Cadence SM
Features For families Pricing Security About
Request early access
Features For families Pricing Security About Request early access

Legal

Privacy Policy — Cadence

Effective date: September 1, 2026

Last updated: September 1, 2026

Privacy contact: [email protected]


1. Scope and privacy roles

Cadence is a business-to-business platform that music studios use to manage scheduling, billing, lessons, and communications. This policy explains how we handle personal information in connection with Cadence.

Our role depends on the information and purpose involved:

  • Studio account and business information. We are the controller (or equivalent business) for information about our studio customers, their staff, and people who contact us directly. This includes account administration, contract administration, security, support, and legal compliance.
  • Family and student information entered by a studio. The studio determines why and how that information is used. The studio is ordinarily the controller (or business), and Cadence acts as its processor/service provider. We use that information only to provide, secure, and support the service, follow the studio’s documented instructions, and meet legal obligations.

If you are a family member or student, your studio is the best first contact for questions about its collection and use of your information. Our agreement with the studio governs our processing of that information.

2. Information we process

Depending on how Cadence is used, we may process:

  • Studio staff account information: name, email address, account role, and a one-way hashed password.
  • Family and parent information: name, email address, phone number, billing address, secondary-guardian and emergency-contact names and phone numbers, and payment-related identifiers. Payment-card data is processed by Stripe; Cadence does not store full payment-card numbers.
  • Student information: name or display name, optional nickname, birthdate, instrument, school, a one-way hashed access PIN, and learning/activity information that the studio records, such as practice sessions, assignments, attendance, gamification activity, and in-app messages.
  • Practice recordings: audio or video a student or teacher uploads, where enabled by the studio and subject to the studio’s applicable consent and authorization requirements.
  • Lesson transcriptions: transcript text generated on Cadence’s own server infrastructure. The source audio is not sent to a third-party transcription service and is deleted after transcript generation.
  • Service, support, and security information: audit records of sensitive actions, support communications, email delivery status, and limited error or diagnostic information necessary to operate and protect the service.

Cadence does not use advertising cookies, advertising pixels, cross-site behavioral advertising, session replay, or marketing analytics. We use essential browser storage and session technology to authenticate users and operate the Service. Our public forms use Cloudflare Turnstile for bot protection; Turnstile may process IP address and browser signals and may use cookies or similar browser storage needed for security. We also process limited error and diagnostic information needed to deliver and secure the Service.

3. How we use information

We use information to provide and administer Cadence; authenticate users; manage scheduling, attendance, billing, payments, learning, and family communications; provide support; maintain security and prevent fraud or abuse; meet legal obligations; and enforce our agreements. We may also use aggregated or de-identified information where permitted by law.

We do not sell personal information. We do not share student personal information for cross-context behavioral advertising, and we do not use student personal information to train external AI models.

4. Legal grounds for processing (EEA, UK, and similar laws)

Where these laws apply, our legal grounds for processing studio-account and business information may include performance of a contract, compliance with a legal obligation, and our legitimate interests in operating, supporting, and securing the service. Where consent is required, we rely on consent and it may be withdrawn as permitted by law.

For family and student information we process on a studio’s behalf, the studio is responsible for identifying the appropriate legal basis and providing any required notices. We process that information under our agreement with the studio and its documented instructions, except where law requires otherwise.

5. How information is disclosed

We disclose information only as needed to provide the service, comply with law, or protect Cadence, studios, families, and others. This may include:

  • the relevant studio and its authorized staff, families, and students, as configured by the studio;
  • service providers that perform hosting, storage, payment, email, calendar, diagnostic, and security functions for us;
  • professional advisers, insurers, auditors, and regulators where necessary;
  • law enforcement or other parties where required by law or reasonably necessary to protect rights, safety, or security; and
  • a buyer, investor, or successor in connection with a corporate transaction, subject to applicable law and contractual protections.

We do not permit service providers to use personal information for their own independent marketing purposes.

Studio leaderboards. If a studio enables a leaderboard, authenticated Cadence users in that studio may see each participating student’s rank, score, and the display name the studio selects. That display name may be the student’s full display name, first name and last initial, nickname, or pseudonym. A parent or guardian may ask the studio to opt the student out; an opted-out student is removed from leaderboard results.

6. Service providers

We use service providers that process information only as necessary for their services and subject to appropriate contractual safeguards. Our current providers include:

ProviderPurposeInformation involved
DigitalOceanApplication hosting and managed PostgreSQL databaseService data
CloudflareFile storage, static-site hosting, network, and TLS servicesUploaded files and web traffic
StripePayment processing and, where enabled, Stripe Connect payoutsBilling identifiers and payment tokens
ResendTransactional email deliveryRecipient email and message content
GoogleOptional studio-enabled calendar syncConnected calendar event details and encrypted OAuth tokens
SentryError monitoring and diagnosticsError metadata and request correlation IDs; not intended to include payloads or secrets
Cloudflare (Turnstile)Bot protection on public signup and lead formsIP address and browser signals on public forms only; no account or student data

The list of record is our subprocessor register; the table above is a snapshot current as of the “Last updated” date. We will update this policy if the list changes materially.

7. Children’s privacy

Cadence may process information about children on a studio’s behalf. Cadence is not directed to children for independent sign-up, and we do not use student information for advertising.

Cadence provides a parent-facing, scope-specific consent flow. A scoped child feature requires current consent for the relevant student and scope. The separate scopes cover: (1) student PIN access, practice logging, and gamification; (2) practice-recording uploads; (3) student-initiated messages; and (4) lesson transcription. For an online grant, an authenticated parent must review the versioned notice and grant consent. That grant records the notice version, typed signature, date and time, IP address, browser information, and a server-side verification basis. Online grants are accepted from the authenticated primary parent account after the parent reviews the notice, chooses the relevant scope, and enters their typed signature. A saved payment method is not used as a consent-verification method. Permitted studio owners and administrators may also separately record supported offline consent.

These product controls are designed to support a studio’s consent process; they are not a determination that any particular deployment satisfies every legal requirement. The studio has the direct relationship with the family and remains responsible for its own family notices and for obligations that cannot lawfully be delegated. Cadence also remains responsible for obligations that applicable law imposes directly on Cadence.

Parents or guardians should send requests concerning a child’s information to the studio. We assist studios in responding as required by our agreement and applicable law. Studios using Cadence remain responsible for determining whether COPPA, FERPA, GDPR/UK-GDPR requirements for children, or other children’s privacy laws apply to their practices.

8. Retention and deletion

We retain personal information for no longer than reasonably necessary for the purposes described in this notice, the studio’s instructions, our legal obligations, dispute resolution, and enforcement of agreements. Current product retention settings include:

  • Lesson transcript text: 30 days by default (the retention setting is deployment-configurable; a longer setting would be reflected in this policy); source audio is deleted after transcript generation.
  • Chat messages and attachments: one year, or shortly after a student is marked inactive, subject to a 48-hour reversal period for accidental deactivation. Completed student-erasure requests delete the student’s chat without that reversal period.
  • Financial records: invoices, charges, refunds, payouts, ledger entries, tax amounts, and payment-processor transaction identifiers are retained for seven years from the applicable transaction or invoice date. We retain payer names and billing addresses only where they form part of an issued invoice or other required accounting record, and restrict access to those records. Full payment-card numbers and CVV codes are never stored by Cadence. Payment-method tokens are held by Stripe and retained while needed for active billing, an open dispute, or an applicable accounting record.
  • Practice recordings: retained while the student is active and for no more than 90 days after the student is marked inactive. They are deleted sooner when an authorized user deletes them, when a student’s data is erased, or when the studio’s account is closed.
  • Student erasure: after the applicable 30-day grace period, identifying information is anonymized and recordings are purged, except information that must be retained by law or for valid recordkeeping purposes.
  • Login events (sign-in history): hard-deleted after 30 days. Enforced by code, and by two independent database-level floors rather than application logic alone: the role used for this prune (app_login_events_prune_job) holds a SELECT policy and a DELETE policy on login_events, both carrying the same 30-day floor, so that connection cannot read or delete a row younger than 30 days regardless of what the application computes.
  • Notification email content: the HTML body and subject line of a sent notification are cleared after 90 days; the notification record itself (type, recipient, timestamps) is retained separately. Enforced by code — a daily sweep prunes delivery HTML/subject content older than a fixed 90-day constant.
  • Logical database backups: encrypted dumps taken for disaster recovery are retained 14 days and stored off-site, then deleted by the retention step of the backup script. Enforced by operator procedure (a scheduled script run and its retention argument), not by a database-side constraint. This is distinct from the 7-day window described below for our managed database provider’s own automatic snapshots and point-in-time recovery, which follow the provider’s own retention rather than our backup script’s.
  • Recordings (practice recordings): retained while the student is active and for no more than 90 days after the student is marked inactive. Enforced by code — a fixed 90-day retention constant backs a daily per-org sweep that purges recordings once a student has been inactive that long.
  • Financial records (seven years): enforced by operator procedure, not by a code-level purge job or scheduled deletion. There is no job that deletes or ages out invoices, ledger entries, refunds, or payouts at any point — the seven-year figure describes how long we keep and rely on these records, not a timer that erases them afterward. Two structural features support the “we do not delete these early” half of the commitment: the ledger is append-only, and the role used for organization-purge processing is not granted any access to invoices, ledger line items, or refunds, so an org purge cannot reach financial records even in error.

Records that survive erasure. Some records are kept after a student’s data is deleted, for these reasons and no others. (1) Teaching records. Notes and assessments written by studio staff in their professional capacity are business records of the studio’s teaching practice. After erasure they are disconnected from the student’s identifying profile, restricted to studio administrators, and permanently deleted no later than three years after the student’s last activity with the studio. Staff-written text may occasionally mention a student by name; we restrict who can see these records rather than editing what teachers wrote. (2) Billing records, as described above, to meet tax and accounting obligations. (3) Consent records. We retain the consent notice version, typed signature, date and time, scope, status, revocation information, relevant verification basis, and associated security metadata for the family’s relationship with the studio plus five years, to document the consent process and our response to it. (4) Security records. Append-only logs of administrative actions are kept for up to seven years to investigate misuse and protect all families’ data. (5) Backups, as described below.

Backups. Information deleted from our active systems may remain in encrypted database backups and point-in-time-recovery records for up to seven days, after which those records expire. Backups are not our seven-year financial-record archive: financial records are retained in access-restricted active accounting records for their stated retention period. We do not use backups to restore deleted personal information. If a backup is restored as part of disaster recovery, deletion requests completed after that backup was taken are re-applied to the restored data before it returns to service.

We may retain de-identified or aggregated information.

Other operational Studio Data will be deleted or anonymized within 60 days after the Studio’s account expires or is terminated, subject to the exceptions above.

Your data, on request

A studio’s primary parent account may request a copy of their family’s data directly in the product. The request assembles the family’s account, guardians, students, enrollments and attendance, invoices and payment/refund history, chat messages the family can see, practice activity, consents, and notifications sent to the family’s users into a single file; recordings and uploaded files are included as time-limited links rather than embedded directly in the file. The file is available for download for 7 days, after which the link expires and the underlying copy is deleted. This is a self-service convenience for a family’s own data; it does not replace a studio’s or Cadence’s other obligations to respond to a privacy request described in Section 9.

Deliverability and suppression

To protect deliverability and to honor bounce and spam-complaint signals from our email provider, an email address that hard-bounces or is reported as unwanted is added to a suppression list and will not receive further email from Cadence until the suppression is cleared. The suppression list stores only the email address, the reason, and timestamps — no message content.

9. Your privacy choices and rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, or a portable copy of your personal information; to withdraw consent; or to appeal a decision about your privacy request where required by law. These are individual privacy rights; bulk export of a studio’s business data is addressed in the Terms of Service.

  • Families and students: contact your studio first. The studio controls student and family information and can submit a request to us where needed.
  • Studios and staff: contact us at [email protected].

We may verify your identity and authority before acting on a request. We will not discriminate against you for exercising applicable privacy rights.

10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These include tenant isolation at the database layer, access controls and audit logging, one-way password and PIN hashing, encryption in transit and at rest, and encryption for calendar tokens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. U.S. service and processing locations

Cadence offers the Service to U.S. studios. Our primary application and database infrastructure are hosted in the United States. Limited processing by our infrastructure providers may occur through their global networks or in locations determined by their service configuration, including Cloudflare’s network and object-storage services. See our subprocessor register for current provider and location information.

If we expand the Service to other regions or undertake processing that requires additional transfer safeguards, we will update this policy and implement the required safeguards before that activity begins.

12. Changes to this policy

We may update this policy from time to time. We will post the revised policy, update the “Last updated” date, and provide additional notice of material changes when required by law.

13. Contact

Questions or requests about this policy may be sent to:

[email protected]

Cadence SM

Studio management with a musician's sense of time.
Built inside a working music studio.

Product

Features For families Pricing Security

Company

About Contact Terms Privacy Children's Privacy Data Processing Addendum Subprocessors
© 2026 Cadence SM. No trackers in the product — and this site lists exactly what it loads.