Privacy Policy
This is the privacy policy for the Rabab Tuner mobile application and this website. The short version: the app collects nothing about you, and there is no server for it to collect anything with.
Application: Rabab Tuner · Android package and iOS bundle identifier app.rababtuner · Platforms: Android and iOS · App version 1.0.0 · Policy version 1.2 · Effective 30 July 2026 · Last updated 30 July 2026
Nothing about you is collected
No sign-up, no name, no email, no device or advertising ID, no usage tracking, no crash reports, no ads, and nothing shared with anyone else. The subscription is billed by the app store, so we never see your payment details either.
Your playing is not recorded
The app listens, works out the pitch, and forgets the sound — all on your phone. The one exception, which you start yourself, is described in section 6.
One optional network call
If you press "Forecast", the place name you typed is sent to a weather API to answer that one request. Nothing else ever leaves the device.
- Scope of this policy
- Who we are and how to contact us
- What "collect" and "share" mean here
- What the app collects
- The microphone: purpose, consent, withdrawal
- What is stored on your device
- Network activity and third parties
- Store privacy declarations
- Permissions
- The subscription and your payment details
- Legal bases and international transfers
- Children's privacy
- Your rights and choices
- Retention, deletion and account deletion
- Security
- This website
- Changes to this policy
- Contact and complaints
1. Scope of this policy
This policy applies to:
- the Rabab Tuner mobile application for Android and iOS, distributed on Google Play and the Apple App Store under the identifier app.rababtuner, including every feature inside it; and
- this website at rababtuner.com, including its contact form.
It does not apply to Google Play, the Apple App Store, or your device's operating system, each of which is governed by its own privacy policy and handles your app downloads, updates, payments (there are none here) and any OS-level diagnostics you have enabled.
This policy sits at a fixed web address that anyone can open from any country, without signing in and without a subscription. The app has not been released yet; when it is, this same page will be linked from both store listings and reachable from inside the app itself.
2. Who we are and how to contact us
Rabab Tuner is published by Key for Business Pty Ltd, an Australian proprietary limited company, which is the data controller for any personal data described in this policy.
Key for Business Pty Ltd (ACN 627 946 874), publisher of the Rabab Tuner application.
Narre Warren VIC 3805, Australia
[email protected] — questions, requests and complaints about privacy.
rababtuner.com/contact.html — an alternative mechanism for submitting privacy inquiries.
We aim to answer any privacy request within 30 days, and will tell you if we need longer.
3. What "collect" and "share" mean here
Because both app stores define these words precisely, this policy uses their definitions:
Transmitting data off your device in a way that allows us or a partner to access it for longer than is needed to answer that request in real time. Processing that happens entirely on your device is not collection.
Transferring data to another company or organisation, other than a processor acting on our instructions to deliver a feature you asked for.
Data that is read, analysed and either discarded or stored in the app's private storage on your phone, and never transmitted.
Data used only in memory, for no longer than is needed to answer the request that produced it, and never persisted.
4. What the app collects
Rabab Tuner collects no personal or sensitive user data. It has no server component, no account system, and no analytics of any kind. Specifically, the app does not collect, transmit, sell, rent, share or monetise:
- names, email addresses, phone numbers, postal addresses or any account credentials — there is no account and no sign-in;
- device identifiers, advertising identifiers, IP-based profiles or fingerprints;
- location data — the app requests no location permission of any kind, coarse or precise, and never accesses the device's location services;
- contacts, photos, media files, documents, calendar, call logs, SMS, health or fitness data;
- usage analytics, event telemetry, crash reports, performance traces or session recordings;
- recordings of your playing, your voice or your surroundings (see sections 5 and 6);
- payment or financial information. Rabab Tuner is a subscription app, but we never see your payment details: Google Play and Apple take the payment, hold the card and manage the subscription. All we ever receive from them is anonymous, aggregated sales reporting — how many subscriptions, in which countries — with no way to identify anyone.
The app contains no analytics SDK, no advertising or attribution SDK, no crash reporter, no remote configuration service and no A/B testing framework. It performs no tracking as defined by Apple's App Tracking Transparency framework, and therefore never presents a tracking permission request.
5. The microphone: purpose, consent, withdrawal
Why the app asks
Rabab Tuner asks for microphone access for one purpose: to hear your instrument so that it can measure pitch and analyse your playing in real time. That covers live tuning, learning each string's timbre, detecting plectrum strokes, following the scale you are playing, measuring how a string decays during a health check, profiling your room's background noise, and the Live Learn feature described in section 6.
Disclosure and consent
Before the operating system's permission dialog appears, the app shows its own plain-language explanation inside the app, in the normal flow of use, describing what the microphone is used for and stating that audio is analyzed on the device and not recorded, stored or transmitted. Only after you accept that in-app disclosure does the system dialog appear, and only your affirmative action on the system dialog grants access. Consent is never inferred from navigation, from a dismissed message, or from continued use.
How the audio is handled
- sound comes straight from the microphone into the app, without being stored on the way;
- each tiny slice of sound is examined at once, then thrown away;
- nothing is written to storage, queued for later, or transmitted anywhere;
- the app stops the microphone as soon as the feature using it finishes, and requests no background audio capability on either platform, so it cannot listen while closed;
- the app never accesses the microphone at launch, only when you start a listening feature.
Withdrawing consent, and using the app without the microphone
You may revoke microphone access at any time in your device settings (Settings → Apps → Rabab Tuner → Permissions on Android; Settings → Privacy & Security → Microphone on iOS), and the app will keep working. No paid or core functionality depends on granting it: long-press any string and the app plays that string's exact target pitch so you can tune entirely by ear. The app is even installable on devices that have no microphone at all. If you decline, the app tells you where the by-ear workflow is instead of repeating the request.
What the app learns, and what it keeps
Some parts of the app do learn from what they hear, but what they keep are numbers, not sound: about a dozen numbers describing how each of your strings sounds; a description of the steady background noise in your room; short summaries of how your strokes begin; and one figure for how long each string rings. None of it can be played back, or turned back into a recording of what you played, and none of it leaves your phone.
6. What is stored on your device
All app state lives in the app's private storage on your phone, using the operating system's own key–value store and app-private file directory. There is no cloud sync, no backup to us, and no mechanism by which we can read any of it.
| Stored item | What it contains | Leaves device? |
|---|---|---|
| Instrument profiles | String names, target frequencies, string and peg counts, reference pitch, headstock layout, and any profile or instrument names you type | No |
| Onboarding flags | Whether the builder, the guided tour and feature announcements have been seen | No |
| How your strings sound | About a dozen numbers per string — not audio | No |
| Your room's background noise | A description of the steady hum, as numbers — not a recording | No |
| How you strike the strings | Short summaries of up to 600 of your own strokes, and what the app learned from them | No |
| Practice history | Totals from your sessions — stroke counts, average timing, how long you played — for up to 60 sessions | No |
| Check-up history | Up to 24 past readings per instrument, with dates | No |
| Accompaniment settings | Key, taal, tempo, volumes and any presets you name | No |
| Weather place name | The place name you last typed into the care screen, if any | Only when you press "Forecast" — see section 7 |
| Live Learn loops | Processed audio files you deliberately created — see below | No |
7. Network activity and third parties
The app is built to work entirely offline, and every feature it is for works in airplane mode. It makes exactly one kind of outbound request, and only after you have both asked for it and agreed to it. The first time you type a place name into the Instrument care screen and press "Forecast", the app shows a dialog naming exactly what will be sent and what will not, and nothing leaves the device unless you choose Allow forecast. Once allowed:
- a geocoding request to Open-Meteo containing only the place name you typed, which returns coordinates and a place label; and
- a forecast request containing those coordinates, which returns hourly humidity and temperature for the next day.
What is not sent: no API key, no account, no device or advertising identifier, no instrument data, no audio, no analytics, and nothing from your device's location services. The place name is text you typed, not a reading of where you are. It is stored locally so you do not have to retype it, and the request exists only to answer that one lookup in real time. If you never press "Forecast", the app never contacts the internet at all.
You can withdraw that consent at any time with Turn off the online forecast on the same screen, which also clears anything already fetched and returns the app to making no network requests at all. The choice is stored on your device only.
Open-Meteo acts as a processor delivering a feature you asked for. Its own terms and privacy practices apply to that request; see open-meteo.com/en/terms. Like any web service, it may keep its own server logs, which are outside our control and which we never receive.
Everyone who could touch data, and on what basis
| Third party | Role | What it receives |
|---|---|---|
| Open-Meteo | Weather API, only on your explicit request | A place name, then coordinates derived from it |
| Google Play | App distribution, updates, and seller of record for the subscription (Android) | Nothing from us. Your Play account, payment and subscription data are handled by Google under its own policy; we receive only anonymous sales totals |
| Apple App Store | App distribution, updates, and seller of record for the subscription (iOS) | Nothing from us. Your Apple Account, payment and subscription data are handled by Apple under its own policy; we receive only anonymous sales totals |
| Website host | Serving this website and delivering contact-form messages | Standard server logs; anything you type into the contact form |
| Google Fonts | Web fonts for this website only — not used by the app | Your browser's font request, as described in section 16 |
No advertising network, data broker, analytics provider, AI service or social platform receives anything, because the app sends them nothing. Any third party that ever has access to data described in this policy is required to protect it at least as strongly as this policy and the app stores' guidelines require, and to use it only to provide the function it was given the data for. Data given for one purpose is never repurposed for another without asking you first.
8. Store privacy declarations
For transparency, these are the declarations made about this app in each store's privacy questionnaire. They are published here so you can hold them to account.
These describe the app, which is what the stores ask about. They are not contradicted by the contact form on this website: writing to us from a web page is not something the app does, and the store questionnaires do not cover it. What that form keeps is set out separately in section 16.
Apple — App Privacy ("privacy nutrition label")
| Question | Declaration |
|---|---|
| Data collected by this app | Data Not Collected in every category |
| Data linked to you | None |
| Data used to track you | None — the app does not use App Tracking Transparency because it does not track |
| Third-party SDKs collecting data | None embedded in the app |
Audio and analysis results are processed on the device and are therefore not "collected" under Apple's definition. The optional weather lookup transmits a typed place name solely to service that request in real time, which likewise falls outside that definition — and it is disclosed in section 7 regardless.
Google Play — Data safety
| Question | Declaration |
|---|---|
| Does the app collect or share required user data types? | No data is collected or shared for any purpose other than the optional forecast described below |
| Optional forecast lookup | Approximate location (a place name you type): optional and behind an explicit in-app consent dialog, used only for app functionality, processed ephemerally, not shared for advertising or analytics, never linked to an identity |
| Is data encrypted in transit? | Yes — the only request the app makes uses HTTPS |
| Can users request data deletion? | Yes — see section 14; all data is local and deletable in the app or by uninstalling |
| Does the app have an account system? | No — so Google Play's account-deletion requirement does not apply |
| Committed to Play Families policy? | The app is rated for general audiences and is not directed to children — see section 12 |
If the developer later removes the optional weather feature, the Data safety declaration becomes "no data collected, no data shared" without qualification.
9. Permissions
| Permission | Why the app asks | Optional? |
|---|---|---|
| Microphone RECORD_AUDIO / NSMicrophoneUsageDescription | Live pitch detection, stroke and scale analysis, decay measurement, room profiling, Live Learn | Yes — the app works by ear without it, and nothing is gated behind it |
| Internet INTERNET | Only the optional weather outlook in Instrument care | Yes — never used unless you press "Forecast" and accept the consent dialog |
The app requests no location, storage, media, camera, contacts, Bluetooth, notification or background-activity permissions, and holds no wake locks other than keeping the screen on while you are actively tuning.
10. The subscription and your payment details
Rabab Tuner is sold as a subscription with a free trial. The commercial side of that is described in section 6 of the terms; this section is only about data.
- We are not the merchant. Google Play and Apple sell the subscription, take the payment and hold the payment method. Your name, card, billing address and purchase history live with them, under their privacy policies — not ours.
- We never receive your payment details. Not the card, not the last four digits, not your billing address, not your store account email.
- What we do receive is the anonymous, aggregated reporting every developer gets from the stores: totals of subscriptions, renewals, cancellations and refunds by country and period. It contains no names, no emails and no device identifiers, and cannot be traced back to an individual.
- How the app knows you have subscribed. The app asks the store on your own device whether there is an active subscription, and gets back a yes or no. That answer is used on the device and is not sent to us — there is no server for it to be sent to.
- Cancelling changes no data. Everything the app has learned stays on your phone, and none of it is transmitted whether you subscribe, cancel or never subscribe at all.
11. Legal bases and international transfers
Where the GDPR, UK GDPR or a similar law applies, our legal bases are:
- Consent (Article 6(1)(a)) — for microphone access, and for the optional weather lookup. Each is requested through an explicit in-app dialog that precedes any use, and each is withdrawable at any time: revoke the microphone in system settings, and turn the forecast off on the Instrument care screen;
- Performance of a contract (Article 6(1)(b)) — for storing your instrument profiles and settings on your device so the app can function as you set it up;
- Legitimate interests (Article 6(1)(f)) — for answering a message you send us, and for keeping this website secure.
No special-category data is processed, and no automated decision-making with legal effect takes place. Because the app stores everything on your own device, there is no international transfer of app data. The optional weather request and this website's hosting may involve servers outside your country; where that happens for personal data, transfers rely on the recipient's own safeguards and, in the EU/UK context, on standard contractual clauses or equivalent mechanisms operated by those providers.
12. Children's privacy
Rabab Tuner is a musical instrument tool suitable for all ages. It contains no advertising, no chat, no user-generated content sharing, no social features and no external links inside the app other than the optional weather lookup, so it is safe for young players to use.
It does contain one purchase: the subscription that keeps the app working after the free trial. That purchase goes through Google Play or the App Store and is subject to whatever payment protections and parental controls you have set there — on both platforms a child's purchase can require a parent's approval, and we recommend turning that on. We never take a payment directly, and the app never asks a child for payment details.
The app is not directed to children for the purposes of the US Children's Online Privacy Protection Act (COPPA), and it is not enrolled in Apple's Kids Category. On Google Play its target audience is declared as general audiences (teen and above), and it is not designed primarily for children. Because it collects no personal information from anyone, it collects none from children either — there is nothing to obtain parental consent for. If you believe a child has somehow provided personal information to us through the contact form, write to us and we will delete it.
13. Your rights and choices
Data-protection laws — including the EU and UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), the Australian Privacy Act 1988, Canada's PIPEDA and comparable regimes — give you rights over personal data held about you. In this case there is almost nothing for us to hold:
- Access and portability — everything the app knows is already on your device and visible in the app's own screens. We hold no copy.
- Correction — every value the app stores is editable in the app.
- Deletion / erasure — see section 14. You can delete individual items in the app or remove everything by uninstalling.
- Withdrawing consent — revoke microphone access in your system settings at any time; the app keeps working by ear. The forecast has its own off switch on the Instrument care screen, which also clears anything it fetched.
- Objection and restriction — there is no profiling, advertising or analytics processing to object to.
- No sale, no sharing, no targeted advertising — we do not sell or share personal information, and never have, so there is no opt-out for you to exercise. We do not respond to Global Privacy Control signals because we run no advertising or tracking that they would apply to.
- Non-discrimination — exercising any right here costs you nothing and takes no feature away. We do not offer a "cheaper if you let us track you" version, because there is no tracking to consent to in the first place.
The only circumstance in which we hold personal data about you is if you send us a message. Then we hold that message and your email address for as long as it takes to answer you and to keep a record of the exchange, and you may ask us to delete it at any time.
14. Retention, deletion and account deletion
The app has no accounts. There is nothing to register, nothing to log in to, and therefore no account to delete — which is why Google Play's account-deletion requirement does not apply to it. Your data is retained entirely at your discretion, because it lives on your device:
| To delete | Do this |
|---|---|
| A saved profile, preset or Live Learn loop | Delete it in the app — Tools → Tuning & configuration profiles, or the ✕ on a loop chip |
| A learned stroke model or room profile | Retrain or reset it from the Practice monitor and Isolation screens |
| Practice or health history | Capped automatically at 60 sessions and 24 snapshots; removed with the app |
| Everything, at once | Uninstall the app. All app data, including any Live Learn audio, is removed by the operating system |
| A message you sent us | Email [email protected] or use the contact form and ask; we will confirm when it is done |
Nothing the app holds is copied to a server, so there is nothing left behind after an uninstall and nothing for us to restore. There is exactly one thing we may hold about you, and only if you chose to send it: a message from the contact form on this website. Section 16 sets out what that contains and how long it is kept — in short, until your question is dealt with, deleted automatically on a schedule, and deleted straight away if you ask. If you would like written confirmation of what we hold about you, ask and we will tell you.
15. Security
App data is stored in the app's private sandbox, isolated from other apps by the operating system and protected by your device's encryption where you have it enabled. Because the app transmits nothing, none of your playing, tuning or practice history is ever exposed to a network, and there is no data in transit to intercept other than the HTTPS weather request you choose to make. The app requests the narrowest set of permissions it can function with, and its microphone path is designed to hold audio for no longer than the few milliseconds an analysis frame needs.
The one place we do hold something is the contact form on this website. Messages travel to us over an encrypted connection and are stored in a database on our own server, protected as follows: the database accepts connections only from the server itself and never from the internet; it is reached by an account that has access to this one database and no other; the passwords involved are held outside the part of the server that the web can reach; the record keeps a scrambled version of your IP address rather than the address itself; and old messages are deleted automatically on the schedule in section 16 so that nothing accumulates that we no longer need. Even so, no website can promise perfect security, so please do not send sensitive personal information — health details, identity documents, card numbers — through the form.
16. This website
This site is a set of static pages. It sets no cookies, runs no analytics, embeds no social or advertising scripts, and builds no profile of visitors. Two things involve another party:
- Web fonts. Your browser requests two typefaces from fonts.googleapis.com and fonts.gstatic.com, which means Google receives that request, including your IP address, as it would for any resource your browser loads. We send nothing identifying with it, and the site remains fully readable if those requests are blocked, because the site falls back to the typefaces already on your device.
- The contact form. What you type goes to our own server and is stored in our own database. It is not handed to any outside form service. We are then sent a copy by email so we can answer you, which our email provider carries the way it carries any email.
What the contact form keeps, and for how long
When you send a message we store the fields you can see — your name, your email address, the topic you chose, the phone model and app version if you filled them in, your message, and the fact that you ticked the consent box. Two things you cannot see are stored with it:
- A scrambled version of your IP address, never the address itself. It is put through a one-way calculation with a secret value, which produces a fixed jumble of characters that cannot be turned back into an address. It exists only so that one computer cannot flood the form with hundreds of messages. It is of no use for identifying you, and we could not reverse it ourselves.
- Your browser's description of itself (the "user agent" — for example "Safari on iPhone"), which helps us reproduce a problem you are reporting.
We keep a message for as long as it takes to deal with it, and no longer. Messages we have answered are deleted after twelve months, anything caught as spam after thirty days, and everything without exception after twenty-four months. That housekeeping runs automatically every night rather than depending on us to remember. You can ask us to delete your message sooner at any time — see section 14 — and we do it properly, by removing the record, not by hiding it.
We hold this so that we can reply to you, which is the reason you wrote to us; in data protection terms, our legitimate interest in answering our own correspondence, together with the consent you give by ticking the box. We do not add your address to any mailing list, we send you nothing you did not ask for, and we do not pass it to anyone else.
Our hosting provider may keep standard server logs, including IP addresses and user agents, for security and abuse prevention, under its own retention policy.
17. Changes to this policy
If the app changes in a way that affects this policy, we will update this page, raise the policy version, and change the "last updated" date above. Material changes will also be noted in the app's release notes and, where a change would require it, the app will ask for your consent again before doing anything new with data. Because the app has no server and no mailing list, we cannot notify you directly; the version of this page current at the time you use the app governs.
The contact form now runs on our own server and stores messages in our own database instead of using an outside form service. Section 16 sets out exactly what is kept, the scrambled form of the IP address used to prevent flooding, and the retention periods, which are now enforced automatically.
Restructured for Google Play User Data policy and Apple App Store Review Guideline 5.1.1 compliance: added publisher identity and privacy contact, store definitions, store declarations, legal bases, international transfers, children's privacy, explicit deletion routes, and a security section.
First published with app version 1.0.0.
18. Contact and complaints
For any privacy question or request:
- Email: [email protected]
- Contact form: rababtuner.com/contact.html
- Post: Narre Warren VIC 3805, Australia
If you are not satisfied with our response, you may complain to a supervisory authority. In Australia that is the Office of the Australian Information Commissioner (oaic.gov.au); in the EU, your national data-protection authority; in the UK, the Information Commissioner's Office. You are welcome to raise it with us first — most things are quicker to fix directly.
Plain-language summary: the app has no account, no server, no ads and no analytics. It listens to your Rabab to tune it, and forgets what it heard. It only writes audio if you deliberately sample your own harmonium or tabla, and that file stays on your phone. The only thing it ever sends anywhere is a place name, and only if you ask for a weather forecast. It is a paid subscription, but the payment happens entirely inside Google Play or the App Store — we never see your card, and paying does not change any of the above.