
Effective date: 17 September 2026
This summarises our privacy practices. For more information, see our full Privacy Policy below.
Duet doesn’t have user accounts and doesn’t collect personal data from you in the app.
We don’t run advertising or third-party tracking SDKs. The only other data we ever see is anonymised website analytics.
Read our full Privacy Policy below.
Questions? Contact me, or email me directly for any urgent privacy-related requests at privacy@myungjoon.com
1. Overview
Welcome to Duet’s Privacy Policy. Duet is an open-source project: it isn’t distributed on the App Store, and its full source code is available on GitHub under the MIT license. We still want its privacy story to be clear — including for the people who were kind enough to join the waitlist while it was open. This Policy explains what we collect, why, and what rights you have over it, while also covering the legal ground required under regulations like the GDPR (EU/UK), CCPA/CPRA (California), and PIPA (Korea). By using Duet or visiting myungjoon.com/duet, you’re agreeing to what’s laid out here. If anything in this Policy doesn’t sit right with you, please don’t hesitate to reach out.
2. Important Definitions
A couple of terms come up often in this Policy, so let’s define them upfront:
Personal Data (sometimes called “PII”) is any information that could be used to identify you specifically. Data that’s been fully anonymised and can’t be traced back to you doesn’t count as such.
Service Providers are the outside tools we rely on to run Duet and its website:
Framer, which builds and hosts the website;
Framer Analytics, which gives us anonymised, aggregated insight into who’s visiting the site; and
GitHub, which hosts Duet’s source code. If you visit the repository, GitHub’s own privacy policy applies there.
3. Who’s Responsible for Your Data
Duet is built and run by Myung Joon Kang, an independent student developer. We’re the one responsible for Duet and any data described in this Policy. There’s no company or team behind this, just us.
4. What We Collect
Using the app.
Duet doesn’t collect any personal data from you.
Beta testing via TestFlight.
Duet’s TestFlight beta has ended. While it ran, Apple shared some device info with us for testers — device type, OS version, battery level, and crash or diagnostic logs — which we only used to fix bugs. We no longer receive this data.
Visiting the website.
The site doesn’t collect anything that identifies you personally from general browsing. We do use Framer Analytics to see anonymised, aggregated stats — referrer, pages visited, general country, OS, browser, and device type — but none of it can be traced back to you as an individual.
The waitlist (closed).
The Duet waitlist is closed, because Duet is no longer coming to the App Store. We collected email addresses for one reason only — to tell people when Duet launched — and since that won’t happen, we have deleted the addresses we held. If you’d like confirmation that yours is gone, just email us.
If you reach out to us.
If you email us directly, we’ll see whatever you choose to share (your name, email, and message) — and we’ll only use it to reply to you.
In practice, here’s how you stay in control:
There’s no in-app account or data to delete, since Duet doesn’t collect anything from you once you’re using the app itself.
5. Why We’re Allowed to Process This
For readers in the EU or UK, here’s the legal basis under the GDPR: the waitlist, while it was open, relied on your consent (Article 6(1)(a)). Everything else rests on our legitimate interest in keeping Duet’s website running smoothly and responding to you (Article 6(1)(f)).
6. How We Use It
Whatever limited data does reach us, we use it only to: keep the site running well, respond to your messages, and meet any legal obligations we’re subject to. We don’t use anything to build a profile of you or make automated decisions about you.
7. The Tools We Rely On
The Service Providers listed in Section 2 help us run Duet’s website and host its source code — they’re not allowed to use your data for anything beyond that. We don’t sell, rent, or trade your data, and we never have. We’d only ever share information if the law required it, or if it were genuinely necessary to protect someone’s safety or rights.
8. How Long We Keep Things
Analytics stay with our Service Provider in aggregated form, per their own retention practices. Waitlist email addresses have been deleted. If you’ve emailed us, we’ll hang on to that conversation for as long as feels reasonable to keep good records.
9. Where Your Data Travels
We’re based between Korea and Canada, and the Service Providers we use may process data in the US, the EU, or elsewhere. Where that happens, we lean on the safeguards those providers already have in place — like standard contractual clauses — to keep things properly protected.
10. Keeping Things Secure
We take reasonable steps to protect any data that does pass through our hands.
11. Your Rights
If GDPR or UK GDPR applies to you, you have the right to ask for a copy of your data, correct it, have it deleted, restrict how it’s processed, object to processing based on legitimate interest, request it in a portable format, withdraw consent at any time, and complain to your local supervisory authority if you’re unhappy with how we’ve handled things. Just contact us and we’ll sort it out.
12. If You’re in California
If you’re a California resident, the CCPA/CPRA gives you the right to know what we collect and why, ask us to delete it, correct it if it’s wrong, opt out of any sale or sharing of it (which we don’t do), and not be treated differently for exercising these rights. Just contact us and we’ll take care of it.
13. Children’s Privacy
Duet isn’t directed at children under 13 (or the relevant age where you live), and we don’t knowingly collect personal data from kids. If we ever find out that’s happened by accident, we’ll delete it as soon as we can.
14. Tracking
We don’t track you across other apps or websites for advertising purposes, so we don’t ask for tracking permission through Apple’s App Tracking Transparency framework — there’s simply nothing to track.
15. Cookies and Site Analytics
The website may use cookies through our Service Providers, but only to generate the anonymised analytics mentioned in Section 4 — nothing that builds a personal profile of you. You can turn cookies off in your browser if you’d like, though some site features might not work as smoothly.
16. Korea’s Personal Information Protection Act (PIPA)
We’re based in Korea, so Korea’s Personal Information Protection Act (PIPA) applies to how we handle personal information, in addition to the GDPR and CCPA/CPRA protections described above. Under PIPA, you have the right to request access to, correction of, deletion of, and suspension of processing of your personal information, and to be told how any of it is used or shared. In practice, this covers the limited data described in Section 4 — mainly aggregated site analytics and anything you’ve sent us directly by email. We don’t operate a separate Chief Privacy Officer function given the small scale of processing involved, but we are personally accountable for PIPA compliance and will handle any request under this section the same way we handle requests under Section 11. If you’d like to exercise a PIPA-specific right, just say so when you contact us and we’ll treat it accordingly.
17. Changes to This Policy
As Duet grows and changes, this Policy might need updates too. Whenever that happens, we’ll update the Effective Date at the top so you can tell something’s changed.
18. Get in Touch
Questions? Contact me, or email me directly for any urgent privacy-related requests at privacy@myungjoon.com
