Privacy Statement

KEDISE — PRIVACY POLICY

Last updated: 2 September 2026

Kedise shows the lyrics of whatever music is already playing on your device. To do that it needs to know what is playing, and it needs to fetch the words from somewhere. This page says exactly what leaves your device, when, and to whom.

It has two parts, and the difference matters:

- What Kedise does today — this is the version you have installed. Everything here is checked against the code.

- What is planned — features that are not in this version. They are listed because we would rather say them in advance than spring them on you later. None of them is switched on today.

——————————————————

WHAT KEDISE DOES TODAY

The short version

- Kedise has no account, no sign-up and no user identifier. That is worth stating plainly and worth not overstating: not assigning you an identifier is not the same as the information being anonymous. Where several details travel together — a country, a clock, what was playing — they can point at a person even with no name attached, and this policy treats them as capable of that rather than claiming otherwise.

- In this version there is no analytics SDK, no crash-reporting SDK and no advertising framework of any kind.

- Kedise never uses GPS, and never looks up where you are from your IP address. It does read the country or region set on your device — see below, because it is not nothing and we would rather say it than bury it.

- Kedise operates no server of its own, and sends nothing to any server operated by Kedise. That is a statement about us, not about the network: fetching lyrics and translating do reach other people's services, and exactly which ones is listed further down.

- One feature turns this device into a server on your own network, and it is off until you switch it on — on iPhone and Android only; the desktop app has no such switch and opens no port. Everything else on this page is about what leaves your device. Show the lyrics on another screen is the one thing that works the other way round: it opens a listening port so that a television or a laptop on the same network can fetch the lyrics page from you. What it serves is the song playing and its words, and nothing else — see below.

What Kedise reads from your device

The title, artist, album and track length of whatever is playing. How it reads them depends on the platform and on the player, and two of those ways need a permission you are asked for — so this is written out in full rather than tidily.

- macOS — Player: Apple Music, Spotify, VLC, QuickTime, Doppler, Vox · How it is read: Kedise asks the application itself, through macOS's own scripting between apps

- macOS — Player: anything playing in a browser tab · How it is read: Safari, Chrome, Brave, Edge, Vivaldi, Opera. Consulted last, because a media player reports what it is playing while a browser tab can only be interpreted

- iOS — Player: Apple Music · How it is read: the system music player, which needs access to your media library

- iOS — Player: Amazon Music, Tidal, SoundCloud and the rest · How it is read: they publish nothing to any app, so the words are read off the screen by the extension you start yourself

- iOS, Android — Player: Spotify · How it is read: Spotify's own SDK, talking to the Spotify app on the same device — and only after you press Connect

- Android — Player: any player · How it is read: NotificationListenerService, after you grant notification access

Windows support is coming soon — see "What is planned" below. Today there is no Windows build to install.

The permissions this needs, and what each one is for

On macOS, permission to control other applications — what macOS calls Apple Events, and what it asks you about the first time. It is how Kedise asks your music app what is playing. The list of applications it may ask is fixed inside the app and cannot grow while it is running: the six players and six browsers above, and nothing else. What it asks them for is the title, the artist, the album and how far into the track you are. It uses the same channel to pause, resume and skip — but only when you press those buttons in Kedise.

Inside a browser tab, Kedise reads the tab's title. If you have switched on your browser's Allow JavaScript from Apple Events setting, it also asks the page for what that page already publishes about its own media: the title, artist and album the site declares, and the position and length of the audio or video playing. It does not read the page's address, its text, its cookies, or anything you type into it.

On macOS you may also grant a music folder, read-only, from Kedise's settings. It is there so that a track played from a file is identified by the song's own tags rather than by its filename. Only folders you pick yourself, never written to, and you can withdraw them in the same place.

On iOS, access to your media library. It is the only way iOS will tell any app what Apple Music is playing. Kedise reads what is playing now; it does not read your library, your playlists or your purchases.

On iOS, the screen-reading extension is one you start yourself, from the system's own screen-recording control. It exists because Amazon Music, Tidal and SoundCloud tell no app anything at all. It looks at the player's screen for the title, the artist and the clock.

No screenshot and no recording is ever saved, what it recognises is never transmitted off your device, and nothing it reads is written down. The title and artist it recognises are handed to the app and held in memory while the song is playing, and that is all.

(A development build does keep the last reading in a file, so that a fault on a phone can be examined afterwards over a cable. It is not in the build you have, and a build like yours removes any that an earlier one left behind.)

That is the whole of it. Kedise does not read your listening history, your purchases, your playlists, or anything else beyond what is described above.

Your country

Kedise reads the country or region configured on your device. It comes from your system's language and region settings — the same setting that decides whether your phone says "color" or "colour" — and never from GPS, and never from geolocating your IP address. Nothing more precise than the country is ever derived: not your region, not your city.

It is a setting, not your location, and the difference is deliberate. It says how your device is configured, which is often where you live and is sometimes not: someone abroad usually keeps their phone as it was, and someone may set a region for reasons of their own. Kedise does not know which of those you are, does not try to find out, and describes this as what it is — a configured preference — rather than as your whereabouts.

Today it is used in one place, and it is sent nowhere: the diagnostic report you can assemble from Settings → General, which is copied to your clipboard. It would also be carried by the usage report described under What is planned — which is not in this version.

One thing no app can promise away: any request to any internet service shows that service your IP address. When Kedise fetches lyrics from lrclib.net, or sends a verse to a translation engine you chose, that service sees the request coming from your connection, and what it does with that is covered by its own privacy policy, not ours. Kedise itself does not resolve your IP into a location.

Where your listening information goes

Always, because this is how lyrics are found

- lrclib.net — What is sent: title, artist, album, track length · Why: the main source of time-synced lyrics

- api.lyrics.ovh — What is sent: title, artist · Why: free fallback, plain text only

- musicbrainz.org, itunes.apple.com — What is sent: artist, album, track number · Why: only when a track carries no title of its own — a CD ripped without tags gives every track a placeholder like "Track 04", and these services turn artist + album + track number back into a real title

Kedise adds no account, no key and no identifier to any of these requests. What it cannot remove is what any HTTP request carries by its nature: your IP address, and the ordinary technical headers a connection is made of. Those reach the service whatever we do, and are covered by that service's own privacy policy rather than this one. Both things are true at once, and the first is a statement about what Kedise puts in — not a claim that these services learn nothing about you.

Only if you turn it on

Translation — off by default. Translation only happens when you switch it on and choose an engine. Which engine you choose decides whether anything leaves your device at all, and that is the first thing to separate:

Translated on your device, sent nowhere. The system translator — Apple's on iOS and macOS, ML Kit on Android — runs on your own device, and no line of the song is transmitted to anyone, not to us and not to the vendor. There is no account, no key and no request. It needs a recent enough system, and it does not cover every language: where your device has no model for the pair you chose, Kedise says so rather than translating badly. On Android the language models are downloaded from Google the first time a pair is used; after that the translating itself happens locally.

Sent to a third party you choose. Every other engine works by sending the lyric text of the song to a service so it can come back translated:

- LibreTranslate — Destination: the server you enter, or libretranslate.com · Needs: your own server, or a key for the public one

- DeepL — Destination: api.deepl.com, api-free.deepl.com · Needs: your own API key

- Google Cloud Translation — Destination: translation.googleapis.com · Needs: your own API key

- Anthropic (Claude) — Destination: api.anthropic.com · Needs: your own API key

- OpenAI — Destination: api.openai.com · Needs: your own API key

- DeepSeek — Destination: api.deepseek.com · Needs: your own API key

- Google Translate, free — Destination: translate.googleapis.com · Needs: nothing

The first one sends nothing anywhere. Your device translates the lyrics itself, with the translator built into the system, and no line of the song leaves it. It is offered first for that reason, and it is the only engine on this list where the question of a third party does not arise. It cannot do every language: where the system has no model for the pair you chose, the app says so rather than translating badly.

LibreTranslate is open source, and the server can be your own. If you enter the address of a server you run, the lyrics go there and nowhere else. If you use the public one instead, they go to libretranslate.com under that service's terms. When you supply a key, Kedise refuses to send it over plain http://, and it never sends anything to a local, loopback or cloud-metadata address.

The last one deserves its own paragraph, because it is not what the others are. It needs no account, and the reason it can work that way is that it is not a published API: it is the endpoint Google's own translation web page and browser extension use (translate.googleapis.com/translate_a/single), called with a client parameter naming one of those clients. Three consequences, and we would rather write them down than let you find them:

- It can stop working at any time, without notice. It already has: on 24 August 2026 the value Kedise had been using began returning HTTP 429 and the app had to switch to another. There is no quota, no contract and nobody to ask.

- Google's terms govern that endpoint, not us. Using it this way is not a use Google has published terms for, and we cannot promise you it is one they sanction.

- It sends the lyrics of whatever is playing to Google, with no account attached but with the IP address of your connection, like any request.

It is deliberately not the default, and the app says on screen where you choose it that it is unofficial and can stop working. If none of that appeals, the system translator above sends nothing anywhere, and LibreTranslate can run on a server you control. That should be a choice you make, not one you discover.

Your use of any of these engines is governed by that provider's own terms and privacy policy.

Musixmatch — off unless you add a key. With your own Musixmatch API key, title and artist are sent to api.musixmatch.com as an additional lyrics source.

Your own lyrics sites. You can add any website as a lyrics source, and Kedise will then request the page it builds from the title and artist. Presets are offered for letras.com, azlyrics.com, genius.com, vagalume.com.br, paroles.net and tekstowo.pl, but none is active until you add it. Addresses you add are checked before use: local, loopback and cloud-metadata addresses are refused, because a source list is exactly the kind of thing people copy from a forum post.

Showing the lyrics on another screen — iPhone and Android only, off by default, and it opens a port. This feature does not exist in the desktop app: on macOS (and on Windows and Linux when they arrive) there is no such switch and no port is ever opened, because a computer already shows the lyrics on the screen you are looking at. On a phone, when you switch this on, Kedise starts a small web server on this device and shows you an address. Any browser on the same local network — a television, a laptop, another phone — can open that address and see the lyrics page. It exists so that the words can go on a screen everyone in the room can read, without an account anywhere and without a third party in the middle.

Four things follow from that, and we would rather write them down than let you discover them:

- It listens on a port — 8420, or the next free one above it — on whatever network this device is joined to. It is reachable from that network only. It is not reachable from the internet unless you have deliberately forwarded that port yourself, and Kedise never asks your router to do so.

- It does not announce itself, and it answers only to an address. Kedise publishes no Bonjour, mDNS or multicast record; the address has to be typed in by hand on the other screen. The server also refuses any request that asks for it by name rather than by address, which is what stops a website you happen to visit from reaching into your network and reading it.

- There is no password, and the protection is not access control. While it is on, anyone on that network can open the address. There is no password worth asking someone to type with a television remote, so what makes this safe to switch on in a hotel or an office is that there is nothing there worth taking: what the page is served is the title and artist of what is playing, the lines of the lyric and its translation, and which line is current. No settings, no keys — not even whether a key is configured — no country, no language, no file paths, no identifier of any kind, and nothing about anything you played before. Only the song that is playing now.

- The page itself fetches nothing from anyone. It is built into the app rather than downloaded: no fonts, no scripts, no images and no analytics come from any other address, so opening it tells no third party what you are listening to. Nothing about this feature reaches us either — Kedise operates no server of its own.

It is off when you install Kedise and stays off until you switch it on. Switching it off stops the server and disconnects anything that was watching.

Spotify — a local connection, opt-in, and it never leaves the device. If you press Connect in Kedise's player settings, Spotify's own SDK opens a connection to the Spotify app installed on the same device and reads its player state directly. Nothing about this goes to Spotify's servers through Kedise, and it is a button rather than something automatic.

What is stored on your device

Kedise stores all of the following on the device itself and sends none of it to us. Read the note on backups at the end of this section, because "on your device" and "nowhere else" are not the same sentence and we would rather be the ones to say so.

- The lyrics cache. Lyrics that have been fetched are kept in a local SQLite database so the same song is not requested twice. Title, artist and the lyric text.

- Your API keys. Any key you enter is stored in the operating system's keychain — encrypted at rest and scoped to Kedise — and not in a preferences file. Keys are never sent anywhere except to the vendor that issued them.

- Your settings.

- The timing corrections you save, song by song. When you nudge the words into time and press save, Kedise remembers that correction so the same song starts right the next time you play it. It is kept as a list of artist|title with a number of milliseconds beside each, in the app's own settings, up to 400 songs — after which the ones you corrected longest ago drop off. It is, plainly, a list of songs you have listened to and adjusted. It is written here in the open rather than disguised, because the lyrics cache beside it already holds the words of those same songs, and hiding one while the other is legible would be for show.

- Versions you pin by hand. If you pick a different transcription for a song, or for a whole album, Kedise remembers which one you chose so you do not have to choose again.

- A short technical log of this session, in memory only. Kedise keeps the last few hundred things it did — a lyrics lookup, a translation, a bridge answering — so that a diagnostic report can explain what happened. It holds song titles. It is never written to a file: it lives in memory, is overwritten as it fills, and is gone when the app closes. Paths and anything shaped like an API key are replaced on the way in, so they cannot be in it to leak.

- The diagnostic report. Kedise can assemble one from Settings → General. It shows you the entire report on screen and copies it to your clipboard. It is not transmitted anywhere. It contains your country and language as described above, and it states whether an API key is configured, never the key itself.

How long it is kept, and how to get rid of it

Plainly, because a policy that does not say this is not saying much:

- The lyrics cache and the translation cache are kept indefinitely. There is no expiry. A song looked up once stays until you clear it or uninstall the app. We would rather write that than imply a tidy retention period that does not exist.

- The timing corrections keep the last 400 songs. Past that, the one you corrected longest ago drops off.

- The session log holds 200 events and never leaves memory. Closing the app ends it.

- Your API keys stay until you delete them.

And you can empty any of it yourself, without asking us — which matters here, because there is nobody to ask:

- Settings → clear the lyrics cache removes the stored lyrics.

- The translation tab has the same for stored translations.

- Settings → General assembles the diagnostic report, shows you all of it on screen and copies it to your clipboard: it is how you see what Kedise holds.

- Uninstalling removes everything else, settings and keys included.

None of this needs a request to us, because none of it is held by us.

One thing "on your device" does not mean: your own backups

Everything above is written where your operating system puts an app's data, and your operating system may copy that to your own cloud backup. Kedise does not switch this on and does not opt out of it: it is your backup, made under your account and your provider's terms, not ours, and we do not receive it.

Concretely, and saying where each of these comes from, because some of it we checked ourselves and some of it is your operating system's business rather than ours:

- What we checked. The lyrics cache and the translation cache (lyrics_cache.db, translations.db) are written to the app's Application Support folder, and your settings — including the timing corrections and the versions you pinned — to the app's preferences. Kedise does not mark any of them as excluded from backup. On macOS the system's own tool reports the cache as [Included] in Time Machine.

- What your system decides, not us. Whether those files then travel to iCloud, to a computer backup or to an Android backup is decided by your platform and your settings, and the rules are the platform's to state and to change. If it matters to you, your operating system's documentation is the authority on it, not this page — what we can tell you is that Kedise does nothing to opt out on your behalf.

- Your API keys are in the system keychain, which is the right place for them — and a keychain that syncs, such as iCloud Keychain, syncs them across your devices by design. That is the keychain doing its job, not Kedise sending anything.

So the honest sentence is this: Kedise sends none of it anywhere, and your own backup may still carry it to your cloud provider. If you would rather it did not, that is a setting on your device, not in this app.

——————————————————

WHAT IS PLANNED

None of the following is in the version you have. It is written here because these are real intentions, and a privacy policy that only appears the day a feature ships is a privacy policy nobody believes.

When any of it does ship, this page is updated first, and the store listings' data-safety declarations are updated with it.

Windows — soon

A Windows build is planned but does not exist yet: there is nothing to install today. When it ships, it will read what is playing through Windows' own System Media Transport Controls (SMTC), the same way any media-key integration does — no more than what the macOS, iOS and Android versions already read, described above.

Usage reports

To know what to fix, we intend to collect aggregate counters and per-song catalogue status — never a log of what you personally listened to. The design splits it into two separate channels that would never be combined, not even on our own server, because it is the combination — not either channel alone — that would turn statistics into a listening history:

- How the app is working — Carries: counters, which player, which platform, app version, country, the full date and time, interface language, translation language and engine · Never carries: no song titles

- Catalogue status — Carries: title, artist, album, edition, track length, which player/platform it was tested on, whether it worked, the translation language if it is a common one, and — if you adjusted the timing — by how much · Never carries: no date, no time, no country, no identifier, no uncommon translation language

The full date and time are safe in the first channel precisely because it carries no song title: knowing the app was used at 22:14 on a Tuesday says nothing about what you listened to. The second channel reports on a recording, not on you — "this song, this edition, plays out of sync on this player" — in the same way an errata list does not say who read the book, and it would say so whether a song worked or not, not only when it fails.

The translation language works differently from the player and platform. There are only a handful of players and platforms, and none of them is rare enough to narrow down who you are. Translation has twenty-some target languages, and a few of them are spoken by very few people — a rare language attached to a specific song title says a great deal more about who asked for it. So the second channel would only ever carry a translation language from a fixed, short list of common ones, decided in advance; anything outside that list is left out entirely, never sent, never counted towards a threshold first. The first channel, which carries no title, can safely record any translation language, common or not.

Whether these reports will be optional is not settled, and this policy will not pretend otherwise. The design intent has been that they are part of how Kedise works rather than a setting — but whether that is lawful without asking you first depends on the legal basis for it, and in Europe on ePrivacy as well as the GDPR, and that is a question for a data-protection adviser and not for the people who wrote the app. It will be answered, and this section rewritten, before a single report is ever sent. Until then nothing leaves your device, which is the one part of this that is not a promise but a fact about the build you have.

What follows is what the reports would contain, and it is exact because the argument for them rests on it: neither channel carries a name, an account, a device identifier, or anything at all that persists from one report to the next, and the two are never joined — not in the app, not on the way out, and not on a server of ours. What each channel carries is the list above, and nothing is added to it quietly: the app refuses to build a report that contains a field belonging to the other channel.

Reports are gathered on your device and handed over when the app next starts, not while you are using it. If there is nowhere to hand them to, nothing is sent and nothing is lost. And Kedise will show you what is waiting to go, in full — the promise that a report carries nothing personal is only worth something if you can check it.

Crash reporting

None of this happens in the version you have installed. It sits under What is planned for a reason: there is no crash-reporting SDK in this build and no server of ours for anything to reach. What follows is the design we intend to implement, written in advance rather than after the fact — read every sentence below in the future tense.

Crash reports will be sent as well, and never whole.

A complete diagnostic report is the most useful document Kedise can produce and the most dangerous thing it could transmit: on one page it holds the song title, the artist, the wall clock, your country, your language, and several hundred lines of what the app had just been doing. Every one of those is harmless on its own. Together they are a listening history.

So a crash report is cut along the same two channels before anything leaves:

- what went wrong, and on what sort of installation → the first channel, with no song title;

- what was playing and how the catalogue handled it → the second, with no clock and no country.

And three parts are not sent at all, in either channel, because they cannot be cut safely:

- Anything you typed. Free text is free text: people put their name in it, or an email address, or the name of whoever they were listening with.

- A region you typed by hand, which is finer than a country — and typed precisely by the people whose region is unusual enough to be worth typing.

- The session log, the running list of what the app just did. Song titles with a clock beside them is a listening sequence, which is the one thing all of this exists to avoid. Leaving it out costs us the part that best explains a fault, and it is still not a close call.

The complete report is unaffected and stays yours: Settings → General still assembles it, still shows you all of it, and still copies it to your clipboard. That one never leaves your device unless you send it yourself.

A server of our own

Today there is none, which is why nothing can be sent anywhere. When there is one, this page will say who runs it, where it is, and how long anything is kept before it receives its first byte.

Paid features, and possibly a free tier with advertising

Kedise may later offer paid features — better translation quality is the obvious candidate — alongside a free tier, and that free tier may carry advertising. If advertising ever ships, this page will say which ad provider is used and what it receives, before it ships, not after. Nothing about the current version shows ads or shares anything with an ad network.

——————————————————

AGE SUITABILITY, AND ONE THING PARENTS SHOULD KNOW

Kedise has genuine educational use: a song with its lyrics on screen and a translation beneath each line is language practice, and that is a large part of why people use it.

But Kedise displays lyrics it did not write. They come from third-party catalogues and from any site you add yourself, and Kedise does not filter them. Popular music contains explicit language, and when it does, Kedise will show it, and translate it. There is no clean-lyrics mode. Anyone choosing this app for a child should know that before installing it.

Kedise is not directed at children and asks nobody their age, so it has no way of telling a child's use from anyone else's. It does not ask for a name, an email address or an account from any user, whatever their age. That is a statement about what Kedise asks for — not a claim that nothing about a user's use of the app exists: the sections above describe exactly what is stored on the device and what reaches a third party when you choose an engine, and those apply to every user alike.

CHANGES TO THIS POLICY

If this changes, the date at the top changes with it.

CONTACT

Questions about this policy: kediseadmin@gmail.com