Privacy Policy
Last updated: 2026-09-14
This policy explains what bandcue does with data: the Android app
(name.gpm.bandcue) and the web app at
https://bandcue-app.gpm.name, which opens the same cloud library in a browser.
The web app has no half of its own. It is static files: the page is served by a container that never sees a song, and every request for a sheet goes from your browser straight to the service described under “The cloud library”. What it keeps in the browser is what it needs to stay signed in — your session, the address you signed in with, the library’s secret if you asked it to be remembered, and your choice of language and theme. Signing out removes them; so does clearing the site’s data.
The short version: your songs are files on your phone, and in the folder you chose. bandcue fetches no chord sheet from anywhere, and hands none to anybody who does not already have it.
Four things can leave the device, all of them named below, and the first three only because you chose them: what you type into the report or messages screens; your library, if you turn on the optional cloud copy; your address, if you make an account so a band can invite you. The fourth is the Play build’s crash reports and usage statistics, which are on when you install it and which the app asks you about on the first launch. See Diagnostics.
Who is responsible
Gabriele Proietti Mattia is the data controller for the processing described here. Contact: apps@gpm.name.
What the app does, in data terms
bandcue keeps each song as a ChordPro text file in its own private storage, and everything on screen is drawn from those files. When you point it at a folder — with Android’s own folder picker — it can read and write the same kind of file in that folder and nowhere else: there is no storage permission, and the app never sees anything you did not point it at.
Songs go into that folder, and come out of it, when you tap. Nothing syncs on its own, and a song already on your phone is never overwritten by one from the folder.
bandcue has no catalogue and nothing is ever fetched on your behalf: every song in your library is one you put there. Since September 2026 one of the ways to put one there is a search you type, and it is worth saying exactly what that is — a chord site opened in a browser view on your own device, on your own connection, one page for the search and one for the result you choose to open. The app reads the text of that page only when you ask it to, shows it to you, and keeps nothing until you say keep. There is no crawl, no list fetched in the background and no copy of anybody’s transcription anywhere in the app.
None of your library is transmitted unless you turn on the cloud copy, which is off until you open it and is described under “The cloud library” below.
Writing in, and reading the answers
bandcue has a report screen — something is wrong, or an idea — and a messages screen where you can read what was written back. Both are in the Info tab, both are optional, and neither runs on its own: nothing is sent until you write something and press send.
This, the store’s billing in the Play build and the donation ask in the F-Droid build, are the only reasons the app asks for internet access at all.
What a report carries
- What you wrote: whether it is a bug or an idea, the title and the description.
- What makes it fixable: the app’s version, your Android version, the phone’s manufacturer and model, and your language tag. Typed into the message by the app — none of it is read from an identifier.
- A screenshot, only if you pick one. Nothing is captured for you. The picture is shrunk and re-encoded on your phone, and what you see before sending is exactly what leaves it — so if part of the screen has nothing to do with the problem, remove it first.
- Your email address, only if you type one. Without it a report is anonymous and cannot be answered; with it, it is how you get a reply.
- A random identifier for that single report, so that sending twice on a bad connection is not counted as two. It is not a device id, it is not stored on your phone, and a second report gets a different one.
It goes to bandcue-app.gpm.name, bandcue’s own service, which passes it on as it is to
apps-management.gpm.name, where the reports of all of Gabriele Proietti Mattia’s apps are read. Both are
run by the author, and bandcue’s service keeps nothing of a report on the way through. It is not
shared with anyone, not used to build a profile and not published: reports are read, given a
state and answered by hand.
No advertising id and no install id, ever. And nothing about your library is attached to a report: not a title, not an artist, not a lyric, not the name of the folder you bound — unless you type it in yourself, or it is in a screenshot you chose to attach.
Reading the answers, and the key that costs
A report is answered by email, to the address you typed into it. That is the whole of what is needed, and if you never open the messages screen nothing below applies to you.
That screen shows what you sent and everything written back, without going to find the mail. Since your reports are yours, it has to be sure it is you: it asks for the address and sends a six-digit code there. Once the code is checked the app keeps a key, and it is the one thing here that resembles a login, so it is worth being exact about it:
- it hangs from the address you proved, never from your phone — nothing about the device goes into it, two phones that prove the same address get two separate keys, and removing the app throws the key away rather than recovering it;
- it works for bandcue only, and opens nothing in any other app;
- the service stores a one-way hash of it, not the key itself;
- it stops working after a year without use, and Sign out withdraws it at the service and not only on your phone.
Sending a report needs none of this. You can report something having proved nothing, and that report carries no identifier of any kind.
Your name on the supporters list
The app can show who paid for it, and that list is public — on this site and in the app. Being on it is a separate decision from paying, taken on a screen of its own, and both defaults are no: somebody who never opens that screen is never listed.
- What is published is the name you typed, and nothing else. Never your address, never an amount, never a date, and never a position — the list is shuffled every time it is drawn.
- How you prove it is yours depends on how you paid. If you bought on Google Play, the app presents the purchase token it is holding — Play never tells an app who bought, so there is nothing to type and no address involved. If you donated, you prove the address you donated from, and the service checks whether a donation is recorded against it.
- The choice belongs to this app. Supporting bandcue is not asking to be named anywhere else.
- It is reversible in one tap, from the same screen.
What stays on your device
- Your songs, one ChordPro file each, exactly as they arrived — the text you pasted or opened is kept whole, so a sheet that displays wrong is never a song that is lost.
- How you play each one: the transposition, the capo and the length you set for the scroll. These stay here on purpose. A transposition is a property of your phone and not of the song, because the file in the folder is the whole band’s.
- Your setlists, their order and your notes on them. Notes never reach the folder.
- The settings: the theme, the stage theme, the font size, the count-in, auto-advance.
- Which folder you bound, as the permission Android gave you for it — not a copy of its contents.
All of it is in the app’s private storage. Uninstalling removes it, as for any app, and it is included in Android’s backup so that a new phone starts where the old one left off.
The permissions, and what each is for
- No storage permission at all. The band’s folder is reached through Android’s Storage Access Framework, which grants access to the one directory you picked. This is checkable on the released APK, and it is meant to be.
- Internet — the report and messages screens, billing in the Play build, and the donation ask in the F-Droid build. No request in the app reaches a chord site, and that is also checkable.
- Notifications — the weekly donation ask in the F-Droid build, and nothing else.
- Microphone — the tuner, and the tempo listener on the tempo pad. Both are off until you open them: nothing listens in the background, ever. What the microphone hears is measured as it arrives and thrown away — how high a note is, and how far apart the beats are. No audio is recorded to a file, and none of it leaves the phone, in either build.
Keeping the screen on is a window flag rather than a permission. A sheet holds it while it is open and the tuner does the same; the On a stand switches in Settings can hold it for the whole app, and it is given back the moment the app is not in front of you.
Diagnostics
This depends on which build you have, and the two are not the same. This page said “there are none, in either build” for longer than that was true, and the correction is below rather than quietly folded into a sentence: the Play build has collected crash reports and usage statistics since version 2026.8.16.
The F-Droid build has none. No crash reporting, no analytics, no usage counters. It does not contain the libraries that would do it, which is the only claim worth making about a build you did not compile yourself.
The Play build contains Firebase Crashlytics and Firebase Analytics, and since 2026.9.5 both are behind a switch under Settings → Diagnostics. What each does, and the default it has:
- Crashlytics — on by default — sends, when the app crashes, the stack trace, the device model, the Android version, the app version and a Crashlytics-generated installation identifier. It does not include your songs, your library secret or the folder you bound.
- Analytics — on by default since 2026.9.9 — records the automatic events the SDK collects, together with the identifiers it collects by default, which include the Android Advertising ID, an app instance identifier, the device model, the OS version and a coarse region. bandcue itself logs no events of its own: nothing about which songs you have, what you typed, or what you played.
Both are on, and the app asks you about them on the first launch — a sheet with the two switches on it, before the app has been used, which you can leave alone or move. That is the same in every app in this family since 4 September 2026.
Usage statistics were off by default until 2026.9.9, and the argument for that is worth keeping because it is the argument for changing back: they carry the Android Advertising ID, which is a cross-app identifier, and bandcue logs no events of its own — so what they send is Google’s automatic collection and nothing that was asked for. What decided it the other way is that two apps by the same person, answering the same question differently, is a difference nobody can explain to somebody using both; and that a switch you are shown before you have used the app is a fairer thing than a switch nobody mentions.
If that trade is not one you want, the switch is under Settings → Diagnostics and it takes effect immediately — and the F-Droid build contains neither SDK at all.
Neither switch existed before 2026.9.5, and both SDKs collected from first launch. This page said the opposite for longer than it should have; the correction and the switch shipped together. Firebase is operated by Google; see the Firebase privacy documentation and the Google Privacy Policy.
Beyond that, the Play build differs from the F-Droid build in containing Google Play Billing.
What the app never does
- No password, anywhere. There is an optional account — see “The account” below — and it is proved by a code sent to an address, or by signing in with Google. Nothing here stores a password, and the app works fully without an account at all.
- No fetching of anybody’s chord sheet on your behalf. There is no scraper, no proxy and no “convenience” endpoint, in either build, behind any flag. Songs get in because you put them in — including through the in-app search, which is your own browser opening the page you asked for and keeping nothing until you keep it.
- No advertising, and no sale or sharing of data with anyone.
- No advertising in the app, and nothing about you sold or shared with anybody for their own purposes. The Play build’s Analytics does collect the Android Advertising ID — that is named under Diagnostics above rather than denied here.
- No location, no contacts, no messages, no photos or files beyond the folder you bound and the single screenshot you may attach to a report.
The account
Optional, and the app is a whole app without one. With no account bandcue keeps ten songs on this phone, and everything that makes it worth having — the sheet, the scroll, the transposition, the editor, every way of getting a song in — works with the radios off and always will.
An account exists for the two things a phone on its own cannot do: keep a copy of your library off this phone, and be invited to a band by somebody who knows your address.
It is an account for all of Gabriele Proietti Mattia’s apps, not for bandcue. One address, one record, shared across them — so a bug report you sent from another app, a donation you made, and this app’s subscription are all the same person. That is deliberate: it is what stops you having three half-accounts and a subscription attached to the wrong one.
How you prove it is yours, in either build:
- A code sent to your address. Six digits, typed into the app. Nothing else is stored about the address, and no password is created.
- Signing in with Google, in the Play build only. Google tells the service your address, your
Google account identifier and the name on the account — and nothing else: no contacts, no
Drive, no calendar, and no permission to act as you anywhere. The consent screen names
gpm-apps, which is that shared account rather than this app alone. - A second address may be attached once a code has proved you can read it, so a work address and a personal one are one account rather than two.
What is kept, and where. The account itself — the address, an optional display name you
choose, and whether a subscription is active — is kept by the service all of Gabriele Proietti Mattia’s apps
share, apps-management.gpm.name. Which bands you are in is kept by bandcue’s own service,
bandcue-app.gpm.name, beside the bands’ songs, together with a copy of your address and of the
name you chose in the form you chose, because that is what the other members of a band see.
bandcue’s service knows you by the account’s identifier and that copy, and nothing else: it asks
the account service who is signed in on every request, and keeps no password, no key and no code
of its own. What is kept nowhere: a password.
Leaving. Closing the account from inside the app takes you out of every band, deletes the bands left with nobody in them and the songs you kept under your own account, and then removes the account itself. An account removed any other way — by asking, or because nobody used it for six months — is removed from bandcue’s service within a day. Your songs are on your phone throughout, and export in full, always — paid, lapsed, or never signed in at all.
The cloud library
An optional cloud backup and sync of your library, opened from Settings and off until you open it. It is in this version, and the sentences above about the app talking to no service do not cover it.
What the service holds, it can read. A song is stored as the text you typed, with its title and artist, under an identifier derived from a secret your phone keeps. The secret is never stored, so a copy of the database does not tell anybody how to reach a library — but it does tell them what is in one. It travels over TLS. It is not encrypted in a way that hides it from Gabriele Proietti Mattia, and you should not use the cloud library for anything you would not want read.
This is a change of direction taken on 30 August 2026, and this page described the old one for longer than it should have. The earlier design had the phone encrypt a song before it left, with a key derived from a phrase we were never told. That is not what shipped. It may come back one day; if it does, this page will say so before it applies to anything.
What is true either way:
- Nothing is public. No catalogue, no search across libraries, no browsing, and no way to reach a library without its secret or an invitation to the band that holds it. One library cannot read another.
- Nothing is fetched. There is no scraper and no proxy. Every sheet is there because somebody typed, pasted or imported it.
- What is sold is storage and sync, never content.
- The shared folder needs none of this — no account, no service — and it is still what most bands should use.
A library and everything in it can be deleted from the app, with the secret that opens it, and that deletion takes the sheets, the setlists and the notes with it.
Legal basis (GDPR)
For readers in the EU/EEA and the UK: what the app does on your device involves no transmission to Gabriele Proietti Mattia and so no processing on that side to which a legal basis under Article 6 would attach.
Where you write in — a report, the messages screen — the processing is based on your request (Article 6(1)(b) and 6(1)(f)): you asked for an answer, and answering you requires keeping what you sent for as long as the question is open.
Retention
A listing — your chosen name — is kept until you take it down, which is one tap on the same screen that put it up.
Reports are kept while they are useful — an open one until it is answered, a closed one as the record of a decision. A screenshot is part of the report it came with and goes when it goes. Ask and yours is deleted, including the address you sent it from.
A sign-in key stops working a year after you last use it, and is withdrawn the moment you press Sign out. Deleting the app removes the copy on your phone.
On your device, your songs and settings remain until you delete them or uninstall the app.
Your rights
Under the GDPR you may request access to, correction of, or deletion of your personal data. For anything you sent from the report or messages screen, write to apps@gpm.name and it is done by hand. For what is on your device, deleting it is a matter of clearing the app’s data or uninstalling it. You retain the right to lodge a complaint with a supervisory authority.
Children
bandcue is not directed at children under 13 and knowingly collects no data from them — or from anyone.
Changes
Material changes will be published on this page with a new date at the top, and significant ones will be noted in the app’s changelog.
Last updated: 2026-09-14