Muzinity is operated by Muzinity LLC, a Nevada limited liability company (“Muzinity,” “we,” “us”). This Privacy Policy describes how we collect, use, share, and protect personal information. It is written to be read by studio owners, teachers, students, and families, not just by lawyers. If anything here is unclear, write to us at privacy@muzinity.com.
This policy covers two things:
- This marketing website (muzinity.com), which anyone can visit.
- The Muzinity application, the music-school management service that studios and schools subscribe to.
Students under 13 are covered by additional protections described in our separate Children’s Privacy Notice. That notice is part of this policy and controls where the two differ for children under 13.
Our role: we work for your music school
Muzinity is business software. Our customers are music schools and studios. When a school uses Muzinity, the school decides which people to enroll, what information to enter, and how long to keep it; Muzinity processes that information to provide the service to the school. If you are a teacher, student, or parent, your relationship is primarily with your school, and many requests (such as correcting your information) are fastest through your school’s administrator.
For children under 13, United States law (COPPA) treats Muzinity as an “operator” with direct obligations to parents. We take on those obligations ourselves; they are described in the Children’s Privacy Notice.
Information we collect
On this marketing website
This website is largely informational. If you type your email into the signup box, it is held briefly in your own browser (session storage) so the pricing page can prefill it; it is not transmitted to us at that point. If you choose a plan and begin signup, we pass the email address you entered, your chosen plan and billing cycle, and (if you used one) a referral code to the Muzinity application. We use Cloudflare Web Analytics, a cookieless, aggregate analytics service, to understand overall site traffic. We do not build visitor profiles, and we do not attach campaign, channel, or acquisition-source information to any account.
In the application: information your school and its members provide
- Account and profile information: names, email addresses, phone numbers, role in the school (studio owner, admin, teacher, student, parent), and preferred language. Birthdays are stored as month and day only. We deliberately never collect or store a birth year or full date of birth.
- Teaching and learning records: lesson schedules, practice logs (duration and notes), journal entries, school announcements and messages, uploaded teaching materials and library files, and practice reward points, achievements, badges, and stickers.
- Billing information: your school’s plan, billing cycle, subscription status, and invoice history. Payment card details are provided directly to our payment processor (Stripe) and are not stored on Muzinity’s servers.
Information about people who are not Muzinity users
- Trial-lesson booking: schools can accept public trial-lesson bookings from prospective families who have no Muzinity account. For these bookings we collect the student’s first and last name, an optional birthday (month and day only), an optional note to the teacher, and contact details: for an adult or teen booking, the student’s email and phone; for a young child, the parent’s name, email, and phone instead of the child’s. The booking form also records whether you opted in to email or text-message reminders and your acceptance of the school’s booking terms.
- Signup handoff: as described above, the marketing site passes only your email, chosen plan and cycle, and an optional referral code. The signup handoff does not carry acquisition-source information, and we do not attach it to any account.
Information collected automatically
- Sign-in and activity records: when your account was last signed in, and audit records of significant actions taken in the application (who did what, and when). Some audit records also capture the content an adult made visible to students; see “How long we keep information” below and the Children’s Privacy Notice.
- Technical and error data: if the application encounters an error, a report may be sent to our error-monitoring service. These reports are scrubbed before sending: email addresses, authentication tokens, card numbers, and similar personal fields are removed, and the report retains only an internal identifier used solely to support the service’s internal operations.
- Operational metrics: aggregate performance measurements (timings, counts) used to keep the service healthy. These are operational statistics, not profiles of individuals.
Fraud-prevention information for the referral program
If your school participates in our referral program, we compare limited information across accounts to prevent abuse: the verified identity behind each account, and a one-way cryptographic fingerprint of the payment method (derived from a fingerprint Stripe provides; we never see or store the card number itself). This lets us detect a person referring themselves or reusing the same payment method on both sides of a referral. The program rules are in the Muzinity Referral Program Terms, available to studio owners in the app under Billing & Membership.
How we use information
We use personal information to:
- provide and operate the service: scheduling, practice logging, progress tracking, messaging, libraries, and rewards;
- create and administer accounts and enforce role-based access within each school;
- send transactional messages that the service requires (invitations, consent notices, booking confirmations and reminders, billing and price-change notices, password resets);
- send optional email notifications, only to recipients who have turned them on (they are off by default for everyone);
- process subscriptions, invoices, credits, and refunds when payments are enabled;
- keep the service secure, prevent fraud and abuse, and maintain audit records;
- comply with legal obligations, including COPPA obligations to parents; and
- improve reliability using aggregate, non-identifying operational data.
In plain English, our bases for doing this are: performing our contract with your school; running our business in ways you would reasonably expect (security, fraud prevention, support); meeting legal obligations; and, for children under 13, verified parental consent.
What we do not do
These are commitments, not aspirations. They reflect deliberate product boundaries:
- We do not sell personal information. Not anyone’s, and never a child’s.
- We do not show advertising in the application, and we do not use anyone’s data for advertising or behavioral targeting.
- We do not track acquisition or marketing attribution against people. We do not attach “how you heard about us,” lead-source, or campaign-attribution information to any account, student, or family.
Service providers
We use a small number of service providers to run Muzinity. Each receives only the information needed for its function, and we require providers to use it only to provide their service to us. We describe them by specific category and purpose, except where you already interact with a provider directly: our payment processor and our hosting and analytics provider are named.
| Provider | What it does | What it may process |
|---|---|---|
| Authentication and account-management provider | Sign-in, accounts, school membership, invitations, password resets | Names, emails, authentication data |
| Stripe (payment processor) | Payment processing, invoicing, subscription billing | Payment card details (held by Stripe, not us), billing name and email, invoice data |
| Email delivery provider | Sending transactional and opted-in email | Recipient email addresses and message content |
| Text-message delivery provider | Text messages, used only for parental-consent notices and confirmations and for trial-booking reminders | Phone numbers and message content for those purposes |
| Cloudflare (website hosting, content delivery, network security) | Site hosting, content delivery, network security, aggregate site analytics | Network traffic passing through its systems; aggregate analytics only |
| Cloud database and file-hosting providers | Database hosting and file storage for uploaded materials | Application data and uploaded files, encrypted at the storage layer (US region) |
| Error-monitoring provider | Application error monitoring | Error reports with direct identifiers removed (emails, tokens, card numbers); an internal identifier is retained for internal operations only |
| Operational-metrics provider | Performance metrics and tracing | Aggregate performance data; no personal profiles |
Some supporting infrastructure (such as an in-memory cache) runs inside our own environment and is not a third-party recipient of your data.
AI features. Muzinity includes optional assistant features (for example, help importing a roster). These features are disabled by default across the platform. When enabled, they are designed to minimize the personal information involved, and staged data and chat transcripts are encrypted at rest. No personal information is sent to an external AI model provider unless we have first configured a provider under a data-processing agreement that requires no training on our data, United States data residency, and deletion when the engagement ends. No such external provider is currently in use. In the future we may engage an enterprise AI API provider on exactly those terms: acting only on our instructions as a service provider, for the purposes described in this policy, with no training on our data, United States data residency, and deletion when the engagement ends. If we do, we will update this policy’s provider disclosures.
We will update this list when providers change. If a change is material to how your information is handled, we will note it under “Changes to this policy.”
How long we keep information
We keep personal information only as long as needed for the purposes above, and we do not keep it indefinitely. In practice, information falls into a small number of retention classes:
- Deleted on erasure. When a person is erased (by their school, by themselves, or by a parent), their day-to-day records are deleted: practice logs, journal entries, notifications, settings, reward data, and their uploaded files (subject to the 30-day safety window described below).
- Deleted on a schedule. Some deletions run on a defined clock. The most important one: if a parent never responds to a consent request for an under-13 student, that student’s collected personal information is deleted within 30 days of the request. See the Children’s Privacy Notice.
- Retained as evidence, for a bounded time. A few records are kept because they prove something happened: consent records (kept as yes/no flags with personal details stripped), email delivery logs, billing and invoice records (kept as required for tax and accounting), and audit records. Audit records, including the safety audit trail of content adults made visible to students, are kept for a maximum of 24 months and are then permanently deleted on a rolling basis. Content a person authored that their school still uses (for example, a teacher’s shared materials) may keep a display-name snapshot after the author’s account is erased, with the underlying account removed.
- Legal holds. If we are legally required to preserve specific records (for example, for litigation), the applicable deletion clocks are suspended for those records until the hold ends.
The 30-day erasure safety window
Erasing a person is serious and mistakes happen, so every erasure first enters a 30-day restorable safety window: the person disappears from the school immediately, and a school administrator can restore the record within 30 days if the erasure was a mistake. After the window closes, deletion is permanent. Deletions required by law (such as the COPPA 30-day non-response deletion) run on their own schedules and are not extended by this window.
Security
We take security seriously and use measures appropriate to the sensitivity of the data, including:
- Tenant isolation: each school’s data is separated from every other school’s using database-level row security, enforced in the database itself, in addition to per-query checks in the application.
- Role-based access control: what a user can see and do is limited by their role; audit records are readable only by school administrators.
- Encryption: connections use HTTPS/TLS; stored data is encrypted at the storage layer by our cloud providers; certain sensitive staging data (such as roster-import working data and assistant chat transcripts) is additionally encrypted at the application level.
- Private file storage: uploaded files live in private buckets and are served through short-lived, expiring links.
- Scrubbing before error reporting: direct identifiers such as email addresses, authentication tokens, and card numbers are removed from error reports before they leave our systems; reports retain an internal identifier used solely to support the service’s internal operations.
- Tamper-evident audit records: audit records are append-only and cannot be edited or deleted by application users, enforced by the database.
- Rate limiting on public-facing endpoints such as booking and consent flows.
No online service can promise perfect security, and we do not. If we learn of a breach affecting your personal information, we will notify affected schools and individuals as required by law.
Children under 13
Muzinity serves music students of all ages, including children under 13. Children cannot sign themselves up; student accounts are created by a school administrator, and when the school indicates a student is under 13, a verified parental consent process is required before the student can use features that store their work. The full details, including what we collect from children, the consent process, and parents’ rights, are in the Children’s Privacy Notice.
Your choices and rights
- Through your school. Your school’s administrators manage your enrollment and most of your profile information. Corrections and most requests are fastest through them.
- Leave a school. You can remove yourself from a school in your account settings (“Leave this school”). Your records at that school are then erased, subject to the 30-day safety window and the bounded evidence retention described above.
- Delete your account. You can delete your entire Muzinity account in your account settings. This erases your information at every school you belong to and removes your sign-in identity. Two limits apply: a student under 13 whose account is consent-managed cannot self-delete (that right belongs to the parent, who can exercise it at any time), and the sole owner of a studio must first transfer ownership or contact us, so a school is not left ownerless by accident.
- Parents of children under 13 have review, revocation, and deletion rights described in the Children’s Privacy Notice.
- Email preferences. Optional email notifications are off by default and can be turned on or off per recipient at any time. Transactional messages required to run the service (such as consent notices and billing notices) are not optional.
- Anything else. Contact us at privacy@muzinity.com and we will help, whether or not your request fits a category above.
We are a United States service launching for United States schools. Whatever state you live in, you can contact us at privacy@muzinity.com and we will honor reasonable requests to access, correct, or delete your personal information, whether or not a statute requires it. If comprehensive state privacy laws become applicable to us as we grow, we will update this policy to describe the specific rights they provide.
Changes to this policy
We will update this policy as the product evolves and will note the date of the latest revision at the top. If a change materially reduces your rights or materially changes how we handle personal information, we will give studio owners advance notice (by email or in-app notice) before the change takes effect. For children under 13, material changes to what we collect or how we use it require new parental consent, as described in the Children’s Privacy Notice.
Contact us
- Privacy questions and requests: privacy@muzinity.com
- Legal notices: legal@muzinity.com
- Mailing address: Muzinity LLC, 5725 S Valley View Blvd Ste 5 #303183, Las Vegas, NV 89118
- Telephone: [Muzinity LLC telephone number to be inserted before publication]
Please also see our Terms of Service and Children’s Privacy Notice.