← Good Ear

Effective: September 13, 2026

Overview

Good Ear is an ear training app for iOS, iPadOS, and Android. This privacy policy explains how Good Ear handles data — both in the app and on this website.

The short version: The app has no accounts and no analytics, and sends nothing to any server of ours. What it keeps stays on your device, apart from a small set of flags your device’s own backup includes. The website processes minimal data as described below.

Data Controller

Pascal Weiß
c/o IP-Management #9711
Ludwig-Erhard-Str. 18
20459 Hamburg, Germany
Email: mail@good-ear.app

The App

Data We Collect

Good Ear does not collect any personal data. The app does not:

  • Require an account or login
  • Use analytics or tracking services
  • Send data to any server we operate (see “Data Stored on Your Device” for the secure-storage entries that your device’s own backup includes)
  • Access your contacts, location, camera, or microphone

Data Stored on Your Device

Good Ear stores the following data locally on your device:

  • Practice statistics (accuracy, scores, streaks)
  • App settings and preferences (selected scales, tempo, voicing options)
  • Purchase status

Most of your app data (practice statistics, settings, scores, purchase status) is stored on your device only, using standard iOS and Android storage mechanisms. It is not sent to any server operated by us, and we have no way of reading it.

The contents of the app’s secure storage are the exception. Today that is a flag recording whether this device has already been granted the free trial, and a flag recording that this device has permanent full access, either because you owned the original paid version of Good Ear or because you bought the Lifetime unlock, together with the date the app first recorded it.

These entries are included in your device’s system backup: the encrypted iCloud backup on iOS and iPadOS, and Android Auto Backup on Android, whenever you have that backup switched on. The backup goes to your own Apple or Google account, never to us. You can switch the backup off in your device’s system settings, and the entries then stay on the device.

On iOS and iPadOS these entries live in the system Keychain, which retains them when you uninstall the app, so that the free trial cannot be claimed a second time on the same device. Everything else listed above is deleted when you uninstall. On Android uninstalling deletes them too, but restoring the device from a backup can bring them back.

Storage on Your Device (§ 25 TDDDG)

Storing the trial flag in your device’s secure storage, and reading it back, falls under § 25(1) TDDDG, which governs storing information on and reading information from terminal equipment. That provision applies to apps and not only to browser cookies, and it applies whether or not the stored information is personal data. It is a separate question from the GDPR legal basis below, and one does not answer the other.

We rely on the exemption in § 25(2) no. 2 TDDDG: the flag is what allows the free trial to be provided on the terms it is offered, namely once per device. It is written at the moment the app first grants you the trial, and nothing is stored for this purpose before that.

In-App Purchases

In-app purchases are handled entirely by the platform store: Apple through StoreKit on iOS and iPadOS, and Google through Google Play Billing on Android. Good Ear does not receive or store any payment information, billing details, or account credentials. For information about how these providers handle your purchase data, refer to Apple’s Privacy Policy and Google’s Privacy Policy.

Device Backup and Recipients

The app sends nothing to any server of ours. The only way an entry can leave your device is your device’s own system backup, which your device performs into your own Apple or Google account when you have that backup switched on. The entries are encrypted before they leave the device. The parties involved are:

  • Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, through the encrypted iCloud backup on iOS and iPadOS. Outside the EEA the corresponding party is Apple Inc., Cupertino, California, USA.
  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, through Android Auto Backup, which stores the data in your Google Drive account. Outside the EEA the corresponding party is Google LLC, Mountain View, California, USA.

Each holds the secure-storage entries described above as part of that backup, and only when you have your device’s backup switched on. On Android 9 and above the backup is end to end encrypted with your device PIN, pattern or password, and it is stored in a private folder in your Google Drive that does not count against your Drive storage quota. On iPhone and iPad the Keychain portion of an iCloud backup is encrypted with a key derived from your device’s Secure Enclave. Neither we nor, for these entries, Apple or Google can read them.

The backup is started by your own device, into your own account, under a setting only you control. Apple and Google act as controllers in their own right for it, not as processors acting on our instructions, and their own privacy policies govern what happens to the backup: Apple and Google.

Because your device makes the backup into your own account, we are not the party that sends the data, so no international transfer by us takes place and no transfer mechanism under Art. 44 to 49 GDPR is engaged on our side. Apple’s own transfers out of the EEA are governed by Standard Contractual Clauses. Google LLC is certified under the EU-US Data Privacy Framework.

Legal basis: to the extent these entries are personal data at all, Art. 6(1)(f) GDPR (legitimate interest). The legitimate interest is keeping the free trial to one grant per device. We have weighed it against your interests: the entries carry no identifier, they never reach a server of ours, and you can prevent the transfer entirely by switching your device backup off. You can object to this processing at any time under Art. 21 GDPR by writing to us. Because we never receive these entries, we cannot delete them for you. What we can do is say what is stored and how you can remove it yourself: switching your device backup off stops the transfer to Apple or Google, and erasing the device removes the entries themselves.

On Android this is controlled by the device-level Backup setting in your system settings. That is a global switch rather than a per-app one, so switching it off applies to more than Good Ear. On iPhone and iPad you can switch iCloud Backup off for the whole device, and there is also a per-app backup list under Settings, iCloud, iCloud Backup. Apple does not document whether that per-app list covers Keychain entries, so switching iCloud Backup off for the device is the reliable way to prevent the transfer.

The entries carry no name, account identifier, device identifier or contact detail: they say only that something already happened on this device. They are kept for as long as the entry exists on the device or in a backup. On iOS and iPadOS the Keychain retains them when you uninstall the app, so uninstalling does not remove them; erasing the device does. On Android uninstalling removes them, but restoring from a backup can bring them back. We cannot delete them, because we never receive them.

Because we hold no identifier for you, we are not in a position to identify you from this data (Art. 11 GDPR), so the rights under Art. 15 to Art. 20 cannot be exercised against it. If you can give us additional information that lets us identify you in relation to these entries, we will act on such a request (Art. 11(2) GDPR), though we keep no record they could be matched against, so in practice there is nothing for that information to unlock.

The Website

Hosting

This website is hosted on Cloudflare Pages (Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA). When you visit this website, Cloudflare processes your IP address and browser metadata in server logs. This is necessary for delivering the website to you.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing the website).

For details, see Cloudflare’s Privacy Policy.

Contact Form

The contact form on the support page is processed by Web3Forms (Speed Starter LLP). When you submit the form, your name, email address, and message are transmitted to Web3Forms servers and forwarded to us via email.

Web3Forms uses CleanTalk and Akismet for spam filtering, which may process your IP address and email.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in responding to your inquiry).

Submitted data is retained by Web3Forms for 30 days and then deleted.

For details, see Web3Forms Privacy Policy.

Cookies and Tracking

This website does not use cookies, analytics, or tracking technologies of any kind.

Fonts

All fonts are self-hosted on this website. No external font services are loaded, and no data is transmitted to third parties for font rendering.

Your Rights

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access (Art. 15): You can request information about what personal data we process.
  • Right to rectification (Art. 16): You can request correction of inaccurate data.
  • Right to erasure (Art. 17): You can request deletion of your data.
  • Right to restriction (Art. 18): You can request that we restrict processing of your data.
  • Right to data portability (Art. 20): You can request your data in a machine-readable format.
  • Right to object (Art. 21): You can object at any time, on grounds relating to your particular situation, to any processing we base on legitimate interest. For the secure-storage entries, see the limits described under “Device Backup and Recipients”.

Apart from the secure-storage entries described under “Data Stored on Your Device”, which never reach a server of ours, the app collects no personal data, so these rights primarily apply to data submitted through the website contact form.

To exercise any of these rights, please use the contact form on our support page.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. The competent authority is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Heilbronner Straße 35, 70191 Stuttgart
Phone: +49 711 6155410
Website: www.baden-wuerttemberg.datenschutz.de

Children’s Privacy

Good Ear is suitable for a general audience, including music students aged 13 and up, and is listed with a mixed target audience (13-15, 16-17, 18+) on Google Play.

Children under 13 (COPPA)

Good Ear does not knowingly collect, use, or disclose personal information from children under 13. The app has no accounts, no login, no analytics, no advertising, and no location tracking, and it sends no data to any server operated by us. The only data that leaves the device is the secure-storage entries described under “Data Stored on Your Device”: device-bound flags carrying no identifier, which the operating system includes in the device backup, and that go to the user’s own Apple or Google account. Because no personal information is collected, no data about a child is retained on any server of ours. Local data on the device can be deleted at any time by uninstalling the app, except for the secure-storage entries, which iOS and iPadOS retain so that the free trial cannot be claimed twice on one device.

If you are a parent or guardian and believe your child has provided personal information to us, please contact mail@good-ear.app and we will promptly delete it. Parents may review, delete, and refuse further collection of their child’s information using the same contact channel.

Children under 16 (GDPR)

The age at which children can consent to their own data processing under the GDPR varies by EU/EEA member state (between 13 and 16). Good Ear does not rely on consent (Art. 6(1)(a) GDPR) for any data processing. Apart from the secure-storage entries described under “Data Stored on Your Device”, which are processed under Art. 6(1)(f) GDPR and go to the user’s own Apple or Google account, no personal data is collected or processed in the app, so parental consent under Art. 8 GDPR is not required.

In line with Recital 38 GDPR, Good Ear does not engage in profiling, behavioural advertising, or marketing of any kind.

Google Play Families Policy

On Android, Good Ear complies with the Google Play Families Policy: no advertising, no third-party analytics, in-app purchases handled exclusively by Google Play Billing, no user-generated content, and no location access. The app does not request the advertising identifier (com.google.android.gms.permission.AD_ID).

Changes to This Policy

If this privacy policy changes, the updated version will be posted at this URL with a new effective date.

Download on the App Store
Privacy Policy · Support · Legal Notice · Acknowledgements

© 2026 Good Ear