Skip to content
HarmonyKeen

Privacy

Your music stays on your computer.

HarmonyKeen is a local-first desktop app. This policy explains what it handles, where it is stored, and what is never collected. HarmonyKeen is made by Malsah Labs LLC, an Arizona limited liability company. Where privacy law uses the term "controller" or "business", it means Malsah Labs LLC for the personal information this policy covers.

Effective September 17, 2026.

Back to homepage

01

Summary

HarmonyKeen is designed so your music projects stay on your device.

  • Your MIDI files, HarmonyKeen project files, generated harmony notes, autosaves, settings, and preferences are processed and stored locally on your device.
  • Files are imported or exported only when you choose to open, save, export, or drag them.
  • HarmonyKeen does not require an account.
  • HarmonyKeen does not provide cloud sync.
  • Your license is checked on your own device, and ordinary use works offline. The app contacts us for three things and nothing else: starting the free trial, activating a license, and checking for updates if you have said yes to that. Each is described in its own section below. It never asks our permission to run.
  • HarmonyKeen does not use advertising, advertising tracking, analytics, session replay, or crash reporting.
  • HarmonyKeen does not sell your data.
  • HarmonyKeen does not access your microphone, camera, precise location, contacts, calendar, health data, or financial data.

02

Information HarmonyKeen Handles

HarmonyKeen may handle the following information locally on your device:

  • MIDI files that you choose to import.
  • HarmonyKeen project files that you choose to open or save.
  • Notes, timing, velocity, tempo, meter, key and scale context, track names, project names, generated harmony notes, and related project settings.
  • Autosave and session recovery data.
  • App preferences, such as theme, audio volume, editing preferences, accessibility preferences, tutorial state, and help preferences.

This information is used to provide the app's core features: importing melodies, generating harmonies, playing back projects, saving projects, restoring sessions, remembering preferences, and exporting MIDI and project files.

03

Local Storage

HarmonyKeen stores project and preference data locally on your device. Depending on the operating system and app runtime, this may include local application storage such as IndexedDB and local storage inside the desktop app's WebView.

Local storage may include:

  • Saved local projects.
  • Autosaves and session recovery data.
  • App settings and preferences.
  • Tutorial and help preferences.

HarmonyKeen does not automatically upload this local project or preference data to HarmonyKeen servers.

04

File Import and Export

HarmonyKeen imports files only when you choose to open or import a file. HarmonyKeen exports files only when you choose to save, export, download, or drag a file out of the app.

Exported files may include:

  • Standard MIDI files (.mid or .midi).
  • HarmonyKeen project files (.hkn).
  • Separate MIDI stem files, if you choose a stem export option.

You control where exported files are saved. Once exported, those files are managed by your operating system and any apps or cloud storage services you choose to use.

Some desktop features may create temporary local MIDI files to support drag-and-drop export. These files are created on your device and are not uploaded by HarmonyKeen.

05

Accounts and Cloud Services

The first public release of HarmonyKeen does not require a HarmonyKeen account and does not include HarmonyKeen cloud sync.

If account features, cloud storage, licensing services, or online collaboration features are added in the future, this Privacy Policy will be updated before those features are used.

06

Licensing and Purchase

HarmonyKeen is a paid app, and this section describes the only personal information involved.

Your license key, and the device check

When you activate HarmonyKeen, the app creates a short scrambled code from an identifier your operating system already provides (the platform UUID on macOS, the machine GUID on Windows). The identifier is combined with a fixed app-specific value and put through a one-way hash.

  • The original operating-system identifier is never stored and never shared.
  • The resulting code is kept on your own device, so the app can tell whether it is running on a machine your license is already bound to.
  • The license check itself is performed entirely on your device and needs no internet connection. Once you hold a license, opening the app, generating harmony and exporting do not contact us. The exceptions are the three listed in the summary above: starting a trial, activating a license, and the daily update check if you have agreed to it.
  • When you activate a license, and when you move one to a different computer, the app sends us that scrambled code together with your license identifier. Those are the only times it is sent for a purchased license. We use it to count how many machines a single license key is being activated on, so we can see when a key has been shared widely. We do not use it to track you, to build a profile, or to control what you can do.
    • The scrambled code is a one-way hash. It cannot be reversed into your machine's identifier, and on its own it does not name you.
    • To be straightforward about it: because that code sits beside a license identifier, and a purchased license is linked to the email you bought with, we could connect the two if we needed to for support. It is pseudonymous rather than anonymous, and privacy law treats it as personal information. We do not use it to build a profile or to track you.
    • Your email is not included in that message, and neither is any file, project, or music data.
    • This never gates your use of the app. If you are offline, or the message fails for any reason, activation still succeeds and the app works normally. It is a record for us, not a permission check.
    • We keep, per license key, a list of these codes with the date each was last seen. When a license is activated on more than one hundred machines, the oldest entry is dropped. We also keep a running count of how many distinct machines a key has ever been activated on; that count is a number only, and it continues past one hundred after the oldest entries have been dropped. We keep both for as long as the license exists, because they only answer a question about that license.
    • If that count reaches a level that suggests a key has been shared widely, our system emails us so a person can look at it. The message names the license, not you, and nothing is decided automatically: no license is ever suspended, downgraded, or switched off as a result. There is no cap on the number of computers you may use, and this does not create one.
  • If the app cannot read a machine identifier, activation still works and nothing is sent. A free trial cannot start in that case, because the code is the only thing that stops one computer taking an unlimited number of trials; the app says so and you can still activate a license.

The free trial

Starting the free trial happens the first time you generate harmony. If the request fails, the app tries again the next time you press Generate, until it succeeds; after that it never asks again.

  • The app sends us the scrambled machine code described above, to ask for a trial license. No email, no name, no account, no files, and nothing about your music. There is nothing to sign up for.
  • Once the trial license comes back, the app makes a second, separate request recording that this license was activated on this machine, exactly as it does for a purchased license. That one carries the license identifier as well as the scrambled code. It is described in the section above.
  • We send back a trial license, which is then stored on your own device and checked there like any other license. Once the trial has started, using the app is offline again.
  • We keep a record that this machine was issued a trial, so the same computer is not issued a second one. That record holds the scrambled code, the license identifier, the dates it was issued and expires, and the trial license itself so the same one can be returned rather than a second one issued. We keep it for two years after the last time that computer asks, then delete it.
  • When a trial starts we note your IP address for two days. It helps us keep the free trial fair, and gives us a rough sense of which countries trials come from. It is not tied to your license, and it is deleted after two days.
  • If we cannot be reached at all, no trial starts and nothing leaves your computer. The app tells you, and you can try again or enter a license key.
  • If we can be reached but decline (for example, too many trials have come from your internet connection that day), then the request did reach us and is covered by everything above. The app tells you what happened.

Our server's own logs

The small service that issues licenses keeps operational logs, the way any web service does.

  • They record that a request happened, whether it succeeded, and for a purchase an order reference, so we can answer "did that order get its key?". By the same reasoning as above, an order reference is pseudonymous rather than anonymous, since we could match it to your purchase.
  • They deliberately do not contain your email address, your license key, or your machine's scrambled code. The code is left out even indirectly: an earlier version logged a license identifier that had part of the code inside it, and that was removed.
  • They are held by Cloudflare under its own retention, and we use them only to keep the service working.

Checking for updates

HarmonyKeen can look for a new version once a day. We ask before it ever does, and it is off until you say yes.

  • We ask on your second launch rather than your first, so a new install is not interrupted by a permission question.
  • If you say no, we do not ask again and no check ever happens. You can still check by hand whenever you want.
  • You can change your mind at any time in Settings, General, Check for updates, in either direction. Withdrawing permission is exactly as easy as giving it.
  • If you say yes, the app requests a single file from downloads.harmonykeen.com at most once every 24 hours, and only while the app is running.
  • That request does not tell us what version you have, what kind of machine you are on, or anything about you. It asks for the same file every time. Many updaters include your version and platform in the request; ours does not.
  • What we receive is what any web request reveals: your IP address, and an identifier for the updater itself which is the same for everyone on the same app version. Handled by Cloudflare as described below. We do not use it to build a profile.
  • Nothing installs by itself. If there is a new version you are told, and it downloads only when you choose to install it.

The plugin. If you allow it, the HarmonyKeen plugin checks once a day whether a newer version has been released. It requests a single file from downloads.harmonykeen.com and reads the version number in it. The request carries nothing about you, your computer, your DAW project, or your music, and is identical from every installation; the only thing identifying it is the standard user-agent string every HTTP client sends. There is no account, identifier, or license key involved, and we do not log it in a way that is linked to you. If you decline, no request is ever made and you are not asked again. Nothing is downloaded or installed either way: the plugin can only tell you an update exists and open the download page if you ask it to. A plugin cannot replace itself while a DAW has it loaded, which is why it tells you rather than doing it.

Buying HarmonyKeen

Purchases are handled by Polar Software, Inc., our merchant of record. Polar collects your payment details and billing information under its own privacy policy. We never see or store your card details.

Polar passes us the email address you bought with, and we use it to:

  • send you your license key,
  • keep a record of the order so we can re-send the key or help with support.

That record is stored in Cloudflare Workers KV. Cloudflare is a global network and may hold or cache it in more than one country; see "International transfers" below. We keep it for as long as we support your license, because a customer who loses their key needs us to be able to find it. We do not use your purchase email for marketing, and we do not sell or share it.

We send the license-key email itself through Resend, a transactional email provider. Resend receives your email address and the license key solely to deliver that one message; we do not use it for marketing or tracking.

If you want your purchase record deleted, email privacy@harmonykeen.com. Deleting it means we can no longer re-issue your key, so your emailed copy becomes your only one.

Support email

If you email us, we keep that correspondence, including any files you choose to attach, for as long as needed to answer you and for a reasonable period afterward in case the issue reopens, normally no more than 24 months after our last exchange with you, unless we need to keep it longer to meet a legal obligation or resolve a dispute.

07

Analytics, Advertising and Tracking

The first public release of HarmonyKeen does not use analytics, advertising SDKs, advertising tracking, or session replay.

HarmonyKeen does not sell user data.

HarmonyKeen does not track you across apps or websites.

This section describes the HarmonyKeen desktop app. The HarmonyKeen website (harmonykeen.com) is covered separately below.

08

Crash Reporting and Diagnostics

HarmonyKeen does not send crash reports or diagnostics. Nothing about errors, usage, or your device leaves your computer.

To be precise about what is in the app rather than only what it does: HarmonyKeen's code includes an error-reporting library (Sentry) that is switched off and sends nothing. It requires a server address to report to, and no address is configured in any release, so it never starts and never transmits. We disclose this because the library is present in the installed files, and we would rather describe it than have you find it and wonder.

If we ever turn it on, we will update this policy in the same release, and it would be limited to technical information such as error messages, stack traces, app version, and operating system version. Music files, project files, note data, and project names would not be collected.

If HarmonyKeen enables third-party crash reporting in a public release, this Privacy Policy will be updated to describe that service and the information it receives.

09

Third-Party Components and Links

HarmonyKeen includes third-party libraries, models, and audio and sample assets that help the app run locally. These components are bundled with the app or loaded from the app's local resources for normal app functionality.

HarmonyKeen may include links to third-party websites for credits, licenses, support, or documentation. Those websites are not operated by HarmonyKeen. If you open a third-party link, that website's own privacy policy applies.

10

This Website

This website uses Cloudflare Web Analytics to count page views. It sets no cookies, stores nothing in your browser, and doesn't fingerprint visitors by IP address, user agent, or anything else, so it can't follow you to other sites or build a profile of you.

The website also counts how many times each demo is played and how far through it people get, so we can see which examples people find worth hearing. A count is a tune's name, a date, and a running total. It carries no identifier, no time of day, and nothing about you, so none of it can be traced back to a person.

We also count how many purchases come from each website that links to us. That count is a number, with nothing in it about you.

The website has no account system and no advertising trackers. Links to third-party websites are governed by their own privacy practices.

11

The Mailing List

If you give us your email address on this website, it is used for one thing: to write to you about new releases, features, and important news. We don't sell it, rent it, or use it to advertise to you anywhere else.

The list is held by Resend, who store the addresses and send the messages on our behalf. This website keeps no copy of your address.

Every message carries an unsubscribe link, and you can ask us to remove you at any time by writing to privacy@harmonykeen.com. Signing up takes effect immediately, with no confirmation email, so check the address before you send it.

12

Information We Do Not Collect

In the first public release, HarmonyKeen does not intentionally collect:

  • Account registration information.
  • Payment or financial data. Your card details go to Polar, our merchant of record, and never reach us. See Licensing and Purchase above.
  • Health data.
  • Contacts.
  • Calendar data.
  • Precise location.
  • Camera input.
  • Microphone input.
  • Advertising identifiers.
  • Cross-app or cross-site tracking data.
  • Session replay recordings.
  • Your MIDI files or HarmonyKeen project files through any automatic upload.

13

Data Sharing

HarmonyKeen does not sell user data.

HarmonyKeen does not share your MIDI files or project files with HarmonyKeen servers because the first public release does not upload those files automatically.

If you choose to export a file, send a file to another person, upload a file to a cloud storage provider, or open a third-party website, your use of those services is controlled by your choices and by those services' privacy policies.

14

Data Retention and Deletion

Server-side retention is described in each licensing subsection above: the trial record (two years), the activation list and its distinct-machine count (both kept while the license exists), the IP counter (two days), and the purchase record. This section covers what is on your own device.

Local project data, autosaves, session data, and preferences remain on your device until they are overwritten, cleared in the app where controls are available, deleted through operating system storage controls, or removed by uninstalling the app and deleting associated app data.

Exported MIDI and HarmonyKeen project files remain wherever you choose to save them until you delete them.

15

Your Privacy Rights

You may ask us to access, correct, or delete the personal information described in this policy. That means your purchase email, your order record, any support correspondence, and the trial and activation records described above, since your music and project data stays on your device and we cannot see or reach it there.

One limit, stated plainly rather than buried: deleting the record that this computer already had a free trial would let the same computer take another one. If you ask us to delete it, we will, and that machine simply becomes eligible for a trial again. Depending on where you live, you may also have the right to restrict or object to our processing, or to receive a portable copy of your information. If we process information based on our legitimate interests, you have the right to object to that use.

Where data-protection law requires a legal basis for processing personal information, we rely on:

  • performing our contract with you, to deliver and support a purchased license and respond to related requests;
  • our legitimate interests in answering pre-purchase, support, and privacy messages, preventing fraud or abuse, and keeping our services reliable and secure; and
  • our legal obligations, such as keeping records or responding to a valid legal request.

We do not use personal information for marketing, advertising, or automated decisions that produce legal or similarly significant effects about you.

To exercise any of these rights, email privacy@harmonykeen.com. We may need to verify that a request concerns your own information before acting on it, and we will respond within the period required by applicable law. These rights are subject to legal exceptions, including records we must keep by law.

International transfers

Malsah Labs LLC is based in the United States. The service providers named in this policy (Polar, Cloudflare, and Resend) may process information in the United States and other countries where they operate. Where applicable law requires safeguards for transferring personal information internationally, we rely on our providers' data-processing terms, which include standard contractual clauses or another recognized transfer mechanism. Contact privacy@harmonykeen.com for more information.

Complaints

If European Economic Area or United Kingdom data-protection law applies to you, you may complain to the data-protection authority where you live or work, instead of or in addition to contacting us. EEA residents can find their authority through the European Data Protection Board; UK residents can contact the Information Commissioner's Office. You do not have to contact us first.

16

California Privacy Rights

If you are a California resident, the California Consumer Privacy Act, as amended, gives you additional rights over the categories of personal information described in this policy, mainly identifiers, such as your email address, and commercial information, such as your order and license records.

We do not sell or share personal information, as those terms are defined under California law, and we do not use or disclose sensitive personal information for any purpose beyond what this policy describes. Because we do not sell or share personal information, there is no "Do Not Sell or Share My Personal Information" link to provide.

You have the right to know what personal information we hold about you, to request its deletion or correction, and not to be discriminated against for exercising these rights. To exercise them, email privacy@harmonykeen.com, and see Your Privacy Rights above for how we handle a request.

17

Security

HarmonyKeen uses a local-first design to reduce unnecessary transmission of user music data. However, files saved on your device are protected by your device, operating system, account, backup, and storage settings. HarmonyKeen project files and exported MIDI files are not encrypted by HarmonyKeen unless a future release explicitly adds that feature.

If a breach of security compromises your personal information in a way that requires notice under applicable law, we will notify you and any required authority within the time that law requires.

18

Children's Privacy

HarmonyKeen is a general music creation tool and is not directed to children under 13. HarmonyKeen does not knowingly collect personal information from children.

19

Changes to This Privacy Policy

HarmonyKeen may update this Privacy Policy when the app changes, when new distribution channels require additional disclosures, or when legal requirements change. The effective date at the top of this policy will be updated when the policy changes.

20

Contact

For privacy questions, contact privacy@harmonykeen.com.