Privacy Policy

Last updated: July 16, 2026 · Draft (pending legal review)

This Privacy Policy describes how Sonotempo collects, uses, and discloses your information, and your privacy rights. Sonotempo is operated by Vastocielo LLC.

Because Sonotempo serves music students who may be children under 13, this policy includes a Children's Privacy section that complies with the Children's Online Privacy Protection Act (COPPA). If you are a parent or guardian, please read that section carefully.

Interpretation and Definitions

Words with initial capitals have the meanings defined below, whether singular or plural.

Information We Collect

From Teachers and Guardians (adults)

About Students (including Children)

Student information is provided by the Guardian, the Teacher, or — where a Guardian has permitted an older Student to have their own login — by the Student. See the Children's Privacy section for the complete description of information relating to Children, how We use it, and Guardian rights.

Usage Data (collected automatically)

Our application does not use advertising identifiers, device fingerprinting, third-party analytics, or cross-site tracking, and does not itself store unique device identifiers.

Our infrastructure Service Providers may automatically log standard technical data at the platform level in order to operate and secure the Service — for example, IP address, browser type and version, timestamps, and diagnostic/error data (Supabase for authentication, Vercel for hosting, Sentry for error monitoring). This data is used only to operate, secure, and debug the Service.

Cookies

We use only essential and functional cookies:

We do not use advertising cookies, analytics cookies, web beacons, tracking pixels, or similar tracking technologies. You can instruct your browser to refuse cookies, but parts of the Service may not function without essential cookies.

How We Use Your Personal Data

We use Personal Data only to operate the Service:

What We do not do. We do not sell Personal Data. We do not run advertising and do not share data with ad networks or data brokers. We do not use behavioral tracking. We do not permit any Service Provider to use Personal Data to train artificial-intelligence models or for any purpose of its own.

Service Providers (with whom data is shared)

We share Personal Data only with the Service Providers below, only so they can perform services that operate Sonotempo, and not for any independent purpose of theirs. Each is bound by contractual terms restricting its use of the data. We do not share Personal Data with affiliates, business partners, or third parties for advertising, promotional, or other outside purposes.

Service ProviderCategoryPurposePersonal Data involved
Anthropic, PBCAI processingGenerating lesson plans and pre-lesson briefs at a Teacher's requestStudent educational records (see Children's Privacy section for the exact items). Anthropic is contractually prohibited from training its models on this data and deletes API inputs/outputs within its standard retention window.
ResendTransactional emailDelivering service emails (reminders, confirmations, notifications)Recipient email address; may include a Student's first name and lesson details in the email body
StripePayment processingTeacher subscription billingTeacher billing details only; no Student data
SupabaseDatabase, authentication & storage infrastructureHosting the Service's data and login systemAll Service data; platform-level authentication logs (IP address)
VercelApplication hostingRunning the Sonotempo applicationPlatform-level request logs (IP address, request metadata)
SentryError monitoringDiagnosing application errorsTechnical error data; configured to exclude personal content and identifiers

We may also disclose Personal Data where required by law, to respond to valid legal process, to enforce our agreements, or to protect the rights, property, or safety of the Company, our users, or the public.

What Other Users Can See

Sonotempo has no public areas and no content feed. Nothing a Student does on Sonotempo is published publicly by default.

Retention of Your Personal Data

We retain Personal Data only as long as reasonably necessary for the specific purposes for which it was collected, and We do not retain Children's Personal Data indefinitely. Our written data retention policy, including the schedule for Children's data required by 16 CFR § 312.10, is set out in the Children's Privacy section below and applies as stated there.

For adult (Teacher and Guardian) data:

We may retain data beyond these periods only where required by law, to resolve disputes or enforce agreements, or in encrypted backups pending routine deletion cycles. When retention ends, data is deleted or anonymized.

Delete Your Personal Data and Your Rights

You may update or delete your information from within your Account settings, or contact Us at support@sonotempo.com to request access to, correction of, or deletion of your Personal Data. Guardians have additional rights over their child's data described in the Children's Privacy section. We may retain certain information where We have a legal obligation or lawful basis to do so.

Depending on your state of residence, you may have additional rights under state privacy law. Sonotempo does not sell or share Personal Data as those terms are defined under such laws.

Children's Privacy (COPPA)

Sonotempo is a platform where independent music teachers work with their students. Some students are children under 13, so we comply with the Children's Online Privacy Protection Act (COPPA). This notice explains — in plain language — what information we collect relating to your child, how we use it, who else touches it, how long we keep it, and the rights you have as a parent or guardian.

The short version: your child participates only through your guardian account and with your consent. You can see everything your child does on Sonotempo. We collect only what the music-lesson service needs, we never sell it, we show no ads, and no company we work with may use your child's data for its own purposes — including training AI models. You can review or delete your child's information, or stop collection entirely, at any time.

Who we are (the operator)

Vastocielo LLC is the sole operator collecting personal information through Sonotempo and responds to all parent inquiries.

How children participate: Guardian Accounts

A child cannot sign up for Sonotempo. Instead:

What information we collect relating to your child

Provided by you or your child's teacher:

Created through using the service:

Only if you have permitted your child to have their own login (collected from the child):

What we do NOT collect from children: audio or video recordings, precise geolocation, biometric information, government identifiers, advertising identifiers, or device fingerprinting. Our app has no third-party analytics and no advertising trackers. Our infrastructure providers do log IP addresses (a persistent identifier under COPPA) at the platform level, solely to keep the service secure and functioning. Those logs are never used to contact anyone, build profiles, or serve advertising — we ensure this by operating no advertising or profiling systems at all, and through our providers' contractual limits on how they may use the data.

For a guardian-managed child, the only email address on file is yours — we hold no contact information for the child.

How we use this information

Only to run the music-lesson service:

We never: sell your child's data; show ads or share data with advertisers or data brokers; use behavioral tracking; or allow anyone — including our AI provider — to train AI models on your child's data.

Can my child make information public?

No. Sonotempo has no public areas for children. Your child's information is visible only to their teacher and to you. Three structural safety rules apply to every minor and cannot be switched off:

  1. A background check gates every Teacher. No Teacher can teach, message, or be connected to your child until they have passed a background check; the Service is built to enforce this and to block any Teacher who has not.
  2. Your child participates through your account. For a guardian-managed child there is no separate child login — you hold and operate the account.
  3. Your child authors no public content. Nothing your child does on Sonotempo is shown beyond their own Teacher and you.

Minor-authored content is never displayed anywhere beyond your child's own teacher and you.

Who else touches this data (disclosure practices)

We share children's personal information only with the service providers that operate Sonotempo, only so they can provide their service to us, and never for their own purposes. Under COPPA these are "support for the internal operations" flows, not third-party disclosures. We do not disclose children's personal information to any third party for advertising, for money or other consideration, or for AI training — under the amended COPPA Rule those disclosures are never "integral" and we simply do not make them (90 FR 16918, 16950).

ProviderCategoryWhat it does for usChild data it processes
Anthropic, PBCAI processing serviceGenerates lesson plans and pre-lesson briefs when your child's teacher requests themAge (derived from date of birth), musical profile, recent lesson records, practice logs, homework, and goals; for pre-lesson briefs, the number of recent unread messages (never their content). The Service does not send your child's name, date of birth, or message content to Anthropic. Anthropic may not train on this data (Anthropic Commercial Terms) and deletes API data within its standard window
ResendTransactional emailSends service emails (reminders, notifications) to you and the teacherChild's first name and lesson details inside emails; a has-login child's email address for mail sent to them
StripePayment processingTeacher billing onlyNone
SupabaseDatabase & login infrastructureStores all service data securelyAll of the data described above, encrypted at rest; platform login logs (IP) for has-login children
VercelHostingRuns the applicationPlatform request logs (IP addresses)
SentryError monitoringHelps us diagnose bugsTechnical error data only; configured to exclude children's personal information

Each provider is bound by written terms restricting use of the data, as required by 16 CFR section 312.8(c). We may also disclose information where the law requires it or to protect the safety of a child or other users.

If Sonotempo were ever acquired or its assets sold, children's personal information could be transferred only to a successor that assumes these same commitments in full; you would receive direct notice first, and any material change in practices would require your new consent before applying to your child.

How long we keep your child's information (retention policy)

This is our written data retention policy for children's personal information under 16 CFR section 312.10. We keep children's personal information only as long as reasonably necessary for the purposes above — never indefinitely.

Your consent — and your right to say no

Before we collect personal information relating to your child, we obtain your verifiable parental consent during the guardian account and per-child setup, where we show you what we collect and how your child participates.

Two important rights within consent:

Your rights as a parent or guardian

At any time, you may:

  1. Review the personal information we have about your child;
  2. Delete it — direct us to delete your child's personal information; and
  3. Refuse further collection or use — withdraw consent and end collection going forward.

How: most of your child's information is directly visible in your guardian dashboard. For a complete review, a deletion request, or consent withdrawal, contact us at support@sonotempo.com or 386.259.2692 from the email address on your guardian account (we verify that requestors are the child's guardian before acting). We will act on deletion requests within 30 days.

If you refuse further collection or direct deletion, your child's participation on Sonotempo may end, since the service cannot operate without the underlying records — but we will never require more information than is reasonably necessary for your child to participate (16 CFR sections 312.6(c), 312.7).

Changes to this notice

If we materially change how we collect, use, or disclose children's personal information, we will notify you directly and obtain new consent before the change applies to your child (16 CFR sections 312.4(b), 312.5).

Security of Your Personal Data

We maintain a written information security program with safeguards appropriate to the sensitivity of the data We hold, including encryption in transit and at rest, row-level access controls, and access-gated file storage. No method of transmission or storage is 100% secure; while We use commercially reasonable safeguards, We cannot guarantee absolute security.

Transfer of Your Personal Data

The Service is operated from the United States, and data is processed on infrastructure located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.

Business Transactions

If the Company is involved in a merger, acquisition, or asset sale, Personal Data may be transferred. We will provide notice before Personal Data is transferred and becomes subject to a different Privacy Policy. Children's Personal Data may be transferred only to a successor that assumes these same commitments in full; guardians will receive direct notice before any such transfer, and any material change in how a child's data would be collected, used, or disclosed requires new parental consent before it applies (16 CFR §§ 312.4(b), 312.5).

Links to Other Websites

Our Service may contain links to websites not operated by Us. We have no control over, and assume no responsibility for, their content or privacy practices. We advise you to review the privacy policy of every site you visit.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of changes by posting the new policy on this page, updating the "Last updated" date, and — for material changes — by email and/or prominent notice before the change takes effect. Material changes to how We collect, use, or disclose Children's Personal Data require new verifiable parental consent before they apply to a Child (16 CFR § 312.4(b), § 312.5).

Contact Us

If you have questions about this Privacy Policy: