Skip to content
Chord and Fret

Privacy Policy

This policy explains, in plain language, what data Chord and Fret handles, why, and what you can do about it. It starts with the part that matters most: if you never create an account, nothing leaves your device.

The whole thing, in five sentences

With no account, nothing leaves your device. The app works entirely offline: saved chords, charts, setlists and preferences live on your phone and nowhere else.

Who is answerable for your data

The party responsible for processing — the “controller”, in the language of the law — is: GROWTHCODE TECNOLOGIA DA INFORMACAO LTDA, Brazilian company number (CNPJ) 59.432.449/0001-71, Av. Adjar da Silva Casé, 800 — Coworking, Floor 1, Indianópolis, Caruaru/PE, ZIP 55.024-740, Brazil.

To talk to us about personal data (to ask, correct or complain), use: privacidade@cifraebraco.app. We answer within 15 days, the deadline set by art. 19 of the Brazilian LGPD.

Data protection officer: Walmir Ferreira da Silva — privacidade@cifraebraco.app.

Using the app without an account

You can install and use the whole app without signing up. In that mode there is no data of yours on our server — not one byte.

Everything you create (saved chords, charts and lyrics you wrote or pasted, setlists, folders, favourite scales, notes) and everything you set (instrument, tuning, theme, language) is written to the device’s own storage. Uninstall the app and it goes with it.

Until there is an account, the registration for notifications stays switched off — and so does syncing, which needs the Pro plan on top of the account.

What we keep once you create an account

The account exists for two purposes and no others: keeping your subscription working and, on the Pro plan, syncing your library between devices. It is created when you sign in with Google or Apple, and the legal basis is performing the contract between you and us.

About youWhat for
An internal identifier for the accountto attach everything of yours to you
Your e-mailto identify the account and talk to you about it
Your display name, when Google or Apple sends oneto call you by your name
The identifier Google or Apple uses for youto recognise you when you sign in again
About your devicesWhat for
An install identifier, drawn at random on the device itselfto know which device each change came from — it is not an IMEI and not an advertising identifier
Platform (Android, iPhone or web) and app versionsupport, and diagnosing version-specific problems
Device languageto write to you in the right language
Notification keyto deliver a notice, when you allow notifications
First and last accesssecurity, keeping track of how many devices use the account, and choosing who gets a notice — for example, people who have not opened the app in a while

Your library: with an account and the Pro plan, what you made starts syncing — saved chords, charts and lyrics, setlists, progressions, folders, favourite scales and your notes. On an account without Pro, nothing of the library leaves the device.

That content is yours. We only store and sync it: we do not read it to build a profile, do not use it to train anything and do not show it to anyone.

Your preferences: we sync a closed list, and it is purely musical — language, instrument, tuning, tuning reference, capo, left-handed, studio mode, theme, search mode, fretboard orientation and four scale options. Nothing that identifies you.

Your subscription: we keep the store and the subscription identifier, which product you bought, what state it is in, when the paid period ends, whether it renews on its own, the amount the store charged, the currency and the storefront (the store country where the purchase was made).

Security: we keep your sessions only as a cryptographic fingerprint — the session code itself is never written down — plus an internal record of the operations our team performs on accounts.

Why the law allows each use

The LGPD only allows personal data to be processed on a legal basis. This is the one for each use we make:

UseLegal basis
Creating the account, keeping your subscription working and, with Pro, syncing your libraryperforming the contract with you (art. 7, V)
Keeping the stores’ notices about your subscription and the amount chargedlegal obligation: tax and accounting record-keeping (art. 7, II)
Access record: IP address, port, date and time of each accesslegal obligation: art. 15 of the Brazilian Internet Civil Framework (art. 7, II)
Account security: connected devices, sessions and the record of what our team doeslegitimate interest in protecting your account and the service (art. 7, IX) and the regular exercise of rights (art. 7, VI)
Account and subscription notices, by notificationperforming the contract with you (art. 7, V), only after you allow notifications
App news, by notificationyour consent, given through the “App news” switch and withdrawable right there (art. 7, I)
Answering what you write to us about your datalegal obligation: arts. 18 and 19 of the LGPD (art. 7, II)

Legitimate interest only covers security — never advertising and never behavioural profiling. If you object to any use based on it, write to privacidade@cifraebraco.app.

How you sign in: Google or Apple only

There is no e-mail-and-password signup. The only way in is your Google or Apple account.

Which means: we never create, never ask for and never store a password of yours. Google and Apple check who you are; what comes back to us is an identifier, your e-mail and, when available, your name.

Apple sends the name only the first time you authorise the app. If you authorise again later it does not repeat the name — and we have no way to go and fetch it.

The tuner’s microphone

The tuner has to hear your string to tell you whether it is sharp or flat. That is the only sensitive permission the app asks for, and it is asked at the moment you use the tuner, not at install time.

The sound is analysed inside the device itself, in real time, only to work out which note is ringing. It is not recorded, not stored and not sent anywhere. Our server does not even have an address capable of receiving audio.

You can withdraw the microphone permission whenever you like, in your system settings. The rest of the app keeps working normally.

What we do not collect

This list matters as much as the one above, and every line of it was checked against the app’s code:

Subscription and payment

The subscription is sold and charged by the App Store or Google Play — never by us.

We do not receive, do not see and do not store any payment data: no card number, no tax number, no billing address, no invoice.

What the store hands back is confirmation that the purchase exists and is valid, along with the product, the state of the subscription, the amount charged, the currency and the storefront country. Keeping the amount charged is keeping a price, not a means of payment: it lets us add up real revenue instead of estimating it.

Cancelling, refunds and changing your payment method are all handled in the store itself. How the subscription works, in the Terms of Use →

Who your data is shared with

We do not sell your data and we do not share it with advertisers. The companies below are involved because the service could not exist without them:

WhoWhat they receive, and why
Apple and Google, as the storesyour purchase and payment data, directly, without passing through us — they are the ones selling and charging
Google Firebasethe credential from your social sign-in, to confirm it is you; it returns an identifier, your e-mail and your name
Google FCMyour device’s notification key and the text of the notice, when you allow notifications
Hostingerhosts our server, our database, these websites and the domain’s mailboxes — that is where what you write to privacidade@cifraebraco.app arrives; acts as a processor, under a data-protection agreement

Sending data across borders

Two steps of the service happen abroad. Sign-in, done by Google Firebase Authentication, runs only in the United States; and delivering notifications (Google FCM) may pass through any Google region. Both are needed to do what you asked for — sign in and receive notices — which is what art. 33, IX of the Brazilian LGPD allows. Apple and Google, as the stores, handle your purchase data on their own account, also outside Brazil. Which data-protection regimes apply to you depends on where the app is published: we are a Brazilian company and operate under the LGPD (Law 13.709/2018). Where you live under a law that grants you more than the LGPD does, that law is what we honour — we do not use our location to give you less.

About our own server: it is in BRAZIL, so the main processing never leaves the country. The backups, however, are kept in the United States — that is an international transfer, covered by the standard contractual clauses in the hosting provider’s Data Processing Addendum.

How long we keep things

WhatFor how long
Your account and your libraryas long as the account exists; deleted when you ask
Sign-in sessionuntil it expires or you revoke it; revoking signs out every device
The device’s access keyup to 365 days
The offline proof of your subscriptionup to 30 days, and at most 3 days when there is a sign of risk; never beyond the end of your entitlement
The stores’ notices about your subscription (renewal, cancellation, refund)5 years, the tax and accounting record-keeping period
Internal record of what our team does on accounts5 years, the period in which what was done can be challenged in court (art. 27 of the Brazilian Consumer Defence Code)
API access record: IP address, port, date and time and, when the access comes from the signed-in app, the account6 months, the period art. 15 of the Brazilian Internet Civil Framework (Law 12.965/2014) imposes on application providers
Access record of these websites: IP address, date and time, page and browser6 months, under the same art. 15; kept by Hostinger, which hosts the websites

Once each period is over, deletion is automatic: a daily routine on our server removes what has expired.

An account left untouched for a long time: today we do not delete an account for being unused. It stays until you ask us to erase it. If that ever changes, we will say so in advance.

Your rights, and how to use them without asking anyone

The law gives you confirmation, access, correction, portability, deletion, and information about who your data is shared with. In the app, the main ones are already a button:

  1. Open the app and go to Settings.
  2. Tap the Account tab.
  3. Open “My data and privacy”: there you see what stays on the device and what stays on the server, export everything to a file, and can delete the account.
  4. Under “My devices” you see the connected devices, with the current one marked, and disconnect the ones you no longer use.

The export hands you exactly what our team would be able to export: it is the very same mechanism, scoped to the owner of the account.

Deletion you ask for really deletes — we never quietly downgrade “delete” into “anonymise”. It asks for confirmation twice, cannot be undone, and is recorded. Step by step for deleting your account →

If you cannot sign in, self-service cannot reach you. In that case, write to us: privacidade@cifraebraco.app. We answer within 15 days, the deadline set by art. 19 of the Brazilian LGPD.

Cookies and browser storage

This site uses no cookies at all. Not ours, not a third party’s, none for measurement and none for advertising. There is no tag manager, no tracking pixel and nothing embedded from another domain.

What does exist is local storage: two pieces of information kept by the browser itself, on your machine, which are never sent to us.

What is storedWhat for
cf-themeto remember whether you chose the light or the dark theme
cf-instto remember which instrument you chose, so pages open on it

You can erase both at any time by clearing this site’s data in your browser. The site keeps working: without them it falls back to your system theme and to the default instrument.

The tuner on this site uses the microphone too. When you start tuning, the browser asks your permission, the audio is analysed on the page itself to find the note, and nothing is recorded or sent. Closing the page ends the access.

Our pages make no calls to third-party servers: fonts, images, audio and code all come from our own domain.

Like every website, the server that delivers these pages notes each access: IP address, date and time, the page requested and the browser. That is not a cookie and it is not stored on your device; it serves security and art. 15 of the Brazilian Internet Civil Framework, which requires that record to be kept for 6 months. It is kept by Hostinger, which hosts the websites.

Notifications

The app only registers a notification key after you create an account and allow notifications in the system. Those are two decisions of yours, and you can undo the second whenever you like, in your phone’s settings.

Notices about your account and your subscription reach anyone who allowed the app’s notifications. News about the app itself — a new feature, a usage tip, a reminder for someone who has not opened the app in a while — only arrives if you switch on “App news”, under Settings › Account › My data and privacy; it starts switched off. A notice may go to one group only: by language, by subscription status or by time since the app was last opened. No notification carries third-party advertising.

To stop only the news, switch “App news” off in the same place. To stop every notification, turn off the app’s notifications in your phone’s settings. None of this affects the rest of the app.

How we protect it

No system is completely safe. If there is ever an incident with meaningful risk, we will tell you and the competent authority, as the law requires.

Minimum age

Using the app does not require signing up, and with no signup there is no personal data processed by us. To create an account and subscribe, the rule is: 13 to use the app; under 18, only with the consent and assistance of whoever is responsible for you. A recurring subscription must be taken out by the legal guardian — that is not our choice: Google’s parental-approval flow does not cover recurring subscriptions, only one-off purchases. The lifetime unlock, being a single purchase, goes through approval normally.

We do not present the app as directed at children, and we ask nobody for a date of birth.

Changes to this policy

When this policy changes in a meaningful way, we update the date at the foot of the page and tell you inside the app. The version in force is always the one published here.

Talking to us

Any question, request or complaint about personal data: privacidade@cifraebraco.app. We answer within 15 days, the deadline set by art. 19 of the Brazilian LGPD.

You may also take your complaint to the data-protection authority that covers you.

Related documents

Terms of Use Delete account Support