Watermelon · Starling Labs
Watermelon is a practice tool for learning song lyrics. It works with music you already own, on your own device. This page explains exactly what that means for your data — what stays on the phone, the few things that leave it, and how to delete everything.
Your music never leaves your device. Watermelon plays files that are already on your phone or tablet. It stores a reference to them — never a copy, and it never uploads audio anywhere.
Your practice stays private. Which lines you loop, which words you hide, how you rated yourself, how far through a song you are — all of it lives in the app's storage on your device and is never sent to us.
We don't run ads or analytics. There is no advertising SDK, no analytics SDK and no tracking of you across other apps or websites in Watermelon.
You can delete everything. One button in the app removes your account, your remaining credits and your history. How to do it.
Most of what Watermelon knows about you never goes anywhere. The following is written to the app's own storage on your phone or tablet, and stays there:
Uninstalling the app removes all of it. Your music files are not touched — Watermelon only ever held a reference to them.
Everything Watermelon sends anywhere is listed here. Nothing else is collected, and there is no background collection while you are not using a feature below.
| What | When | Where it goes |
|---|---|---|
| A song's title, artist, album and length | When you search for lyrics for that song | LRCLIB (lrclib.net), a community lyrics database. If it finds nothing, the artist and title are tried against lyrics.ovh. |
| A song's title and artist | When the app looks for cover art | Apple's iTunes Search API |
| Your name, email address, profile picture and Google account identifier | When you sign in | Google, and Firebase Authentication (a Google service) on our behalf |
| Your credit balance, and one row for each credit spent or bought — each row carries the title of the song it relates to | While you use credits | Cloud Firestore (Google Cloud), under your account |
| A list of the songs you've unlocked for practice — title, artist and length | When you unlock a song | Cloud Firestore (Google Cloud), under your account. This is what lets a song you've already paid for come back on a new phone instead of charging you twice. |
| What you bought, and the store's receipt for it | When you buy credits | Apple's App Store or Google Play, and RevenueCat, which verifies the purchase for us |
| Your device platform and the app's version | When the app checks for an update | Expo (EAS Update), which hosts our app updates |
| Your email address | Only if you type it into a sign-up sheet at one of our live demos | A Google Form and Sheet that we own |
Lyrics searches are made from your device, and the lyrics that come back are stored on your device. We don't keep a record of what you searched for.
Watermelon uses Google sign-in, and signing in is required to use the app. We do this for one reason: your credits belong to your account rather than to a phone, so they survive a reinstall, follow you to a new device, and can't be farmed by reinstalling to collect the free ones again. We never see or handle your Google password.
When you sign in, we store the following against your account:
Song titles reach us this way and no other. The song's audio, its lyrics, and everything about how you practiced it stay on your device.
Credits are bought through Apple's App Store or Google Play. Your payment details never reach us — the store handles the transaction and tells us only that it happened, through RevenueCat, which verifies store receipts on our behalf. We record which pack was bought, how many credits it was worth, and when.
A credit unlocks that song's practice tools permanently, on any device you sign in on. We don't track how much you practice, or judge whether you used it enough — nothing about how you work a song ever leaves your phone.
Watermelon does not ask for your photos, contacts, location or microphone, and it never records audio.
You can remove everything we hold, at any time, without asking us. Deleting is permanent, and unused credits are not refundable. Your music files are never touched either way. There's a separate page with the full detail, including exactly what is deleted and what we're required to keep: Delete your account.
Open Account, scroll to the bottom, and tap Delete my account. This deletes your account, your remaining credits and your credit history from our servers, and clears your song list and settings from that device. If you're not signed in, the same button appears as Erase my data and clears that device.
If you've already uninstalled Watermelon, email support@builtbystarling.com from the address you signed in with and ask us to delete your account. We'll confirm and delete it within 30 days.
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. The app gives you deletion directly; for anything else, email us and we'll answer within 30 days. We won't treat you differently for asking.
Depending on where you live, you may have additional rights — for example under the GDPR in the UK and EEA, or the CCPA in California — including the right to object to or restrict processing, the right to data portability, and the right to complain to your local data protection authority. We rely on your consent to use your Google account details, and on our legitimate interest in running a working, fairly-priced app for the credit records that make purchases possible. Our services run on Google Cloud and may process your data on servers outside your country, including in the United States.
Watermelon isn't directed at children under 13, and we don't knowingly collect personal information from them. If you believe a child has given us their information, email us and we'll delete it.
Everything the app sends travels over an encrypted connection. Your account data is readable and writable only by you, enforced by rules on the database itself rather than by the app being polite: a signed-in device can spend its own credits, and nothing else. Credits can only be added by our server, and only after a store has confirmed a real purchase. No system is perfectly secure, but we've kept what we hold small on purpose — the less there is, the less there is to lose.
If this policy changes, the new version appears on this page and the "last updated" date changes with it. If a change is significant, we'll say so plainly here rather than leaving you to find it.
Questions about this policy, or about your data, go to support@builtbystarling.com. A real person reads it.