Legal
Privacy policy
This policy covers the B♭ Studio website, the iPhone and iPad apps, and the studio management platform. Frank's Musik Services LLC owns and operates all three. Last updated October 3, 2026.
The short version
B♭ Studio is a product of Frank's Musik Services LLC. In this policy, “we” means Frank's Musik Services LLC. We don’t sell your information. We don’t use it for advertising, and there is no advertising in the app or on this site. We don’t track you across other apps or websites, so the app never shows Apple’s “Ask App Not to Track” prompt. We don’t use your information, or a studio’s records, to train machine-learning models.
Most of the personal information in B♭ Studio isn’t ours. It belongs to the music studio you deal with, and we hold it on the studio’s behalf. That decides who you should write to, so it comes first below.
Who is responsible for your information
B♭ Studio is owned and operated by Frank's Musik Services LLC. We also run Frank's Musik, a music studio that teaches lessons online, on this same software. For that one studio we are both the software company and the studio. What it holds about its own families is handled the way this policy describes for any studio.
Three things are covered here, and they work differently.
- This website. We run it, and we are responsible for anything you send through it. We are the controller.
- The studio platform, and the apps that read it. Each studio runs its own installation. The studio decides what it records about its students and families, how long it keeps that, and who on its staff can see it. The studio is the controller, and we are the processor, acting on its instructions.
- Operating the software. We keep a small set of records so that we can run the service safely: sign-in events, device details and error reports. We use them for security and support and for nothing else.
If you are a parent, a student or a member of studio staff, your relationship is with your studio. Ask the studio to correct or delete something and it can do that itself. If it needs us, we help. You can also write to us directly and we’ll pass your request on. See Contact.
This website
This site is a set of static pages. It sets no cookies, runs no analytics, loads no third-party scripts and has no tracking pixels.
It has one form, the waitlist. If you fill it in, we store:
- Your email address (required).
- Optionally, your studio name, roughly how many students you have, which lines of business you run, and any note you write.
- The country the request came from, and the website you arrived from if one was sent. We don’t store your IP address. We work out the country from it and discard the address.
- The date and time you submitted it.
This is kept in a database run by Cloudflare. When a signup arrives, it is also passed to n8n, an automation tool we run on our own server. n8n forwards it to our Microsoft 365 mailbox and Teams so that a person sees it. We use it to email you about B♭ Studio and for nothing else. There is no newsletter, and we don’t sell or rent the list.
The iPhone and iPad app
The app signs you in to your studio’s portal and shows you what the studio holds about your account. It is a view of the studio’s records, not a separate collection of ours.
What it collects
- Your sign-in. The address you sign in with, and a session token kept in the device Keychain so you aren’t asked to sign in every time.
- Device details, recorded with each sign-in. Device model and name, the vendor identifier Apple gives this app on this device, operating system version, app version and build, language, time zone, screen and connected-display information, and whether the device supports a keyboard or pointer. That last item only says whether such input is possible. It is not a record of anything you type or press.
- Network details, recorded by the server. Your IP address and connection information at the time of a sign-in.
- Location, only if you allow it. The app asks once, while you’re using it, at sign-in. We use it to notice a sign-in from somewhere unusual for your account. It isn’t collected in the background, and we don’t use it to build a profile of where you go.
- A notification token, only if you allow notifications. Apple issues a token for this app on this device so the studio can send lesson reminders and similar notices. Turning notifications off, or deleting the app, ends it. Your studio can see that a phone is registered to your account: its model, when it was registered and last seen, and the last six characters of its identifiers. It never sees the full token. The studio can remove a phone that is no longer in use.
- Screenshots you choose to send, when you attach up to four to a problem report. The app can’t see your photo library beyond the images you select.
- A problem report, only if you send one. If you use Report a problem, we receive what you write, the screen you were on, technical details the app captured about what went wrong, and any screenshots you attached. See Problem reports for where that goes.
- The camera, only when you scan a payment card. This lets you enter card details without typing them. See Payments.
- The microphone, only while the tuner is open. The tuner listens to your instrument to work out which note you’re playing and how many cents sharp or flat it is. That happens on your phone. The audio isn’t recorded, saved or sent anywhere, whether to us, your studio or anyone else, and the tuner stops listening when you leave it.
- Face ID, Touch ID or your passcode, to re-open the app. After the app has been fully closed or left idle for a while, it asks you to prove you’re the person holding the phone before it shows your account again. iOS checks your face or fingerprint. It never reaches the app, us or your studio. The app is only told whether you passed.
- What you log for practice. The date, the minutes and an optional note, if you choose to record a session. Using the metronome or the tuner isn’t recorded.
What it doesn’t do
- No advertising, and the app doesn’t read the advertising identifier.
- No tracking across other companies’ apps or websites. That is why the app never shows the “Ask App Not to Track” prompt.
- No third-party analytics or attribution kits. The only outside component in the app is Stripe’s payment sheet, which appears when you pay.
- No background location, no access to your contacts, and no health or fitness data. Nothing from the microphone is recorded.
If you refuse a permission
The app still works. If you refuse location, the sign-in is recorded as having no location, which is a normal outcome. If you refuse notifications, reminders reach you some other way, depending on the studio. If you refuse the microphone, the tuner can’t listen, and the metronome and everything else keep working. None of these limits what you can see or do in your account.
The studio platform
A studio’s installation holds the records it needs to run a music studio. Depending on what the studio uses, that can include names and contact details for families and students, lesson schedules and attendance, notes a teacher writes after a lesson, invoices, payments and account balances, agreements and the signatures on them, instrument repairs, messages between a family and the studio, practice logs, and preferences for how a family wants to be contacted.
It can also include what a studio records about a student’s support needs so that their teaching can be adapted. That information is sensitive, and the software treats it that way. It is released only to the staff roles the studio names, the software records who granted that access, and earlier versions of a note are kept instead of overwritten.
The platform keeps an append-only audit trail of actions taken in it: who did what, and when. The database won’t let anyone edit or erase those entries, including us. We built it that way so the trail can be trusted. It affects deletion, which is covered below.
The studio decides what to collect and how long to keep it. We don’t use any of it for our own purposes.
Problem reports
Staff, parents and students can report a problem from the studio platform and from the app. Each report is filed as an issue in a GitHub repository that the studio or we have set up for the purpose, so someone can read it and fix it. Because GitHub holds those issues, it appears in the list of companies below.
What goes to GitHub: what you write, the screen you were on, a description of your browser or device, any technical details captured about the error, the time you sent it, and an internal reference number for your record in the studio’s system. For a report from a parent or student, that reference is a number and not a name, and the system adds no name of its own. For a report from a member of studio staff, their name is included.
What doesn’t: screenshots. They stay in the studio’s own system, and the report only links to them, because a screenshot of a family’s portal shows a family’s details.
What you type is filed exactly as you typed it, and anyone with access to that repository can read it. Please don’t put card numbers, passwords or other sensitive details in a report.
Students and children
Many students are under 18, and some are young children. We don’t knowingly collect anything directly from a child for our own purposes, and our software isn’t directed at children. Information about a student reaches the platform because a parent or guardian, or the studio, entered it.
When a studio gives a student their own portal access, the software limits what a minor can reach. Billing is withheld from a student account no matter how the studio has set its permissions, so a settings mistake can’t expose a family’s financial information to a child.
There is no advertising, no profiling and no sale of information at any age. A parent or guardian who wants to see, correct or remove what is held about their child should ask the studio, which can act right away. If you’d rather come to us, write to us and we’ll route it and follow up.
Payments
Card payments are handled by Stripe. Card numbers go from your device to Stripe directly. We, the app and the studio’s installation never store them. What comes back is a reference and the last few digits, so a family can tell one saved card from another.
Apple Pay. If you pay with Apple Pay, Apple gives Stripe a payment token specific to your device instead of your card number. The app, we and your studio never see your card number. Apple’s own privacy policy describes how it handles Apple Pay.
Scanning a card with the camera is a convenience for entering those details. The scan isn’t saved as an image.
Companies that handle data for us
These are the services involved, what each is for, and roughly what reaches it. Each has its own privacy policy, which covers how it handles what it receives.
| Service | What it is for | What reaches it |
|---|---|---|
| Cloudflare | Hosting this website and the waitlist database; hosting the studio platform’s web app and API; DNS and security filtering | Waitlist submissions; everything sent to or from the platform passes through its network |
| Stripe | Card payments, Apple Pay payments and payouts | Card details or an Apple Pay token, payment amounts, the payer’s identifiers |
| Microsoft | Staff sign-in, studio email and calendars, and online lessons on Teams | Staff identities, messages the studio sends, online lesson attendance and chat |
| Supabase | The studio platform’s database and private file storage; sign-in for family portal accounts | Everything a studio records, including uploaded files and screenshots; the address and credentials a family signs in with |
| Apple | Delivering notifications to the app, and Apple Pay | A notification token and the notice being delivered; with Apple Pay, a payment token from your device |
| GitHub | Filing problem reports so they can be fixed | What the reporter writes, the screen, technical details and an internal reference number rather than a name. Screenshots are not sent |
| Twilio | Text messages, where a studio uses them and consent was given | Phone number and message content |
| Lob | Printing and mailing paper statements and notices | Name, postal address and the document being sent |
A studio supplies its own accounts for several of these, so which ones are in use depends on the studio. Credentials for them are stored encrypted, and the software never shows them again once they are saved.
How long anything is kept
- Waitlist signups are kept until you ask us to remove them, or until the list has served its purpose.
- A studio’s records are kept for as long as the studio wants them and we run its installation. A studio may have to keep some of it, such as invoices and payment records, for its own tax and accounting reasons.
- Problem reports are kept as a record of what went wrong and how it was fixed. Ask us and we’ll deal with one you sent, as described under Deleting your data.
- Sign-in and device records are kept as security history. Refused sign-ins are kept too, because an attempt nobody could identify is worth being able to look back at.
Deleting your data or your account
Waitlist. Email us and we’ll remove it within 30 days. You don’t need to give a reason.
A portal or app account. Your account belongs to your studio, so the fastest route is to ask the studio. It can revoke portal access itself, right away. You can also write to hello@bflatstudio.com, and we’ll work it out with your studio and confirm when it’s done. Deleting the app from your device stops notifications to it but doesn’t delete the account.
What deletion can’t reach. The audit trail described above is append-only by design, so the record that an action happened at a certain time stays. Records a studio must keep by law, such as invoices and payment history, also stay for as long as the law requires. We’ll tell you which of these applies instead of telling you everything is gone.
How it is protected
- Everything travels over encrypted connections.
- Staff access is controlled by permissions stored per role and checked on every request. A studio can change them itself.
- Credentials a studio saves for outside services are encrypted, and no part of the software shows them again.
- On your phone, the session is kept in the device Keychain.
- Actions are written to the audit trail, which can’t be edited or erased.
No system is perfect. If something goes wrong that affects you, we’ll tell the studio, and where the fault is ours, we’ll tell you.
Your rights
Depending on where you live, you may have the right to ask what is held about you, to have it corrected or deleted, to get a copy of it, and to object to some uses. We honor these requests wherever we can, whether or not the law where you live requires it.
For a studio’s records, the studio decides and we help. For anything we hold ourselves, ask us directly. We won’t charge you for asking, and we won’t treat you differently for it.
The studio platform’s database and file storage are in Supabase’s US East (N. Virginia) region, and the platform’s servers run in the eastern United States. Traffic reaches them through Cloudflare’s network, which has data centers in many countries, so a request can pass through one near you on its way. If you use B♭ Studio from outside the United States, your information is handled in the United States.
Changes to this policy
When the software starts or stops collecting something, this page changes, and so does the date at the top. If a change is significant, such as a new kind of information or a new company handling it, we’ll say so on this page.
Contact
Write to hello@bflatstudio.com for anything on this page, including a request to see or delete what is held about you. A person at Frank's Musik Services LLC reads it.
Questions about your own studio’s records, such as a lesson note, an invoice or what the studio holds about your child, are best answered by the studio, because the records are theirs. You’re welcome to write to us anyway, and we’ll make sure it gets dealt with.