Privacy Policy

Last updated : 18/08/2026

This policy explains what personal data the Cymbra services (published by NEETROF) process, why, on what legal basis, who it is shared with, how long it is kept, and what your rights are. It covers the Cymbra account, shared across the Cymbra services; processing specific to a product is set out in an annex (see Annex A — Cymbra Music).

1. Data controller

NEETROF — SASU, SIREN 948723887, 42 IMPASSE DUFERMONT, 59510 HEM, FRANCE. Contact: gfortin@neetrof.fr.

2. Data we process

We apply data minimisation: we only collect what is necessary to operate your account and the application.

Data Source Purpose
Email address you (email sign-up) or your provider (Google/Apple) account identifier, verification, password reset
Password (argon2 hash, never in clear text) you (email sign-up) authentication
External sign-in identifier (Google/Apple “sub”) Google / Apple “Sign in with Google/Apple”
Handle and display name you identification within the app
App preferences you remember your settings
Session tokens (refresh tokens) generated at login keep you signed in
Technical logs (IP address, timestamps, errors) server security, abuse prevention, correct operation
Subscription status (plan, source, start/end dates), opaque identifiers of the subscription at the purchase channel (Apple, Google, Paddle — via RevenueCat for the App Store and Google Play), beta campaigns joined, access codes used purchase channel / you activate the Premium plan on your devices, manage trials and betas

We do not collect precise location data, do not sell any data, and do not use third-party advertising or advertising trackers. We never receive or store your card numbers, billing addresses or invoices: they are processed exclusively by the purchase channel (Apple, Google, Paddle).

4. Processors and third parties

We share only what is necessary with providers acting on our behalf:

Your data is hosted in the European Union (France). Apart from the subscription verification described above (RevenueCat, United States, under Standard Contractual Clauses), we do not transfer data outside the EU.

5. Retention

6. Security

Encryption in transit (TLS), passwords stored as an argon2 hash (never in clear text), encrypted backups stored off the server, restricted server access. As no measure is infallible, we cannot guarantee absolute security.

7. Your rights (GDPR)

You have the rights of access, rectification, erasure, restriction, objection and portability.

8. Minors

Cymbra is not intended for children under 12; we do not knowingly collect their data.

9. Changes

We may update this policy; the “Last updated” date above will change accordingly. We will inform you of any material change.

10. Contact

gfortin@neetrof.fr — NEETROF, 42 IMPASSE DUFERMONT, 59510 HEM, FRANCE.


Annex A — Cymbra Music

The Cymbra Music service lets you upload your own content. For that purpose, in addition to §2, we process:

Data Source Purpose
Uploaded files (scores, piano sounds / soundfonts) you provide playback and practice features
Associated metadata (file name, origin attestation, timestamp) you management and traceability of your content