LEGAL · IN THE RHYTHM
In The Rhythm Privacy Policy
Version 1.0
Last updated: 30 August 2026
Effective from: 1 September 2026
A short summary written for younger readers is at In The Rhythm in plain words.
Contents
- Who we are
- Who this policy covers
- What we collect
- What we do not collect
- How we use your information
- If you are 13 to 17
- What a connected teacher can see
- Analytics and crash reports
- Who helps us run the app, and where your information goes
- How long we keep things
- Deleting an account
- Reports and blocking
- Your rights and choices
- How we protect information, and the limits
- Changes to this policy
- Contact, response times, and complaints
1. Who we are
In The Rhythm is run by Garden Recording Orchestra Ltd, a company registered in England and Wales with company number 16360681, whose registered office is at 44 Conduit Street, Gloucester, England, GL1 4TU. In this policy, "we" and "us" mean Garden Recording Orchestra Ltd. Under data protection law, we are the "controller" of your information. That means we are responsible for deciding what is collected and how it is used.
You can email us at support@intherhythm.org.
The app is available in the United Kingdom and Hong Kong. The Service is not offered in the European Economic Area. Because we are established in the United Kingdom, UK GDPR and the Data Protection Act 2018 apply to everything we do with your information, wherever you live. If you are in Hong Kong, the Personal Data (Privacy) Ordinance also protects you.
2. Who this policy covers
In The Rhythm is a music practice tracking app. There are two kinds of accounts. Musician accounts log practice. Teacher accounts connect to musicians and follow their progress.
Everyone using the app is 13 or over. No one under 13 can create an account: the age gate refuses it on the device, and the database refuses it again on the server, so the rule holds even if the app itself is bypassed. People aged 13 to 17 can have musician accounts only, and their signup includes a confirmation that a parent or guardian has agreed; section 6 explains what that does and does not create. Teacher accounts are for adults aged 18 or over, and the database refuses a teacher account with any younger age band.
At signup the app asks for your birth month and year, and nothing more precise. It uses them to decide which of these rules apply to you, then discards them. Section 3 explains exactly what is kept instead, because the honest answer has a catch.
3. What we collect
3.1 Your account
We collect an email address and a password. The password is stored hashed, never in readable form. You choose a username and a display name.
While you type a username at signup, each candidate you try is checked against our server to see if it is taken, so those attempts reach our systems before any account exists.
We store which role your account has, and your age record. The age record is worth explaining carefully. We do not store your birth month and year themselves. We store your age band (13 to 17, or 18 plus) and, for the 13 to 17 band, the date the account will automatically move to the adult band. That date is the first day of the month after your 18th birthday month, so anyone who can see it can work backwards to your birth month and year. In practice, for a 13 to 17 account, we hold your date of birth at month precision, even though no date-of-birth field exists. The promotion date is hidden from other users and from your own device's normal data access; only we can read it. The signup details (age band, promotion date, role, username, and name) are also kept inside the account's sign-in record.
You may add a profile photo. It is optional.
3.2 Practice logs
Every practice session you save records when it started, how long it ran, and its status (draft or submitted). You can add a rating from 1 to 5, four more 1-to-5 reflection scores (rhythm, technique, interpretation, dynamics), a short "what you worked on" line of up to 500 characters, and notes of up to 2,000 characters. Every one of those is optional. This applies to musicians and to teachers logging their own practice.
3.3 Focus line
Musicians have a single focus line of up to 200 characters ("what will you work on this week"). Musicians write their own, and a connected teacher can write or change it too; section 7 explains that channel and its controls. Earlier versions of the focus line are kept in a background history log for up to 12 months (section 10).
3.4 Connections
To connect a teacher, a musician generates a 6-character code that expires after 24 hours and works once. We store the connection itself, the codes, and a background log of code redemption attempts. That log records which teacher tried and the outcome, and deliberately never records the code that was typed.
3.5 Teacher comments
A connected teacher can leave one comment per practice session, chosen from a fixed list of 25 supportive phrases. Free text is impossible there at the database level. We store which phrase, on which session, from which teacher, and when.
3.6 Feedback you send us
If you send feedback through the app we store its type, subject, and message. You can optionally add a contact email and up to three screenshots. Feedback also records your device's operating system and version, the app version, and your role.
3.7 Reports and blocks
If you report someone, we store the reason, what the report is about, your optional written details of up to 1,000 characters, a snapshot of the reported account's username and display name, and, for reports about a specific comment or focus line, a copy of that content. If a musician blocks a teacher, we store the block and a snapshot of the teacher's username and name. Section 12 explains what happens to a report after you send it.
3.8 Settings
We store your accessibility and app settings: dyslexia font, text size, reduce motion, haptics, theme, the notification toggles, your device's time zone (synced automatically, used to time reminders), and your analytics answer with a server-set timestamp.
3.9 Notifications
Notifications are off until you switch a notification type on and your device grants permission; nothing is sent before both happen. To deliver them we store a push token for your device, which only exists once permission is granted. There are three notifications, all with fixed wording: your teacher left feedback, one of your students practised, and a reminder if you have not practised for three days. The in-session water and stretch banners are generated on your device and never leave it.
3.10 Background records
Some records exist for safety and reliability rather than as features. We keep: a log of notifications sent (sender, recipient, type, whether it succeeded), the code attempt log (3.4), the focus history (3.3), and, for reports, a per-report delivery record tracking whether the alert email about it was sent.
Signing in creates a session record that includes your IP address and device details; Supabase, our platform, keeps these as part of running sign-in. Supabase can also keep its own log of sign-in events; when we last checked, on 11 August 2026, that log was empty.
3.11 On your device
Your device holds: your sign-in tokens, your in-progress practice draft (cleared when you save, reset, or sign out), a note of whether we asked about notification permission, and the age gate result (your age band and, for 13 to 17, the promotion date). The age gate result is never cleared, even after sign-out or account deletion, so on a shared device it reveals the band, and the derivable birth month and year, of the last person who answered the age gate.
4. What we do not collect
There is no advertising in the app, no advertising or tracking software built into it, and the Android advertising ID permission is absent from the app. Nothing in the app shares information with advertisers or data brokers, because nothing exists to do it: no advertising, attribution, or data-sharing software of any kind is built in.
The app never records audio and cannot: it has no microphone permission and no camera permission. Profile photos and feedback screenshots come only from your photo library, and every image is re-encoded before upload, which strips hidden metadata including GPS location.
We do not collect your location. The only location-adjacent value is your device's time zone. We do not access your contacts. There are no cookies inside the app. There is no third-party or social sign-in. The app is free: no payments, subscriptions, or prices exist anywhere in it. There is no direct messaging feature; the only ways one account's words reach another are the ones described in sections 3 and 7.
No one under 13 can create an account, so the app holds no information about children under 13 at all. We also hold nothing about your parent or guardian: no name, no email address, and no record of the confirmation described in section 6, which stores nothing.
5. How we use your information
We use what we collect to:
- Run the app: create your account, save and show your practice logs, and connect musicians with teachers. This, and the account emails that make it work (address confirmation and password reset), rest on our contract with you (Article 6(1)(b)).
- Apply the age rules: your age band decides which accounts and features you can have, so we process it as part of the same contract (Article 6(1)(b)).
- Send the three notifications in section 3.9, only if you switch them on. They rest on your consent (Article 6(1)(a)), and you can withdraw it at any time in Settings or in your device's permission settings.
- Count how the app is used, only if you say yes (section 8). This rests on your consent (Article 6(1)(a)).
- Receive crash and error reports so we can fix the app (section 8). This rests on our legitimate interest in keeping the app working (Article 6(1)(f)); the reports are built to carry no account identity.
- Handle safety reports, content snapshots, and blocking. This rests on our legal obligations to keep users safe, including under the Online Safety Act 2023 (Article 6(1)(c)).
- Answer support requests and feedback, as part of our contract with you (Article 6(1)(b)).
- Prevent abuse: rate limits on sign-in and on code guessing, the code attempt log, and the profanity filters. These rest on our legitimate interest in the security of the service (Article 6(1)(f)).
6. If you are 13 to 17
This section is written for you, not your parents.
Your parent or guardian. When you signed up, you ticked a box confirming that a parent or guardian read the Terms and this policy and agreed you can use the app. We take that at face value. We do not contact them, we do not ask them for anything, and we store nothing about them: no name, no email, and no record of the confirmation itself. The tick gates the signup and creates no data.
What is off, and stays off unless you change it. Analytics is off until you say yes, saying no changes nothing about how the app works, and the app never nudges you to switch it on. Once you answer, it does not ask again; Settings is where you change your mind. Notifications are off until you turn them on.
Nobody can find you. There is no feed, no search for other users, no public profiles, no recommendations, and no messaging. The only person who can ever see your practice is a teacher you connected yourself, with a code you generated, and drafts are never visible to anyone.
What a connected teacher can see and write. A connected teacher reads what you submit, exactly as you wrote it, and writes two things that you read. One is your weekly focus line, up to 200 characters, which is filtered, kept in a history log, and reportable straight from the focus card. The other is their own display name, which is checked for links, handles and phone numbers rather than for wording. Everything else a teacher can send you is chosen from fixed phrases. Section 7 has the full picture.
Ending a connection. Disconnect or block at any time. Live access stops at once. Comments already left remain, and nothing a teacher already read can be taken back.
Your rights are yours. You do not need a parent to use them. Email us yourself to ask what we hold, get a copy, correct something, or complain, and delete your account yourself from Settings whenever you want. Section 13 lists everything.
When you turn 18. On the first day of the month after your 18th birthday month, your account moves to the adult band automatically and silently; the stored promotion date is cleared, and nothing else visibly changes.
One thing your device keeps. The age gate answer (your band, and the date you move up) stays on the device and is never cleared, even if you sign out or delete the account. On a shared device, the next person can see the band of whoever answered last.
What survives deletion. Deleting your account removes it and everything in it immediately and permanently. A few safety records last longer, none more than 12 months. Your photo and any feedback screenshots are removed straight after, and if that fails they stay until they are removed by hand. Sections 10 and 11 list each one.
7. What a connected teacher can see
Connecting is always started by the musician: they generate the code, and the teacher types it in. Once connected, a teacher can read every practice session the musician submits, in full and verbatim: the date, the duration, the rating and all four reflection scores, the "what you worked on" line, and the notes. Drafts are never visible. The teacher also sees the focus line and who wrote it, and the musician's username and display name. The app says this on the code screen at the moment of sharing, and it is worth repeating here: submitted notes and reflections are read by the connected teacher exactly as written.
A connected teacher can also write the focus line. It is one of two places in the app where a teacher writes free text that a musician reads: a single field of up to 200 characters, checked against a word list, with every version kept in the history log, and reportable from the focus card itself. The musician can always overwrite it, and can disconnect or block the teacher at any time. The database blocks a teacher from writing it for any under-13 account, a guard that stands even though no such accounts can currently exist.
The second is the teacher's own display name, which appears on the musician's list of connected teachers. It is checked for shape rather than for wording, for the reason section 14 gives: a word list would reject real surnames. A musician can report or block a teacher from that same list.
The app never displays these to a teacher, but because the sharing rule works row by row rather than field by field, a connected teacher's device is technically able to read a few more fields on the account: its age band and under-13 flag (always false, since under-13 accounts cannot exist), the web address of its profile photo if it has one, and when the account was created and last updated. A connected teacher can never see: the account's email address, notification token, settings, analytics answer, feedback, reports, blocks, or the promotion date.
A musician can connect more than one teacher, and every actively connected teacher sees the same things. Teachers can comment on sessions only from the fixed list of 25 phrases (section 3.5).
Either side can end a connection at any time, and a musician can also block a teacher. Ending it cuts off all live access at once. It does not remove comments the teacher already left, and it cannot take back anything the teacher has already read or saved.
8. Analytics and crash reports
Usage analytics (PostHog). The app asks once, on your first signed-in entry, whether we may count how the app gets used. Nothing whatsoever reaches PostHog unless you say yes: the analytics software is not even started before that point, and no analytics identifier and no analytics storage are created on your device until you consent. Saying no changes nothing about how the app works, the app never prompts you again, and you can change your answer any time in Settings.
If you say yes, we count things like which screens open and events like starting, stopping, and saving a practice session with their durations, along with your role and basic device details such as model, operating system, app version, language, and time zone. What you write is never included: notes, reflections, "worked on" text, ratings, your username, your email, and your age record are never sent as analytics. A consented account gets an analytics profile keyed to its account ID with its role. The counting is done for us by PostHog, in the United States.
If you withdraw consent, new events stop immediately. An event already queued on your device at that moment can still send; the software keeps its queue and offers no way for us to purge it.
Crash and error reports (Sentry). If the app crashes outright, a crash report is always sent, for every user and regardless of any consent answer, so we can fix it. A crash report contains what broke (the technical error and stack trace), the device model, operating system version, and app version and build. It contains no account identity on any path: nothing attaches your user ID, the report's user field is deleted outright, and the crash report's activity trail is emptied. Reports about errors the app recovered from are sent only if you consented to analytics. Sentry sees your IP address at the network level when a report travels, and its project setting to prevent storing IP addresses is enabled. Sentry processes in the United States and keeps reports for 30 days; that window is set by Sentry's plan and is not something we can change.
9. Who helps us run the app, and where your information goes
We are a very small operation and rely on service providers. Each processes information only to provide its service to us, under a data processing agreement.
Supabase (United States, us-east-1 region) runs our database, sign-in, storage, and server functions. Everything the app stores lives there, and every read and write the app makes is a Supabase request. Supabase also sends the account emails: address confirmation and password reset codes.
PostHog (United States) provides the usage analytics in section 8, and receives nothing until analytics is switched on.
Sentry (United States) receives the crash and error reports in section 8.
Expo. To deliver notifications we use Expo (Expo Application Services, United States). When you turn notifications on, your device sends Expo an identifier for your device, the notification token your phone gets from Apple or Google, and identifiers for this app. Expo gives back a token that we store so we can send you reminders. The notifications themselves only ever contain fixed wording. They never contain your name, your username, your practice records or your reflections. Apple (APNs) and Google (FCM) receive the device push token as the transport layer that carries every notification to your phone.
Resend (Plus Five Five, Inc., United States) sends the report alert email described in section 12, which tells us a report has been filed without carrying the report's content or anything you wrote. Resend's current sub-processors are listed at https://resend.com/legal/subprocessors.
Google (Google Asia Pacific Pte. Ltd., Singapore) hosts our support mailbox, so everything emailed to support@intherhythm.org is processed by Google as our mail provider.
GitHub Pages hosts our website, including this policy. The site itself runs no scripts and collects nothing; GitHub, as the host, records ordinary request logs including IP addresses.
Apple and Google, as the app stores, receive install and platform-level data under their own terms when you download and run the app.
Where we transfer personal data outside the United Kingdom, we rely on the International Data Transfer Agreement issued by the Information Commissioner, or the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or, where a provider is certified, the UK Extension to the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards that apply by emailing our support address.
10. How long we keep things
Every piece of stored information falls into one of four groups: kept while your account is alive, deleted with your account, kept on a stated timer, or kept with no timer. We list all four, because a reassuring single paragraph would not be honest. The cleanup job that enforces the timers runs weekly, so each timer can run up to 7 days over.
Kept while your account is alive. Everything in section 3 is kept for as long as your account exists, until you delete the account or delete the individual item yourself. Nothing expires on its own, with two exceptions that run whether or not the account is alive: connection codes, which expire after 24 hours by design, and the timed background records in the table below, which age out on their own timers. Your practice history in particular has no expiry: a session you logged five years ago will still be there.
Deleted immediately with your account: your sign-in record and sessions, profile, username, display name, and email; every practice session including all its text; your current focus line; your connections, unused codes, and blocks; comments others left on your sessions; your feedback; all your settings including the analytics consent record; and your PostHog analytics profile with its events, which we ask PostHog to delete as part of account deletion. If that PostHog request fails, your account is still deleted, the failure is logged, and the profile may remain at PostHog until fixed by hand.
Your photo and feedback screenshot files are removed straight after the account is deleted, not as part of it. If a removal fails, the failure is logged and the file may remain until it is removed by hand. There is no timer on it. While a profile photo remains, it keeps the public web address described in section 14.
Kept on a stated timer, and these survive account deletion until the timer ends:
| What | How long | Notes |
|---|---|---|
| Reports | 12 months from filing | Deleted then whether or not a person ever read them. If the reporter deletes their account, their ID and their written details are removed from the report; the snapshots about the reported account and the content copy remain. If the reported person deletes their account, their ID is removed but the snapshots of their username and name, and the content copy, remain. |
| Report delivery record | With its report | Deleted whenever the report is. |
| Focus line history | 12 months per entry | This can include text a teacher wrote about a musician, kept up to 12 months after that musician deletes their account. |
| Notification log | 12 months per entry | Covers all three notification types. Holds bare account IDs that outlive deleted accounts. |
| Support mailbox email, including report alerts | 12 months from arrival | Deleted by an automatic retention rule on the mailbox. |
| Code attempt log | 90 days per entry | Holds a teacher's account ID, which outlives a deleted teacher account. |
| Connection codes | About 8 days | Codes expire after 24 hours and are wiped 7 days after expiry. |
| Crash reports at Sentry | 30 days | Sentry's plan window. Contain no account identity. |
| Analytics events at PostHog | Up to 1 year | PostHog's plan window, for consented accounts. The person profile itself is deleted with your account. |
Kept with no timer. We state these plainly because "for as long as necessary" is not a period. Preset comments you left on other people's sessions are kept indefinitely with your name detached. Supabase's own sign-in event log has no deletion timer; when we last checked, on 11 August 2026, it was empty. A sign-in session on your device lasts until you sign out; on the current plan there is no automatic session expiry. Resend keeps its own record of emails it sent for us, on Resend's terms. GitHub keeps its ordinary website request logs, on GitHub's terms. And the age gate result stored on your own device is never cleared (section 3.11).
There are no backups of any of this. That removes a common retention caveat, and it also means nothing deleted can ever be restored, by us or anyone.
11. Deleting an account
Open Settings, choose Delete Account, and confirm your password. Deletion is a single operation: the account and everything in the "deleted immediately" group of section 10 go together, at once. It takes effect immediately, it cannot be undone, and there is no grace period and no backup to restore from. This also applies to a single practice session you delete yourself: it is gone.
A few tidy-up steps run right after the main deletion: removing photo and screenshot files, removing the PostHog profile, and sweeping the focus history. If one of those fails, your account is still fully deleted and anything left behind is logged. The focus history is bounded by the timers in section 10 either way. A stored file and a PostHog profile are not: each stays until it is removed by hand.
What remains after deletion is exactly the "stated timer" and "no timer" material in section 10. In our own app database, nothing that identifies you outlives your deletion by more than 12 months. That limit does not reach the no-timer items in section 10 that sit outside that database: a photo or screenshot file whose deletion failed sits in our storage rather than our database, with no timer on it, and the platform's own sign-in event log, Resend's record of the emails it sent for us, and GitHub's website request logs are kept on those providers' terms, with no deletion timer set by us. The headline items in our database: a report filed about you keeps snapshots of your username and display name for up to 12 months; a report you filed keeps its content but loses your ID and your written words; teacher-written focus history about you can persist up to 12 months; and emails already sent cannot be recalled, though the support mailbox deletes them at 12 months.
12. Reports and blocking
Musicians can report a connected teacher, a specific comment, or a teacher-written focus line. Teachers can report a connected musician. A report carries the items in section 3.7.
Here is what happens when you press send, stated exactly. The report is saved to our database first, so it cannot be lost. At the same moment, an alert email is generated to our support mailbox telling us a report exists; the email carries no content from the report and nothing you wrote, which stay in the database where we read them. If that email fails to send, it is retried automatically, and repeated failure raises a separate failure alert. There is no report review screen inside the app; that email is how a person learns your report exists. Reports go to a real person, and we aim to respond to safety reports usually within 3 working days.
One honest limit: a report is deleted 12 months after it was filed whether or not a person ever read it; nothing in the system marks a report as reviewed.
After sending, there is no in-app screen showing your past reports, no way to edit one, and no way to withdraw one yourself; email us to withdraw a report. You are never told whether someone has reported you, and the person you report is not told either.
Blocking. A musician can block a teacher. Blocking ends the connection and makes reconnection impossible: any code the blocked teacher tries, including a brand new one, behaves exactly like an invalid code. The teacher is never told a block exists. The attempt is recorded in the code attempt log. Blocking is reversible by the musician alone, in Settings; unblocking does not reconnect anyone, since a fresh code would still be needed.
If a child is in immediate danger, contact your local emergency services first. The report system is not an emergency service.
13. Your rights and choices
Much of this you can do yourself, in the app: view and edit your username, your display name, and your password; view, edit, and delete practice sessions; edit your focus line; change every setting including the analytics answer; view connected teachers; and disconnect, block, or unblock.
Some things need an email to us instead. There is no download button in the app: if you want a copy of your information, email us and we will compile it for you in a machine-readable format. The account email address cannot be changed inside the app; email us to request a change. The age band cannot be changed inside the app by anyone; if it is genuinely wrong, email us.
Wherever you live, you can ask us to: tell you what we hold about you, correct it, delete it, give you a copy, restrict or object to how it is used, and withdraw any consent you gave. We answer data rights requests within one calendar month. If you are 13 to 17, these rights are yours to use directly, without a parent.
You also have the right to complain to a data protection authority. United Kingdom: Information Commissioner's Office, ico.org.uk. Hong Kong: Office of the Privacy Commissioner for Personal Data, pcpd.org.hk. Complaints about a decision we made are handled under the procedure in our Terms of Service, and using it never limits your right to go to a regulator or court.
14. How we protect information, and the limits
What we do: every connection is encrypted in transit, and data is stored with Supabase, whose platform encrypts data at rest. Access rules are enforced row by row inside the database itself, not just in the app, so a teacher's account can only ever read connected musicians' submitted data, and one account cannot read another's private records. Passwords are stored hashed. Email confirmation is on. Deleting an account requires re-entering the password. Sign-in and code redemption are rate limited, so codes cannot be guessed by hammering. Every uploaded image is re-encoded, which strips hidden metadata including location. The age fields on accounts are locked against change by any app user.
What we do not have, stated so this section cannot mislead: there is no two-factor authentication. The signed-in session on your device is kept in the app's ordinary storage, not the device's hardware-secured storage. There are no backups. Nothing is end-to-end encrypted; like most services of this kind, stored content is technically readable by the operator, and handling reports depends on that. A profile photo, while the account exists, sits at a web address that anyone holding the address can open without signing in, and photo addresses cannot be discovered in bulk. Free text in notes, reflections, feedback, and report details is not filtered for language; usernames and focus lines are checked against a word list, and display names are checked for shape (no links, no handles, no phone numbers) rather than words, because a word list would reject real surnames.
15. Changes to this policy
We may update this Policy from time to time. If we make a material change, we will notify you before it takes effect by email to the address associated with your account, and we will update the effective date at the top of this Policy. For non-material changes, such as corrections or clarifications, we will update the effective date without separate notice.
If we transfer the Service to another company, whether by sale, merger, or reorganisation, your information may transfer with it. The receiving company will be bound to handle it in accordance with this Policy, and we will tell you before that happens.
16. Contact, response times, and complaints
Email support@intherhythm.org, or write to Garden Recording Orchestra Ltd, 44 Conduit Street, Gloucester, England, GL1 4TU. We aim to respond to safety reports usually within 3 working days, to general support within 5 working days, and to data rights requests within one calendar month. For complaints about our decisions, see the complaints procedure in the Terms of Service; for complaints to an authority, see section 13.
If a child is in immediate danger, contact your local emergency services.