Noctave

Privacy policy

Last updated: October 9, 2026.

Noctave is built to work without an account and without a network. This page explains what data is processed, why, for how long, by whom, and how to exercise your rights.

This English version is a translation provided for convenience. In case of any difference, the French version prevails.

In short

1Data controller

Matthias Vogel EI, trading as 418 DevOps, 2 Chemin des Rochers, 67120 Molsheim, France — admin@418devops.fr. More details in the legal notice.

2Without an account: everything stays on your device

Playing, learning, importing a piece and making progress work without an account or a network. Your progress, your reading statistics, your settings (including calibrated latency and your keyboards) and your library are stored on your device and, if you turned it on, in the Android backup of your own Google account, which can also transfer them to a new device. That backup is made by Android, under your Google account: Noctave can't read it and receives nothing from it. Your sign-in session is never copied into it: after a restore, just sign in again. To erase everything, uninstall the app and delete its backup in your device's Google settings.

Bluetooth and USB permissions are only used to talk to your MIDI keyboard: the notes you play are evaluated on the device and sent nowhere. On Android 11 and older, Android files the search for Bluetooth devices under the “Location” permission: Noctave only asks for it to find your keyboard, and never reads your location.

The app only contacts the Noctave server if you're signed in, or if you open the account screens or scanning. Without an account, it only reads the service's configuration there (is scanning open? is the app up to date?), without sending anything about you; as with any visit, your IP address then appears in the technical logs (section 7). Without an account, a purchase of Noctave Plus stays between your device and Google Play: nothing about it is sent to the Noctave server, not even the install campaign the app keeps on the device (section 6), as long as you don't sign in to a Noctave account on this device: when you sign in, the purchase (and its campaign) is attached to that account, like a purchase made while signed in. If Google refunds a purchase that was never attached to an account, it tells the server (token and order number, linked to nobody), which keeps it one year so that it can no longer open Noctave Plus (section 10).

Switching accounts on a device: when you sign out or delete your account, your progress, imported pieces and reading series stay on the device. If another Noctave account then signs in on it, this data is never sent to it automatically: the app first asks whether to add it to that account, or to erase it from the device and start from the account's data. Until someone chooses, nothing is sent. Erasing it from the device doesn't affect the previous account: if it still exists, it keeps its data on the server; if it was deleted, the device's copy was the last one.

3The microphone: listening stays on your device

To play a piano without a MIDI cable, you can choose your tablet's microphone as a source (Devices › Microphone). Noctave first explains what it's for, then Android asks for your permission: never before you choose it. You can refuse; everything else in the app works without it.

The sound is analysed in real time, on your device, to recognise the notes you play. It is never recorded, kept or sent: the app only holds the last second and a half at most in memory, long enough to analyse it, and erases it as it goes. Nothing is written to a file, nothing goes to the Noctave server or to anyone else. Only the result (the note recognised and when, the sound level, the measured latency) is used for the display and the game, and it stays on the device too.

Noctave only listens while a screen that needs it is open (today the microphone diagnostics, soon playing and learning with the microphone), and never in the background: listening stops as soon as you leave that screen or the app. While it listens, Android shows its microphone indicator.

You can withdraw the permission at any time in Android's settings (Apps › Noctave › Permissions), or choose “Stop using it” in Devices › Microphone.

4With an account: what the server keeps

The account is optional. It lets you find your progress on several devices. The server then keeps:

For an account created with an email address

For an account created with “Continue with Google”

In every case

5Score scanning (Noctave Plus)

With Noctave Plus, you can take pictures of a printed score, or send a PDF, to turn it into a playable piece. The pages then go to Noctave's server, which keeps:

Taking the pictures (Android) goes through Google's document scanner (ML Kit, provided by Google Play services): it finds the page, straightens it and cleans it on your device, and only hands Noctave the pages you keep. Noctave doesn't ask for permission to use the camera: Google's scanner does. Google Play services may send Google technical information about how this component works (usage metrics, diagnostics), under Google's own responsibility and according to its privacy policy; the pictures themselves are not sent to Google. You can also import a PDF or images without this scanner. The scanner drops the pages for a moment in the app's cache, which erases them at once and keeps them in memory until they're sent. Before sending, the app removes the hidden details of images on your device (EXIF including the GPS position, the camera, the date and the software; XMP, IPTC, comments, thumbnails): only what is needed to display them stays (color profile, resolution) and, for a photo taken sideways, its orientation. An image it can't read to the end isn't sent. For a PDF, it erases the document properties written in plain text (title, author, software, dates) and uncompressed metadata; those compressed or encrypted inside the file may remain: export your pages as images instead if you want to be sure.

The pages are read on Noctave's server, by the free software Audiveris. They are sent to no other service and only serve to produce your score: no sharing, no model training. Only photograph the score: avoid leaving a face, a name or a personal document in the picture.

The scan is erased from the server as soon as you add its score to your library, right away if you delete it or your account, and automatically 30 days after the upload at the latest. These files are not copied into the server's backups. The score you add to your library stays on your device (and with your account if you're signed in, like your other imports).

Notification: if you accept it, Noctave shows you a notification when a score is ready while the app is in the background. It's made on your device: no push notification service is used and no identifier is sent. You can turn it off in Android's settings (Apps › Noctave › Notifications).

6Buying Noctave Plus

Noctave Plus is bought in the app, through Google Play. The payment happens at Google, with the payment methods of your Google account: Noctave never sees or keeps your payment details, your name or the address of your Google account. For a purchase made in the European Economic Area or the United Kingdom, Google Commerce Limited (Ireland) sells Noctave Plus as the merchant of record: Google then processes your Google account, your payment and your receipt under its own responsibility, according to its privacy policy.

Google Play hands the app a proof of purchase (a purchase token, with the product and the state of the payment), which opens Noctave Plus on the device; the app only remembers, on the device, that Plus is open there. Noctave sends Google no identifier of your Noctave account.

With a Noctave account, the app hands this token to Noctave's server (including for a purchase made before you signed in, at the first sign-in on the device), which checks it with Google (Google Play Developer API) before opening Plus on your account, then confirms the delivery of the purchase to Google. For each purchase, the server keeps:

Install campaign: at the first launch, the app asks Google Play once which link it was installed from (the install "referrer", no permission needed). It only keeps, on your device, the source and campaign name of the link ("reddit-launch", "yt-bio"…), otherwise "other"; everything else (including any click identifier) is forgotten at once. This name designates a link Noctave published, never a person: no advertising, device or click identifier. It is sent to the server only with a purchase of Noctave Plus, and only with a Noctave account (including for a purchase made before you signed in, at the first sign-in on the device); the server keeps it only if it is one of Noctave's campaigns (otherwise "other"). It tells which channels (videos, forums, teachers, press, ads) bring purchases, to choose where to talk about Noctave. Without an account, it stays on the device and goes away with the app.

Google tells the server when a purchase is paid, cancelled or refunded (notifications delivered by Google Cloud Pub/Sub), and the server also reads the list of refunded purchases: Noctave Plus is then removed from your account, and from the device. The server keeps only the purchase token, the product, the order number, the date and state of the payment, the type of purchase (test, promo code) and the type of event: neither your name, nor your address, nor your payment details.

Earlier purchases on the website: if you bought Noctave Plus on this website before October 3, 2026, with Stripe, the server keeps the accounting record of that purchase (date, amount, status, identifiers of the payment at Stripe, acceptance of the terms of sale); Stripe keeps on its side, for its own obligations, the customer record created at payment.

7Technical logs

Like any web server, the Noctave server records each visit to the website and each call from the app: IP address, date and time, requested address, response, referring page and the browser or device it announces. The API's log also records some events (account created or deleted, purchase verified, email sent, scan) with the account's internal identifier and, for a purchase, Google's order number: never your email address or password. These logs are used for security (spotting an attack, limiting password attempts) and for fixing outages. They're never used for analytics or to track you.

To limit abuse, the server also counts, in memory only and for 15 minutes at most, requests per IP address and per account, and wrong passwords per email address.

8Purposes and legal bases

WhyDataLegal basis (GDPR)
Creating your account, signing you in, syncing your devicesEmail address or Google identifier, password (hash), progress, reading statistics, settings, imports, sessionsPerformance of the contract: the terms of use (Art. 6(1)(b))
Reading the scores you scan (Noctave Plus)Pages sent (photos or PDF), resulting scorePerformance of the contract (Art. 6(1)(b))
Opening Noctave Plus bought on Google Play, on your device and on your account: checking the purchase with Google and confirming its deliveryAccount identifier, purchase token, product, order number, date and state of the payment, test purchasePerformance of the contract: the terms of sale (Art. 6(1)(b))
Knowing which Noctave links bring purchases of Noctave Plus, and how often each short link is openedInstall campaign attached to the purchase; short links counter (no personal data)Legitimate interest: choosing where to make Noctave known, without tracking anyone (Art. 6(1)(f))
Removing Noctave Plus after a refund or a cancellation, and keeping a refunded purchase from being used againToken and state of the purchase, Google's notificationsPerformance of the contract (Art. 6(1)(b)); legitimate interest: preventing fraud (Art. 6(1)(f))
Keeping the accounting record of earlier purchases made on the website (Stripe)Record of each purchaseLegal obligation (Art. 6(1)(c))
Telling you when Noctave comes out on the platform you chose (waitlist)Email address, platform, language, dates of the request and of the confirmationConsent, which you can withdraw at any time in one click (Art. 6(1)(a))
Sending you the “forgot password” linkEmail address, languagePerformance of the contract (Art. 6(1)(b))
Protecting the service and your data: logs, attempt limits, backupsIP address, logs, database copyLegitimate interest: the security of the service (Art. 6(1)(f))
Answering your messagesYour email address and what you writeLegitimate interest: replying to you (Art. 6(1)(f))
Answering a request from an authorityDepending on the requestLegal obligation (Art. 6(1)(c))

No decision producing legal effects concerning you, or similarly significantly affecting you, is made by automated means. Your reading statistics measure your success note by note only to show you your progress in the app; they serve no other purpose.

9Who receives your data

Only the publisher has access to the server and the database. Your data is never sold, rented or shared for advertising. These providers are involved:

Account data is stored in the European Union. Google (and Stripe, for earlier purchases made on the website) may process data outside the European Union (notably in the United States), with the safeguards provided by the GDPR (EU–U.S. Data Privacy Framework and standard contractual clauses).

10How long

DataRetention
Account, progress, reading statistics, settings, importsAs long as your account exists. When you delete a piece, its file and title are erased from the server right away; only its identifier and deletion date remain, so your other devices delete it too.
Unused accountAn account without sign-in for 3 years is deleted with everything it keeps. An email warns you a month before: just sign in to keep it. An account created with Google, with no address on record, is deleted without an email.
After the account is deletedImmediate erasure from the server, with everything linked to the account. Backups, kept to recover from an outage, are deleted within 15 days, as is the list of deleted accounts (an internal identifier and a date, to delete them again if a backup is restored). What's saved on your device stays there; if another account signs in on it, this data is never sent to it unless you choose so (section 2). To erase it, uninstall the app.
Sign-in sessionsA session expires after 30 days without use, or when you sign out; its traces are erased 30 days later at the latest.
Scanned scores: pages sent and resulting scoreErased as soon as the score is added to your library, right away if you delete the scan or your account, and automatically 30 days after the upload at the latest. Never copied into backups.
Pages before sendingIn the app's memory, until they're sent or you leave the screen (the scanner drops them for a moment in the app's cache, which erases them at once)
Noctave Plus purchases on Google Play (reference of the purchase)As long as your account exists, and erased with it: the purchase stays with your Google account. A purchase refunded before being attached to an account is kept one year, linked to nobody, so that it can no longer open Noctave Plus.
Earlier purchases made on the website, with Stripe (accounting record)10 years after the purchase (French Commercial Code, article L123-22), even after the account is deleted: the link to the account is then erased from Noctave's database (Stripe keeps its customer record, see section 6). A purchase started but never paid is erased within 7 days.
WaitlistUntil the email of the release you chose, then erased; at once if you unsubscribe; 7 days without confirmation; 2 years at most
“Forgot password” link1 hour, single use; its trace is erased a day later
Technical logs15 days at most
Short links counter (clicks per link, day and kind of device, nothing about you)No limit: it holds no personal data
Messages you send usAs long as needed to handle your request, and 3 years at most
Sound captured by the microphoneNot kept: analysed in memory as it comes (a second and a half at most), never recorded or sent
Data on your deviceUntil you erase it or uninstall the app; its copy in the Android backup of your Google account follows Google's rules (you can delete it in your device's Google settings)

11Security

All traffic goes over HTTPS. Passwords, session tokens and reset links are never stored in plain text. On your device, the session is kept in the system's secure storage, and is never copied into the Android backup. The server is administered by the publisher only, and the database is backed up every night.

12Your rights

You have the right to access your data, to rectify it, to erase it, to restrict its processing, to object to it and to receive it in a readable format (portability). Under French law, you can also give instructions about what happens to your data after your death.

If you believe your rights aren't respected, you can lodge a complaint with the French data protection authority, the CNIL: cnil.fr, or 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — or with the authority of the EU country where you live.

13Minors

Noctave is meant for teenagers and adults (13 and over); it can be played without an account. To create an account under the age of 15, you need the consent of a parent or guardian, who can also exercise the rights described above; a minor only buys Noctave Plus with the consent of their parents.

14Cookies and local storage

This website sets no cookies and uses no analytics tools. It only remembers, in your browser (local storage), the language you chose. The account pages keep nothing between visits.

Exception, on your request: the “Confirm with Google” button (account deletion page) loads Google's module, which may set its own cookies.

15Waitlist

On the Waitlist page, you can ask to be told when Noctave comes out on Android or on iPhone and iPad. It has nothing to do with a Noctave account. The server then keeps:

Double opt-in: an email leaves at once, with a link to open; until you open it, you're not signed up, and the request is erased after 7 days. Once signed up, you get a single email, on the day of the release you chose, then your address is erased from the list. You can unsubscribe before, in one click, with the link of the confirmation email (or your mail app's "Unsubscribe" button): the address is erased at once. If the release doesn't happen within two years, the address is erased anyway.

The emails are sent by Mailjet (section 9), without tracking pixel or redirect link. The list serves nothing else: no newsletter, no advertising, no sharing.

16Changes

This policy will follow Noctave as it grows. Before features that process other data arrive — for instance a second service reading scanned scores —, it will be updated and say exactly what changes. The date at the top of the page shows the latest version.