Muzinity is a music-school management platform used by studios and schools to organize lessons, practice, and progress. Some students who use Muzinity are under 13. This notice explains what information we handle about those students, how parents give and control consent, and the rights every parent has, consistent with the Children’s Online Privacy Protection Act (COPPA) and the FTC’s COPPA Rule (16 CFR Part 312). It supplements our Privacy Policy and controls where the two differ for children under 13.
Who we are and how to reach us
The operator responsible for children’s personal information collected through Muzinity is:
Muzinity LLC
5725 S Valley View Blvd Ste 5 #303183
Las Vegas, NV 89118
[Muzinity LLC telephone number to be inserted before publication]
Email: privacy@muzinity.com
Email is the fastest way to reach us. Your music school can also help with most requests, but the responsibilities in this notice are ours, and you can always come to us directly.
Children do not sign themselves up
Children cannot create their own Muzinity accounts. No account can be created on this website, and in the application, student accounts are created only by a school’s administrator. Whether a student is under 13 is indicated explicitly by the school’s administrator when the account is created; it is never derived from information collected from the child. We do not collect full birth dates from anyone: a birth month and day (never a year) may be entered by the school (or, for a trial-lesson booking, by the booking parent) for birthday display, and it is not requested from the child or used to determine age.
Many of the youngest students use parent-managed accounts that have no login and no email address at all: the parent is the account’s contact, and the child’s information is limited to what the school enters to run lessons.
When an administrator flags a student as under 13, the student’s account is placed in a limited state, and the parental consent process below begins before the student can use features that store their work.
What we collect from children under 13, and how
We collect the minimum needed to run music lessons. For a student under 13, the categories are:
- Name, and an email address where the student signs in with their own login (parent-managed accounts have no email or login);
- Practice logs and journal entries (duration and notes), used to track progress and provide feedback;
- Lesson schedule, used to coordinate lessons with teachers;
- Messages the student sends or receives within the platform; and
- Reward points and achievements earned, used for learning motivation.
How it is collected: the name, schedule, and account details are entered by the school’s administrator or teachers; practice logs, journal entries, and messages are created by the student’s own use of the platform after consent; reward points accrue automatically from practice activity. We do not collect geolocation, photos, voice recordings, or persistent identifiers used for advertising or cross-service tracking from children, and we do not use cookies to profile children.
Students in group lessons may appear to other members of their group and those members’ families by first name, along with practice tasks they finish, inside the school’s private space. Lesson materials are created and assigned by adults, not collected from the child.
Trial-lesson bookings for young children. When a family books a trial lesson for a young child through a school’s public booking page, the form collects the parent’s name, email, and phone number instead of the child’s contact information. The child’s information is limited to a first and last name and an optional birth month and day.
We never condition a child’s participation on extra data. A child’s participation in lessons and practice is never conditioned on disclosing more personal information than is reasonably necessary for those activities.
How we use children’s information
Only to provide the service to the child’s school: scheduling lessons, recording practice and progress, enabling teacher and school communication, and motivating practice through rewards. We do not use children’s information for advertising, marketing, profiling, or any purpose unrelated to music instruction, and we build no marketing or acquisition data about children or their families.
Our disclosure practices
- We never sell children’s personal information.
- We never make children’s personal information publicly available, and the platform gives children no way to make it public: there are no public profiles, no public posting, and messaging happens only inside the school’s private space.
- We show no advertising to anyone in the application, and we do not permit behavioral advertising or third-party tracking of children.
- We share children’s personal information only with the service providers that operate the platform itself, described by specific category and purpose in our Privacy Policy: our authentication and account-management provider (sign-in, where a child has a login); our cloud database and file-hosting providers (storing the school’s records and files); our email and text-message delivery providers (delivering consent notices, confirmations, and reminders to parents); and our error-monitoring provider (which receives only error reports from which personal details such as email addresses, authentication tokens, and card numbers have been removed; reports retain an internal identifier used solely to support the service’s internal operations). These providers may use the information only to provide their service to us, must keep it confidential and secure, and never receive it for their own purposes. We do not disclose children’s personal information to any other third party, except if required by law (for example, a lawful subpoena) or to protect a child’s safety.
- AI features and children. Muzinity’s optional assistant features are disabled by default, and no external AI model provider is in use today. If we enable such features in the future, we may use an enterprise AI service provider that would act only on our instructions, for the same purposes described in this notice, under a contract prohibiting training on the data, requiring United States data residency, and requiring deletion when the engagement ends: a service provider, not an independent user of the data. If AI features involving children’s personal information are ever enabled, we will update these disclosures first, and if the change is material we will obtain new parental consent before it applies to your child.
Because children’s information is used internally and shared only with these service providers, we are able to use the streamlined “email plus” consent method described below.
Parental consent: how “email plus” and “text plus” work
Before a student flagged as under 13 can use the features that store their work, a parent or guardian must give verifiable consent. The process:
- Direct notice. When the school creates a consent-required student account, Muzinity sends the parent a direct notice by email (or, where the school has provided a parent’s mobile number for this purpose, by text message). The notice describes exactly what information is or would be collected (the five categories above), how it is used, that parental consent is required before collection and use, the parent’s rights, how to consent, and that if the parent does not respond, the child’s collected information will be deleted.
- One-click affirmation. The parent consents with one click in that notice. The student’s access is restored immediately.
- Delayed confirmation (“plus”). About 24 hours later, the parent receives a follow-up confirmation of the consent, which includes a link to revoke it. This delayed second message is the “plus” step: it helps confirm the consent really came from the parent, since a child with brief access to a parent’s inbox would be unlikely to intercept both messages.
What a “gated” student can and cannot do. Until consent is given, a flagged student who has their own login can sign in and look around, but cannot use the features that store their work (such as practice logging and journal writing). Consent unlocks those features immediately.
If the parent never responds, the child’s collected personal information is deleted within 30 days of the consent request (the 30-day response deadline). This deletion is automatic.
If we materially change what we collect from children or how we use or disclose it, we will send parents a new notice and obtain new consent before the change applies to their child.
Parents’ rights
A parent or guardian has three separate rights, each available at any time, and each is independent of the others:
- Review. You can review the personal information collected about your child. Through your own Muzinity parent account you can see your child’s practice, progress, and journal; to review everything we have collected, ask your music school or contact us at privacy@muzinity.com. We will verify that you are the child’s parent before providing records: for example, by confirming that the request comes from the parent email address (or phone number) on the child’s consent record, and by asking for additional confirmation where a request is unusual or sensitive.
- Revoke consent (stop collection and use). You can revoke consent using the revoke link in the confirmation message or the consent management page in the app. Revoking stops Muzinity from collecting or using your child’s information going forward and locks the features that store the child’s work. Revoking does not by itself delete information already collected; that information is held, unused, for a bounded wind-down and is covered by the deletion right below. We keep revocation separate from deletion so that revoking, and later changing your mind, does not destroy your child’s practice history.
- Delete. You can require deletion of your child’s account and collected personal information, using the account deletion option in the app or by asking your music school. For a consent-managed student under 13, the deletion right belongs to the parent: the child cannot delete (or accidentally delete) their own account. Deletion arms a 30-day undo window (the same window the Privacy Policy calls the erasure safety window) during which the school can cancel a mistaken request; after the window, deletion is permanent. Deletion erases the child’s information at every school the child belongs to.
Exercising any of these rights, including refusing further collection, does not require you to pay anything, and a school may not condition a child’s participation in lessons on your waiving them. If the school’s relationship with the family ends, the school can also erase the child’s records; the same undo window applies.
The safety audit record, disclosed plainly
One category of records survives deletion for a bounded time, and we want parents to understand it rather than find it in fine print.
Muzinity keeps an append-only audit record of content that adults made visible to students: announcements, lesson notes, and journal tasks that a teacher or administrator created, edited, or deleted, together with who could see them at the time. This record exists for child-safety accountability: if a question ever arises about what an adult communicated to a student, the school’s administrators (and only they) can answer it, and no one can quietly edit or erase the trail. Concretely:
- it records content authored by adults and shown to students, not the child’s own practice logs or journal entries;
- it is access-controlled (readable only by the school’s administrators), append-only (the database blocks edits and deletions), and every export of it is itself audited;
- it survives consent revocation and account deletion, so an erasure cannot be used to destroy evidence of adult-to-student communication; and
- it is automatically and permanently deleted on a rolling basis after a maximum of 24 months, so nothing in it is retained indefinitely.
Consent records themselves are kept only as yes/no evidence flags with personal details stripped. A parent phone number provided for text-message consent is stored only with the consent record, never on the child’s profile, and is removed when the consent record’s personal details are stripped.
How long we keep children’s information
We retain a child’s personal information only as long as reasonably necessary for the specific purposes it was collected for (running the child’s music lessons at their school), and never indefinitely. In practice:
- While the child is an active student, the five categories above are retained so the service works: schedules and messages for coordination, practice logs and rewards so the child’s progress history is available to the child, parents, and teachers.
- On deletion (by the parent, or by the school when the relationship ends), the child’s personal information is erased after the 30-day undo window described above.
- On non-response to a consent request, collected information is deleted within 30 days of the request (the 30-day response deadline). These are two separate 30-day periods: the response deadline is how long a parent has to answer a consent request before automatic deletion; the undo window is how long a mistaken deletion can be reversed.
- On revocation of consent, collection and use stop immediately; retained information is held only for a bounded wind-down and remains subject to the parent’s deletion right.
- The safety audit record described above is deleted on a rolling basis after at most 24 months. Email delivery logs (proving a consent notice was sent) and stripped consent-evidence flags are kept as compliance evidence for as long as we are required to demonstrate compliance, and contain no more than that evidence requires.
Contact
Questions about this notice, or requests concerning your child’s information, can be sent to the studio or school that manages your child’s account, or directly to Muzinity at privacy@muzinity.com. Please also see our Privacy Policy and Terms of Service.