Skip to content
Chord & Fret
Instrument

Privacy Policy

This policy explains, in plain language, what data Chord & Fret handles, why, and what you can do about it. It starts with the part that matters most: if you never create an account, nothing leaves your device.

The whole thing, in five sentences

With no account, nothing leaves your device. The app works entirely offline: saved chords, charts, setlists and preferences live on your phone and nowhere else.

Who is answerable for your data

The party responsible for processing — the “controller”, in the language of the law — is: GROWTHCODE TECNOLOGIA DA INFORMACAO LTDA, Brazilian company number (CNPJ) 59.432.449/0001-71, Av. Adjar da Silva Casé, 800 — Coworking, Floor 1, Indianópolis, Caruaru/PE, ZIP 55.024-740, Brazil.

To talk to us about personal data (to ask, correct or complain), use: privacidade@cifraebraco.app. We answer within 15 days, the deadline set by art. 19 of the Brazilian LGPD.

Data protection officer: Walmir Ferreira da Silva — privacidade@cifraebraco.app.

The marked passages above are still to be filled in by the person who publishes the app. They are visible on purpose: an honest blank beats an invented sentence.

Using the app without an account

You can install and use the whole app without signing up. In that mode there is no data of yours on our server — not one byte.

Everything you create (saved chords, charts and lyrics you wrote or pasted, setlists, folders, favourite scales, notes) and everything you set (instrument, tuning, theme, language) is written to the device’s own storage. Uninstall the app and it goes with it.

Until there is an account, syncing stays switched off, and so does the registration for notifications.

What we keep once you create an account

The account exists for two purposes and no others: syncing your library between devices and keeping your subscription working. It is created when you sign in with Google or Apple, and the legal basis is performing the contract between you and us.

About youWhat for
An internal identifier for the accountto attach everything of yours to you
Your e-mailto identify the account and talk to you about it
Your display name, when Google or Apple sends oneto call you by your name
The identifier Google or Apple uses for youto recognise you when you sign in again
About your devicesWhat for
An install identifier, drawn at random on the device itselfto know which device each change came from — it is not an IMEI and not an advertising identifier
Platform (Android, iPhone or web) and app versionsupport, and diagnosing version-specific problems
Device languageto write to you in the right language
Notification keyto deliver a notice, when you allow notifications
First and last accesssecurity, and keeping track of how many devices use the account

Your library: with an account, what you made starts syncing — saved chords, charts and lyrics, setlists, progressions, folders, favourite scales and your notes.

That content is yours. We only store and sync it: we do not read it to build a profile, do not use it to train anything and do not show it to anyone.

Your preferences: we sync a closed list, and it is purely musical — language, instrument, tuning, tuning reference, capo, left-handed, stage mode, theme, search mode, fretboard orientation and four scale options. Nothing that identifies you.

Your subscription: we keep the store and the subscription identifier, which product you bought, what state it is in, when the paid period ends, whether it renews on its own, the amount the store charged, the currency and the storefront (the store country where the purchase was made).

Security: we keep your sessions only as a cryptographic fingerprint — the session code itself is never written down — plus an internal record of the operations our team performs on accounts.

How you sign in: Google or Apple only

There is no e-mail-and-password signup. The only way in is your Google or Apple account.

Which means: we never create, never ask for and never store a password of yours. Google and Apple check who you are; what comes back to us is an identifier, your e-mail and, when available, your name.

Apple sends the name only the first time you authorise the app. If you authorise again later it does not repeat the name — and we have no way to go and fetch it.

The tuner’s microphone

The tuner has to hear your string to tell you whether it is sharp or flat. That is the only sensitive permission the app asks for, and it is asked at the moment you use the tuner, not at install time.

The sound is analysed inside the device itself, in real time, only to work out which note is ringing. It is not recorded, not stored and not sent anywhere. Our server does not even have an address capable of receiving audio.

You can withdraw the microphone permission whenever you like, in your system settings. The rest of the app keeps working normally.

What we do not collect

This list matters as much as the one above, and every line of it was checked against the app’s code:

Subscription and payment

The subscription is sold and charged by the App Store or Google Play — never by us.

We do not receive, do not see and do not store any payment data: no card number, no tax number, no billing address, no invoice.

What the store hands back is confirmation that the purchase exists and is valid, along with the product, the state of the subscription, the amount charged, the currency and the storefront country. Keeping the amount charged is keeping a price, not a means of payment: it lets us add up real revenue instead of estimating it.

Cancelling, refunds and changing your payment method are all handled in the store itself. How the subscription works, in the Terms of Use →

Who your data is shared with

We do not sell your data and we do not share it with advertisers. The companies below are involved because the service could not exist without them:

WhoWhat they receive, and why
Apple and Google, as the storesyour purchase and payment data, directly, without passing through us — they are the ones selling and charging
Google Firebasethe credential from your social sign-in, to confirm it is you; it returns an identifier, your e-mail and your name
Google FCMyour device’s notification key and the text of the notice, when you allow notifications
Hostingerhosts our server and our database; acts as a processor, under a data-protection agreement
E-mail delivery servicethe recipient address and the content of the message — Hostinger, which hosts the cifraebraco.app mailboxes and sends through smtp.hostinger.com

Sending data across borders

Apple and Google process data outside Brazil in any case, so part of the processing happens abroad, under each company’s own contractual safeguards. Which data-protection regimes apply to you depends on where the app is published: we are a Brazilian company and operate under the LGPD (Law 13.709/2018). Where you live under a law that grants you more than the LGPD does, that law is what we honour — we do not use our location to give you less.

About our own server: it is in BRAZIL, so the main processing never leaves the country. The backups, however, are kept in the United States — that is an international transfer, covered by the standard contractual clauses in the hosting provider’s Data Processing Addendum.

How long we keep things

WhatFor how long
Your account and your libraryas long as the account exists; deleted when you ask
Sign-in sessionuntil it expires or you revoke it; revoking signs out every device
The device’s access keyup to 365 days
The offline proof of your subscriptionup to 30 days, and at most 3 days when there is a sign of risk; never beyond the end of your entitlement
E-mail verification link24 hours
Internal record of operations on accounts5 years, matching the Brazilian tax and accounting period
Server access log (the IP address calling the API)6 months, the period art. 15 of the Brazilian Internet Civil Framework (Law 12.965/2014) imposes on application providers

An account left untouched for a long time: today we do not delete an account for being unused. It stays until you ask us to erase it. If that ever changes, we will say so in advance.

Your rights, and how to use them without asking anyone

The law gives you confirmation, access, correction, portability, deletion, and information about who your data is shared with. In the app, the main ones are already a button:

  1. Open the app and go to Settings.
  2. Tap the Account tab.
  3. Open “My data and privacy”: there you see what stays on the device and what stays on the server, export everything to a file, and can delete the account.
  4. Under “My devices” you see the connected devices, with the current one marked, and disconnect the ones you no longer use.

The export hands you exactly what our team would be able to export: it is the very same mechanism, scoped to the owner of the account.

Deletion you ask for really deletes — we never quietly downgrade “delete” into “anonymise”. It asks for confirmation twice, cannot be undone, and is recorded. Step by step for deleting your account →

If you cannot sign in, self-service cannot reach you. In that case, write to us: privacidade@cifraebraco.app. We answer within 15 days, the deadline set by art. 19 of the Brazilian LGPD.

Cookies and browser storage

This site uses no cookies at all. Not ours, not a third party’s, none for measurement and none for advertising. There is no tag manager, no tracking pixel and nothing embedded from another domain.

What does exist is local storage: two pieces of information kept by the browser itself, on your machine, which are never sent to us.

What is storedWhat for
cf-themeto remember whether you chose the light or the dark theme
cf-instto remember which instrument you chose, so pages open on it

You can erase both at any time by clearing this site’s data in your browser. The site keeps working: without them it falls back to your system theme and to the default instrument.

The tuner on this site uses the microphone too. When you start tuning, the browser asks your permission, the audio is analysed on the page itself to find the note, and nothing is recorded or sent. Closing the page ends the access.

Our pages make no calls to third-party servers: fonts, images, audio and code all come from our own domain.

Notifications

The app only registers a notification key after you create an account and allow notifications in the system. Those are two decisions of yours, and you can undo the second whenever you like, in your phone’s settings.

We use notifications for notices about your account and your subscription. Withdrawing the permission does not affect the rest of the app.

How we protect it

No system is completely safe. If there is ever an incident with meaningful risk, we will tell you and the competent authority, as the law requires.

Minimum age

Using the app does not require signing up, and with no signup there is no personal data processed by us. To create an account and subscribe, the rule is: 13 to use the app; under 18, only with the consent and assistance of whoever is responsible for you. A recurring subscription must be taken out by the legal guardian — that is not our choice: Google’s parental-approval flow does not cover recurring subscriptions, only one-off purchases. The lifetime unlock, being a single purchase, goes through approval normally.

We do not present the app as directed at children, and we ask nobody for a date of birth.

Changes to this policy

When this policy changes in a meaningful way, we update the date at the foot of the page and tell you inside the app. The version in force is always the one published here.

Talking to us

Any question, request or complaint about personal data: privacidade@cifraebraco.app. We answer within 15 days, the deadline set by art. 19 of the Brazilian LGPD.

You may also take your complaint to the data-protection authority that covers you.

Related documents

Terms of Use Delete account