This Privacy Policy explains how Robert Charles Ollech ("we", "us") collects, uses, and protects information through LessonBase (the "Service"), a tool for independent music teachers to manage students, lessons, attendance, and payments.
LessonBase is used by music teachers to manage their own studio. Teachers create accounts and enter information about their students on their students' behalf. Parents and students may be given a separate login (an access code) by their teacher to view lesson notes, attendance, and make payments.
Some students managed through this Service are children under 13. We do not knowingly collect information directly from children through this Service — all student information is entered by the teacher (or, for their own account, the parent) as part of managing music lessons, not through any interaction by the child with the Service itself. The teacher is responsible for their own relationship with the student/parent and for any consent required under applicable law (including COPPA) for the information they choose to enter about a student.
Reviewing and deleting a child's information. A parent may, at any time: (a) contact their child's teacher to review, correct, or remove their child's information; (b) use the "Delete My Data" option in the parent portal to erase their child's personal information directly; or (c) email us at support@lessonbase.app. When a deletion request is made, we promptly remove personal identifiers — the student's and parent's names, contact details, access codes, and all free-text notes and assignments — across our systems, and we close the associated parent login.
De-identified records. After personal identifiers are removed, we may retain de-identified records that no longer identify any individual — for example, lesson dates, payment amounts, attendance status, and musical-piece titles, linked only by a random token that carries no name or contact information. Because this information is no longer personal information, we may keep it and use it to operate, analyze, improve, and develop the Service. We do not attempt to re-identify it or link it back to any child.
We use the following service providers (sub-processors) to operate the Service. We do not sell your data.
SMS and mobile information. Phone numbers provided for text message reminders, and the associated SMS opt-in/consent records, are used solely to send the messages described in this policy. No mobile information, phone numbers, or SMS opt-in and consent data will be shared with, sold, or rented to third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party, other than Twilio, our SMS delivery provider, solely as needed to deliver the messages. You can opt out of texts at any time by replying STOP.
SMS reminders: your choices. SMS lesson reminders are optional and are only sent to a phone number where consent has been recorded. You can opt out at any time by replying STOP, and get help by replying HELP. Message frequency varies — typically one message per scheduled lesson. Message and data rates may apply. Opting out of texts does not affect your account, and you will continue to receive lesson information by email and in the app.
This section is our written data retention policy, published here as required by 16 C.F.R. § 312.10. We do not retain children's personal information indefinitely.
A teacher can delete an individual student at any time, and a parent can delete their own child's data from the parent portal using the "Delete My Data" option. To request deletion of your account or data, email support@lessonbase.app.
How deletion works here. When a student is deleted — by their teacher, by their parent, or by us on request — we run a de-identification process that immediately strips every identifier across all of our tables: the student's name, the parent's name, email and phone, all login codes, and every free-text field including lesson notes and descriptions. The parent's linked account is deactivated and all login codes stop working at once.
What remains afterwards is non-identifying: amounts, dates, attendance status, lesson counts, and piece titles, under an anonymous token that is not traceable back to any person. We keep that remainder to understand how the Service is used and to improve it.
We want to be straightforward about this rather than describe it as simple deletion. Two things follow from it, and you should know both:
On backups specifically. Removing a record from a live database does not by itself remove it from a backup taken yesterday. That is true of every service that keeps backups, and pretending otherwise would be dishonest. Our answer is a fixed 30-day rolling window: backups older than 30 days are destroyed automatically, so a deleted child's information cannot persist beyond that anywhere in our systems.
Passwords are hashed with bcrypt. Sessions use signed, time-limited tokens. Data is encrypted in transit (HTTPS). Each teacher's studio data is isolated from every other studio. Backups are stored off-site and access-restricted. No system is perfectly secure, and we cannot guarantee absolute security.
You can update or delete your own account information at any time from Settings. Parents/students should contact their teacher to update or remove their information, since the teacher controls that data.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Questions about this policy: support@lessonbase.app