Privacy Policy
Information under Art. 13 GDPR (DSGVO)
Last updated 3 October 2026
Who is responsible
Martin Neuschulz, Kurt-Eisner-Straße 58, 04275 Leipzig, Germany. Email hi@keyfu.app. Full details are in the legal notice.
KeyFu is a one-person business. We have not appointed a data protection officer.
In short
What you play stays on your device. The app reads your MIDI keyboard and analyzes your playing locally. It never records audio, and raw MIDI never leaves the device. Your practice history is stored only on your device, and we do not back it up. Our server receives what it needs to run your account, the coach and the subscription. Everything beyond that, such as problem reports, reported replies and the usage data you can choose to share, is described below.
KeyFu shows no ads. We do not sell your data or share it for advertising, we do not use Apple’s advertising identifier, and we do not track you across other apps or sites.
Part 1 — This website
Hosting
keyfu.app is hosted on Cloudflare Pages. Cloudflare processes the technical data any web server receives in order to deliver a page, including your IP address. The legal basis is our legitimate interest in operating a working, secure site (Art. 6(1)(f) GDPR).
The beta waitlist
If you enter your email address to join the beta, our server sends you a confirmation message through Cloudflare. Your address is not added to any list yet: the link in the message carries it in encrypted form, it expires after 7 days, and only Cloudflare’s send log holds the address (see “How long data is kept”). When you open the link and press the button on that page, we add your address to our list at Brevo (Brevo GmbH, Berlin, Germany), with the date you signed up, the date you confirmed and the versions of the texts you agreed to. This is double opt-in, and it is also the record of your consent (Art. 6(1)(a) GDPR).
We use the address to contact you about the beta and the launch of KeyFu. At the launch, this includes an email with your personal code for a discounted first year of KeyFu Pro, and one reminder before the code expires. When we invite you to the beta, we give your address to Apple, which sends you the TestFlight invitation and runs TestFlight as its own controller. Legal basis: for the invitation, taking the step you asked for when you joined the beta (Art. 6(1)(b) GDPR); for the emails about the launch and your code, your consent (Art. 6(1)(a) GDPR). We never pass your address on after you unsubscribe.
Invitation status. App Store Connect shows us whether you have accepted Apple’s invitation and installed the beta. A few days after each wave, we count this only as totals per wave, to decide when to invite the next group. We do not store who accepted or installed. If your invitation is still open after 4 days, we ask Apple once to send it to you again. Legal basis: for the totals, our legitimate interest in running the beta at a pace we can support (Art. 6(1)(f) GDPR); for the reminder, the step you asked for when you joined the beta (Art. 6(1)(b) GDPR).
Optional questions. After you confirm, our welcome email links to a few optional questions: whether you have a MIDI keyboard, whether you have an iPhone or iPad, what you play for, which country you live in, and whether you are 18 or older. For your country you choose from the countries where the beta is open, or “Somewhere else”; we never ask for your birthday. Your answers are stored with your address in Brevo and used only to choose who is invited in each wave. Your country also decides whether we may email you the founder code, because the rules for such emails differ between countries. We can invite only adults who live in a country where the beta is open, so without those two answers we cannot invite you. We also note when we sent you the welcome email and the invitation. Legal basis: for your country and age, the steps you asked us to take before joining the beta (Art. 6(1)(b) GDPR); for the other answers, your consent (Art. 6(1)(a) GDPR); for checking by country whether we may email you the founder code, our legitimate interest in following the email rules of the country you live in (Art. 6(1)(f) GDPR). You can withdraw your consent or have your answers deleted at any time by writing to hi@keyfu.app; otherwise they are deleted together with your address.
News and offers (only if you tick the box). The form has an optional box for news and offers about KeyFu by email. It is not ticked in advance, and joining the beta does not depend on it. If you tick it, the confirmation message names this too, and your click confirms both. We store which version of the consent text you confirmed and when you confirmed it. Legal basis: your consent (Art. 6(1)(a) GDPR).
You can withdraw at any time using the unsubscribe link in any email (it leads to a page on keyfu.app with one button), or by writing to hi@keyfu.app. Withdrawal does not affect processing that already happened. Without the news consent, we use your address until your code for the discounted first year can no longer be redeemed (14 days after KeyFu’s App Store launch, and at the latest on 31 March 2027) or you unsubscribe, whichever comes first; with it, until you unsubscribe. Then we remove it from our list. If you unsubscribed, Brevo keeps your address on a block list so that you get no further email from us. To be able to prove your confirmation, we keep its record (address, time, consent text) for 3 years after the end of the year in which we stopped using your address (Art. 6(1)(f) and Art. 17(3)(e) GDPR).
No email tracking. We send our emails through Cloudflare. They contain no tracking image, and their links lead straight to our website or to the service the email names, without passing through anyone else’s server. We do not learn whether you opened an email or clicked a link. The images in our emails (our logo, a photo of Martin) load from keyfu.app and are the same for everyone. Links to our website carry a label naming the email they came from. The link to the optional questions in the welcome email carries the number of your entry at Brevo and a signature, and so does the unsubscribe link, so that your answer reaches your entry.
Our server never writes your address to a log. It passes it to Cloudflare to send the confirmation, and to Brevo once you confirm, and keeps nothing in between.
Bot protection. Our server rejects sign-ups that fill in a field people cannot see, and Cloudflare briefly blocks a connection (by its IP address) that sends many sign-ups within a few seconds. Nothing is stored in your browser for this. Legal basis: our legitimate interest in keeping automated sign-ups out (Art. 6(1)(f) GDPR).
You may have arrived through a tagged link, such as an invitation from another tester or a link we posted in a community. In that case the short code is stored next to your address in Brevo, so we can tell which channels actually reach people, and, if the link came from a tester, to credit that tester with a count (see Part 3). It is a code, not a profile, and it rests on the same consent as the address itself.
Part 2 — The KeyFu app
What never leaves your device
Raw MIDI stays on your device. The app does not record you, and there is no microphone in the practice loop at all. What you play is read from your MIDI keyboard and analyzed locally. The analysis covers which notes you played, their timing and how hard you struck them. Hand position, posture and fingering are not captured.
Your account
You need an account to use the app, and accounts use Sign in with Apple. Apple gives us a pseudonymous identifier that it creates for your use of KeyFu. We do not ask Apple for your name or your email address, and we do not receive them. At sign-in, Apple also gives our server a token that lets us end KeyFu’s access to your Apple account. We store it encrypted and use it only for that, when you delete your account. Legal basis: performance of the contract you entered by signing up (Art. 6(1)(b) GDPR).
The account lets our server apply the coach’s fair-use limits, your subscription and the free plan and trial. It does not hold your practice history.
When you create your account, the app tells our server which version of our terms of use it showed you. We store that version (its date), which language version you accepted, whether the French version was offered first, and the time of your first acceptance with your account identifier. We use this record only to show which terms you agreed to and when. It is included in your data export and deleted when you delete your account. Legal basis: our legitimate interest in being able to prove the terms of our agreement (Art. 6(1)(f) GDPR).
If you give us your email address yourself, for the waitlist or a problem report, the sections on those explain what happens to it.
Writing to us. If you email us, we use your address and your message to answer you. Legal basis: Art. 6(1)(b) GDPR where you write about your use of KeyFu or about joining the beta, otherwise our legitimate interest in answering you (Art. 6(1)(f) GDPR). How long we keep emails is under “How long data is kept”.
Your practice history stays on your device
Your practice history and what the app learns from it (your skill state, goal and streak, your keyboard and headphone calibration, saved plans and your conversations with the coach) are stored only on the device you practice on. We do not copy them to our server. So they do not move to another device through your account, and they are not restored if you delete and reinstall the app. Deleting the app deletes them. Your device’s own backup may include them: on iPhone and iPad, iCloud Backup (under Apple’s terms) or a backup on your computer; on a Mac, a backup of the Mac. We have no access to it. To keep a copy of your own, use Export My Data (see “Your rights”) before you delete the app.
Our server holds only what the sections below describe: your account and the records of which terms you accepted and of your consent to health details in the chat, coach usage and daily usage counters, your subscription, the free plan and trial, crash reports sent by app versions before 30 September 2026, a log of changes we make to your account by hand, and, if you share usage data, a daily count of usage reports.
The coach
The coach can build a plan, recap a session, summarize a week, or reply when you write to it. For that, the request is sent through our server to one of these AI providers: Anthropic (Claude) or OpenAI (GPT). Which provider answers depends on the feature, and if one is unavailable the request can go to another. The request contains the text you wrote, the last messages of your conversation (at most 12, including the coach’s replies), your goal and a summary of your practice state (skill levels, recent sessions, key, keyboard size, session length and your plan), never your audio or raw MIDI. Our server checks who you are, but does not attach your account identifier or anything else that names you. Text you type yourself is sent as you wrote it, so it contains whatever you put in it.
The providers use the request to write the reply and do not use it to train their models. Under their own terms they also keep it for a limited time to detect misuse and to meet legal duties: up to 30 days, and longer where a request is flagged for misuse (at Anthropic up to 2 years, and its classification scores up to 7 years) or the law requires it. Until 25 September 2026, some requests could also go to Google (Gemini), whose terms let it keep them for 55 days to detect misuse. These copies are separate from ours and are deleted by the providers.
Your permission. Before the first request goes to an AI provider, the app asks whether you allow it. If you say no, nothing is sent to them: the coach shows short pre-written messages instead, and you cannot chat with it. One exception: if you write that you are thinking about harming or killing yourself, the app answers at once with a fixed message pointing you to free helplines. Your message is still not sent anywhere. You can change your answer at any time under Settings → Support & legal → “Use AI for coach replies”. Your answer is stored only on your device. Legal basis for the requests you allow: Art. 6(1)(b) GDPR, because the coach is part of the service. For health information you write in the chat, the legal basis is your explicit consent (see “Safety checks”).
Your conversations with the coach are kept on your device. Our server keeps an identical request and its reply for 10 minutes, so a retry or a double tap does not cost a second call. After that it is no longer used, and a daily cleanup deletes it, normally within a day. For each coach call we log the feature used, the model, the token cost and the day against your account, and we count your messages per day. We use this to apply your message allowance (Art. 6(1)(b) GDPR) and to keep an eye on what the coach costs us (our legitimate interest, Art. 6(1)(f) GDPR). After 90 days a cost entry loses its link to your account and is kept under a random number instead (see “Business figures”). The cost itself always stays in our books. Daily counts are deleted after 8 days, and at once when you delete your account.
Safety checks. Our server checks your latest chat message for words suggesting you may want to harm or kill yourself, and for words about pain or injury. Because these checks read health information, they run only with your explicit consent (Art. 9(2)(a) GDPR), which we ask for before your first chat message. When you agree or withdraw, our server stores that with your account identifier, the version of the consent text and the time, so that we can show your consent. Legal basis for this record: our legitimate interest in being able to prove it (Art. 6(1)(f) GDPR). It is included in your data export and deleted when you delete your account. If the crisis check finds such words, you get a fixed message, marked “Automatic message”, that points you to free helplines. Under it, in most countries where KeyFu is offered, the app names a national crisis line for the country of your App Store account; it reads that country on your device and sends it nowhere. No AI provider receives your message, we do not keep it in our cache, and it does not count against your allowance. If the pain check finds such words, your message goes to the AI provider as described above, and the reply tells you to stop playing for today and to have a doctor or physical therapist look at it if it keeps coming back. Health information you write in other messages goes to the AI provider the same way, under the same consent. The result of a check is not stored with your account; we only count, per calendar year and without any account identifier, how often the helpline message was shown. You can withdraw your consent at any time by switching off “Use AI for coach replies” or by writing to hi@keyfu.app. The chat then stops, practice works as before, and processing before your withdrawal stays lawful. For a message it cannot send, for example when you are offline or have not allowed AI yet, the app runs the crisis check on your device only; that check sends nothing.
To improve the coach, we keep some coach requests for up to 30 days as a reduced sample. The sample has no account identifier, no clock time and none of your own text, only coarse categories. It cannot be traced back to you.
Reporting a reply. If a coach reply seems wrong or inappropriate, you can press and hold it and choose “Report this reply”. We then receive the text of that reply (up to 4,000 characters), a random message number and the date and time. We store them without your account identifier, but the reply can repeat things you told the coach, so we treat reports as personal data. To have one deleted, write to hi@keyfu.app with the day and the reply. We use reports to find and fix bad replies. They are deleted after 180 days. To limit abuse, our server counts how many replies your account reported on a given day. That count is stored with your account for that day only, never with the reports, and is deleted the next day. Legal basis: our legitimate interest in a coach that is safe and correct (Art. 6(1)(f) GDPR).
Usage data (only if you allow it)
The app shares usage data only if you allow it. It asks once, after your first practice session has ended: “Share usage data” or “No, thanks”. Closing the question counts as no. Until you say yes, nothing is sent, and the app stores and reads nothing on your device for this purpose.
If you say yes, two things are sent:
- To TelemetryDeck (TelemetryDeck GmbH, Germany): which screens and steps you use and where a flow stops, such as setup steps, practice sessions, features used and purchase steps (never payment details). Each signal carries technical context: device model and architecture, screen size and orientation, operating system, app version and build, language, region, time zone, display settings such as dark mode, calendar context (such as the day of the week and the hour of the day), accessibility settings, and whether the app came from TestFlight or the App Store, plus a random identifier the app creates for this installation.
- To our own server, when a session ends: what kind of session it was (plan, routine, library or song), whether the coach set the key or you picked it, whether it had an exercise you hadn’t played before, roughly how long you played and how much of it on songs (in 5-minute steps), and whether you skipped an item or changed the length of the day’s plan. On day 7 and day 30 after you created your account, the app also sends how many different exercises you had played by then, as a range. These are stored only as totals, without your account identifier, without a time of day, and without song titles or anything you played. Against your account we store only how many such reports arrived on a given day and whether your day-7 and day-30 reports were counted, not what they said. We use this to limit abuse, to keep small groups hidden and to count, as totals only, how many people practice per day, week and month and how many come back after 1, 7 and 30 days. After 31 days these daily entries lose their link to your account and are kept under a random number instead (see “Business figures”).
Neither contains your name, your Apple account, your messages to the coach or the notes you played. The random installation identifier makes the data pseudonymous, not anonymous. TelemetryDeck hashes it again with its own key, so we cannot match usage data to you or to a support email.
You can change your answer at any time under Settings → Support & legal → “Share usage data”. Switching it off stops sending at once and deletes the identifier and all usage data kept on your device, and the daily counts our server holds for your account. If you used an earlier version of the app, it treats you as not yet asked and deletes its earlier identifier. Legal basis: your consent (Art. 6(1)(a) GDPR, and § 25(1) TDDDG for what is stored on or read from your device). Withdrawing does not affect what was sent before.
Crash reports
The app currently sends us no crash reports of its own. Crash reports reach us through Apple: from TestFlight testers, and from App Store users who chose in their device settings to share analytics with app developers, under Apple’s terms. Reports the app sent before 30 September 2026 are kept with your account identifier for up to 90 days, or until you delete your account, then deleted. Legal basis for keeping them: our legitimate interest in a working app (Art. 6(1)(f) GDPR).
We also count failed server requests per day and route, as totals without any account identifier.
TestFlight. If you test KeyFu through Apple’s TestFlight, Apple passes us crash reports, usage information and any feedback or screenshots you choose to send there. If we invited you by email, App Store Connect also shows us your email address, your name if Apple has one, whether you accepted the invitation, the date you installed a build, and how many sessions and crashes you had. Apart from the wave totals and the one reminder described under “The beta waitlist”, we use all of this only to find and fix problems. We copy your feedback and screenshots, with the app build, device model, system version and date, to our own computer and delete the copy after 90 days. We do not keep the email address Apple sends with it. Our bug tracker receives only a report number, the build, the screen, the kind of problem, the device model, the system version and the date. Legal basis: our legitimate interest in a working app (Art. 6(1)(f) GDPR).
Problem reports (beta testers)
During the beta, testers can send us a problem report from the app. Nothing is sent until you tap Send. The report screen shows the screenshot that will be sent and lists everything else under “What gets sent”. Each report is a separate decision.
What a report contains: the kind of problem and your description; a screenshot of the screen you were on, with coach messages, text fields and your account details painted over before it leaves the device; the app build, device model and system version. If you switch on Attach the last 2 minutes, it also contains what happened in the app just before: screens opened, the app going to the background and back, your keyboard connecting or disconnecting (connection type and size), the kind of audio output (for example built-in speaker or Bluetooth), app error codes, and for each exercise pass its tempo, how many notes were judged and how early or late they were on average. It never contains the notes themselves, what you tapped, device or headphone names, chat text or anything you typed elsewhere in the app, and its times are relative to the moment of the report. If you enter an email address, it is stored too (see below).
Not linked to your account. A report gets a random report number (such as K7Q-4M2) and is stored without your account identifier. What you write, the screenshot and your device details can still point to you, so we treat every report as personal data. To limit abuse, our server counts how many reports an account sends per day. It uses a code derived from your account identifier that changes every day and is deleted the next day; the count is not stored with the report. Legal basis for this count: our legitimate interest in preventing misuse of the report function (Art. 6(1)(f) GDPR).
Optional email. If you enter your address, we send you one receipt with the report number and your own description (never the screenshot or the app events), through Cloudflare. The address is stored separately from the report, is used only for this receipt and for questions about this report, never for marketing, and is deleted together with the report. If you write to us or reply to the receipt, your email is kept in our mailbox and deleted after 90 days as well, unless it is still needed to answer you.
Where and how long. Reports are stored with Cloudflare in the European Union (R2 storage in the EU jurisdiction) and deleted automatically after 90 days. To work on a report, we download it to our own computer. That copy, and any of our notes that quote your description, are deleted after 90 days as well. A report that could not be sent yet waits on your device (at most 20 reports, for at most 7 days) and is removed when you sign out or delete your account.
Legal basis: your consent, given by tapping Send (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future. To have a report deleted earlier, write to support@keyfu.app and quote the report number, or reply to the receipt email. Because reports are not linked to your account, the report number is the surest way for us to find yours. Without it, tell us what you remember, such as the day and what you wrote, and we will look. If we still cannot tell which report is yours, we tell you so. The same applies if you want a copy of a report.
Purchases
KeyFu Pro is sold as a subscription through Apple’s App Store. Apple handles the sale and payment, and we never see your payment details. When you buy, restore or open the app, our server receives Apple’s signed record of your subscription. It stores the product, the Apple transaction number that ties the subscription to your account, its status and expiry date, and any offer or offer code used. Apple also notifies our server directly when a subscription renews, expires, is refunded or is revoked, so that what you can use stays correct. A notification that arrives before the matching account is known is held for at most 30 days. Legal basis: Art. 6(1)(b) GDPR.
Free plan and trial
The free version includes a set number of planned sessions, and new players first get a short trial of the full plan. To apply this, our server keeps against your account how many planned sessions you have had, the day of your last free one, the plan you currently hold and for which installation, and when your trial ended. Legal basis: Art. 6(1)(b) GDPR.
One trial per device. Earlier builds of the app could ask Apple’s DeviceCheck service for a one-time token from your device. Since 30 September 2026 our server ignores such a token: it no longer asks Apple about your device and no longer marks it. Current versions of the app no longer ask for it.
Business figures
To run KeyFu as a business, we need to know over time what the coach costs per account and per subscription, and how many people keep practicing. For this, your account gets a random number that says nothing about you (a “figures ID”).
After the periods above (90 days for coach cost entries, 31 days for the daily count of usage reports), these entries carry only that number instead of your account identifier, together with the month your account was created and your plan (free or Pro). The daily count of usage reports exists only if you share usage data. We look at these figures only as totals and never to judge a single person.
The link between your account and the figures ID is kept on our server, separately from the entries. When you delete your account, that link is deleted at once, and the entries can no longer be connected to you. After 24 months the cost entries lose the figures ID too, and the usage counts are deleted.
Legal basis: our legitimate interest in understanding costs and use of our service (Art. 6(1)(f) GDPR). You can object at any time by writing to hi@keyfu.app; we then remove the figures ID from your entries.
Part 3 — The beta community on Discord
Beta testers are invited to a KeyFu server on Discord. Joining is optional, and the app works without it.
Discord itself
Discord is run by Discord Inc. (United States), and for users in the European Economic Area by Discord Netherlands BV, under its own terms and privacy policy. Discord decides how it processes your account, your messages and what you post, and it is responsible for that. The exception is the moderation settings we chose, described below. We see what any server member sees: your Discord name, your profile picture and what you write in the server. We do not use Discord’s server statistics (Server Insights).
Moderation. We have set up Discord’s own tools for our server. AutoMod blocks spam, mass mentions, links to other Discord servers and offensive words. Discord’s filter checks images from all members for explicit content.
When AutoMod blocks a message, Discord shows the message and its sender in a channel only Martin can read. A mass mention also mutes the sender for 10 minutes. We use this only to keep the server safe. Legal basis: our legitimate interest in a safe community (Art. 6(1)(f) GDPR).
For anything that happens in our server, write to hi@keyfu.app. We handle what is ours and tell you what only Discord can do.
The KeyFu bot
The server has a bot that we run on our own server (Cloudflare). It does the following.
Access and build pings. When you tap Accept the rules, the bot gives you the tester role, which opens the other channels. It also gives you a role for pings about new builds, which the 🔔 button turns off and on. These roles are stored by Discord, not by us.
Bug reports with /bug. When you send a report with /bug, the bot creates a ticket in our private bug tracker on GitHub (GitHub, Inc., United States) and a thread for it in the server. GitHub receives only what you wrote in the form and a link to the thread, not your Discord name or user ID. The form asks you to leave out personal details. Our server (Cloudflare) stores which ticket belongs to which thread and your Discord user ID as the person who reported it, so that the bot can post status updates in your thread. When the ticket’s status changes, the bot posts a short note there and mentions you.
Answers in #testflight-help. When you ask a question in #testflight-help, the bot sends the text of your question to Anthropic (Claude) to choose the matching answer from our list of prepared answers. Anthropic receives only the question text, without your name or user ID, and returns nothing but the choice. The bot then posts the prepared answer as a reply. If no prepared answer fits, it does not reply and passes a link to your question on to Martin. We do not keep the text of your question. We keep a record of the answer the bot posted, and to which message, so that a ❓ reaction can reach Martin.
Invitation links. With /invite, a tester gets a personal link to our website. Its code is derived from the tester’s Discord user ID. When someone joins the waitlist through that link and confirms, we count it for the tester. The tester sees only the number of confirmed sign-ups, never names or addresses, and at 3 gets the Scout role and a short message from the bot. We store the tester’s Discord user ID, the code and when the role was given, until 3 months after the beta ends.
Build announcements. The bot posts new TestFlight builds in #announcements. This uses no member data.
Legal basis: our legitimate interest in running the beta community, fixing reported problems and answering common questions quickly (Art. 6(1)(f) GDPR). You can object at any time. Write to hi@keyfu.app, or simply do not use /bug and #testflight-help: you can report problems from the app and ask questions at support@keyfu.app instead.
Who receives data
We work with these providers. Each processes data on our behalf under a data processing agreement (Art. 28 GDPR), with two exceptions. On our plan GitHub works under its own terms, so we send it no names, user IDs or account identifiers, only report texts. TelemetryDeck works under its own terms, which treat the usage data as anonymous and exclude a processing agreement; we treat the data as pseudonymous (see “Usage data”).
| Provider | What for |
|---|---|
| Cloudflare, Inc. | Website hosting, our server, the database, problem-report storage (in the EU), the Discord bot, sending our emails |
| Anthropic Ireland, Limited | Coach replies (Claude); choosing a prepared answer in #testflight-help |
| OpenAI Ireland Ltd. | Coach replies (GPT) |
| TelemetryDeck GmbH | App usage statistics, only with your consent |
| Brevo GmbH, Berlin | The beta waitlist: your address, your answers and the record of your consent (Brevo sends no emails for us) |
| GitHub, Inc. | Our private bug tracker: the text of reports sent with /bug in Discord, without your name or user ID; for problem reports and TestFlight feedback only a report number, the build, the screen, the kind of problem, the device model, the system version and the date |
Apple’s and Discord’s own services. Sign in with Apple, App Store distribution and payment are Apple’s own services. Apple (Apple Inc. / Apple Distribution International Ltd.) runs them as its own controller, under its privacy policy. Discord runs its platform as its own controller (see Part 3).
Our email and notes. Separately, Apple stores the emails you send to our keyfu.app addresses and our working notes on reports and requests (iCloud Mail and iCloud Drive).
Some of these providers are based in the United States or pass data on to companies there. The safeguards, as the providers’ own documents state them: Cloudflare and GitHub rely on the EU–US Data Privacy Framework and also on EU standard contractual clauses (Art. 46(2)(c) GDPR). Anthropic Ireland, Limited relies on EU standard contractual clauses and may pass data on to Anthropic, PBC in the United States and to its cloud providers (Google Cloud, Amazon Web Services, Microsoft Azure), which can process it in other countries worldwide. OpenAI Ireland Ltd. passes data on to OpenAI companies in the United States, the United Kingdom and Japan and to its service providers, under EU standard contractual clauses or an adequacy decision of the European Commission. By OpenAI’s list of 9 July 2026, these providers process data in the EU and in Australia, Brazil, Canada, India, Indonesia, Japan, Malaysia, Mexico, Norway, Singapore, South Africa, South Korea, Switzerland, the United Arab Emirates, the United Kingdom and the United States; Cloudflare, their network provider, handles each request in its data center nearest to where it starts. Requests flagged for misuse can also be reviewed in the Philippines. Brevo stores data in the EU but may use service providers in the United States and India, under the Data Privacy Framework or standard contractual clauses. To learn which safeguard applies to a provider, or to get a copy of it, write to hi@keyfu.app.
How long data is kept
- Account, the Apple token, the record of the terms you accepted, the record of your health consent (each agreement and withdrawal), subscription record and free-plan and trial state: while your account exists. They are deleted when you delete your account.
- Coach cost entries: linked to your account for 90 days, then kept under a random figures ID for 24 months, then without it. The cost itself stays in our books. Daily counters behind your allowances: 8 days; the count of replies you reported only until the end of that day.
- Daily count of usage reports (only if you share usage data): linked to your account for 31 days, then kept under the figures ID for 24 months, then deleted. Switching usage data off deletes them at once.
- Link between your account and its figures ID: while your account exists. When you delete your account, the counters are deleted and the link is deleted at once.
- Changes we make to your account by hand (for example a free Pro upgrade or a reset of your limits): while your account exists; deleting your account removes your identifier from this log.
- Practice history on your device: until you delete the app. Delete Account also erases it from the device.
- Backups: deleted data can remain in our database provider’s backups for up to 30 days before it is overwritten.
- Crash reports: up to 90 days, and at the latest when you delete your account.
- Coach request cache (your request and its reply): used for 10 minutes, then deleted by a daily cleanup, normally within a day. It is deleted at once when you delete your account.
- Usage data at TelemetryDeck: kept there as pseudonymous statistics in the EU, without a fixed deletion date. Because it cannot be traced back to you, it cannot be deleted for you individually.
- Copies kept by the AI providers: under their own terms, as described under “The coach”.
- Reduced coach samples, weekly usage totals and the yearly count of helpline messages: contain no account identifier. Samples are kept for up to 30 days; the yearly count until the end of the following calendar year.
- Reported coach replies: 180 days. They contain no account identifier. The count of replies an account reported: until the end of that day.
- Problem reports, our working copies of them, and the email address given with one: 90 days, or earlier on request. Unsent reports on your device: at most 7 days. The daily counter behind the report quota (a code derived from your account identifier that changes daily, not linked to any report): deleted the next day.
- Our copies of TestFlight feedback: 90 days. Your email address is not kept. Apple keeps its own copy under its own terms. The entry in our bug tracker (report number, build, screen, kind of problem, device model, system version, date) stays as a record of the bug.
- Invitation status from App Store Connect: we do not store it. We keep only the totals per wave, which contain no identifier.
- Apple notifications about a subscription whose account is not yet known: at most 30 days.
- DeviceCheck marks set before 30 September 2026, if any: stay with Apple for the device; we no longer read or set them.
- Waitlist address and your answers to the optional questions: used until your code for the discounted first year can no longer be redeemed (14 days after the App Store launch, at the latest 31 March 2027) or you unsubscribe; with the news consent, until you unsubscribe. After you unsubscribe, it stays on Brevo’s block list. The record of your confirmation (address, time, consent text): 3 years after the end of the year in which we stopped using the address.
- Cloudflare’s log of the emails we send (address, subject, time, delivery status): for as long as Cloudflare keeps it to deliver mail and fight abuse. We do not copy or export it.
- Brevo’s log of the emails it sent for us before 3 October 2026 (address, time, delivery status): 1 month, so until early November 2026.
- Emails you send us: while we need them to help you, and at the latest 2 years after your last message, unless the law requires us to keep them longer. Emails about a problem report: 90 days, unless still needed to answer you.
- Discord bug tickets: the ticket on GitHub holds what you wrote and the link to the thread, without your name or user ID, and stays as a record of the bug. The link between ticket, thread and your Discord user ID is stored on our server until 12 months after the ticket is closed, or, while it stays open, until 12 months after it was filed. Then it is deleted.
- Records of bot answers in #testflight-help: 30 days. The text of your question is not kept.
If you live outside the EU
KeyFu is available in many countries outside the EU. Everything above applies to you as well. Where the law of your country adds something, you find it here.
Switzerland
Your data goes to these countries: Germany and other EU countries, Ireland, the United States and India. Coach requests can also be processed in other countries. OpenAI’s providers work in the countries named under Who receives data. Anthropic’s cloud providers can process them anywhere in the world: Anthropic does not name these countries, it chooses the location for each request, for speed and availability. Germany and the EU count as adequate under Swiss law.
For the United States, India and any other country, the safeguards described under “Who receives data” apply. You can complain to the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
United States and California
Your age. In the United States the app asks for your age range once: from Apple where your device supports it, otherwise by asking you. Only the result is kept (passed or not passed), and only on your device. Neither the range nor the result is sent to us, and we never ask for a birthday. Export My Data includes the result, and deleting your account removes it.
We do not sell your personal information, and we do not share it for advertising. We let no third party use KeyFu to follow you across other sites or apps over time.
Because we do not track you across sites in the first place, KeyFu has nothing to switch off when your browser sends a Do Not Track signal. We treat all visitors the same way.
The data we collect, who receives it and how to see or correct it are described above and under “Your rights”. The date at the top shows when this policy last changed.
Canada
Martin Neuschulz is accountable for your personal information. Reach him at hi@keyfu.app.
Your data is processed outside Canada: in Germany and other EU countries, Ireland, the United States and India, and coach requests possibly in the other countries named under Who receives data or, at Anthropic, anywhere in the world. While it is there, courts and authorities of those countries may be able to access it under their laws.
You can ask to see and correct your data. You can also complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Japan and South Korea
Your data goes to the providers below, outside your country, each bound by contract to protect it. To learn how these countries protect personal data, and how each provider protects yours, write to hi@keyfu.app.
- KeyFu (Martin Neuschulz), Germany: everything described in this policy. For: running KeyFu. Kept: as under “How long data is kept”.
- Cloudflare, Inc., United States: account, coach usage and subscription records, crash reports, coach requests, problem reports (stored in the EU), Discord bot records, the emails we send you (address, subject, delivery status). For: website, our server and database, sending our emails. Kept: while your account exists; reports 90 days; backups up to 30 days.
- Anthropic Ireland, Limited, Ireland, passing data on to the United States and to cloud providers worldwide: coach requests; questions in #testflight-help. For: coach replies; choosing a prepared answer. Kept: up to 30 days, longer if flagged for misuse (up to 2 years) or required by law.
- OpenAI Ireland Ltd., Ireland, passing data on to the United States and the other countries named under Who receives data: coach requests. For: coach replies. Kept: up to 30 days, longer if flagged for misuse or required by law.
- TelemetryDeck GmbH, Germany: usage data, only with your consent. For: usage statistics. Kept: pseudonymous statistics, no fixed deletion date.
- Brevo GmbH, Berlin, Germany, with service providers in the United States and India: email address, consent record, link code. For: the waitlist and your consent record. Kept: used until the founder code can no longer be redeemed (14 days after the App Store launch, at the latest 31 March 2027) or you unsubscribe (with the news consent, until you unsubscribe), then only on a block list and as a record of your confirmation for 3 years after the end of that year; send log 1 month.
- GitHub, Inc., United States: text of
/bugreports, without your name or user ID; for problem reports and TestFlight feedback only a report number, build, screen, kind of problem, device model, system version and date. For: our bug tracker. Kept: as a record of the bug.
Data goes to a provider each time you use the feature it serves, over an encrypted connection. To stop a transfer, don’t use that feature, for example the coach; KeyFu then cannot provide it.
To reach a provider, use the contact in its privacy policy, or write to us.
Our safeguards are described under “Security”.
Singapore
Under Singapore’s Personal Data Protection Act, our contact for data protection is Martin Neuschulz, hi@keyfu.app.
Your rights
Under the GDPR you may request access to your data, correction, erasure, restriction of processing and data portability (Art. 15–20). You can withdraw a consent at any time with effect for the future.
Your right to object (Art. 21 GDPR)
You can object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest (Art. 6(1)(f) GDPR). In this policy that is: hosting of this website, bot protection on the waitlist form, the record of your waitlist confirmation, answering emails that are not about your use of KeyFu, the record of which terms you accepted, the record of your health consent, checking by country whether we may email you the founder code, control of coach costs, business figures, reported coach replies, the daily counts behind the report limits, crash reports, TestFlight feedback, the totals of accepted and installed beta invitations, and the KeyFu bot and moderation on Discord. We then stop, unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims.
You can object to the use of your data for direct marketing at any time, without giving reasons. We then stop using it for that purpose. Use the unsubscribe link in any email, or write to hi@keyfu.app.
No automated decisions with legal effect. We make no decisions about you that are based solely on automated processing and have legal or similarly significant effects (Art. 22 GDPR). The app applies fixed rules, for example your coach allowance and the age check. If you think a rule was applied to you wrongly, write to hi@keyfu.app and a person looks at it.
For the data stored under your account, the app has two buttons under Settings → You & account. Using them proves to us that the account is yours; an email cannot, because we never receive your email address from Apple. Export My Data gives you a copy of the practice data stored on your device and of the main records our server holds under your account. For a complete copy of everything we hold, including coach cost entries, daily usage counters, your subscription record and full crash reports, write to hi@keyfu.app and include the “userId” line from your export. We answer within one month. Delete Account deletes your account on our server and then erases KeyFu’s data on your device. Deleting your account does not cancel a KeyFu Pro subscription. Cancel it in your App Store settings.
Some data is not stored under your account, so these buttons do not reach it: problem reports and reported replies, emails you sent us, and what the KeyFu bot and our bug tracker hold about you from Discord. For those, and for any other request, write to hi@keyfu.app. What Apple, Discord and the AI providers keep under their own terms, you can ask them about directly.
You also have the right to complain to a supervisory authority (Art. 77 GDPR). For us that is the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte), Maternistraße 17, 01067 Dresden, Germany, datenschutz.sachsen.de.
Security
Connections are encrypted (HTTPS/TLS). Keys for the AI providers live only on our server, never in the app, and every request to our server is authenticated per session.
Changes
The app is in beta, and this policy will change as the app does. The date at the top is the version you are reading.