Keybop Privacy Policy
Last updated: 27 September 2026
Keybop is a piano-learning app. This policy explains what data the app handles, why, who else receives it, how long it is kept and how to delete it.
Who we are
Keybop is made by Kuldeep Kumar, an independent developer, who is the data controller for the data described here (“we”). Contact: hello@zeroenginestudio.com.
Microphone
Keybop asks for microphone access so it can hear the notes you play on an acoustic piano or digital keyboard, and, in Listen Mode and the composer, a song played out loud near your device. Audio is analysed entirely on your device, in real time, to detect pitches. No audio is ever saved or sent off the device. Listen Mode and the composer keep only the notes they heard, on your device. Notes from a MIDI keyboard are handled the same way.
Accounts
Keybop works without an account. When you first open it, an anonymous account (a random id) is created automatically so your practice progress can be backed up. You can optionally create an account with an email address and password, or continue with Google or Apple, to use your progress on more than one device. Accounts are handled by Google Firebase Authentication.
- Email and password: your email address. Your password is stored by Firebase Authentication; we never see it.
- Google: Google shares your email address, name and profile picture.
- Apple: Apple shares a unique identifier, an email address (your own, or a private relay address if you choose Hide My Email) and your name, if you choose to share it.
Keybop uses the email address to show which account you are signed in to, to send the password-reset emails you ask for, and to check whether the account is on our list of staff test accounts. The name and picture link are kept in the account record but not used or shown.
Cloud backup
The following data is stored in Google Firebase (Authentication and Cloud Firestore) under your account id:
- Your email address, if your account has one.
- Your practice progress: best scores and practice counts per piece, lesson steps completed, XP, pieces kept on the free plan, streak freezes used, the lesson you were last in, your starting level, and practice time per day and per hour of the day (used for your streak and to suggest a reminder time).
- A few app settings: your instrument, keyboard size and microphone preference.
Your first name, if you give it, stays on your device and is never sent. So do the pieces you compose, the songs Listen Mode writes down and anything you export to share. Your goal, if you pick one, stays on your device too, except as one field of the optional analytics below, never with your name or account id.
Purchases
Keybop Premium is sold through the App Store or Google Play, which process the payment under their own terms. We never see your card or payment details. RevenueCat, our subscription service, checks whether your account has Premium each time the app starts. It receives your keybop account id (the random id above, not your email or name), the store’s purchase and subscription records for it (products, dates, prices and storefront country) and technical data such as your platform, app version and IP address.
App configuration and lesson packs
Every copy of the app downloads its configuration (which features are switched on, and experiment settings) from Firebase Remote Config, and new lesson packs from our website on Firebase Hosting. These requests carry a random installation id and technical details such as app version, operating system, language and country or region, and, like any internet request, your IP address. They do not contain your name, email address or practice data.
Optional analytics
Anonymous product analytics are off by default. If you turn on “Share anonymous usage analytics” in Settings, Keybop sends learning-funnel events such as lessons and practice sessions started or completed, accuracy bands, and subscription-screen interactions to Google Firebase Analytics and PostHog (on its EU servers). Firebase Analytics also records its standard app events, such as first open, app updates and in-app purchases, with a random app-instance id, your device model and operating system, and an approximate location derived from your IP address. These events do not contain your name, email address, account id, audio, recordings, played notes, or MIDI events. Session replay is disabled. You can turn analytics off again in Settings at any time.
Reminders and sharing
The daily practice reminder is scheduled on your device; there is no push service. When you share a piece, the video, picture or WAV file is made on your device and handed to your device’s share sheet; Keybop hosts nothing. Keybop adds a file to your photo library only when you choose Save, and never reads your library.
Who receives data
- Google Firebase (Authentication, Cloud Firestore, Remote Config, Hosting, and Analytics if you opt in): Firebase privacy documentation.
- RevenueCat (subscription status and purchase history): RevenueCat privacy policy.
- PostHog, only when you opt in to analytics: PostHog privacy policy.
- Apple and Google, as the app stores and as sign-in providers when you choose them, under their own privacy policies.
Google Firebase, RevenueCat and PostHog process this data only on our behalf, under data-processing terms that require them to protect it at least as well as this policy describes. Some of them process data outside your country, including in the United States.
What we don't do
- No ads, no advertising identifiers, and no tracking across other companies’ apps or websites.
- We do not sell your data or use it for advertising.
How long we keep it
- Backups belonging to anonymous accounts that were never linked to an email, Google or Apple account are deleted automatically after 90 days without use.
- Accounts and their backups are kept until you delete the account.
- Purchase records are kept by the stores and RevenueCat for accounting and so purchases can be restored. They are tied to the random account id, not to your name or email; email us to have RevenueCat’s copy deleted.
- Analytics events are kept for the retention period set in Firebase Analytics and PostHog, and are not linked to your account.
Deleting your account and data
You can delete your account and its cloud backup at any time, directly in the app: Settings → Account & Backup → Delete account. This permanently removes your account and all data stored about you in our backend. On iPhone, deleting an account that uses Sign in with Apple also revokes Keybop’s Sign in with Apple access. Deleting your account does not cancel a subscription; cancel it in the store where you bought it. See detailed instructions.
Your choices and rights
We process account, backup and purchase data to provide the service you ask for, and analytics data only with your consent. You can use Keybop without an account, turn analytics off at any time, and ask us for a copy of your data, to correct it or to delete it by emailing us. You can also complain to your local data protection authority.
Children
Keybop is a general-audience app and is not directed at children. It never asks for your age, and an account is optional. If you are a parent or guardian and believe your child has created an account, email us and we will delete it.
Changes
When this policy changes, we update the date at the top of this page.
Contact
Questions or data requests: hello@zeroenginestudio.com. Help with the app: support.