Privacy Policy
Information under Art. 13 GDPR (DSGVO)
Last updated 30 September 2026
Who is responsible
Martin Neuschulz, Kurt-Eisner-Straße 58, 04257 Leipzig, Germany. Email [email protected]. Full details are in the legal notice.
KeyFu is a one-person business. We have not appointed a data protection officer.
In short
What you play stays on your device. The app reads your MIDI keyboard and analyzes your playing locally. It never records audio, and raw MIDI never leaves the device. Your practice history is stored only on your device, and we do not back it up. Our server receives what it needs to run your account, the coach and the subscription. Everything beyond that, such as crash and problem reports and the usage data you can choose to share, is described below.
KeyFu shows no ads. We do not sell your data or share it for advertising, we do not use Apple’s advertising identifier, and we do not track you across other apps or sites.
Part 1 — This website
Hosting
keyfu.app is hosted on Cloudflare Pages. Cloudflare processes the technical data any web server receives in order to deliver a page, including your IP address. The legal basis is our legitimate interest in operating a working, secure site (Art. 6(1)(f) GDPR).
The beta waitlist
If you enter your email address to join the beta, that address is sent to Brevo (Brevo GmbH, Berlin, Germany), which stores it and sends you a confirmation message. Nothing is stored on our side until you click the link in that message. This is double opt-in, and it is also the record of your consent (Art. 6(1)(a) GDPR).
We use the address to contact you about the beta and the launch of KeyFu. When we invite you to the beta, we give your address to Apple, which sends you the TestFlight invitation and runs TestFlight as its own controller.
News and offers (only if you tick the box). The form has an optional box for news and offers about KeyFu by email. It is not ticked in advance, and joining the beta does not depend on it. If you tick it, the confirmation message names this too, and your click confirms both. We store which version of the consent text you confirmed, and Brevo records when you confirmed. Legal basis: your consent (Art. 6(1)(a) GDPR).
You can withdraw at any time using the unsubscribe link in any message, or by writing to [email protected]. Withdrawal does not affect processing that already happened. Without the news consent, your address is deleted when the beta program ends or when you unsubscribe, whichever comes first. With it, your address is kept until you unsubscribe.
Email statistics. Our emails contain a small image and links that pass through Brevo first. Brevo uses them to count how often an email was opened and how often its links were clicked. We have set Brevo to keep these counts only as totals, so neither we nor Brevo record whether you opened an email or clicked a link. Links to our website carry a label naming the email they came from, not you. Legal basis: our legitimate interest in knowing whether our emails reach people (Art. 6(1)(f) GDPR).
Our server never writes your address to a log. It is passed to Brevo and not retained in between.
Bot protection. When you start filling in the form, the page loads Cloudflare Turnstile. It checks your IP address and technical properties of your browser to tell people from bots, and it never sees your email address. You normally see nothing. If Cloudflare is unsure, it may ask you to tick a box. Turnstile also stores a small value in your browser, inside Cloudflare’s own frame on our page. It does not expire by itself, and you can remove it by clearing this site’s data in your browser. Storing and reading it serves only to protect the form (§ 25(2) no. 2 TDDDG). Legal basis for the check: our legitimate interest in keeping automated sign-ups out (Art. 6(1)(f) GDPR). Cloudflare also uses these signals as its own controller to improve its bot detection (Turnstile Privacy Addendum).
You may have arrived through a tagged link, such as an invitation from another tester or a link we posted in a community. In that case the short code is stored next to your address in Brevo, so we can tell which channels actually reach people. It is a code, not a profile, and it rests on the same consent as the address itself.
Part 2 — The KeyFu app
What never leaves your device
Raw MIDI stays on your device. The app does not record you, and there is no microphone in the practice loop at all. What you play is read from your MIDI keyboard and analyzed locally. The analysis covers which notes you played, their timing and how hard you struck them. Hand position, posture and fingering are not captured.
Your account
You need an account to use the app, and accounts use Sign in with Apple. Apple gives us a pseudonymous identifier that it creates for your use of KeyFu. We do not ask Apple for your name or your email address, and we do not receive them. At sign-in, Apple also gives our server a token that lets us end KeyFu’s access to your Apple account. We store it encrypted and use it only for that, when you delete your account. Legal basis: performance of the contract you entered by signing up (Art. 6(1)(b) GDPR).
The account lets our server apply the coach’s fair-use limits, your subscription and the free plan and trial. It does not hold your practice history.
When you create your account, the app tells our server which version of our terms of use it showed you. We store that version (its date) and the time of your first acceptance with your account identifier. We use this record only to show which terms you agreed to and when. It is included in your data export and deleted when you delete your account. Legal basis: our legitimate interest in being able to prove the terms of our agreement (Art. 6(1)(f) GDPR).
If you give us your email address yourself, for the waitlist, a support request or a problem report, the sections on those explain what happens to it.
Your practice history stays on your device
Your practice history and what the app learns from it (your skill state, goal and streak, your keyboard and headphone calibration, saved plans and your conversations with the coach) are stored only on the device you practice on. We do not copy them to our server. So they do not move to another device through your account, and they are not restored if you delete and reinstall the app. Deleting the app deletes them. Your device’s own backup (iCloud Backup or a backup on your computer) may include them, under Apple’s terms; we have no access to it. To keep a copy of your own, use Export My Data (see “Your rights”) before you delete the app.
Our server holds only what the sections below describe: your account and the record of which terms you accepted, coach usage, your subscription, the free plan and trial, crash reports, and, if you share usage data, a daily count of usage reports.
The coach
The coach can build a plan, recap a session, summarize a week, or reply when you write to it. For that, the request is sent through our server to one of these AI providers: Anthropic (Claude) or OpenAI (GPT). Which provider answers depends on the feature, and if one is unavailable the request can go to another. The request contains the text you wrote, your goal and a summary of your practice state, never your audio or raw MIDI. Our server checks who you are, but does not attach your account identifier or anything else that names you. Text you type yourself is sent as you wrote it, so it contains whatever you put in it.
The providers use the request to write the reply and do not use it to train their models. Under their own terms they also keep it for a limited time to detect misuse and to meet legal duties: up to 30 days, and longer where a request is flagged for misuse (at Anthropic up to 2 years) or the law requires it. Until 25 September 2026, some requests could also go to Google (Gemini), whose terms let it keep them for 55 days to detect misuse. These copies are separate from ours and are deleted by the providers.
Your permission. Before the first request goes to an AI provider, the app asks whether you allow it. If you say no, nothing is sent to them: the coach shows short pre-written messages instead, and you cannot chat with it. One exception: if you write that you are thinking about harming or killing yourself, the app answers at once with a fixed message pointing you to free helplines. Your message is still not sent anywhere. You can change your answer at any time under Settings → Support & legal → “Use AI for coach replies”. Your answer is stored only on your device. Legal basis for the requests you allow: Art. 6(1)(b) GDPR, because the coach is part of the service.
Your conversations with the coach are kept on your device. Our server keeps an identical request and its reply for 10 minutes, so a retry or a double tap does not cost a second call. After that it is no longer used, and a daily cleanup deletes it, normally within a day. For each coach call we log the feature used, the model and the token cost against your account. This lets us enforce the fair-use limits and keep an eye on costs. These entries are kept while your account exists.
Safety check. When you write to the coach, our server checks your latest message for words suggesting you may want to harm or kill yourself. If it finds them, the coach sets the piano aside and its reply ends with a pointer to free helplines. Otherwise your message still goes to the AI provider as described above, with an instruction to answer it with care. If a limit would otherwise stop the coach, or no AI provider can be reached, you get a fixed message with that pointer instead: no AI provider receives your message, and it does not count against your allowance. The result of the check is not stored with your account or your text; we only count, per day, how often it happened. The app runs the same check on your device for a message it cannot send, for example when you are offline or have not allowed AI yet; that check sends nothing.
To improve the coach, we keep some coach requests for up to 30 days as a reduced sample. The sample has no account identifier, no clock time and none of your own text, only coarse categories. It cannot be traced back to you.
Reporting a reply. If a coach reply seems wrong or inappropriate, you can press and hold it and choose “Report this reply”. We then receive the text of that reply (up to 4,000 characters), a random message number and the date and time. We store them without your account identifier, but the reply can repeat things you told the coach. We use reports to find and fix bad replies. They are deleted after 180 days. To limit abuse, our server counts how many replies your account reported on a given day. That count is stored with your account, like the count of your coach messages, and not with the reports. Legal basis: our legitimate interest in a coach that is safe and correct (Art. 6(1)(f) GDPR).
Usage data (only if you allow it)
The app shares usage data only if you allow it. It asks once, after your first practice session has ended: “Share usage data” or “No, thanks”. Closing the question counts as no. Until you say yes, nothing is sent, and the app stores and reads nothing on your device for this purpose.
If you say yes, two things are sent:
- To TelemetryDeck (TelemetryDeck GmbH, Germany): which screens and steps you use and where a flow stops, such as setup steps, practice sessions, features used and purchase steps (never payment details). Each signal carries technical context: device model, operating system, app version, language, region, time zone, coarse calendar context (such as the day of the week) and accessibility settings, plus a random identifier the app creates for this installation.
- To our own server, when a session ends: whether it had an exercise you hadn’t played before, roughly how long you played (in 5-minute steps), and whether you changed the day’s plan. These are stored only as weekly totals, without your account identifier, without a time of day, and without song titles or anything you played. To limit abuse and keep small groups hidden, we store against your account only how many such reports arrived on a given day, not what they said.
Neither contains your name, your Apple account, your messages to the coach or the notes you played. The random installation identifier makes the data pseudonymous, not anonymous. TelemetryDeck hashes it again with its own key, so we cannot match usage data to you or to a support email.
You can change your answer at any time under Settings → Support & legal → “Share usage data”. Switching it off stops sending at once and deletes the identifier and all usage data kept on your device. If you used an earlier version of the app, it treats you as not yet asked and deletes its earlier identifier. Legal basis: your consent (Art. 6(1)(a) GDPR, and § 25(1) TDDDG for what is stored on or read from your device). Withdrawing does not affect what was sent before.
Crash reports
If the app crashes or hangs, your iPhone or iPad (Apple’s MetricKit) produces a technical report: call stacks, the reason the app stopped, device model, OS and app version. The app forwards these reports to our own server so that we can find and fix the fault. They contain no practice data and no text you wrote. They are stored with your account identifier for up to 90 days, are included in your data export, and are deleted with your account. Legal basis: our legitimate interest in a working app (Art. 6(1)(f) GDPR).
We also count failed server requests per day and route, as totals without any account identifier.
TestFlight. If you test KeyFu through Apple’s TestFlight, Apple passes us crash reports, usage information and any feedback or screenshots you choose to send there. We use them only to find and fix problems. We copy your feedback and screenshots, with the app build, device model, iOS version and date, to our own computer and delete the copy after 90 days. We do not keep the email address Apple sends with it. Our bug tracker receives only a report number, the build, the screen, the kind of problem, the device model, the iOS version and the date. Legal basis: our legitimate interest in a working app (Art. 6(1)(f) GDPR).
Problem reports (beta testers)
During the beta, testers can send us a problem report from the app. Nothing is sent until you tap Send, and the report screen first shows you exactly what will be sent. Each report is a separate decision.
What a report contains: the kind of problem and your description; a screenshot of the screen you were on, with coach messages, text fields and your account details painted over before it leaves the device; the app build, device model and iOS version. If you leave Attach the last 2 minutes switched on, it also contains what happened in the app just before: screens opened, the app going to the background and back, your keyboard connecting or disconnecting (connection type and size), the kind of audio output (for example built-in speaker or Bluetooth), app error codes, and for each exercise pass its tempo, how many notes were judged and how early or late they were on average. It never contains the notes themselves, what you tapped, device or headphone names, chat text or anything you typed elsewhere in the app, and its times are relative to the moment of the report. If you enter an email address, it is stored too (see below).
Not linked to your account. A report gets a random report number (such as K7Q-4M2) and is stored without your account identifier. To limit abuse, our server counts how many reports an account sends per day, using a salted code that changes daily; that count is not stored with the report.
Optional email. If you enter your address, we send you one receipt with the report number and your own description (never the screenshot or the app events), through Brevo (Brevo GmbH, Berlin, Germany). The address is stored separately from the report, is used only for this receipt and for questions about this report, never for marketing, and is deleted together with the report. If you write to us or reply to the receipt, your email is kept in our mailbox and deleted after 90 days as well, unless it is still needed to answer you.
Where and how long. Reports are stored with Cloudflare in the European Union (R2 storage in the EU jurisdiction) and deleted automatically after 90 days. To work on a report, we download it to our own computer. That copy, and any of our notes that quote your description, are deleted after 90 days as well. A report that could not be sent yet waits on your device (at most 20 reports, for at most 7 days) and is removed when you sign out or delete your account.
Legal basis: your consent, given by tapping Send (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future. To have a report deleted earlier, write to [email protected] and quote the report number, or reply to the receipt email. Because reports are not linked to your account, the report number is the surest way for us to find yours. Without it, tell us what you remember, such as the day and what you wrote, and we will look.
Purchases
KeyFu Pro is sold as a subscription through Apple’s App Store. Apple is the seller (merchant of record) and handles payment, and we never see your payment details. When you buy, restore or open the app, our server receives Apple’s signed record of your subscription. It stores the product, the Apple transaction number that ties the subscription to your account, its status and expiry date, and any offer or offer code used. Apple also notifies our server directly when a subscription renews, expires, is refunded or is revoked, so that what you can use stays correct. A notification that arrives before the matching account is known is held for at most 30 days. Legal basis: Art. 6(1)(b) GDPR.
Free plan and trial
The free version includes a set number of planned sessions, and new players first get a short trial of the full plan. To apply this, our server keeps against your account how many planned sessions you have had, the day of your last free one, the plan you currently hold and for which installation, and when your trial ended. Legal basis: Art. 6(1)(b) GDPR.
One trial per device. So that a trial cannot be restarted with a new Apple ID, the app asks Apple’s DeviceCheck service for a one-time token from your device. Our server uses it to ask Apple whether a trial has already ended on this device, and to mark the device when yours ends. Apple keeps this one mark for us per device. Neither we nor Apple learn who you are from it, and no KeyFu identifier goes to Apple. The mark stays with Apple after you delete your account, so a new account on the same device does not start a new trial. Legal basis: our legitimate interest in preventing misuse of the trial (Art. 6(1)(f) GDPR).
Part 3 — The beta community on Discord
Beta testers are invited to a KeyFu server on Discord. Joining is optional, and the app works without it.
Discord itself
Discord is run by Discord Inc. (United States), and for users in the European Economic Area by Discord Netherlands BV, under its own terms and privacy policy. Discord decides how it processes your account, your messages and what you post, and it is responsible for that. We see what any server member sees: your Discord name, your profile picture and what you write in the server. We do not use Discord’s server statistics to look at individual members.
The KeyFu bot
The server has a bot that we run on our own server (Cloudflare). It does three things.
Access and build pings. When you tap Accept the rules, the bot gives you the tester role, which opens the other channels. It also gives you a role for pings about new builds, which the 🔔 button turns off and on. These roles are stored by Discord, not by us.
Bug reports with /bug. When you send a report with /bug, the bot creates a ticket in our private bug tracker on GitHub (GitHub, Inc., United States) and a thread for it in the server. GitHub receives only what you wrote in the form and a link to the thread, not your Discord name or user ID. The form asks you to leave out personal details. Our server (Cloudflare) stores which ticket belongs to which thread and your Discord user ID as the person who reported it, so that the bot can post status updates in your thread. When the ticket’s status changes, the bot posts a short note there and mentions you.
Answers in #testflight-help. When you ask a question in #testflight-help, the bot sends the text of your question to Anthropic (Claude) to choose the matching answer from our list of prepared answers. Anthropic receives only the question text, without your name or user ID, and returns nothing but the choice. The bot then posts the prepared answer as a reply. If no prepared answer fits, it does not reply and passes a link to your question on to Martin. We do not keep the text of your question. We keep a record of the answer the bot posted, and to which message, so that a ❓ reaction can reach Martin.
Legal basis: our legitimate interest in running the beta community, fixing reported problems and answering common questions quickly (Art. 6(1)(f) GDPR). You can object at any time. Write to [email protected], or simply do not use /bug and #testflight-help: you can report problems from the app and ask questions at [email protected] instead.
Who receives data
We work with these providers. Each processes data on our behalf under a data processing agreement (Art. 28 GDPR), with two exceptions. On our plan GitHub works under its own terms, so we send it no names, user IDs or account identifiers, only report texts. TelemetryDeck works under its own terms, which treat the usage data as anonymous and exclude a processing agreement; we treat the data as pseudonymous (see “Usage data”). Cloudflare also acts as its own controller where it uses Turnstile signals to improve its bot detection.
| Provider | What for |
|---|---|
| Cloudflare, Inc. | Website hosting, bot protection for the waitlist form, our server, the database, problem-report storage (in the EU), the Discord bot |
| Anthropic Ireland, Limited | Coach replies (Claude); choosing a prepared answer in #testflight-help |
| OpenAI Ireland Ltd. | Coach replies (GPT) |
| TelemetryDeck GmbH | App usage statistics, only with your consent |
| Brevo GmbH, Berlin | The beta waitlist, news and offers if you asked for them, receipts for problem reports |
| GitHub, Inc. | Our private bug tracker: the text of reports sent with /bug in Discord, without your name or user ID; for problem reports and TestFlight feedback only a report number, the build, the screen, the kind of problem, the device model, the iOS version and the date |
Apple’s and Discord’s own services. Sign in with Apple, App Store distribution and payment are Apple’s own services. Apple (Apple Inc. / Apple Distribution International Ltd.) runs them as its own controller, under its privacy policy. Discord runs its platform as its own controller (see Part 3).
Our email and notes. Separately, Apple stores the emails you send to our keyfu.app addresses and our working notes on reports and requests (iCloud Mail and iCloud Drive).
Some of these providers are based in the United States or pass data on to companies there. The safeguards, as the providers’ own documents state them: Cloudflare and GitHub rely on the EU–US Data Privacy Framework and also on EU standard contractual clauses (Art. 46(2)(c) GDPR). Anthropic Ireland, Limited relies on EU standard contractual clauses and may pass data on to Anthropic, PBC in the United States and to its cloud providers (Google Cloud, Amazon Web Services, Microsoft Azure), which can process it in other countries worldwide. OpenAI Ireland Ltd. passes data on to OpenAI companies in the United States, the United Kingdom and Japan and to its service providers, under EU standard contractual clauses or an adequacy decision of the European Commission. By OpenAI’s list of 9 July 2026, these providers process data in the EU and in Australia, Brazil, Canada, India, Indonesia, Japan, Malaysia, Mexico, Norway, Singapore, South Africa, South Korea, Switzerland, the United Arab Emirates, the United Kingdom and the United States; Cloudflare, their network provider, handles each request in its data center nearest to where it starts. Requests flagged for misuse can also be reviewed in the Philippines. Brevo stores data in the EU but may use service providers in the United States and India, under the Data Privacy Framework or standard contractual clauses. To learn which safeguard applies to a provider, or to get a copy of it, write to [email protected].
How long data is kept
- Account, the Apple token, the record of the terms you accepted, subscription record, free-plan and trial state, coach cost entries, and the daily count of usage reports (only if you share usage data): while your account exists. They are deleted when you delete your account.
- Practice history on your device: until you delete the app. Delete Account also erases it from the device.
- Backups: deleted data can remain in our database provider’s backups for up to 30 days before it is overwritten.
- Crash reports: up to 90 days, and at the latest when you delete your account.
- Coach request cache (your request and its reply): used for 10 minutes, then deleted by a daily cleanup, normally within a day. It is deleted at once when you delete your account.
- Usage data at TelemetryDeck: kept there as pseudonymous statistics in the EU, without a fixed deletion date. Because it cannot be traced back to you, it cannot be deleted for you individually.
- Copies kept by the AI providers: under their own terms, as described under “The coach”.
- Reduced coach samples, weekly usage totals and daily safety-check counts: contain no account identifier. Samples are kept for up to 30 days; daily counts are kept without a fixed deletion date.
- Reported coach replies: 180 days. They contain no account identifier.
- Problem reports, our working copies of them, and the email address given with one: 90 days, or earlier on request. Unsent reports on your device: at most 7 days. The salted daily counter behind the report quota (no account identifier, not linked to any report): deleted the next day.
- Our copies of TestFlight feedback: 90 days. Your email address is not kept. Apple keeps its own copy under its own terms. The entry in our bug tracker (report number, build, screen, kind of problem, device model, iOS version, date) stays as a record of the bug.
- Apple notifications about a subscription whose account is not yet known: at most 30 days.
- The DeviceCheck mark: kept by Apple for the device, also after you delete your account (see “Free plan and trial”).
- Turnstile check: we keep nothing; the result is used once. Cloudflare’s value in your browser stays until you clear this site’s data.
- Waitlist address: until the beta program ends or you unsubscribe. With the news consent, until you unsubscribe, together with the version of the consent text you confirmed.
- Brevo’s log of the emails we send (address, time, delivery status): 1 month. Brevo keeps no copy of the content of our confirmation and receipt emails.
- Emails you send us: while we need them to help you, and at the latest 2 years after your last message, unless the law requires us to keep them longer. Emails about a problem report: 90 days, unless still needed to answer you.
- Discord bug tickets: the ticket on GitHub holds what you wrote and the link to the thread, without your name or user ID, and stays as a record of the bug. The link between ticket, thread and your Discord user ID is stored on our server while the ticket is open and up to 12 months after it is closed. Then it is deleted.
- Records of bot answers in #testflight-help: 30 days. The text of your question is not kept.
If you live outside the EU
KeyFu is available in many countries outside the EU. Everything above applies to you as well. Where the law of your country adds something, you find it here.
Switzerland
Your data goes to these countries: Germany and other EU countries, Ireland, the United States and India. Coach requests can also be processed in other countries. OpenAI’s providers work in the countries named under Who receives data. Anthropic’s cloud providers can process them anywhere in the world: Anthropic does not name these countries, it chooses the location for each request, for speed and availability. Germany and the EU count as adequate under Swiss law.
For the United States, India and any other country, the safeguards described under “Who receives data” apply. You can complain to the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
United States and California
Your age. In the United States the app asks for your age range once: from Apple where your device supports it, otherwise by asking you. Only the range is kept, for example “18 or older”, and only on your device. It is never sent to us and is never a birthday. Export My Data includes it, and deleting your account removes it.
We do not sell your personal information, and we do not share it for advertising. We let no third party use KeyFu to follow you across other sites or apps over time.
Because we do not track you across sites in the first place, KeyFu has nothing to switch off when your browser sends a Do Not Track signal. We treat all visitors the same way.
The data we collect, who receives it and how to see or correct it are described above and under “Your rights”. The date at the top shows when this policy last changed.
Canada
Martin Neuschulz is accountable for your personal information. Reach him at [email protected].
Your data is processed outside Canada: in Germany and other EU countries, Ireland, the United States and India, and coach requests possibly in the other countries named under Who receives data or, at Anthropic, anywhere in the world. While it is there, courts and authorities of those countries may be able to access it under their laws.
You can ask to see and correct your data. You can also complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Japan and South Korea
Your data goes to the providers below, outside your country, each bound by contract to protect it. To learn how these countries protect personal data, and how each provider protects yours, write to [email protected].
- KeyFu (Martin Neuschulz), Germany: everything described in this policy. For: running KeyFu. Kept: as under “How long data is kept”.
- Cloudflare, Inc., United States: account, coach usage and subscription records, crash reports, coach requests, problem reports (stored in the EU), Discord bot records. For: website, our server and database. Kept: while your account exists; reports 90 days; backups up to 30 days.
- Anthropic Ireland, Limited, Ireland, passing data on to the United States and to cloud providers worldwide: coach requests; questions in #testflight-help. For: coach replies; choosing a prepared answer. Kept: up to 30 days, longer if flagged for misuse (up to 2 years) or required by law.
- OpenAI Ireland Ltd., Ireland, passing data on to the United States and the other countries named under Who receives data: coach requests. For: coach replies. Kept: up to 30 days, longer if flagged for misuse or required by law.
- TelemetryDeck GmbH, Germany: usage data, only with your consent. For: usage statistics. Kept: pseudonymous statistics, no fixed deletion date.
- Brevo GmbH, Berlin, Germany, with service providers in the United States and India: email address, consent record, link code. For: waitlist, news if you asked for them, receipts. Kept: until the beta ends or you unsubscribe (with the news consent, until you unsubscribe); send log 1 month.
- GitHub, Inc., United States: text of
/bugreports, without your name or user ID; for problem reports and TestFlight feedback only a report number, build, screen, kind of problem, device model, iOS version and date. For: our bug tracker. Kept: as a record of the bug.
Data goes to a provider each time you use the feature it serves, over an encrypted connection. To stop a transfer, don’t use that feature, for example the coach; KeyFu then cannot provide it.
To reach a provider, use the contact in its privacy policy, or write to us.
Our safeguards are described under “Security”.
Singapore
Under Singapore’s Personal Data Protection Act, our contact for data protection is Martin Neuschulz, [email protected].
Your rights
Under the GDPR you may request access to your data, correction, erasure, restriction of processing and data portability (Art. 15–20), and you may object to processing based on legitimate interest (Art. 21). You can withdraw a consent at any time with effect for the future.
For the data stored under your account, the app has two buttons under Settings → You & account. Export My Data gives you a copy of the practice data stored on your device and of what our server holds under your account. Delete Account deletes your account on our server and then erases KeyFu’s data on your device. Deleting your account does not cancel a KeyFu Pro subscription. Cancel it in your App Store settings.
Some data is not stored under your account, so these buttons do not reach it: problem reports and reported replies, emails you sent us, and what the KeyFu bot and our bug tracker hold about you from Discord. For those, and for any other request, write to [email protected]. What Apple, Discord and the AI providers keep under their own terms, you can ask them about directly.
You also have the right to complain to a supervisory authority (Art. 77 GDPR). For us that is the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte), Maternistraße 17, 01067 Dresden, Germany, datenschutz.sachsen.de.
Security
Connections are encrypted (HTTPS/TLS). Keys for the AI providers live only on our server, never in the app, and every request to our server is authenticated per session.
Changes
The app is in beta, and this policy will change as the app does. The date at the top is the version you are reading.