Skip to content

Security: ChrisCollins24/Keygrid

SECURITY.md

Security policy

Supported versions

Only the latest release of Keygrid receives security fixes. Please update before reporting a problem.

How Keygrid handles your data

  • Audio files are analyzed entirely on your Mac and are never uploaded.
  • Keygrid doesn't collect analytics or send data anywhere.
  • Your song history is stored locally: on Mac in ~/Library/Application Support/com.keygrid.analyzer/history.json, on Windows in %APPDATA%\com.keygrid.analyzer\history.json.
  • The only time Keygrid opens a web address is when you click a link in the app, which opens in your default browser.

Reporting a vulnerability

Please don't open a public issue for security problems.

Report them privately using GitHub's private vulnerability reporting, or email keygridapp@gmail.com. Include:

  • the Keygrid version, and your macOS or Windows version,
  • what the problem is and how to reproduce it,
  • what impact you think it has.

You'll get a response as soon as possible, usually within a few days. Once a fix is released, you'll be credited in the release notes if you'd like.

There aren't any published security advisories