Privacy Policy

TianoChoirs app · Last updated 3 August 2026

This policy describes how personal data is processed in the TianoChoirs app in accordance with the EU General Data Protection Regulation (GDPR). We use your personal data only for the purposes described in this policy.

1. Data controller

Elektronituotanto (sole trader)
Business ID: 3149166-6
Address: Linnaistenkuja 2 C, 04400 Järvenpää, Finland
Email:

For any questions about data protection, please contact the email address above.

2. What personal data we process

CategoryData
Account dataEmail address and password. The password is stored securely as a hash — we cannot see it.
Profile dataDisplay name, optional profile picture, notification language, voice part, and optional age group (13–17 / 18–64 / 65+), if you provide it.
Choir membershipWhich choirs you belong to, your role in the choir (member/admin/owner), and email addresses related to invitations.
ContentSheet music and files you upload, markings you make on them, calendar events and sign-ups (RSVP), and chat messages and images you attach.
Audio recordingsVoice parts and other audio files you record or upload in the app (e.g. rehearsal tracks), which you save to choir content.
InteractionReactions and pins you add to messages, and reports and user blocks related to moderation.
FeedbackFeedback you send through the app.
Notification dataFor push notifications, your device's push token and user identifier.
Technical dataIP address, device information and usage logs collected by our service providers for security and service operation.

The app may request permission to use your device's camera to scan sheet music, your microphone to record voice parts, and to access image and audio files if you add them. These permissions are used only for that function.

3. Purposes and legal bases

PurposeLegal basis (GDPR)
Providing the service: account, profile, choir activity, sheet music, calendar and chatPerformance of a contract (6.1 b)
Notifications about events and choir activity (push/email)Contract / legitimate interest (6.1 b/f)
Security, abuse prevention, content moderation and loggingLegitimate interest (6.1 f)
Handling feedback and improving the serviceLegitimate interest (6.1 f)
Age group and possible ad targeting in the futureConsent (6.1 a) — no ads are shown at present
Compliance with legal obligationsLegal obligation (6.1 c)

4. Who we share data with (processors)

We do not sell your personal data. We use the following service providers who process data on our behalf:

ServicePurposeLocation
SupabaseDatabase, authentication, file storage and real-time messagingEU (Frankfurt, Germany)
ResendSending emails (confirmations, invitations, reminders)United States
OneSignalDelivering push notificationsUnited States

No advertising or payment services are currently in use. If any are introduced, we will update this policy and, where necessary, ask for your consent.

5. Transfers outside the EU

The database and files are located in the EU. Resend and OneSignal process data in the United States. These transfers use safeguards approved by the EU (Standard Contractual Clauses, SCC, and/or the EU–US Data Privacy Framework).

6. Retention

We retain personal data related to your account for as long as your account exists. Chat content additionally has its own lifecycles:

When you delete your account in the app, the personal data related to your account (profile, content) is deleted. Shared choir content (sheet music, events, channel messages) remains available to the other members of the choir. Backups rotate and are removed according to the normal backup cycle.

7. User-generated content and moderation

The choir chat allows sharing messages and images. To maintain a safe environment and meet app store requirements, we provide ways to report an inappropriate message and to block an individual user. When you submit a report, the reported message and the names of the reporter and author are forwarded to the service operator for handling — never to other users.

Chat communication is not end-to-end encrypted. Protection is based on TLS encryption in transit, encryption at rest, database access control (Row Level Security) and EU data location. The operator may review content where necessary for moderation and legal obligations (e.g. notice-and-takedown).

8. Your rights

You have the following rights regarding your personal data under the GDPR:

You can exercise your rights by contacting . If you believe your data is being processed unlawfully, you may lodge a complaint with a supervisory authority (in Finland, the Office of the Data Protection Ombudsman, tietosuoja.fi).

9. Children's privacy

The service is intended for users aged 13 and over. Processing the data of a child under 13 requires a guardian's consent. We do not knowingly collect data from children under 13 without a guardian's consent.

10. Cookies and identifiers

This website (tianochoirs.com) is a static informational site and does not use tracking or advertising cookies. The app itself uses device identifiers to deliver push notifications and to ensure the technical operation of the service. The app does not use advertising cookies.

11. Changes to this policy

We may update this policy. We will notify you of significant changes in the app or by email. The current version is always available on this page.