Music Master

Privacy Policy

Version 1.0 · Effective 12 September 2026 · Applies to musicmaster.app, the schools site (*.musicmaster.app), student.musicmaster.app and demo.musicmaster.app

In plain English

This summary is for convenience only. The full policy below is what applies.

1.Who we are and scope

  1. 1.1Music Master is operated by Music Master App, a sole trader business of Pedro Ferreira, ABN 71 608 106 413, 48 Prince St, Alberton SA 5014, Australia (Music Master, we, us).
  2. 1.2This policy explains how we collect, hold, use and disclose personal information, and how you can access or correct it or make a complaint. It applies to all of our services:
    • the schools site — a per-school address on *.musicmaster.app with a teacher dashboard, Course Builder and Assessment Builder;
    • the free student site at student.musicmaster.app;
    • the demo site at demo.musicmaster.app, which holds sample data only;
    • the marketing site at musicmaster.app, which has a contact form.
  3. 1.3We handle personal information in accordance with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). Where a school is subject to its own state or territory privacy law (for example the South Australian Information Privacy Principles for government schools), we assist the school to meet it.
  4. 1.4Pedro Ferreira is our nominated Privacy Officer. Contact details are in section 15.
  5. 1.5For licensed schools, this policy should be read together with our Terms of Service. If the two conflict on a privacy matter, this policy applies.

2.What information we collect

  1. 2.1Students on the schools site. When a student plays a module on their school's site we record:
    • first and last name, as typed by the student (a school may instruct students to use initials or a code instead);
    • the class code the student chooses from a list;
    • the module and mode played;
    • results — number correct, total questions and percentage — and the duration of the attempt;
    • a random session identifier, the app version, and the browser's user-agent string (the text a browser sends to identify its type and version).
    We do not collect student passwords or accounts, email addresses, dates of birth or photos.
  2. 2.2Students on the free student site. There is no account and nothing personal is sent to our servers. Progress and settings are stored only in the browser's local storage on the student's own device.
  3. 2.3Teachers. For each teacher account on the schools site we hold a name, school email address, a password (stored only as a bcrypt hash — we cannot read it), the school identifier, and login timestamps.
  4. 2.4Marketing contact form. If you use the contact form on musicmaster.app we receive the name, email address, school and message you enter. The form is handled by Netlify Forms.
  5. 2.5Demo site. The demo site contains sample data only. Anything entered there is not treated as a real school's data and may be cleared at any time.
  6. 2.6Microphone and camera. No part of the service uses the device microphone or camera. Aural-training modules only play sound through the device speakers; nothing is recorded.
  7. 2.7Cookies and tracking. We do not use cookies or trackers for advertising or analytics. See section 13 for the login token and local storage we do use.
  8. 2.8We do not collect sensitive information (such as health, religion or ethnicity) and ask that it not be entered into the service.

3.How we collect it

  1. 3.1We collect information directly from the person using the service: a student typing their name and choosing a class code before playing, a teacher signing in or managing the dashboard, or a person filling in the contact form.
  2. 3.2Results, duration, session identifier, app version and user-agent string are generated automatically by the app when a student completes an attempt on the schools site, and are sent to our database with the student's name and class code.
  3. 3.3Teacher accounts are created by the school or by us at the school's request. Class codes are set up by the school's teachers.
  4. 3.4We do not collect personal information about students from third parties, and we do not import student lists from other systems.

4.Why we collect, use and disclose it

  1. 4.1We collect, use and disclose personal information only to:
    • run the service for the school — show results to the school's own teachers, track course progress and grade assessments;
    • support and secure the service, including diagnosing faults and detecting misuse;
    • invoice licensed schools and communicate with the school's contact about the licence;
    • respond to enquiries sent through the contact form.
  2. 4.2We do not sell personal information, use it for advertising or market research, use it to train artificial-intelligence or machine-learning systems, or use it for profiling or automated decision-making about a person.
  3. 4.3We may use aggregated, non-identifying usage figures (for example how many attempts were made across all schools) to monitor and improve the service.
  4. 4.4We will not use or disclose personal information for any other purpose unless the law requires or permits it, or the person (or the school on their behalf) consents.

5.Who we share it with

  1. 5.1The school. A student's results on the schools site are shown to the authorised teachers of that student's school. Access is limited by role-based access and row-level security so that teachers see only their own school's data.
  2. 5.2Music Master's operator. Pedro Ferreira can access school data for support and maintenance of the service.
  3. 5.3Students. Students can only submit their own results. They cannot view other students' data.
  4. 5.4Sub-processors. Only two third parties process personal information on our behalf. Their staff are bound by their own security and confidentiality obligations.
    Sub-processorContactData typesPurposeLawful basisCountry
    Supabase Inc. supabase.com
    privacy@supabase.io
    Student results and names, class codes, teacher accounts, courses and assessments, backups Managed database, authentication and backups Performance of our contract with the school / consent Australia (AWS Sydney, ap-southeast-2)
    Netlify Inc. netlify.com
    privacy@netlify.com
    Application files (no student or teacher data); marketing contact-form submissions (name, email, school, message) Hosting and content delivery network; contact-form handling Performance of our contract with the school / consent United States (infrastructure); Sydney edge for file delivery
  5. 5.5We will tell licensed schools before adding a sub-processor that would process school data.
  6. 5.6We do not share personal information with anyone else, except where the law requires us to (for example a lawful request from a court or regulator). We would tell the affected school of any such request unless prohibited from doing so.

6.Overseas disclosure

  1. 6.1Student and teacher data is stored in Australia and is not disclosed overseas.
  2. 6.2Application files (the web pages, scripts, images and sounds that make up the app) are served by Netlify's content delivery network. These files contain no personal information.
  3. 6.3Submissions made through the marketing contact form are processed by Netlify Forms and may be handled in the United States. By submitting the form you consent to this. Do not use the contact form to send student information; email us instead.

7.Where and how it is stored and secured

  1. 7.1Location. All school data is stored in a managed PostgreSQL database operated by Supabase on Amazon Web Services in the Sydney, Australia region (ap-southeast-2). Backups are kept in the same region.
  2. 7.2Encryption. Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).
  3. 7.3Separation. Row-level security in the database separates each school's data from every other school's data.
  4. 7.4Other safeguards. We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure, including:
    • teacher passwords stored only as bcrypt hashes, with a minimum length of 14 characters;
    • least-privilege access keys — the key used by the student app can only insert results, not read or change them;
    • security headers on all pages;
    • regular automatic backups;
    • an incident response plan.
  5. 7.5No system is completely secure. If we become aware of a breach, section 11 applies.

8.How long we keep it

  1. 8.1Student results. We encourage schools to clear student results at the end of each school year using the dashboard. Results otherwise remain while the school's licence is active.
  2. 8.2End of licence. When a school's licence ends, we keep the school's data for 30 days so the school can export it, then delete it, unless the school asks us to delete it sooner.
  3. 8.3Teacher accounts. Deleted on request from the teacher or the school, and when the school's data is deleted under clause 8.2.
  4. 8.4Contact-form submissions. Kept for up to 12 months, then deleted.
  5. 8.5Backups. Supabase retains daily database backups for 7 days, after which they roll over automatically. Deleted data therefore disappears from backups within 7 days of deletion.
  6. 8.6Free student site. Nothing is held by us. Data in the browser's local storage stays until the student clears it or the browser removes it.

9.Access and correction

  1. 9.1Through the school. Teachers can view, correct, rename, merge and delete student records in the dashboard at any time. Students and parents should ask their school's teacher first, as the school controls its own data.
  2. 9.2Directly with us. Any individual or school can email us to ask what personal information we hold about them, to have it corrected, or to have it deleted. We may need to confirm the person's identity, or confirm the request with the school, before acting.
  3. 9.3Requests are free of charge and we act on them within 14 days. If we cannot meet a request (for example because the law requires us to keep the information) we will tell you why in writing.
  4. 9.4A school may also ask us to export all of its data at any time.

10.Complaints

  1. 10.1If you believe we have mishandled your personal information, or breached the APPs, please email our Privacy Officer at the address in section 15 with the details.
  2. 10.2We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. We will tell you the outcome and the reasons in writing.
  3. 10.3If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

11.Data breaches

  1. 11.1If we become aware of unauthorised access to, or disclosure or loss of, personal information, we will notify the affected schools without undue delay and give them details of what information and which people were affected, what we have done to contain it, and what we recommend they do.
  2. 11.2We comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), including notifying the OAIC and affected individuals where the scheme requires it.
  3. 11.3Schools should tell us promptly if they become aware of unauthorised use of a teacher account or their school site, so that we can respond.

12.Children and schools

  1. 12.1The schools site is used by school students under the supervision of their school. The school decides which students use the service, what name format they use, and obtains any parental or guardian consent that its own policies or applicable law require.
  2. 12.2We do not knowingly collect personal information from children outside a school context. The free student site collects none.
  3. 12.3Schools can reduce the personal information collected to almost nothing by instructing students to enter initials or a name code instead of a full name.
  4. 12.4If a parent or guardian believes we hold information about their child that should not be there, they should contact the school or email us, and we will work with the school to correct or delete it.

13.Cookies and local storage

  1. 13.1We do not use cookies for advertising or analytics, and we do not use third-party tracking scripts.
  2. 13.2The schools site stores a login session token in the browser's local storage so that teachers stay signed in. It is removed when the teacher signs out.
  3. 13.3The free student site stores progress and settings in the browser's local storage on the device. This data stays on the device and is not sent to us.
  4. 13.4Browser local storage can be cleared at any time through the browser's settings. Clearing it will sign a teacher out, and on the free student site will reset progress.

14.Changes to this policy

  1. 14.1We may update this policy from time to time. Updates are published on this page with a new version number and effective date.
  2. 14.2For any material change we will email each licensed school's contact at least 30 days before the change takes effect.
  3. 14.3Earlier versions are available on request.

15.Contact

  1. 15.1Privacy questions, access, correction or deletion requests, and complaints should be sent to our Privacy Officer, Pedro Ferreira.
Email
musicmaster@musicmaster.app
Post
Music Master App, 48 Prince St, Alberton SA 5014, Australia
ABN
71 608 106 413
Contact. Questions about this policy, or a data access, correction or deletion request: musicmaster@musicmaster.app