Last updated: January 2026
1. Privacy at a Glance
General Information
The following provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.
2. Data Controller
The party responsible for data processing on this website is:
The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.
3. Data We Collect
In the course of using Rightkey, we collect and process the following personal data:
Account Data
- Email address (for login and communication)
- Username (optional)
- Password (stored encrypted)
Usage Data
- Your practice sessions (date, duration, musical piece)
- Your music piece library
- Uploaded sheet music files
- Practice statistics and progress
Technical Data
- IP address (for error diagnosis only)
- Browser and device information
4. Legal Bases for Processing
We process your data based on the following legal grounds:
- Contract Performance (Art. 6(1)(b) GDPR): To provide our service and store your practice data.
- Legitimate Interests (Art. 6(1)(f) GDPR): For error fixing, security, and service improvement.
5. Third-Party Services and Data Transfers
We work with the following service providers:
Supabase (Database and Authentication)
Purpose: Storing your account data, practice sessions, and music pieces
Location: EU
Privacy Policy: supabase.com/privacy
Railway (Hosting)
Purpose: Hosting and operating the web application
Location: USA
Privacy Policy: railway.app/legal/privacy
Sentry (Error Monitoring)
Purpose: Detecting and fixing technical errors
Location: EU (Frankfurt)
Privacy Policy: sentry.io/privacy
GoatCounter (Analytics)
Purpose: Privacy-friendly, anonymized usage analytics
Location: EU
Note: No cookies, no personal data, GDPR compliant
Privacy Policy: goatcounter.com/help/privacy
6. Cookies
We only use technically necessary cookies:
- Session Cookie: For your login status (required)
Tracking cookies are not used. GoatCounter operates without cookies.
7. Data Retention and Deletion
- Account Data: Until you delete your account
- Practice Data and Music Pieces: Until you delete your account
- Uploaded Files: Until you delete your account
- Technical Logs: 30 days
Upon account deletion, all your data is permanently deleted.
8. Your Rights
Under the GDPR, you have the following rights:
- Right of Access (Art. 15): You can request information about your stored data.
- Right to Rectification (Art. 16): You can request correction of inaccurate data.
- Right to Erasure (Art. 17): You can request deletion of your data.
- Right to Restriction (Art. 18): You can request restriction of processing.
- Right to Data Portability (Art. 20): You can export your data in a common format.
- Right to Object (Art. 21): You can object to processing.
To exercise your rights, contact us at hello@rightkey.app.
You also have the right to lodge a complaint with a data protection supervisory authority.
9. Data Security
We implement technical and organizational measures to protect your data:
- SSL/TLS encryption of all data transfers
- Encrypted storage of passwords
- Regular security updates
- Access restrictions on data
10. Changes to This Privacy Policy
We reserve the right to update this privacy policy. Significant changes will be communicated to you via email.