Privacy Policy
Last updated: 2 October 2026
Effective date: [EFFECTIVE DATE]
EtudeSpark is operated by Timbre Foundry Pty Ltd (“EtudeSpark,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, retain, and protect information that identifies or can reasonably be linked to a person (“Personal Data”) through the EtudeSpark teacher web service, iOS application, websites, and related support services (together, the “Service”). Personal Data includes “personal information” as that term is used in applicable privacy laws. A “User” is an adult account holder who uses the Service. A “Guardian” is an adult authorized to manage a child's use of the Service, and a “Teacher” is an adult music educator or studio operator. Children use adult-managed profiles and are not independent account holders.
1. The account and family model
Only an adult Teacher or Guardian may register an EtudeSpark account. A Guardian confirms their authority to manage a child's use and Personal Data when they add or claim that child.
If the Premium Repertoire Vault is launched, a family account has one primary Guardian. Only that Guardian may buy, restore, bind, or manage the subscription. A currently linked co-Guardian may use the family's Premium access only for a child to whom that Guardian is linked; they do not need a separate subscription and do not gain access to another child merely because they are linked to the primary Guardian. A family may have no more than four covered children. This is EtudeSpark family access, not Apple App Store Family Sharing.
Children do not receive independent usernames, email-address logins, or passwords. A child uses a profile connected to an adult-managed relationship. Before a Guardian joins, a Teacher may create a limited unclaimed roster placeholder containing only a first name or alias, instrument, and broad practice level. Its purpose is to organize the Teacher's private roster, prepare teaching assignments, and invite a Guardian. It is not a child account or an active child-facing profile. Until a Guardian claims it, the child cannot use it and EtudeSpark blocks practice telemetry, recordings, server audio, device registration, YouTube access, contact information, and other child-generated data from being attached to it. EtudeSpark does not ask a child for an email address, telephone number, postal address, date of birth, or independent login credential.
Sharing an existing child's profile. A linked Guardian can create a temporary QR code and equivalent link. A recipient signs in with Apple, separately accepts data-processing terms and attests their authority, and explicitly requests access. Every new co-Guardian membership requires approval by the still-linked sharing Guardian or the child's current primary Guardian. Signing in, possessing a code, supplying a name or relationship, and using any email address do not establish authority or grant access. Before approval, the recipient receives no child name, identifier, photograph, teacher details, or activity through this flow. Only authorized decision-makers see the pending request's self-declared identity details; the requester can check their own status.
Adding an already linked Guardian to a new child. When creating another child, the primary Guardian may explicitly select a Guardian who is currently linked with them to a different child. After a device-owner check, that selected Guardian receives access to the new child's profile immediately. The server confirms the existing shared-child relationship and the primary Guardian's authority for the new child. This flow does not use a QR code or send a new access request, and it does not record a new consent or authority attestation from the added Guardian for the new child. The primary Guardian's child-creation consent and authority attestation are recorded separately. Other children are not shared automatically.
The code admits new requests for 15 minutes. A timely request has its own 24-hour approval deadline. Cancellation, replacement, removal of the sharing Guardian, or approval of another request invalidates unresolved requests under that code. Canceling a code does not remove access already approved. The server stores a token hash, and the app keeps the raw code in memory while needed. Closing the screen clears its copy but does not cancel a link already sent. Links copied into other applications and screenshots cannot be recalled.
The authenticated sharing screen shows the child's existing avatar, photo, or initials and name to help the sharing Guardian identify the correct profile. Anyone viewing or photographing that screen can see those details. The encoded QR and Share link contain only an opaque capability URL, without child information. Public landing pages and link previews remain generic. If the app was not installed when the link was opened, the recipient must reopen it after installation or obtain a fresh code.
2. Children, parental consent, and the device-owner gate
EtudeSpark is designed to be used by children only with adult involvement. Guardians control child profiles, sharing, teacher relationships, optional audio uploads, and third-party video consent. Teachers must not use EtudeSpark to bypass a Guardian, collect unnecessary child data, or direct a child to create an account.
The iOS app uses Apple's LocalAuthentication system as a device-owner gate for specified sensitive actions, including creating and displaying a child-profile sharing code, adding an already linked Guardian to another child, approving or declining co-Guardian access requests, deleting an account, signing out, removing a child, withdrawing a teacher relationship, withdrawing data-sharing consent, and deleting uploaded audio. The operating system may satisfy the check with Face ID, Touch ID, or the device passcode. EtudeSpark receives only the success or failure of that check. We do not receive, store, or transmit a face scan, fingerprint template, or device passcode.
The gate is an additional family-safety control. It does not independently prove that the person is the child's legal guardian, replace legally required verifiable parental consent, or lock every Settings or Family screen. Third-party-video consent is not subject to this device-owner gate.
Where the US Children's Online Privacy Protection Act (“COPPA”) applies, we will provide the required direct notice and obtain verifiable parental consent before collecting Personal Data online from a child under 13, unless a legal exception applies. A Guardian may review a child's Personal Data, revoke consent, refuse further collection, and request deletion by using the controls described below or contacting us. We will not require a child to disclose more Personal Data than is reasonably necessary to participate in an activity.
Where the EU or UK GDPR applies, a Guardian must authorize consent-based processing for a child below the applicable national age of digital consent. That age varies by country. We may use other lawful bases where permitted, such as performing our contract with the adult account holder, complying with law, or our legitimate interests in security and operating the Service, provided those interests do not override a child's rights.
3. Information we collect
We collect the following categories of Personal Data when relevant to the features a User enables. We obtain it from Users and linked adults, from activity in the Service, and from authentication, device, payment-entitlement, and video providers where applicable. A field may be absent when it is optional or a feature is disabled.
A. Adult Teacher and Guardian account information
- account and studio identifiers, and the Firebase authentication identifier and provider;
- name, email address, and role (Teacher or Guardian);
- adult-eligibility confirmation, account timestamps, and the accepted Terms and Privacy Policy versions with acceptance time and signup source;
- time zone;
- for Teachers: studio name, optional public profile and publication setting, profile and studio images, teaching focus, calendar preferences, and deletion schedule;
- for child-profile sharing: the sharing Guardian and requesting account, a temporary requester-name snapshot and optional self-declared relationship, sharing/request status and deadlines, and approval or decline outcomes; no recipient email address is collected for this flow; and
- device registration information if push notifications are enabled, such as a push token, platform, and associated child profile.
Firebase processes login credentials. EtudeSpark's Cloud SQL database stores the Firebase identifier, not the adult's password hash. Apple also processes information when an adult uses Sign in with Apple.
B. Child profile and relationship information
- child profile identifier, display name, optional nickname, and an optional selected animal avatar ID;
- the Teacher who created an unclaimed roster placeholder, and any merge or pseudonymization state;
- Guardian relationship, permissions, and request/link/remove status;
- Teacher enrollment status, origin (Guardian request or unclaimed roster placeholder), instrument, level, and dates; and
- append-only consent records: the child, consent type, granted or withdrawn state, the adult actor, and the time.
The app does not ask for a child's date of birth or collect it for experience styling. We also do not collect a child's independent email address, password, telephone number, or postal address. A primary linked Guardian may select a pre-made animal avatar, initials, or an optional profile photo. Selecting a photo uploads a small JPEG thumbnail to EtudeSpark's database. Image metadata is removed before storage. Linked Guardians and Teachers with an active enrollment can view the shared profile image through authenticated requests. The authenticated sharing screen may also display it inside a QR code, as described above; public landing pages do not display it. Choosing an animal or initials, removing the photo, or deleting or pseudonymizing the child profile removes the stored thumbnail. Other Guardians and Teachers cannot upload or replace the child's photo. Authorized viewers may save screenshots; removing access cannot recall copies they have already saved.
Instrument and level are stored on the child–Teacher enrollment rather than on the child profile, because they describe that teaching relationship rather than the child. Consent, assignments, lessons, sessions, takes, and other feature records are stored in separate child-linked records described below.
C. Music-learning, assignment, and studio information
- assignments and practice units: the piece or catalog reference, category, stage, focus points, target tempo, status, and associated dates;
- practice instructions (Spots): labels, measure ranges, repetition goals, and tempo;
- repertoire and bookshelf records: work, composer, book identifiers, notes, and showcase selections;
- teacher-created reference recordings: title, status, duration, and associated analysis;
- Teacher lesson schedules: dates and times, time zone, recurrence, duration, format, location, status, and cancellations;
- Guardian-managed family lesson plans for a child without an active Teacher: first lesson, time zone, duration, and one-to-four-week recurrence. A saved plan is kept while a Teacher is connected and can resume afterward;
- practice goals and practice sessions: dates and times, active practice time, goals, the assignments engaged, and an optional 1–5 effort rating;
- lesson-save flags; and
- studio payment reminders: the schedule and due dates, lesson count, label, optional amount, private Teacher note, and reminder status. EtudeSpark does not use these records to process tuition payments or store payment-card numbers.
D. Practice recordings and analysis
If recording is used, the app stores the take's identifier, the child and assignment it relates to, recording time and duration, and technical analysis of the performance such as alignment and coverage measurements.
Raw practice audio is held on the device. Before any longer-term storage or sharing, on-device processing attempts to detect and remove speech, and the app provides review, trim, and mute controls. The Guardian must review the retained selection and remove unintended speech before approval. Automated detection and human review reduce the risk of voice disclosure but cannot guarantee that a recording contains no voice or other identifying sound.
Free tier. Processed performance audio remains on the Guardian's device only. It is kept there for a limited period and is excluded from device backups, so it does not transfer to a replacement device or to the Guardian's iCloud account. EtudeSpark does not upload or store free-tier performance audio on its servers, and Teachers cannot play it through EtudeSpark. EtudeSpark may sync non-audio practice metadata and derived metrics, such as take count, recording duration, recording time, assignment association, and practice-analysis results. A Teacher may see the metrics made available for an enrolled child but does not receive the audio or a transcript.
Premium tier, if offered. The Premium Repertoire Vault is audio-only. It may receive only a frozen, voice-redacted audio render after an active covered-family entitlement, the primary Guardian's separate consent to vault storage for the child, and a Guardian's approval tied to that exact render. A payment is not consent or approval. Authorized Guardians may access their linked children's recordings; Teachers can see practice metadata but cannot play a child's take through the Service.
E. Reference videos and YouTube information
EtudeSpark stores a curated reference-video record containing the platform, validated YouTube video ID, editorial label and prompt, status, link, and curation history. We do not store a child's YouTube account, YouTube search history, per-child viewing history, or OAuth token, and our server does not download YouTube media.
After an adult enables third-party video for a child and the user chooses to load a video, the app loads an official YouTube IFrame player from youtube-nocookie.com. Google/YouTube may directly receive information including IP address, device and browser/WebView data, cookies or similar storage, video interaction, and advertising information. See Section 8.
F. Technical, security, and support information
- request, session, calendar-feed and audit records: the actor, action, affected record, and time;
- device/app configuration, Remote Config values, operating state, network and diagnostic events, security events, and error logs;
- account-deletion receipts containing a hash of the authentication identifier, role/provider, deletion states, counts, external-service outcomes, failures, and times;
- first-party onboarding interactions for newly created child profiles: setup steps, practice starts and saves, help use, hint dismissals, timestamps, active-use time, and random onboarding identifiers. These events exclude names, piece-title text, and audio; authenticated delivery verifies the Guardian’s access to the child; and
- information you provide in a support, privacy, copyright, or safety request.
The iOS app uses Firebase Authentication and Firebase Remote Config. It does not use a third-party analytics or crash-reporting SDK. We will update this Policy before materially changing that practice.
4. How we use information
We use Personal Data to:
- authenticate adults, confirm legal-age account eligibility, and maintain accounts, studios, child profiles, and authorized relationships;
- deliver assignments, schedules, practice tools, optional recordings, reference videos, reminders, and progress features;
- display a selected animal avatar to linked Guardians and the active Teacher to help them recognize the child profile;
- let Guardians control consent, sharing, teacher access, and deletion;
- operate, secure, debug, support, and improve the Service;
- prevent fraud, abuse, copyright infringement, unauthorized access, and child-safety risks;
- provide portability, deletion, and other privacy responses;
- enforce our Terms, preserve evidence for disputes or legal holds, and comply with law; and
- communicate service, security, support, and account notices.
We do not use a child's Personal Data for EtudeSpark behavioral advertising. We do not sell Personal Data or share it for EtudeSpark cross-context behavioral advertising. Google/YouTube may process data independently when someone loads a video, as described in Section 8.
5. Legal bases in the EEA and UK
Depending on the activity, we rely on:
- contract: to provide the Service requested by the adult account holder;
- consent: for activities such as optional child audio upload, optional third-party video, and other processing where law requires consent;
- legitimate interests: to secure, maintain, troubleshoot, and improve the Service, prevent misuse, and communicate about it, balanced against the rights of adults and children; and
- legal obligation or legal claims: to comply with law, answer valid requests, and establish, exercise, or defend claims.
A person may withdraw consent at any time. Withdrawal does not make earlier lawful processing unlawful. If processing is necessary to provide a requested optional feature, that feature may stop after consent is withdrawn.
6. When we disclose information
We disclose Personal Data only as reasonably necessary to:
- Teachers and Guardians: within authorized studio, enrollment, invitation, and family relationships. Teachers may receive practice metadata for enrolled children, but cannot play child-take audio through the Service. Guardians control optional storage choices;
- Google Cloud and Firebase: for hosting, database storage, authentication, configuration, security, and operational infrastructure;
- Cloudflare: for private Premium Repertoire Vault storage, if offered, and any separately configured static-content or security services. Premium child audio is not served through a public storage domain or global edge cache;
- Apple: for Sign in with Apple, operating-system authentication, and App Store purchases if subscriptions are offered;
- Google/YouTube: when a User loads a YouTube reference video, as described in Section 8;
- service providers and professional advisers: under contracts and confidentiality duties for hosting, security, support, communications, legal, accounting, and compliance functions;
- authorities or affected parties: when reasonably necessary to comply with law, protect a child or another person, investigate misuse, enforce agreements, or protect rights and security; and
- a transaction successor: in a merger, financing, reorganization, or sale, subject to appropriate notice and protections.
Teachers are responsible for their own handling of information they obtain outside EtudeSpark and for complying with professional, school, studio, safeguarding, and privacy duties.
7. International transfers and storage locations
We host application and database Personal Data in [PRIMARY HOSTING COUNTRY AND REGION]. If the Premium Repertoire Vault is offered, approved audio is stored and processed in [PREMIUM AUDIO STORAGE COUNTRY]. Apple, Google/YouTube, support, and other providers may process Personal Data in other countries under their own arrangements.
Australian Users. Personal Data, including Premium audio if a User chooses that feature, may be transferred to, stored, and processed outside Australia in the locations described above. When Australian Privacy Principle 8 applies to an overseas disclosure, we take the steps required by that principle.
EEA and UK Users. Where Personal Data is transferred outside the EEA or UK, we use an applicable lawful transfer mechanism and any required safeguards. Contact us to request information about the safeguards that apply to your Personal Data.
8. YouTube API Services and Google
Where the video feature is available, EtudeSpark uses YouTube API Services, specifically the YouTube IFrame Player API, to display curated reference videos.
By using the YouTube features in EtudeSpark, Users agree to be bound by the YouTube Terms of Service. Information Google receives is subject to the Google Privacy Policy.
The player is not loaded merely by opening an assignment. It is loaded only after third-party-video consent is active and a person chooses to load a video. We use YouTube's privacy-enhanced embed domain, require an action to start playback, disable picture-in-picture, stop playback when the app is not active, and tear down the player when leaving. The WebView uses persistent website storage, so these measures do not eliminate cookies, local storage, network disclosure, Google processing, or ads. EtudeSpark does not block or modify YouTube advertisements or player controls, download YouTube media, or reward people for watching videos.
A Guardian can turn off third-party-video consent in the Family controls, after which EtudeSpark withholds the playable reference from the child's assignment. EtudeSpark does not request YouTube OAuth access or store Google Authorized Data. If a User has separately connected a Google account to another service, they can review that access at the Google Security Settings page. Revoking Google authorization does not delete EtudeSpark account information; use the deletion methods below as well.
YouTube may display links or controls that open content outside EtudeSpark. Google/YouTube determines its own data practices, content, ads, and availability under its terms and policy.
Google/YouTube may set cookies or use similar storage after a User loads the player. Their retention periods are governed by Google's policies and the User's device and browser settings. EtudeSpark does not control those periods.
9. Retention
We keep Personal Data only for the period reasonably necessary for the purposes above, subject to legal, safety, dispute, backup, and audit requirements. We set periods by data type, purpose, the User's choices, and applicable law.
- raw audio never leaves the device. A local-only or unconfirmed voice-redacted take is retained for at least 30 days from capture unless the Guardian deliberately deletes it or device/app data is erased. A confirmed Premium copy may permit guardian-authorized local offload. The app may delete media due for removal on its next available execution opportunity; it does not silently evict in-window media to make room for a new recording;
- free-tier performance audio is not retained on EtudeSpark servers, and it is not retained in any device backup. After the on-device retention period it is deleted from the device and only non-audio practice metadata remains. Because the audio never leaves the device, lost, replaced, or erased devices do not restore it;
- Premium server storage, if offered, is limited to the consented, per-render-approved, voice-redacted audio described above. Confirmed audio remains in standard storage for 365 days and then moves to lower-access storage. It is not subject to time-based terminal deletion and is not promised to be permanent. It may be deleted after withdrawal of vault-storage consent, an explicit take/child/family/account deletion, a valid legal requirement, or a later policy change with prospective notice and any required consent;
- if Premium access lapses, authorized linked Guardians can stream confirmed audio for 60 days after paid access ends. After that, it remains stored but locked until renewal, subject to the deletion events above. Lapse does not itself delete local or operator-held audio;
- temporary requester-name and relationship snapshots are erased when a request is approved, declined, canceled, superseded, or otherwise resolved. At its 24-hour deadline they become unavailable to resolvers and are erased by the next retention sweep. A relationship copied into an approved membership remains ordinary membership data. Request/session identifiers, deadlines, consent/authority evidence, and outcomes follow the existing audit and account/profile deletion rules. Admission abuse counters contain only an account identifier, minute window, and count; windows older than an hour are removed at the next retention sweep and account deletion removes them;
- an unclaimed roster placeholder enters a staged restriction and pseudonymization process after inactivity; default milestones include dormancy at 90 days, minimization at 180 days, and later pseudonymization, subject to disputes and legal holds;
- account, studio, assignment, lesson, practice, reminder, consent, audit, and relationship records are kept while needed to provide the Service and for reasonable legal, accounting, safety, and dispute periods; and
- deletion receipts retain a limited authentication reference and operational outcomes needed to prove and finish deletion without retaining the deleted account profile.
Short-lived operational copies, deletion queues, and backups may remain until their normal deletion cycles complete. We isolate data from ordinary use while deletion is being completed, where appropriate.
10. Security
We use measures designed to protect Personal Data, including adult authentication through Firebase, device-owner checks for specified iOS actions, private network access for Cloud SQL, encryption in transit, cloud encryption and key management, signed short-lived media links where applicable, consent checks, audit records, audio redaction, and deletion workflows.
No method is perfectly secure. Adults should secure their devices and accounts, use strong unique credentials, review linked Teachers and Guardians, and report suspected misuse to [SECURITY EMAIL].
11. Your privacy choices and rights
Subject to applicable law, an adult account holder or authorized Guardian may request:
- access to and a copy of Personal Data;
- correction of inaccurate information;
- deletion or de-identification;
- data portability in a commonly used format;
- restriction of or objection to certain processing;
- withdrawal of consent;
- review of a decision made solely by automated means, where applicable; and
- information about disclosures, categories, sources, purposes, and retention.
Family record download. A Guardian can obtain a structured JSON file containing their account details and legal-acceptance record and, for each linked child:
- the profile, connected adults and Teachers, and consent history;
- assignments, practice spots, sessions, goals, milestones, showcase selections, and bookshelf records;
- recording descriptions, Teacher lessons, any saved Guardian-managed family lesson plan, and payment due dates.
The file excludes a Teacher's private notes and lesson locations, security tokens, network and device details stored with consent events, and other adults' email addresses and account identifiers. Recordings are described, not embedded; the file has no audio bytes, signed links, or object keys. A Guardian may separately request access to operator-held Premium audio, if offered, through the verified privacy-request process. We cannot provide audio that exists only on a User's device.
In-app controls. A Guardian can manage consent and relationships in Family settings. Uploaded audio can be revoked or deleted behind the device-owner gate. A Guardian can delete their account in iOS Settings; the app performs device-owner authentication and recent-authentication checks before sending the request. Depending on relationships and legal needs, removing a child may detach the Guardian, delete family-only information, or pseudonymize the child while retaining limited Teacher records. Deleting an EtudeSpark account does not cancel an Apple subscription.
Teacher controls. A Teacher can download the studio-record CSV available in CRM account-deletion settings. A Teacher may request immediate deletion or a scheduled seven-day deletion; access is suspended during the waiting period. Some tenant anchor, family, accounting, dispute, or safety records may be pseudonymized or retained when deletion of another person's records would be inappropriate.
Privacy requests. Email [PRIVACY EMAIL] with the adult account email, the request, jurisdiction, and the child profile involved, if any. Do not send identity documents unless we ask through a secure process. We may verify identity and authority, narrow or deny a request where permitted, and explain our decision. We will respond within the period required by applicable law. An authorized agent may submit a request where law permits; we may require proof of authorization and verify the User's identity.
EEA/UK residents may complain to their local data-protection authority. Australian residents may complain to the Office of the Australian Information Commissioner after first giving us a reasonable chance to respond. California residents may complain to the California Privacy Protection Agency or Attorney General.
California notice
California residents may have rights to know and access, correct, and delete Personal Data; to obtain information about its categories, sources, purposes, recipients, and retention; to opt out of sale or sharing; to limit certain uses of sensitive Personal Data; and to be free from discrimination for exercising rights. EtudeSpark does not sell or share Personal Data for its own cross-context behavioral advertising. If our practices require an opt-out, we will provide the required controls and honor applicable opt-out preference signals. Google/YouTube independently processes information when its player is loaded, as described above.
12. Automated analysis
The Service may calculate practice and audio indicators such as tempo, coverage, repetition, alignment, or possible voice segments. These are coaching aids, may be inaccurate, and are not used to make legal or similarly significant decisions about a child. Adults and Teachers should use judgment rather than treating automated output as an assessment of ability, character, or eligibility.
13. Third-party links and services
The Service may link to Apple, Google, YouTube, a Teacher's public page, or other services. Their privacy practices are governed by their own notices. EtudeSpark is not responsible for a third party's independent service, content, or privacy practice, but this does not limit rights that cannot lawfully be excluded.
14. Changes to this Policy
We may update this Policy to reflect changes in the Service, law, or providers. We will post the updated date and provide additional notice or obtain renewed consent where required, particularly before materially changing how children's Personal Data, recordings, or YouTube features are used.
15. Contact us
Questions, child-safety reports, privacy requests, and complaints may be sent to:
Timbre Foundry Pty Ltd / EtudeSpark
[REGISTERED POSTAL ADDRESS]
[PRIVACY EMAIL]
[PRIVACY TELEPHONE]
We will investigate complaints and respond within a reasonable period. Nothing in this Policy limits any non-waivable privacy or consumer right.