Privacy Policy

Last updated: 2026-09-14

This policy explains what bandcue does with data: the Android app (name.gpm.bandcue) and the web app at https://bandcue-app.gpm.name, which opens the same cloud library in a browser.

The web app has no half of its own. It is static files: the page is served by a container that never sees a song, and every request for a sheet goes from your browser straight to the service described under “The cloud library”. What it keeps in the browser is what it needs to stay signed in — your session, the address you signed in with, the library’s secret if you asked it to be remembered, and your choice of language and theme. Signing out removes them; so does clearing the site’s data.

The short version: your songs are files on your phone, and in the folder you chose. bandcue fetches no chord sheet from anywhere, and hands none to anybody who does not already have it.

Four things can leave the device, all of them named below, and the first three only because you chose them: what you type into the report or messages screens; your library, if you turn on the optional cloud copy; your address, if you make an account so a band can invite you. The fourth is the Play build’s crash reports and usage statistics, which are on when you install it and which the app asks you about on the first launch. See Diagnostics.

Who is responsible

Gabriele Proietti Mattia is the data controller for the processing described here. Contact: apps@gpm.name.

What the app does, in data terms

bandcue keeps each song as a ChordPro text file in its own private storage, and everything on screen is drawn from those files. When you point it at a folder — with Android’s own folder picker — it can read and write the same kind of file in that folder and nowhere else: there is no storage permission, and the app never sees anything you did not point it at.

Songs go into that folder, and come out of it, when you tap. Nothing syncs on its own, and a song already on your phone is never overwritten by one from the folder.

bandcue has no catalogue and nothing is ever fetched on your behalf: every song in your library is one you put there. Since September 2026 one of the ways to put one there is a search you type, and it is worth saying exactly what that is — a chord site opened in a browser view on your own device, on your own connection, one page for the search and one for the result you choose to open. The app reads the text of that page only when you ask it to, shows it to you, and keeps nothing until you say keep. There is no crawl, no list fetched in the background and no copy of anybody’s transcription anywhere in the app.

None of your library is transmitted unless you turn on the cloud copy, which is off until you open it and is described under “The cloud library” below.

Writing in, and reading the answers

bandcue has a report screen — something is wrong, or an idea — and a messages screen where you can read what was written back. Both are in the Info tab, both are optional, and neither runs on its own: nothing is sent until you write something and press send.

This, the store’s billing in the Play build and the donation ask in the F-Droid build, are the only reasons the app asks for internet access at all.

What a report carries

It goes to bandcue-app.gpm.name, bandcue’s own service, which passes it on as it is to apps-management.gpm.name, where the reports of all of Gabriele Proietti Mattia’s apps are read. Both are run by the author, and bandcue’s service keeps nothing of a report on the way through. It is not shared with anyone, not used to build a profile and not published: reports are read, given a state and answered by hand.

No advertising id and no install id, ever. And nothing about your library is attached to a report: not a title, not an artist, not a lyric, not the name of the folder you bound — unless you type it in yourself, or it is in a screenshot you chose to attach.

Reading the answers, and the key that costs

A report is answered by email, to the address you typed into it. That is the whole of what is needed, and if you never open the messages screen nothing below applies to you.

That screen shows what you sent and everything written back, without going to find the mail. Since your reports are yours, it has to be sure it is you: it asks for the address and sends a six-digit code there. Once the code is checked the app keeps a key, and it is the one thing here that resembles a login, so it is worth being exact about it:

Sending a report needs none of this. You can report something having proved nothing, and that report carries no identifier of any kind.

Your name on the supporters list

The app can show who paid for it, and that list is public — on this site and in the app. Being on it is a separate decision from paying, taken on a screen of its own, and both defaults are no: somebody who never opens that screen is never listed.

What stays on your device

All of it is in the app’s private storage. Uninstalling removes it, as for any app, and it is included in Android’s backup so that a new phone starts where the old one left off.

The permissions, and what each is for

Keeping the screen on is a window flag rather than a permission. A sheet holds it while it is open and the tuner does the same; the On a stand switches in Settings can hold it for the whole app, and it is given back the moment the app is not in front of you.

Diagnostics

This depends on which build you have, and the two are not the same. This page said “there are none, in either build” for longer than that was true, and the correction is below rather than quietly folded into a sentence: the Play build has collected crash reports and usage statistics since version 2026.8.16.

The F-Droid build has none. No crash reporting, no analytics, no usage counters. It does not contain the libraries that would do it, which is the only claim worth making about a build you did not compile yourself.

The Play build contains Firebase Crashlytics and Firebase Analytics, and since 2026.9.5 both are behind a switch under Settings → Diagnostics. What each does, and the default it has:

Both are on, and the app asks you about them on the first launch — a sheet with the two switches on it, before the app has been used, which you can leave alone or move. That is the same in every app in this family since 4 September 2026.

Usage statistics were off by default until 2026.9.9, and the argument for that is worth keeping because it is the argument for changing back: they carry the Android Advertising ID, which is a cross-app identifier, and bandcue logs no events of its own — so what they send is Google’s automatic collection and nothing that was asked for. What decided it the other way is that two apps by the same person, answering the same question differently, is a difference nobody can explain to somebody using both; and that a switch you are shown before you have used the app is a fairer thing than a switch nobody mentions.

If that trade is not one you want, the switch is under Settings → Diagnostics and it takes effect immediately — and the F-Droid build contains neither SDK at all.

Neither switch existed before 2026.9.5, and both SDKs collected from first launch. This page said the opposite for longer than it should have; the correction and the switch shipped together. Firebase is operated by Google; see the Firebase privacy documentation and the Google Privacy Policy.

Beyond that, the Play build differs from the F-Droid build in containing Google Play Billing.

What the app never does

The account

Optional, and the app is a whole app without one. With no account bandcue keeps ten songs on this phone, and everything that makes it worth having — the sheet, the scroll, the transposition, the editor, every way of getting a song in — works with the radios off and always will.

An account exists for the two things a phone on its own cannot do: keep a copy of your library off this phone, and be invited to a band by somebody who knows your address.

It is an account for all of Gabriele Proietti Mattia’s apps, not for bandcue. One address, one record, shared across them — so a bug report you sent from another app, a donation you made, and this app’s subscription are all the same person. That is deliberate: it is what stops you having three half-accounts and a subscription attached to the wrong one.

How you prove it is yours, in either build:

What is kept, and where. The account itself — the address, an optional display name you choose, and whether a subscription is active — is kept by the service all of Gabriele Proietti Mattia’s apps share, apps-management.gpm.name. Which bands you are in is kept by bandcue’s own service, bandcue-app.gpm.name, beside the bands’ songs, together with a copy of your address and of the name you chose in the form you chose, because that is what the other members of a band see. bandcue’s service knows you by the account’s identifier and that copy, and nothing else: it asks the account service who is signed in on every request, and keeps no password, no key and no code of its own. What is kept nowhere: a password.

Leaving. Closing the account from inside the app takes you out of every band, deletes the bands left with nobody in them and the songs you kept under your own account, and then removes the account itself. An account removed any other way — by asking, or because nobody used it for six months — is removed from bandcue’s service within a day. Your songs are on your phone throughout, and export in full, always — paid, lapsed, or never signed in at all.

The cloud library

An optional cloud backup and sync of your library, opened from Settings and off until you open it. It is in this version, and the sentences above about the app talking to no service do not cover it.

What the service holds, it can read. A song is stored as the text you typed, with its title and artist, under an identifier derived from a secret your phone keeps. The secret is never stored, so a copy of the database does not tell anybody how to reach a library — but it does tell them what is in one. It travels over TLS. It is not encrypted in a way that hides it from Gabriele Proietti Mattia, and you should not use the cloud library for anything you would not want read.

This is a change of direction taken on 30 August 2026, and this page described the old one for longer than it should have. The earlier design had the phone encrypt a song before it left, with a key derived from a phrase we were never told. That is not what shipped. It may come back one day; if it does, this page will say so before it applies to anything.

What is true either way:

A library and everything in it can be deleted from the app, with the secret that opens it, and that deletion takes the sheets, the setlists and the notes with it.

For readers in the EU/EEA and the UK: what the app does on your device involves no transmission to Gabriele Proietti Mattia and so no processing on that side to which a legal basis under Article 6 would attach.

Where you write in — a report, the messages screen — the processing is based on your request (Article 6(1)(b) and 6(1)(f)): you asked for an answer, and answering you requires keeping what you sent for as long as the question is open.

Retention

A listing — your chosen name — is kept until you take it down, which is one tap on the same screen that put it up.

Reports are kept while they are useful — an open one until it is answered, a closed one as the record of a decision. A screenshot is part of the report it came with and goes when it goes. Ask and yours is deleted, including the address you sent it from.

A sign-in key stops working a year after you last use it, and is withdrawn the moment you press Sign out. Deleting the app removes the copy on your phone.

On your device, your songs and settings remain until you delete them or uninstall the app.

Your rights

Under the GDPR you may request access to, correction of, or deletion of your personal data. For anything you sent from the report or messages screen, write to apps@gpm.name and it is done by hand. For what is on your device, deleting it is a matter of clearing the app’s data or uninstalling it. You retain the right to lodge a complaint with a supervisory authority.

Children

bandcue is not directed at children under 13 and knowingly collects no data from them — or from anyone.

Changes

Material changes will be published on this page with a new date at the top, and significant ones will be noted in the app’s changelog.

Last updated: 2026-09-14