Privacy Policy for ToneRig

Effective Date: June 28, 2026
Last Updated: August 7, 2026

Joshua Aquino (“we,” “our,” or “us”) built ToneRig as a commercial app for iPhone and iPad. This Privacy Policy explains how ToneRig handles your information.

The short version: ToneRig does not sell your information, show advertising, or track you across apps or websites. All audio processing happens on your device. Information leaves your device in only three cases: anonymous crash diagnostics if the app or its Audio Unit extension crashes (see Section 1), an anonymous, non-personal event when you purchase ToneRig Pro or leave a tip (see Section 1), and — only if you choose to use it — sign-in with the optional third-party TONE3000 service (see Section 4).

By using ToneRig, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the app.


1. Information We Collect

ToneRig has no developer-operated user accounts, behavioral analytics, advertising, or cross-app tracking. It collects only the limited diagnostic and purchase information described below: crash diagnostics when the app crashes, and a single anonymous event when you purchase ToneRig Pro or leave a tip. We do not otherwise operate servers that receive information about you or your use of the app.

Audio

ToneRig processes audio from your connected instrument or audio interface in real time, on your device, to produce sound. This audio is never recorded, stored, or transmitted. It exists only momentarily in memory while being processed and played back.

Information Stored Only on Your Device

The following is stored locally on your device and is never sent to us:

  • Presets and settings: your signal chains, effect settings, and app preferences (stored in on-device app storage / UserDefaults).
  • Imported files: Neural Amp Model (.nam) files and impulse response (.wav) files you import remain on your device.
  • TONE3000 sign-in tokens: if you sign in to TONE3000 (Section 4), the resulting authentication tokens are stored securely in the iOS Keychain on your device. They are not shared with us.

Crash Diagnostics

ToneRig uses Firebase Crashlytics, a service provided by Google, to identify and fix crashes. When the app or its Audio Unit extension crashes, Crashlytics may automatically receive:

  • the crash stack trace, exception or signal information, and relevant app state;
  • the app version, bundle identifier, and crash timestamp;
  • general device and operating-system information, such as the device model, architecture, OS version, memory, and disk information; and
  • random Crashlytics, Firebase installation, and session identifiers used to group duplicate crashes and estimate how many installations are affected.

ToneRig does not attach your name, email address, TONE3000 account, presets, imported files, or audio to Crashlytics reports. Google Analytics is not included in the app, so Crashlytics does not collect Analytics breadcrumb logs.

Purchase Analytics

When you purchase the paid ToneRig Pro upgrade, or leave an optional tip, the app sends a single, one-time event to our own infrastructure so we can see that a sale occurred without waiting on Apple’s delayed reporting. This event contains only:

  • the product identifier and its displayed price;
  • a randomly generated anonymous installation identifier — a value created on your device that is not tied to your name, email, Apple Account, or any other account; and
  • the app version.

This information is not linked to your identity, is used only to measure sales, and is never used for advertising, never combined with data from other companies, and never shared with data brokers or any advertising network. Your payment is processed entirely by Apple — we never receive your payment details. Restoring a previous purchase does not send this event.

Information We Do NOT Collect

  • We do not require an account with us.
  • We do not record, store, or transmit your audio.
  • We do not use behavioral analytics or advertising services.
  • We do not track you across other apps or websites.
  • We do not add user names, email addresses, or custom user identifiers to Crashlytics reports.

2. How We Use Information

Crash diagnostics are used only to identify, prioritize, and fix stability problems. Purchase-event information is used only to confirm and count new Pro purchases and tips. Data created in ToneRig (presets, imported models, settings) is used solely on your device to provide the app’s functionality.


3. How We Share Information

We do not sell, rent, or trade your information, and we do not use it for advertising or cross-app tracking. Crash diagnostics are processed by Google through Firebase Crashlytics. Purchase events are delivered to Discord. Requests made through the optional TONE3000 integration go directly to TONE3000. These providers process information under their own terms and privacy policies. We do not share this data with advertisers or data brokers.


4. Third-Party Service: TONE3000

ToneRig includes an optional integration with TONE3000 (https://www.tone3000.com), a third-party service for browsing and downloading Neural Amp Model tones. This integration is used only if you choose to sign in.

  • Sign-in: You authenticate directly with TONE3000 using your own TONE3000 account. You never enter a TONE3000 password into ToneRig; sign-in happens through TONE3000’s own secure web flow (OAuth). ToneRig receives only the access tokens needed to act on your behalf, which are stored in your device’s Keychain.
  • What is exchanged: When signed in, ToneRig communicates with TONE3000 to show your account name, browse tones, and download tones you select. These requests go directly to TONE3000.
  • TONE3000’s responsibility: Any information you provide to TONE3000, and any data TONE3000 collects, is governed by TONE3000’s own privacy policy, not this one. We are not affiliated with TONE3000. Please review their privacy policy at https://www.tone3000.com.
  • Disconnecting: You can sign out at any time in Settings, which deletes the stored tokens from your device.

ToneRig is an independent product and is not affiliated with, endorsed by, or sponsored by TONE3000 or the Neural Amp Modeler project.


5. Data Retention

Firebase states that Crashlytics retains crash stack traces and associated installation identifiers for 90 days before beginning removal from its live and backup systems. Purchase-event notifications remain in the developer’s private Discord workspace until deleted. Data stored on your device (presets, imported files, settings, and any TONE3000 tokens) remains until you delete it within the app or delete the app, which removes all of its local data.


6. Data Security

ToneRig relies on the security protections built into iOS:

  • TONE3000 sign-in tokens are stored in the iOS Keychain.
  • Network communication with Firebase, Discord, and TONE3000 uses encrypted connections (HTTPS/TLS).
  • Your audio and your imported files never leave your device through ToneRig.

No method of storage or transmission is 100% secure, but ToneRig is designed to keep your data on your device.


7. Your Privacy Rights

You can remove local ToneRig data at any time by deleting your presets and imported files in-app or by deleting the app. Because ToneRig does not associate Crashlytics or purchase-event installation identifiers with a name or email address, we generally cannot identify a particular report as yours. Contact us with a privacy request and we will assist where reasonably possible.

  • European Union (GDPR): The data controller is Joshua Aquino (support@joshaquino.com). Diagnostic and purchase-event information is processed for the legitimate interest of maintaining app reliability and operating the purchase system. You may contact us with any questions, and you have the right to lodge a complaint with your local Data Protection Authority. Data you share with TONE3000 is controlled by TONE3000.
  • California (CCPA): We do not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising any privacy right.
  • India (DPDP): The data fiduciary is Joshua Aquino (support@joshaquino.com). Contact us with any question or request concerning the diagnostic or purchase-event information described above.
  • Philippines (Data Privacy Act of 2012, RA 10173): The personal information controller is Joshua Aquino (support@joshaquino.com). You may contact us with any concern and, where applicable, raise complaints with the National Privacy Commission.

To exercise any right or ask a question, contact us at support@joshaquino.com.


8. Children’s Privacy

ToneRig is not intended for children under 13, and we do not knowingly associate diagnostic or purchase-event information with a child’s identity. If you believe a child has provided personal information through the app, contact us at support@joshaquino.com.


9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will update the “Last Updated” date above and post the revised policy at its public URL (https://joshaquino.com/tonerig/privacy). Your continued use of ToneRig after changes are posted constitutes acceptance of the updated policy.


10. Contact Us

If you have questions or concerns about this Privacy Policy: