Privacy Policy
Kignit is designed so that most of your data never leaves your device. This policy explains, in plain language, what data is processed, why, and what control you have.
Effective date: Pending owner confirmation · Last updated: Pending owner confirmation
This document is a draft. It has not yet completed owner and legal review and is not yet in effect.
Who is responsible
The Kignit app and this website are operated by the operator of Kignit (pending owner confirmation: legal owner name). For anything in this policy, contact support@kignit.online.
The short version
- Your learning progress (lessons, scores, streaks, practice history) is stored only on your device. We do not have it.
- An account is optional. Learning works without one.
- Songs you import stay on your device. Audio is uploaded only when you explicitly confirm a song analysis, and the uploaded file is deleted from our systems right after processing, at most within 24 hours.
- The microphone is used on your device to hear your playing. That audio is never recorded to our servers or uploaded.
- The app currently contains no advertising, no third-party analytics, and no session-replay software. The website sets no cookies.
- We do not sell your personal data.
Data stored only on your device
The following never leaves your device unless you back up your device (for example with iCloud device backups, which are controlled by you and Apple):
- Learning progress: completed lessons, exercise scores, mastery, practice streaks, and experience points.
- Practice statistics used by the in-app coach.
- Local practice profiles (up to five per device).
- App settings, including language choice.
- Imported song audio files, stored in the app's private storage.
- Chord charts and analysis results saved with your songs.
Microphone input for tuning and playing feedback is analyzed on the device in real time. It is not recorded, stored, or uploaded, and the practice statistics derived from it are aggregates, never raw audio.
Account information (optional)
You can create an account with an email address and password, with Sign in with Apple, or with Google. When you do, we store your email address, a display name if your sign-in provider shares one, and account timestamps. Authentication is handled by Supabase, our backend provider. Passwords are stored by Supabase in hashed form; we never see them.
Before you create an account, the app may use an anonymous device-scoped session so that song analysis can work. An anonymous session is not linked to your name or email.
Song analysis
When you ask Kignit to analyze an imported song:
- You must first confirm that you have the right to use the audio, and then separately confirm the upload. Nothing is uploaded without that explicit confirmation.
- The audio file is uploaded over an encrypted connection to a private storage bucket using a short-lived, single-purpose upload link.
- Analysis runs on a private worker we operate on Railway, our hosting provider. It detects chords, key, tempo, and song sections. We do not send your audio to third-party machine-learning services, and our system records and enforces that uploaded audio is processed temporarily and is not permitted to be used for model training.
- The uploaded audio file is deleted from our systems as soon as the analysis finishes (whether it succeeds or fails), and in every case within 24 hours of upload.
- What remains on our servers afterwards is the analysis job record: the chord, key, and tempo results, file metadata (format, size, duration), timestamps, and your consent confirmations. These records are retained until your account and its data are deleted (pending owner confirmation: exact retention period for analysis records).
Purchases and subscriptions
Kignit Pro subscriptions are billed by Apple through the App Store. We never see your payment card details. Subscription state is processed by RevenueCat, our subscription-management provider, which assigns a random app user identifier and tells our backend which entitlements are active so that Pro features and analysis credits work. Our backend stores that identifier, your subscription product and its state, and analysis credit records.
Diagnostics and analytics
The app currently includes no third-party crash reporting, analytics, or advertising software. Practice statistics used by the coach stay on the device. If we add crash reporting or analytics in the future, we will update this policy first.
Website
This website (kignit.online) is hosted on Vercel. Vercel generates short-lived technical request logs (such as IP address and requested page) needed to serve and secure the site. The website sets no cookies and includes no analytics or advertising trackers.
Why we process data, and whether it is linked to you
| Data | Purpose | Linked to you? |
|---|---|---|
| Email, display name | Account sign-in, support | Yes, to your account |
| Uploaded song audio (transient) | Producing the chord analysis you requested | Linked to your account or anonymous session until deleted |
| Analysis results and metadata | Showing your chord charts, fairness of credit use | Yes, to your account or anonymous session |
| Subscription and credit records | Unlocking Pro, granting analysis credits | Yes, via a RevenueCat identifier |
| Website request logs (Vercel) | Serving and securing the website | Not combined with app data |
Who processes data on our behalf
- Apple: App Store payments and, if you use it, Sign in with Apple.
- RevenueCat: subscription state management.
- Supabase: authentication, database, and temporary audio storage.
- Railway: hosts the private audio-analysis worker we operate.
- Google: only if you choose Sign in with Google.
- Vercel: hosts this website and its technical logs.
These providers process data for us under their own security and privacy commitments. Data may be processed on servers located outside your country (pending owner confirmation: confirm hosting regions and transfer wording).
How long we keep data
- Uploaded audio: deleted after processing, at most 24 hours.
- Account data, analysis results, and subscription records: kept while your account exists, then deleted on account deletion, except where we are legally required to keep specific records (pending owner confirmation: final retention schedule).
- Website logs: short-lived technical logs retained by Vercel per its log retention.
Deleting audio and your data
You can remove an imported song's audio, or the whole song, from your device at any time inside the app. To delete your account and the server-side data linked to it, see Delete Your Account and Privacy Choices.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise these rights by emailing support@kignit.online. Where processing is based on consent, such as uploading a song for analysis, you can decline at any time; each upload asks for consent individually. See Privacy Choices for how requests work.
Children
Kignit is not directed to children under 13 (pending owner confirmation: minimum age), and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact support@kignit.online and we will delete it.
Security
Data in transit is encrypted. Uploaded audio lives in a private bucket that is not publicly accessible and is reachable only through short-lived signed links minted by our backend. Server tables that hold personal data deny direct client access. No system is perfectly secure, and we cannot guarantee absolute security, but we design for minimal data and short retention so there is less to protect.
Changes to this policy
When this policy changes, we will update the effective date above and, for significant changes, explain them in the app or on this website.
Contact
Privacy questions and requests: support@kignit.online. General support: support@kignit.online.