Legal
App Privacy Policy
MPE Keys desktop app for macOS and Windows
Last updated: 2 September 2026
MPE Keys collects no personal data. There is no analytics, no tracking, no advertising, no crash reporting service, no user account and no sign in of any kind.
Your playing is processed on your own computer, in the moment, and is never stored or transmitted by the app.
1. Scope
This policy describes the MPE Keys desktop application: the macOS version from the Mac App Store, and the Windows version from Steam or bought directly from this website.
MPE Keys is built from the same source as MPE Insight and carries two of its modules, the Keyboard and the PB / Mod display. Everything below describes MPE Keys as it actually ships; where the two products differ, the difference is named.
The website you are reading this on is a separate matter with its own hosting logs and its own consent based analytics. Those are described in the Website Privacy Policy. Nothing on that page applies to the app.
2. What the app works with, and what happens to it
MPE Keys draws MIDI performance data as a keyboard. To do that it reads the following while it runs:
- MIDI input from the instruments and ports you enable, including note, velocity, pressure, pitch bend and controller data.
- A MIDI file that you pick yourself in a file dialog, if you use the built-in player.
- Your computer keyboard and mouse, while Typing Keys or Mouse Mode are switched on, so that key presses and clicks can become notes.
All of this is processed in memory and drawn to the screen. None of it is written to disk, sent to a server or shared with anyone.
No camera, no images, no video. Unlike MPE Insight, this app carries no FORGE module: there is no webcam feature and no picture or film is ever read. The code for it is not merely switched off, it is not in the build.
Files leave the app only when you ask for them. A recording is written as a MIDI file or as CSV to the location you choose in a save dialog, and nowhere else.
3. What the app stores on your own computer
The app keeps a small amount of state so that it looks the way you left it. This data stays on your machine, is never transmitted, and is not personal data in any meaningful sense:
- Settings and layout, for example colours, keyboard design, key range and which MIDI ports you enabled.
- Your snapshots and presets, which hold module settings and nothing else.
- A crash log, if the app ever fails. It is a plain text file holding an error message, a time stamp and the app version. It is never transmitted. The dialog you see after a crash only reveals the file on your disk, so that you can decide whether to send it in yourself.
- A licence activation file, in the version bought directly from this website only. See section 4.
You can delete all of it by removing the app's data folder:
- macOS:
~/Library/Application Support/de.christophek.mpe-keys - Windows:
%APPDATA%\de.christophek.mpe-keys
The licence activation file of the direct version sits in a folder of its own beside it, de.christophek.mpe-keys-license, so that uninstalling the app does not silently consume one of your activations. Delete that folder too if you want to remove every trace.
4. Network connections
What the app contacts depends entirely on where you got it. This is not a setting, it is a difference in the shipped program itself: the licensing and update code is compiled out of the store versions rather than merely switched off.
Mac App Store and Steam
These versions make no network requests at all. There is no licence check, no update check, and no device identifier is generated or transmitted. The App Store privacy label reads "Data Not Collected", and that is accurate.
Version bought directly from this website
This version contacts exactly two addresses, both only for the purpose named:
- Licence activation at
api.lemonsqueezy.com. When you activate, your licence key and a device fingerprint are sent so that the licence can be tied to one machine. The fingerprint is a short value calculated from your computer name and your user name. The calculation runs in one direction only: the fingerprint is what leaves your computer, the names themselves never do. It is also salted per product, so the same machine looks different to MPE Keys and to MPE Insight and deactivating one never touches the other. - Update check at
www.christophek.de, where the app reads a small file listing the current version number. It is an ordinary web request that transmits no usage data.
Neither request carries anything about what you play or how you use the app.
5. Permissions the app asks for on macOS
Under the macOS sandbox an app has to declare what it may do. Two declarations are visible in MPE Keys, and it is worth being precise about why each exists:
- Files you select. The app can read only the files you pick in a dialog, and write only where you point a save dialog. It has no access to the rest of your disk.
- Network client. This one is purely technical and does not mean the app goes online. macOS renders the interface through WKWebView, and WKWebView loads every document, including the pages that ship inside the app itself, through its own networking helper process. The sandbox counts that as network access. Without the declaration the window simply stays blank. In the Mac App Store version, nothing in the product opens a connection.
No camera declaration. MPE Insight asks for one because its FORGE module can use a webcam as a visual source. MPE Keys has no such module and therefore never asks.
6. On device processing, and no AI services
Everything MPE Keys does happens on your own hardware, offline. There is no cloud service behind any feature, and no machine learning model of any kind ships in this app: the depth estimation that MPE Insight uses for its three dimensional effects belongs to FORGE, which is not part of this build.
Nothing here takes a prompt or produces text, imagery, audio or music of its own.
7. Purchases, and what I learn from them
The app itself never handles payment. Purchases are made through the store you bought from, and each store is the seller of record for its own channel:
- Apple for the Mac App Store, Valve for Steam. From both I receive aggregated sales and usage statistics that cannot identify an individual. I do not receive your name, your email address or your payment details.
- Lemon Squeezy for direct purchases from this website. As seller of record they process the payment and issue the invoice. Their order record, which I can see, includes the buyer's email address and billing country, because that is how the licence key is delivered and how support requests can be matched to a purchase. I use it for that and for nothing else. It is never sold or passed on.
If you write to me for support, I keep the correspondence for as long as it takes to help you, and delete it when it is no longer needed.
Legal basis for handling a direct purchase and its support: Art. 6(1)(b) GDPR (performance of a contract).
8. Data Controller
Christophe Kalkau
Johannes-Drach-Str. 55A
97753 Karlstadt, Germany
Email: mail@christophek.de
9. Your Rights
Under the GDPR you have the following rights with regard to me as the data controller:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
In practice there is very little for me to act on, because the app sends me nothing. Anything the app stores is on your own computer and under your control, and you can remove it as described in section 3.
To exercise your rights, please contact: mail@christophek.de
You also have the right to lodge a complaint with the competent data protection supervisory authority. For Bavaria, this is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.
10. Changes to This Policy
This policy may be updated if the app gains a feature that changes how data is handled, or if the applicable legal requirements change. The "Last updated" date above indicates the currently applicable version.