Privacy Policy
Version 1.0.0 · Effective 7/23/2026
Privacy Policy
The short version
Here is the plain-English summary. The rest of this policy explains each point in more detail.
- Who we are. Crescendo Music Academy is an online music-lesson video platform for people in the United States. Our legal entity name is Crescendo Music Academy, and the business operates under that name.
- What we collect. We collect the information we need to sign you in, run your account, deliver lessons, take payment, keep the service safe, and follow the law. We do not collect more than we need.
- Video and payments. Videos stream to you straight from our video provider, so the video does not pass through our own servers. We never store your full card number; our payment company handles that.
- We do not sell your information. We do not sell your personal information, we do not use it for targeted advertising, and we do not track you across other websites or apps. There are no advertising trackers or ad networks on the site.
- Children come first. Only an adult can set up and control a learner profile for a child under 13, and only after we give the adult a clear notice and the adult gives us verified permission (consent). A child under 13 never gets their own login or email from us. Teens 13 to 17 can only get a limited login after a parent or guardian approves it. See the Children's Privacy section below.
- Your choices. You can ask to see, correct, delete, or restrict your information, withdraw consent, or have us review a decision. We offer these choices to everyone in the United States, not just people in states that require them.
- Program status. The parts of Crescendo that let children and teens sign up are built but are not turned on yet at launch. Minors cannot currently sign up.
Effective date: July 23, 2026 Version: 1.0.0
1. Who we are and what this policy covers
Crescendo Music Academy ("Crescendo," "we," "us," or "our") runs an online music-lesson video course platform. This Privacy Policy explains how we handle personal information when you:
- visit our website,
- create an account or sign in,
- set up or manage a learner,
- buy or use music lessons,
- contact us for support, or
- ask us to act on your privacy rights.
Crescendo is meant for people in the United States. We are not offering the service to people outside the United States at this time.
Crescendo Music Academy is the legal entity that operates the Service. It is a sole proprietorship that operates under the name Crescendo Music Academy from Houston, Texas.
You can reach us about privacy at:
- Privacy email: [email protected]
- Support email: [email protected]
- Mailing address: Crescendo Music Academy, Houston, Texas, USA — contact by email preferred at [email protected]
2. Information we collect
We only collect what we need to run the service. Here is what we may collect, grouped by type. The exact fields are set by the production data inventory.
| What we collect | Examples | Why we collect it |
|---|---|---|
| Account and sign-in info | Name, email, Google sign-in ID, profile image, session and login details, account status | To sign you in, run your account, and keep it secure |
| Learner info | Learner display name, age band (not a full birth date), instrument interests, lesson progress, practice activity and notes, achievements (XP, streaks), annotations | To personalize and save learning activity |
| Guardian and consent info | The relationship between an adult and a learner, permissions, which notices we showed, consent decisions, how consent was verified, and the dates | To set up and prove guardian authority and parental consent |
| Payment info | Payment company customer ID, subscription, purchase, refund, and access records | To take payment, run subscriptions, and give access to what was bought |
| Technical and security info | IP-based security data, browser and device type, request and error logs, security events | To keep the service safe, reliable, and free of fraud |
| Communications and choices | Support requests, privacy requests, accessibility requests, and (for adults) email preferences | To answer you and honor your choices |
A few important points:
- We use an age band, not a full birth date. For example, we record that a learner is "under 13" or "13 to 17," not their exact date of birth.
- We never store your full card number. Our payment company handles card numbers directly.
- Video links do not carry your identity. When you watch a lesson, the short-lived video link contains only a video ID and a security token. It does not contain your name, email, account ID, or viewing history.
- A child under 13 never gets their own login, email address, or Google sign-in. See the Children's Privacy section.
We do not collect precise location, contact lists, biometric identifiers, government ID documents, public photos, or advertising profiles.
3. How we collect information
We get information in these ways:
- You give it to us. For example, when an adult creates an account, sets up a learner, buys a lesson, or contacts support.
- We collect it automatically. For example, security and reliability data such as an IP-based signal, browser type, and error logs when you use the site.
- From companies that help us run the service. For example, our sign-in provider confirms your Google login, and our payment company confirms a payment. These companies are described in Section 6.
We do not buy child profiles, and we do not add advertising data to anyone's profile.
Before an adult signs in to start setting up a learner, we use a short-lived, anonymous routing record. It only notes the general path (for example, an adult account or a certain age band). It does not contain an email, a login ID, a child's name, or any learning data.
4. How we use information
We use personal information to:
- sign you in and keep accounts secure;
- provide lessons, learner profiles, progress, practice tracking, and access to what was purchased;
- set up and manage guardian authority and parental consent;
- take payments and handle subscriptions, refunds, and support;
- keep the service working, fix problems, prevent fraud, and improve it;
- follow the law and handle privacy requests; and
- send marketing email to adults who opt in, always with an easy way to unsubscribe.
We do not use your information for targeted advertising, and we do not make automated decisions about you that have legal or similarly significant effects without human review.
5. Our legal basis for using information (context)
We are a US-only service, so we do not rely on the GDPR's legal-basis framework. In plain terms, we use your information to:
- do what you asked (run your account, deliver a lesson you bought);
- keep the service safe and working (security, fraud prevention, reliability);
- follow the law (tax, consumer-protection, and children's-privacy rules); and
- act on your consent where we ask for it (for example, adult marketing email and verified parental consent for a child under 13).
6. Who we share information with
We share the smallest amount of information needed with companies that help us run Crescendo. These companies may only use it to do the job we hired them for, and they must meet the controls in our vendor review. Here are the categories:
| Type of company | What it does for us | What it may receive |
|---|---|---|
| Sign-in provider (Google) | Confirms your login | Name, email, profile image, and sign-in IDs. It does not receive our age records. |
| Payment company (Stripe) | Takes payment and handles subscriptions, refunds, and disputes | Adult payer identity and payment data, plus one opaque order ID. It does not receive a child's identity, age, viewing, practice, or consent data. |
| Video provider (Bunny) | Stores and streams lesson video | A video ID, a security token, and network/request data. It does not receive our account or learner IDs. |
| Hosting provider (VPS) | Runs the application and database | Production application and database data, as our infrastructure host |
| Storage and delivery (Cloudflare, Cloudflare R2) | Delivers the site securely and stores files and encrypted backups | Network and security data; uploaded files and encrypted database backups |
| Error and monitoring tools (Sentry, and similar) | Helps us find and fix problems | Scrubbed error and diagnostic data, with personal details removed before sending |
| Email provider (Resend) | Sends account and (for adults) opted-in email | Adult or guardian email address and basic delivery data |
Important: These are the companies we currently rely on and the purposes they serve. We review each company before it handles personal information, each may use the data only to provide its service to us, and we update this list when a company is added or removed.
We may also share information when:
- the law requires it, or to respond to a valid legal request;
- it is needed to protect people, the public, or the service; or
- the business is involved in a reviewed sale, merger, or similar transaction.
We give lesson-viewing information extra care. Before we would ever disclose who watched what, we apply heightened review, consistent with the Video Privacy Protection Act.
We do not sell your personal information. We do not share it for cross-context behavioral advertising, and we do not use targeted advertising based on learning activity. We do not knowingly disclose a child's personal information for any optional commercial purpose.
7. Where your information is stored and processed
Crescendo is intended for users in the United States. Our application and database run on a server located in the United States, and your account, learner, payment, and consent records are stored there and with the providers listed in Section 6. Some of those providers (for example, our content-delivery/security network and our video provider) operate global edge networks and may process limited technical delivery data — such as network and security information — at edge locations outside the United States while serving a request; they remain bound to use that data only to provide their service to us.
8. How long we keep information
We keep information only as long as we need it for the purpose we collected it. We may also keep it to meet a legal, tax, accounting, dispute, or security need, or to keep evidence of a consent decision. We give child data the shortest workable retention period.
When you make a valid deletion request, we remove or de-identify your information across our active systems and the companies that process data for us. The only exceptions are narrow, documented cases where the law requires or allows us to keep it. Our encrypted backups expire on a set schedule, and we use safeguards so that deleted information is not brought back into active use if a backup is ever restored.
The retention period for each category of information is set by the purpose it serves:
- Account and learner records are kept while the account or learner profile is active, then deleted or de-identified through our deletion process.
- Payment and transaction records are kept for as long as tax, accounting, and dispute rules require.
- Consent, approval, and legal-acceptance evidence is kept while it remains the proof of an authorization and for the period needed to demonstrate compliance.
- Security and diagnostic logs are kept for a short rolling window unless a documented incident requires a longer hold.
- Temporary records — such as privacy-request exports and pending correction proposals — expire and are purged automatically on a fixed short schedule.
9. Your privacy rights and choices
Depending on where you live and the situation, you can ask us to:
| Your right | What it means |
|---|---|
| Access | See the personal information we have about you |
| Correction | Fix information that is wrong |
| Deletion | Delete your information, with narrow legal exceptions |
| Restriction | Limit how we use your information |
| Withdraw consent | Take back a consent you gave |
| Review a decision | Ask a person to review how we handled your request |
We offer our core access, correction, and deletion process to everyone in the United States, even where a state law does not require every right.
A verified parent or guardian can use these rights for a learner they manage. See the Children's Privacy section.
How to make a request. You can submit a request through your account or by contacting us:
- Authenticated request page: https://crescendomusicacademy.com/account/privacy
- Privacy contact: [email protected]
We will verify your identity and your authority before we act, so that we do not give someone else's information to the wrong person. We try to do this without asking for more identity documents than needed. We will not treat you unfairly or cut off service because you used a privacy right.
If you are a Texas resident, the Texas Data Privacy and Security Act may give you specific rights, including the right to appeal if we decline a request; we describe the appeal path when we respond to a request.
10. Cookies and similar technology
We use only the cookies and similar technology needed to run the service, such as keeping you signed in, keeping the site secure, processing payments, playing video, and remembering your settings.
- We do not allow cross-context behavioral advertising.
- We do not run advertising trackers, ad-network pixels, or child-directed analytics.
- We do not sell or share information through tracking technology.
The cookies we set are limited to essential first-party cookies: authentication and session cookies that keep you signed in, and security cookies that protect sign-in and forms. Our product analytics, when enabled, is cookieless — it sets no cookies and stores nothing in your browser, so it needs no consent banner or opt-out. Video playback and payment pages may use cookies set by our video and payment providers solely to deliver those functions.
11. How we protect information
We protect information with steps that include:
- access controls and least-privilege access;
- keeping secret keys only in secure, server-only files;
- encrypting information in transit;
- limiting how long we keep data;
- reviewing the companies that help us; and
- monitoring, encrypted backups, and an incident-response process.
No online service can be completely secure, so we cannot promise perfect security. If a security incident affects your information, we will notify you and the right authorities as the law requires, based on your state and the facts of the incident.
12. Children's Privacy
This section is for parents and guardians. It explains how we handle information about learners under 13, and about teens 13 to 17. It adds to the rest of this policy.
12.1 A child under 13 cannot sign up on their own
A child under 13 cannot create an account, use a Google login, give us an email address, or buy content. Only a verified parent or legal guardian can set up and control a learner profile for a child under 13, and only after we give the adult a clear, direct notice and the adult gives us verified parental consent.
Before consent, we store only a short-lived setup record tied to the adult and the intended age band. We do not ask for the child's name or any learning information until consent succeeds.
12.2 What we collect about a child after consent
After a parent or guardian consents, we collect only the minimum needed:
- a parent-chosen learner display name and an "under 13" age band;
- instrument, course, lesson, progress, practice, XP, streak, and annotation information;
- the content an adult purchaser assigned to the learner;
- limited device, playback, security, and diagnostic information needed to deliver and protect the service; and
- any support or accessibility information a guardian chooses to give us.
We do not need a child's email, full birth date, precise location, contact list, biometric identifier, public photo, or advertising profile.
12.3 How we use a child's information
We use a child's information only to provide music lessons, save progress, support the learner and guardian, keep the service secure, and meet legal duties. We do not use it for behavioral advertising, direct marketing to children, public profiles, social discovery, or unrelated profiling. There are no public child profiles, no comments, and no child-to-child messaging.
12.4 Who processes a child's information
Only reviewed companies may handle the minimum child information needed for hosting, video delivery, storage, security, diagnostics, support, and verifying parental consent. They may not use it for their own advertising or for unrelated purposes.
The reviewed companies that may handle child information are the providers listed in Section 6, each limited to the purpose and data shown there; no other company receives child information.
12.5 Parent and guardian rights
A verified parent or guardian may:
- review the child's personal information and activity;
- correct information that is wrong;
- refuse any further optional collection or sharing;
- withdraw consent and stop future collection;
- delete the learner profile and eligible child information; and
- ask us to review a request decision.
You can use these rights through your account controls or by contacting us:
- Guardian account controls: https://crescendomusicacademy.com/account (learner management at https://crescendomusicacademy.com/account/learners)
- Children's privacy contact: [email protected]
We will confirm your authority first. We will not require a purchase, or more information about your child than reasonably needed, as a condition of taking part.
12.6 Teens ages 13 to 17
A teen 13 to 17 may get a limited login only after the required parent or guardian approval. A teen is never the person who pays or owns the billing account. We do not market directly to teens, and the same "no public profiles, no ads, no social features" rules apply.
Parent or guardian approval for teen use is separate from the verified parental consent required for a child under 13. One is never used in place of the other.
12.7 Keeping and deleting a child's information
We keep a child's information only while it is needed for the consented learning service, for security, or for a narrow legal duty, and then we delete it using our deletion process. When a parent or guardian withdraws consent, we stop the affected collection right away. Encrypted backups expire on their schedule, and we use safeguards so deleted information is not restored into active use.
In practice, that means a child's learning records are kept only while the learner profile remains active under a valid parental consent; consent evidence is kept while it remains the proof of that authorization and for the period needed to demonstrate compliance; and security logs follow the same short rolling window described in Section 8. When consent is withdrawn or the profile is deleted, we delete or de-identify the child's information through our deletion process, subject only to the narrow legal exceptions in Section 8.
12.8 If we change how we handle a child's information
If we make a material change to how we collect, use, or share a child's information, we will give a new direct notice and get new verified parental consent before the new practice begins.
Program status: The parts of Crescendo that let children under 13 and teens sign up are designed and built but are not turned on at launch. Minors cannot currently create or use an account. When we enable these features, this policy and the direct parental notice will govern them.
13. How to contact us and make a request
For any privacy question or request, contact us at:
- Privacy email: [email protected]
- Support email: [email protected]
- Mailing address: Crescendo Music Academy, Houston, Texas, USA — contact by email preferred at [email protected]
- Authenticated request page: https://crescendomusicacademy.com/account/privacy
We will respond within the time the law requires. If we cannot verify your identity or authority, we may not be able to act on the request, and we will explain why.
14. Changes to this policy
Each published version of this policy has an effective date and a fixed version number. If we make a material change, we will give an appropriate notice in the product or directly to you, and, where the law requires it, we will ask for new consent before the changed use begins. A privacy policy is a notice, not a hidden consent checkbox.
15. Additional important points
- No sale of personal information. We do not sell your personal information and do not share it for cross-context behavioral advertising. There is no "Do Not Sell or Share" action to take because we do not do either.
- Links to other sites. If we link to a site we do not run, that site has its own privacy practices, and this policy does not cover it.
- Governing law. This policy is governed by the laws of the State of Texas and applicable US federal law. Disputes are handled as described in our Terms of Service (in the state and federal courts located in Harris County, Texas, or in small-claims court where a claim qualifies).
- US-only service. Crescendo is intended for users in the United States.
Effective date: July 23, 2026 Version: 1.0.0