IGNIFY

Privacy Policy

Version 2.0.0 · Effective June 28, 2026

This Privacy Policy describes how IGNIFY, Inc. ("IGNIFY", "Ignify", "we", "us", or "our") collects, uses, shares, and protects information about you when you use the IGNIFY mobile applications (iOS and Android, bundle identifier us.ignify.app), our public website at ignify.us, and our customer dashboard at app.ignify.us (collectively, the "Platform").

IGNIFY is a technology platform that connects students and families with independent music studios and teachers ("Studios"). IGNIFY is not a Studio or a teacher, does not deliver lessons itself, and is not a party to the lesson relationship between you and a Studio. This Policy covers IGNIFY's own handling of your information; a Studio's separate handling of information it receives through the Platform is governed by that Studio's own practices.

For questions about this Policy or to exercise your privacy rights, contact us at privacy@ignify.us. For other legal matters, contact legal@ignify.us.


1. Information We Collect

Information you (or a guardian) provide directly.

Information collected automatically.

Information from connected integrations.

2. How We Use Your Information

We use your information to:

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use your data to train external foundation models (see Section 4).

3. How We Share Information

We share information only with the categories of recipients listed below, each for the specific purpose stated. Several recipients act as our service providers or sub-processors and process information on our behalf under contract.

RecipientRoleWhat is sharedPurpose
Studios you belong to or book withThe relationship you joinedName, email, enrollment, bookings, attendance, finalized reportsDeliver lessons, manage enrollment and scheduling
Teachers within those StudiosThe relationship you joinedName, finalized lesson reports, lesson-related contentDeliver lessons and reports
Family members you addedA user you authorizedLinked profile, schedule, and reports within your familyCoordinate scheduling and reporting within the family
Amazon Web Services (AWS)Cloud infrastructure sub-processorAll Platform data (encrypted in transit and at rest)Cloud hosting and infrastructure for the Platform — including compute, storage, database, authentication, messaging, email and push/SMS delivery, content moderation, video calling, logging, and our own speech-to-text transcription.
Anthropic, PBC (Claude API)AI sub-processorLesson transcript text only — never raw audio — when recording is enabled and consent has been givenDraft completed-lesson reports. Anthropic processes this content under its Commercial Terms, which contractually prohibit using it to train Anthropic's models. See Section 4.
Square (Block, Inc.)Payment / invoicing provider (Studio-selected)Invoice and booking records (amounts, line items, family name and email) when a Studio connects Square — never card numbers, security codes, or expiryHosted checkout and collection of funds, and invoice reconciliation, for Studios that select Square
QuickBooks Online (Intuit Inc.)Payment / invoicing provider (Studio-selected)Invoice and booking records (amounts, line items, family name and email) when a Studio connects QuickBooks Online — never card numbers, security codes, or expiryHosted checkout and collection of funds, and invoice reconciliation, for Studios that select QuickBooks Online
Wave (Wave Financial Inc.)Payment / invoicing provider (Studio-selected)Invoice and booking records (amounts, line items, family name and email) when a Studio connects Wave — never card numbers, security codes, or expiryHosted checkout and collection of funds, and invoice reconciliation, for Studios that select Wave
Firebase / GoogleMobile analytics, crash, and push (apps only)Push tokens (FCM); a pseudonymous account identifier and role; crash and performance diagnosticsNotifications, analytics, and crash reporting
Apple Inc.Identity and push providerSign in with Apple identity; push tokens (APNs)Sign-in and push delivery to iOS devices
Google LLCSign-in and calendarSign-in profile; Google Calendar data when you connect it (OAuth)Sign-in and calendar import
Legal and safety authoritiesLegal obligationWhat valid legal process requiresComply with subpoenas, court orders, and lawful requests; protect safety

We do not share your personal information with advertisers or data brokers. We use no third-party advertising or analytics trackers on our websites (see Section 12).

Google user data — Limited Use

When you connect Google Calendar, IGNIFY's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not transfer it except as needed to provide the feature you requested, to comply with applicable law, or in connection with a merger or acquisition.

4. AI and Lesson Reports

A central feature of IGNIFY is AI-assisted draft completed-lesson reports. Here is exactly how that works.

What is recorded. When a teacher starts recording a lesson — and only then, with the consent described in Section 5 — the lesson audio is captured, sent over an encrypted connection, and stored on IGNIFY's infrastructure. Recording is teacher-initiated and off by default; it is not always-on.

How audio becomes a transcript. Lesson audio is transcribed by our own self-hosted speech-to-text transcription, running on our cloud infrastructure. The audio is not sent to any third-party transcription service.

What is sent to Anthropic. Only the transcript text — never the raw audio — is sent to Anthropic, PBC through Anthropic's first-party Claude API to draft a report. We do not route this content through any intermediary model-hosting service.

Consent is enforced before AI processing. The Platform checks that the required consent exists before any transcript text is sent to Anthropic. This check is fail-closed: it runs when a report job is submitted, again immediately before the model is called, again if an error occurs, and is re-checked at the time of the call. If valid consent is not present, no transcript is sent.

No model training — a contractual commitment. Anthropic operates the Claude API under its Commercial Terms, which contractually prohibit Anthropic from using API content to train its models. This "no training on your data" protection is a contractual commitment by Anthropic, not a technical control implemented in our code. We rely on Anthropic's contractual terms for it.

Teacher review is required. AI output is a draft. A teacher, Studio owner, or admin must review and finalize each report before it is shared. Reports are not delivered to families automatically.

Bug-report voice notes. When you file a bug report, you may attach an optional short voice note. That clip is transcribed to text on IGNIFY's own infrastructure; the resulting transcript is what we store with the bug report.

Speaker labels are heuristic, not biometric. Where a report attributes speech to "the teacher" or "the student," those labels come from talk-time heuristics, not from a biometric voiceprint. We do not create or store biometric identifiers or voiceprints, and this pipeline is not intended to generate "biometric information" under the Illinois Biometric Information Privacy Act (BIPA).

5. Recording and Consent

Recording is off by default. All recording-consent settings default to off. No recording occurs unless a teacher initiates it and the applicable consent has been captured.

Granular, revocable consent. Consent is granular: it can be given globally and per-Studio, and it can be revoked at any time. The Platform keeps an immutable audit history of consent changes.

Per-session acknowledgment. For a recorded session, the relevant participant or guardian is asked to explicitly accept or decline before recording proceeds.

Calls are not recorded by IGNIFY. Voice and video calls placed through the Platform are not recorded on our servers. Only lesson audio and "lab" uploads are recorded and processed as described in this Policy.

Revoking consent. You may revoke recording consent at any time in the app's consent settings. Revocation applies to future recordings; it does not unpublish reports that were already finalized.

6. Children's Privacy (COPPA)

IGNIFY is used by families, and children participate through guardian-managed profiles. We take the following positions, and we describe them honestly rather than overstating.

Children do not create their own accounts. Children participate only as guardian-added child profiles that a parent or guardian creates and manages, and a guardian-added child profile is not given its own login. We do not intend for a child under 13 to create or operate an independent account, and we describe below the current limits of our age screening for self-registration.

What we collect for a child profile. As stated in Section 1, only the child's first name, date of birth, relationship to the guardian, and a stock avatar — plus the lesson attendance, finalized reports, and (only with the guardian's consent) lesson audio tied to the child's enrolled classes. We do not collect a child's last name, photo, location, payment, or independent contact information.

We do not knowingly permit under-13 self-registration, and we flag suspected under-13 accounts for review. Because the pre-signup age gate has been removed, it is possible for a Google or Apple social sign-in to create an account identity before the person's age is known. When an account is identified as belonging to a child under 13 outside the guardian-managed model, the app flags the account for review; decommissioning is handled manually and is not yet automated.

Verifiable parental consent. We are working to adopt a verifiable parental consent method consistent with COPPA (16 CFR § 312.5). Until that mechanism is in place, we do not represent that we obtain verifiable parental consent in every case, and we rely on the guardian-managed model and the decommissioning practice described above. We do not claim that we never receive any information relating to a child under 13.

Guardian rights. A guardian may, at any time, from inside the app or by emailing privacy@ignify.us, review what we have collected about their child, correct or delete it, delete the entire child profile, revoke consent for lesson audio, or request an export of the child's data. We do not condition a child's participation on collecting more information than is reasonably necessary.

If you believe a child has provided us information outside the guardian-managed model, contact privacy@ignify.us and we will act to remove it.

7. Data Security

We use the following safeguards, and we describe their scope precisely.

No method of transmission or storage is completely secure. If you suspect a security problem, contact security@ignify.us.

8. Data Retention

We retain personal information for as long as needed to provide the Platform and for the specific periods below. These periods are disclosed in full; do not rely on any shorter summary you may have seen previously.

9. Account Deletion

You can delete your account at any time from inside the app (Profile → Account → Delete my account → confirm), from the web at https://app.ignify.us/auth/delete-account, or by emailing privacy@ignify.us.

How deletion works. When you delete your account, we place it in a 30-day tombstone state. If you do not cancel within that window by signing back in, we then perform an irreversible hard purge. The purge removes your records across our databases, deletes your stored avatar image, removes your stored push-notification tokens and the corresponding push-provider registration, and removes your identity from our authentication system. Surviving references to you in other users' data are anonymized, and the deletion is recorded in an audit log.

Deleting a sole guardian's account removes the family's data. If you are the only guardian on a family account, deleting your account cascade-deletes the family's data, including the child profiles you created and their associated consent records. This is intentional: a child profile exists only under a guardian's account and is not retained once its sole guardian is removed.

Honest scope limits — please read.

If you need data removed from a sub-processor, contact privacy@ignify.us and we will assist where we are able.

10. Your California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to:

To exercise these rights, contact privacy@ignify.us or use the account-deletion path in Section 9. We will respond within the time required by law (generally 45 days).

11. Your European Privacy Rights (GDPR / UK GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the right to access, rectify, erase, restrict, and port your personal data; to object to processing based on our legitimate interests; to withdraw consent where processing is based on consent; and to lodge a complaint with your supervisory authority. Erasure is subject to the legally required retention and scope limits described in Sections 8 and 9.

The legal bases on which we process your data include contractual necessity (delivering the service you signed up for), legitimate interests (operating, securing, and improving the Platform), legal obligation (retention required by law), and consent (recording features and any processing for which consent is required).

Submit requests to privacy@ignify.us. We respond within the time required by applicable law (generally one month).

12. Cookies and Tracking

Our websites. Our customer dashboard sets a single first-party cookie (currentStudioId, SameSite=Lax) used solely to route you to the correct Studio context. Authentication tokens are held in your browser's local storage, not in cookies. We set no third-party analytics or advertising cookies on our websites; the only third-party resource our sites load is Google Fonts.

Our mobile apps. The Firebase Analytics, Crashlytics, and Performance described in Section 1 are present in the mobile apps only, not on our websites. They use the pseudonymous identifiers described there and do not carry your raw email, phone, name, or date of birth.

No cross-context behavioral advertising. We do not sell or share personal information for cross-context behavioral advertising. Our iOS apps do not access the Apple Identifier for Advertisers (IDFA).

You can control cookies through your browser settings; disabling the essential first-party cookie may prevent parts of the dashboard from working.

13. International Transfers

Our infrastructure is hosted on AWS in the United States. If you use the Platform from outside the United States, your information will be transferred to, stored, and processed in the United States. Where required for transfers from the EEA, the United Kingdom, or Switzerland, we rely on standard contractual clauses and our providers' data-processing terms.

14. Changes to This Policy

We may update this Policy. We will notify you of material changes by email or in-app notice before they take effect and, where required, will prompt you to re-accept the updated Policy in the app. The "Effective" date at the top of this page shows when the current version took effect.

15. Contact

IGNIFY, Inc. — Privacy Team