Privacy policy
Last updated: October 9, 2026.
Noctave is built to work without an account and without a network. This page explains what data is processed, why, for how long, by whom, and how to exercise your rights.
This English version is a translation provided for convenience. In case of any difference, the French version prevails.
In short
- Without an account, nothing is sent to Noctave: progress, reading statistics, settings and imported pieces stay on your tablet or phone (and in the Android backup of your Google account, if you turned it on, which Noctave can't read).
- With an account, the server keeps what it needs to sync: your email address (or your Google account's identifier, a number without your address), your progress, your reading statistics, your settings and your imports.
- The microphone, if you choose it, listens on your device only: the sound is analysed live to recognise your notes, never recorded or sent.
- Score scanning (Noctave Plus): pages are photographed with Google's document scanner, which processes them on your device; those you send are read on Noctave's server, then erased together with the resulting score as soon as it's in your library, and 30 days after the upload at the latest.
- If you buy Noctave Plus, you pay in the app through Google Play: Noctave never sees your payment details. With a Noctave account, the server keeps the reference of your purchase to open Plus on your devices.
- No analytics, no tracking cookies, no ads, no data sold. To know where to talk about Noctave, only a click counter on our short links, and the name of the link that brought the app, attached to a purchase of Plus made with an account (sections 6 and 7): nothing that designates you.
- You can delete your account at any time, in the app or on this page: everything is erased, and backups are gone within 15 days.
- Controller
- Without an account
- Microphone
- With an account
- Score scanning
- Buying Noctave Plus
- Logs
- Purposes and legal bases
- Recipients
- Retention
- Security
- Your rights
- Minors
- Cookies
- Waitlist
- Changes
1Data controller
Matthias Vogel EI, trading as 418 DevOps, 2 Chemin des Rochers, 67120 Molsheim, France — admin@418devops.fr. More details in the legal notice.
2Without an account: everything stays on your device
Playing, learning, importing a piece and making progress work without an account or a network. Your progress, your reading statistics, your settings (including calibrated latency and your keyboards) and your library are stored on your device and, if you turned it on, in the Android backup of your own Google account, which can also transfer them to a new device. That backup is made by Android, under your Google account: Noctave can't read it and receives nothing from it. Your sign-in session is never copied into it: after a restore, just sign in again. To erase everything, uninstall the app and delete its backup in your device's Google settings.
Bluetooth and USB permissions are only used to talk to your MIDI keyboard: the notes you play are evaluated on the device and sent nowhere. On Android 11 and older, Android files the search for Bluetooth devices under the “Location” permission: Noctave only asks for it to find your keyboard, and never reads your location.
The app only contacts the Noctave server if you're signed in, or if you open the account screens or scanning. Without an account, it only reads the service's configuration there (is scanning open? is the app up to date?), without sending anything about you; as with any visit, your IP address then appears in the technical logs (section 7). Without an account, a purchase of Noctave Plus stays between your device and Google Play: nothing about it is sent to the Noctave server, not even the install campaign the app keeps on the device (section 6), as long as you don't sign in to a Noctave account on this device: when you sign in, the purchase (and its campaign) is attached to that account, like a purchase made while signed in. If Google refunds a purchase that was never attached to an account, it tells the server (token and order number, linked to nobody), which keeps it one year so that it can no longer open Noctave Plus (section 10).
Switching accounts on a device: when you sign out or delete your account, your progress, imported pieces and reading series stay on the device. If another Noctave account then signs in on it, this data is never sent to it automatically: the app first asks whether to add it to that account, or to erase it from the device and start from the account's data. Until someone chooses, nothing is sent. Erasing it from the device doesn't affect the previous account: if it still exists, it keeps its data on the server; if it was deleted, the device's copy was the last one.
3The microphone: listening stays on your device
To play a piano without a MIDI cable, you can choose your tablet's microphone as a source (Devices › Microphone). Noctave first explains what it's for, then Android asks for your permission: never before you choose it. You can refuse; everything else in the app works without it.
The sound is analysed in real time, on your device, to recognise the notes you play. It is never recorded, kept or sent: the app only holds the last second and a half at most in memory, long enough to analyse it, and erases it as it goes. Nothing is written to a file, nothing goes to the Noctave server or to anyone else. Only the result (the note recognised and when, the sound level, the measured latency) is used for the display and the game, and it stays on the device too.
Noctave only listens while a screen that needs it is open (today the microphone diagnostics, soon playing and learning with the microphone), and never in the background: listening stops as soon as you leave that screen or the app. While it listens, Android shows its microphone indicator.
You can withdraw the permission at any time in Android's settings (Apps › Noctave › Permissions), or choose “Stop using it” in Devices › Microphone.
4With an account: what the server keeps
The account is optional. It lets you find your progress on several devices. The server then keeps:
For an account created with an email address
- your email address;
- your password, never in plain text: only a hash (argon2id) that can't be turned back into it;
- the language of emails (French or English), the date the account was created, the date of your last sign-in (to the day, to delete an unused account, section 10) and that of any warning email.
For an account created with “Continue with Google”
- your Google account identifier, an opaque number Google assigns to every account. Noctave asks for no permission on your Google account and keeps neither your email address, nor your name, nor your picture: the signed proof Google hands the app, which the app passes on to the server, contains them, but the server only reads the identifier and keeps nothing else;
- the chosen language, the date the account was created and the date of your last sign-in (to the day).
In every case
- your progress: unlocked levels, best scores, stars, including those of the versions adapted to small keyboards (with their number of keys);
- the pieces you practised in Learning: for each one, the piece and the date of your last session (to show them first on the home screen of all your devices);
- your reading statistics: for each series of reading exercises, its date, length and settings, and for each note shown, the note, whether you played it right at the first try (otherwise the key you played) and your reaction time;
- your settings shared across devices (language, note names, hand colors, note speed, learning aids, score display…);
- your imported pieces: the MIDI or MusicXML file, its file name, its title, its composer, how the hands are split, its size and its import and correction dates;
- if you link a Google account to your email account, that Google account's identifier;
- your sign-in sessions (tokens stored as hashes, with their expiry date), and your access to Noctave Plus if you have it: the reference of your purchase on Google Play (section 6), or an access given to you, with its end date if any;
- if you ask for a new password, a single-use link, also stored as a hash, valid for one hour.
5Score scanning (Noctave Plus)
With Noctave Plus, you can take pictures of a printed score, or send a PDF, to turn it into a playable piece. The pages then go to Noctave's server, which keeps:
- the pages you sent (photos or PDF), renamed by the server;
- the resulting score (a MusicXML file);
- the state of the scan (waiting, in progress, done or failed) and its dates.
Taking the pictures (Android) goes through Google's document scanner (ML Kit, provided by Google Play services): it finds the page, straightens it and cleans it on your device, and only hands Noctave the pages you keep. Noctave doesn't ask for permission to use the camera: Google's scanner does. Google Play services may send Google technical information about how this component works (usage metrics, diagnostics), under Google's own responsibility and according to its privacy policy; the pictures themselves are not sent to Google. You can also import a PDF or images without this scanner. The scanner drops the pages for a moment in the app's cache, which erases them at once and keeps them in memory until they're sent. Before sending, the app removes the hidden details of images on your device (EXIF including the GPS position, the camera, the date and the software; XMP, IPTC, comments, thumbnails): only what is needed to display them stays (color profile, resolution) and, for a photo taken sideways, its orientation. An image it can't read to the end isn't sent. For a PDF, it erases the document properties written in plain text (title, author, software, dates) and uncompressed metadata; those compressed or encrypted inside the file may remain: export your pages as images instead if you want to be sure.
The pages are read on Noctave's server, by the free software Audiveris. They are sent to no other service and only serve to produce your score: no sharing, no model training. Only photograph the score: avoid leaving a face, a name or a personal document in the picture.
The scan is erased from the server as soon as you add its score to your library, right away if you delete it or your account, and automatically 30 days after the upload at the latest. These files are not copied into the server's backups. The score you add to your library stays on your device (and with your account if you're signed in, like your other imports).
Notification: if you accept it, Noctave shows you a notification when a score is ready while the app is in the background. It's made on your device: no push notification service is used and no identifier is sent. You can turn it off in Android's settings (Apps › Noctave › Notifications).
6Buying Noctave Plus
Noctave Plus is bought in the app, through Google Play. The payment happens at Google, with the payment methods of your Google account: Noctave never sees or keeps your payment details, your name or the address of your Google account. For a purchase made in the European Economic Area or the United Kingdom, Google Commerce Limited (Ireland) sells Noctave Plus as the merchant of record: Google then processes your Google account, your payment and your receipt under its own responsibility, according to its privacy policy.
Google Play hands the app a proof of purchase (a purchase token, with the product and the state of the payment), which opens Noctave Plus on the device; the app only remembers, on the device, that Plus is open there. Noctave sends Google no identifier of your Noctave account.
With a Noctave account, the app hands this token to Noctave's server (including for a purchase made before you signed in, at the first sign-in on the device), which checks it with Google (Google Play Developer API) before opening Plus on your account, then confirms the delivery of the purchase to Google. For each purchase, the server keeps:
- your account identifier, the purchase token and the product;
- Google's order number (
GPA.…), the date of the payment and its state (pending, paid, cancelled, refunded), whether it is a test purchase, and whether it was obtained with a promo code; - whether the delivery was confirmed to Google, and the date of any refund;
- the install campaign: the name of the Noctave link the app was installed from (for example "reddit-launch"), or "other".
Install campaign: at the first launch, the app asks Google Play once which link it was installed from (the install "referrer", no permission needed). It only keeps, on your device, the source and campaign name of the link ("reddit-launch", "yt-bio"…), otherwise "other"; everything else (including any click identifier) is forgotten at once. This name designates a link Noctave published, never a person: no advertising, device or click identifier. It is sent to the server only with a purchase of Noctave Plus, and only with a Noctave account (including for a purchase made before you signed in, at the first sign-in on the device); the server keeps it only if it is one of Noctave's campaigns (otherwise "other"). It tells which channels (videos, forums, teachers, press, ads) bring purchases, to choose where to talk about Noctave. Without an account, it stays on the device and goes away with the app.
Google tells the server when a purchase is paid, cancelled or refunded (notifications delivered by Google Cloud Pub/Sub), and the server also reads the list of refunded purchases: Noctave Plus is then removed from your account, and from the device. The server keeps only the purchase token, the product, the order number, the date and state of the payment, the type of purchase (test, promo code) and the type of event: neither your name, nor your address, nor your payment details.
Earlier purchases on the website: if you bought Noctave Plus on this website before October 3, 2026, with Stripe, the server keeps the accounting record of that purchase (date, amount, status, identifiers of the payment at Stripe, acceptance of the terms of sale); Stripe keeps on its side, for its own obligations, the customer record created at payment.
7Technical logs
Like any web server, the Noctave server records each visit to the website and each call from the app: IP address, date and time, requested address, response, referring page and the browser or device it announces. The API's log also records some events (account created or deleted, purchase verified, email sent, scan) with the account's internal identifier and, for a purchase, Google's order number: never your email address or password. These logs are used for security (spotting an attack, limiting password attempts) and for fixing outages. They're never used for analytics or to track you.
To limit abuse, the server also counts, in memory only and for 15 minutes at most, requests per IP address and per account, and wrong passwords per email address.
Short links (noctavepiano.com/go/…, in our videos, posts or on a flyer): when you open one, the server adds one click to that link's counter for the day, noting only the kind of device (Android, iPhone or iPad, other) that decides where it sends you: Google Play, the iOS waitlist or this website. The counter keeps neither your IP address, nor your browser, nor any identifier: nothing that tells two clicks apart or recognizes you. It only tells which links get opened, to choose where to talk about Noctave. Like any visit, opening the link also appears, for 15 days at most, in the technical logs above.
8Purposes and legal bases
| Why | Data | Legal basis (GDPR) |
|---|---|---|
| Creating your account, signing you in, syncing your devices | Email address or Google identifier, password (hash), progress, reading statistics, settings, imports, sessions | Performance of the contract: the terms of use (Art. 6(1)(b)) |
| Reading the scores you scan (Noctave Plus) | Pages sent (photos or PDF), resulting score | Performance of the contract (Art. 6(1)(b)) |
| Opening Noctave Plus bought on Google Play, on your device and on your account: checking the purchase with Google and confirming its delivery | Account identifier, purchase token, product, order number, date and state of the payment, test purchase | Performance of the contract: the terms of sale (Art. 6(1)(b)) |
| Knowing which Noctave links bring purchases of Noctave Plus, and how often each short link is opened | Install campaign attached to the purchase; short links counter (no personal data) | Legitimate interest: choosing where to make Noctave known, without tracking anyone (Art. 6(1)(f)) |
| Removing Noctave Plus after a refund or a cancellation, and keeping a refunded purchase from being used again | Token and state of the purchase, Google's notifications | Performance of the contract (Art. 6(1)(b)); legitimate interest: preventing fraud (Art. 6(1)(f)) |
| Keeping the accounting record of earlier purchases made on the website (Stripe) | Record of each purchase | Legal obligation (Art. 6(1)(c)) |
| Telling you when Noctave comes out on the platform you chose (waitlist) | Email address, platform, language, dates of the request and of the confirmation | Consent, which you can withdraw at any time in one click (Art. 6(1)(a)) |
| Sending you the “forgot password” link | Email address, language | Performance of the contract (Art. 6(1)(b)) |
| Protecting the service and your data: logs, attempt limits, backups | IP address, logs, database copy | Legitimate interest: the security of the service (Art. 6(1)(f)) |
| Answering your messages | Your email address and what you write | Legitimate interest: replying to you (Art. 6(1)(f)) |
| Answering a request from an authority | Depending on the request | Legal obligation (Art. 6(1)(c)) |
No decision producing legal effects concerning you, or similarly significantly affecting you, is made by automated means. Your reading statistics measure your success note by note only to show you your progress in the app; they serve no other purpose.
9Who receives your data
Only the publisher has access to the server and the database. Your data is never sold, rented or shared for advertising. These providers are involved:
- OVH SAS (France) provides the dedicated server that runs the website and the API; the publisher operates it alone.
- Mailjet (Sinch Mailjet SAS, France; servers in the European Union) sends the emails of your account: new password, security notices, warning before an unused account is deleted, and those of the waitlist (section 15). It only receives your address and the message on those occasions.
- Google (Google Commerce Limited and Google Ireland Limited, Ireland) sells Noctave Plus through Google Play and collects the payment, under its own responsibility (section 6). Noctave's server exchanges with Google, through the Google Play Developer API and Google Cloud Pub/Sub, only the token and the state of the purchase, to check it, confirm its delivery and learn of a refund; to deliver these notifications, Google Cloud acts as the publisher's processor.
- Google (Google Ireland Limited) provides, through Google Play services, the document scanner used to photograph scores (see section 5): the pages are processed there on your device; only technical information about this component may be sent to Google.
- Google (Google Ireland Limited) also handles “Continue with Google”: Google verifies your identity and sends Noctave a signed proof containing your account identifier. Google then acts under its own responsibility, according to its privacy policy. On this website, Google's module is only loaded if you tap “Confirm with Google” (account deletion page).
Account data is stored in the European Union. Google (and Stripe, for earlier purchases made on the website) may process data outside the European Union (notably in the United States), with the safeguards provided by the GDPR (EU–U.S. Data Privacy Framework and standard contractual clauses).
10How long
| Data | Retention |
|---|---|
| Account, progress, reading statistics, settings, imports | As long as your account exists. When you delete a piece, its file and title are erased from the server right away; only its identifier and deletion date remain, so your other devices delete it too. |
| Unused account | An account without sign-in for 3 years is deleted with everything it keeps. An email warns you a month before: just sign in to keep it. An account created with Google, with no address on record, is deleted without an email. |
| After the account is deleted | Immediate erasure from the server, with everything linked to the account. Backups, kept to recover from an outage, are deleted within 15 days, as is the list of deleted accounts (an internal identifier and a date, to delete them again if a backup is restored). What's saved on your device stays there; if another account signs in on it, this data is never sent to it unless you choose so (section 2). To erase it, uninstall the app. |
| Sign-in sessions | A session expires after 30 days without use, or when you sign out; its traces are erased 30 days later at the latest. |
| Scanned scores: pages sent and resulting score | Erased as soon as the score is added to your library, right away if you delete the scan or your account, and automatically 30 days after the upload at the latest. Never copied into backups. |
| Pages before sending | In the app's memory, until they're sent or you leave the screen (the scanner drops them for a moment in the app's cache, which erases them at once) |
| Noctave Plus purchases on Google Play (reference of the purchase) | As long as your account exists, and erased with it: the purchase stays with your Google account. A purchase refunded before being attached to an account is kept one year, linked to nobody, so that it can no longer open Noctave Plus. |
| Earlier purchases made on the website, with Stripe (accounting record) | 10 years after the purchase (French Commercial Code, article L123-22), even after the account is deleted: the link to the account is then erased from Noctave's database (Stripe keeps its customer record, see section 6). A purchase started but never paid is erased within 7 days. |
| Waitlist | Until the email of the release you chose, then erased; at once if you unsubscribe; 7 days without confirmation; 2 years at most |
| “Forgot password” link | 1 hour, single use; its trace is erased a day later |
| Technical logs | 15 days at most |
| Short links counter (clicks per link, day and kind of device, nothing about you) | No limit: it holds no personal data |
| Messages you send us | As long as needed to handle your request, and 3 years at most |
| Sound captured by the microphone | Not kept: analysed in memory as it comes (a second and a half at most), never recorded or sent |
| Data on your device | Until you erase it or uninstall the app; its copy in the Android backup of your Google account follows Google's rules (you can delete it in your device's Google settings) |
11Security
All traffic goes over HTTPS. Passwords, session tokens and reset links are never stored in plain text. On your device, the session is kept in the system's secure storage, and is never copied into the Android backup. The server is administered by the publisher only, and the database is backed up every night.
12Your rights
You have the right to access your data, to rectify it, to erase it, to restrict its processing, to object to it and to receive it in a readable format (portability). Under French law, you can also give instructions about what happens to your data after your death.
- Delete your account: directly in the app (Settings › Account and app › Delete my account) or on noctavepiano.com/compte/suppression.
- For everything else: write to admin@418devops.fr. You'll get an answer within one month. To protect your account, you may be asked to prove it's yours (for example by writing from its address).
If you believe your rights aren't respected, you can lodge a complaint with the French data protection authority, the CNIL: cnil.fr, or 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — or with the authority of the EU country where you live.
13Minors
Noctave is meant for teenagers and adults (13 and over); it can be played without an account. To create an account under the age of 15, you need the consent of a parent or guardian, who can also exercise the rights described above; a minor only buys Noctave Plus with the consent of their parents.
15Waitlist
On the Waitlist page, you can ask to be told when Noctave comes out on Android or on iPhone and iPad. It has nothing to do with a Noctave account. The server then keeps:
- your email address, the release you chose (Android, or iPhone and iPad) and the language of the emails;
- the date of the request, of the last confirmation email, and of your confirmation.
Double opt-in: an email leaves at once, with a link to open; until you open it, you're not signed up, and the request is erased after 7 days. Once signed up, you get a single email, on the day of the release you chose, then your address is erased from the list. You can unsubscribe before, in one click, with the link of the confirmation email (or your mail app's "Unsubscribe" button): the address is erased at once. If the release doesn't happen within two years, the address is erased anyway.
The emails are sent by Mailjet (section 9), without tracking pixel or redirect link. The list serves nothing else: no newsletter, no advertising, no sharing.
16Changes
This policy will follow Noctave as it grows. Before features that process other data arrive — for instance a second service reading scanned scores —, it will be updated and say exactly what changes. The date at the top of the page shows the latest version.