legal or similarly significant effects. Edi's coaching and any recovery or trend figures are suggestions for you to read, nothing more.
Who We Share Data With
We do not sell or rent your personal data. We share data only with the service providers that operate Upscore, and with the game services you choose to connect, and only as needed to run the app:
- Supabase: database, authentication, and backend hosting (stores your account, scores, goals, sessions, heart rate readings and connected-service tokens)
- Vercel: hosting for the app and the website
- Apple: Apple Health (with your permission), Sign in with Apple if you use it, and App Store payment processing on iOS
- Google: Health Connect (with your permission), Google sign-in if you use it, and Google Play payment processing on Android
- Anthropic: AI chat processing (your message and score context only; never health data)
- OpenAI: reading photos of an arcade screen, only if you use those features (the photo only; never health data)
- PostHog: product usage analytics (tied to your account when signed in; never heart rate or calorie values)
- Sentry: crash and error diagnostics
- RevenueCat: subscription management
- Score services you connect: Sanbai, PhaseII, LIFE4, e-amusement or Pump It Up receive your sign-in token when we fetch your plays. When you submit to LIFE4, your scores and proof photos go to LIFE4.
- Discord: internal alerts to our team about payment and abuse issues, containing your account id only, never your email, scores or health data
Each provider is permitted to use your data only to provide its service to us, and is required to protect it consistent with this policy.
Data Storage & Transfer
Your data is stored in Supabase, hosted on AWS in the United States. All data is transmitted over HTTPS. Database access is protected by Row Level Security, so users can only access their own data. If you use Upscore from outside the United States, your data will be transferred to and processed in the United States. For people in the UK and the EU, we rely on the safeguards the law recognises for sending data to the United States: the standard contractual clauses and the UK International Data Transfer Addendum in our providers' data processing terms, and, for providers certified under it, the EU-US Data Privacy Framework and its UK Extension. Email us and we will tell you which safeguard applies to a provider and send you a copy. If a breach exposes your data, we will tell you without undue delay and within the time the law requires, and tell the authorities the law names.
Data Retention
We keep your data for as long as your account is active. Heart rate readings, scores and chat feedback are kept while your account is active. Connected service tokens are kept until you disconnect the service. Analytics events and crash reports are kept by PostHog and Sentry for a fixed period under their retention settings; email us for the current periods. Internal alerts in Discord carry only your account id. When you delete your account, your data is removed right away, and copies in our operational backups are removed within 30 days, except limited records we must keep by law (for example, transaction records held by the app store and RevenueCat). Copies held by PostHog and Sentry expire on their retention schedules.
A profile photo is kept until you remove it or delete your account. Removing it deletes the stored image. Because images are cached by your device and by content delivery networks for performance, a copy already downloaded to a device may persist in that device's cache for a period after removal.
Your Rights
- Access: You can view your data in the app at any time.
- Deletion: Delete your account in the app under Profile > Settings > Delete Account. Your account and data are removed right away, and backups within 30 days. You can also email us to ask.
- Health data control: Revoke Upscore's access in your device's health settings at any time. On iOS you can also stop Upscore from storing your heart rate on our servers under Profile > About and Privacy > Health. Our Consumer Health Data Notice has more.
- Connected services: Disconnect any score service in the app at any time, which deletes the token we kept.
- Profile photo: Add or remove your photo at any time in the app under Profile.
- Object: You can object at any time to any use we base on our legitimate interests, including analytics and crash reports. Contact us and we will stop.
- Subscriptions: Manage or cancel subscriptions in your App Store (Apple ID) account settings on iOS, or your Google Play account settings on Android, depending on where you purchased.
Depending on where you live, for example under the UK GDPR, the EU GDPR, the California Consumer Privacy Act, the Washington My Health My Data Act, or Japan's Act on the Protection of Personal Information, you also have the right to ask what data we hold about you and receive a copy of it in a common, machine-readable format, to have it corrected, to have it deleted, to restrict how we use it, and to withdraw any consent you gave, without it affecting anything done before. Email us to use any of these rights. We may ask you to confirm who you are. We will answer within one month, free of charge. If a request is complex we may need up to two months more, and we will tell you. If you are in the UK and are not satisfied with our answer, you can complain to the Information Commissioner's Office at ico.org.uk. If you are in the EU, you can complain to the data protection authority in your country.
Children's Privacy
Upscore is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has an account, email us and we will close it and delete its data, including any profile photo.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated through the app or via email. The "Last updated" date at the top reflects the most recent revision.
Contact
For privacy questions, data deletion requests, copyright notices or concerns: rinon@edi.dance, or by post to Pink Lumenade LLC, 3130 Balfour Rd, Suite D #1023, Brentwood, CA 94513.