Privacy Policy
This policy describes how personal data is processed in the TianoChoirs app in accordance with the EU General Data Protection Regulation (GDPR). We use your personal data only for the purposes described in this policy.
1. Data controller
Elektronituotanto (sole trader)
Business ID: 3149166-6
Address: Linnaistenkuja 2 C, 04400 Järvenpää, Finland
Email: support@tianochoirs.com
For any questions about data protection, please contact the email address above.
2. What personal data we process
| Category | Data |
|---|---|
| Account data | Email address and password. The password is stored securely as a hash — we cannot see it. |
| Profile data | Display name, optional profile picture, notification language, voice part, and optional age group (13–17 / 18–64 / 65+), if you provide it. |
| Choir membership | Which choirs you belong to, your role in the choir (member/admin/owner), and email addresses related to invitations. |
| Content | Sheet music and files you upload, markings you make on them, calendar events and sign-ups (RSVP), and chat messages and images you attach. |
| Audio recordings | Voice parts and other audio files you record or upload in the app (e.g. rehearsal tracks), which you save to choir content. |
| Interaction | Reactions and pins you add to messages, and reports and user blocks related to moderation. |
| Feedback | Feedback you send through the app. |
| Notification data | For push notifications, your device's push token and user identifier. |
| Technical data | IP address, device information and usage logs collected by our service providers for security and service operation. |
The app may request permission to use your device's camera to scan sheet music, your microphone to record voice parts, and to access image and audio files if you add them. These permissions are used only for that function.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service: account, profile, choir activity, sheet music, calendar and chat | Performance of a contract (6.1 b) |
| Notifications about events and choir activity (push/email) | Contract / legitimate interest (6.1 b/f) |
| Security, abuse prevention, content moderation and logging | Legitimate interest (6.1 f) |
| Handling feedback and improving the service | Legitimate interest (6.1 f) |
| Age group and possible ad targeting in the future | Consent (6.1 a) — no ads are shown at present |
| Compliance with legal obligations | Legal obligation (6.1 c) |
4. Who we share data with (processors)
We do not sell your personal data. We use the following service providers who process data on our behalf:
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage and real-time messaging | EU (Frankfurt, Germany) |
| Resend | Sending emails (confirmations, invitations, reminders) | United States |
| OneSignal | Delivering push notifications | United States |
No advertising or payment services are currently in use. If any are introduced, we will update this policy and, where necessary, ask for your consent.
5. Transfers outside the EU
The database and files are located in the EU. Resend and OneSignal process data in the United States. These transfers use safeguards approved by the EU (Standard Contractual Clauses, SCC, and/or the EU–US Data Privacy Framework).
6. Retention
We retain personal data related to your account for as long as your account exists. Chat content additionally has its own lifecycles:
- Chat message text is deleted automatically after 12 months.
- Images sent to chat are deleted automatically after 4 months.
When you delete your account in the app, the personal data related to your account (profile, content) is deleted. Shared choir content (sheet music, events, channel messages) remains available to the other members of the choir. Backups rotate and are removed according to the normal backup cycle.
7. User-generated content and moderation
The choir chat allows sharing messages and images. To maintain a safe environment and meet app store requirements, we provide ways to report an inappropriate message and to block an individual user. When you submit a report, the reported message and the names of the reporter and author are forwarded to the service operator for handling — never to other users.
Chat communication is not end-to-end encrypted. Protection is based on TLS encryption in transit, encryption at rest, database access control (Row Level Security) and EU data location. The operator may review content where necessary for moderation and legal obligations (e.g. notice-and-takedown).
8. Your rights
You have the following rights regarding your personal data under the GDPR:
- Right of access to your data
- Right to rectify inaccurate data
- Right to erasure — you can delete your account directly in the app (see Account & data deletion)
- Right to restrict and object to processing
- Right to data portability
- Right to withdraw your consent at any time
You can exercise your rights by contacting support@tianochoirs.com. If you believe your data is being processed unlawfully, you may lodge a complaint with a supervisory authority (in Finland, the Office of the Data Protection Ombudsman, tietosuoja.fi).
9. Children's privacy
The service is intended for users aged 13 and over. Processing the data of a child under 13 requires a guardian's consent. We do not knowingly collect data from children under 13 without a guardian's consent.
10. Cookies and identifiers
This website (tianochoirs.com) is a static informational site and does not use tracking or advertising cookies. The app itself uses device identifiers to deliver push notifications and to ensure the technical operation of the service. The app does not use advertising cookies.
11. Changes to this policy
We may update this policy. We will notify you of significant changes in the app or by email. The current version is always available on this page.