Privacy policy
Last updated: October 4, 2026.
1. Summary
We keep the minimum the course needs to work. Our database does not keep your account's email, name or photo: they stay with the sign-in service. What we keep is what is part of the product: your progress, your account's choices, what you decide to save or write to us, your plan and, if you use classes, the class data. Outside the database, we keep for 6 months the access records the law requires. We do not sell data, show ads or use advertising trackers. Below is each piece of data, what it is for, who it is shared with, how long it is kept and how you exercise your rights.
2. Who is responsible
The controller of your personal data is TEAM ONE TECNOLOGIA LTDA, CNPJ 46.552.150/0001-09, which offers Solmiza, in the sense of Brazil's General Data Protection Law (Law 13.709/2018, the LGPD): the one who decides how it is handled on this site. For anything about your data, including reaching the data protection officer, the channel is the contact form (section 22).
3. Account and sign-in
Sign-in, with a code sent to your email or with your Google account, is handled by Clerk, our authentication service. Clerk keeps your email, the profile name and photo when there are any, and the data of each session, such as the IP address and the browser, under its own privacy policy. If you sign in with Google, Google gives Clerk your name, your email and your photo. In our database, your account is only the identifier Clerk creates for it.
Next to that identifier we keep the date the account was created and four choices: the app's language, how you want to read notes (as letters, C D E, or as syllables, Do Re Mi), the time zone your browser reports, so your study day turns over at midnight where you live, and whether you want to receive the streak reminder email. If the account was created as a teacher account, we also keep that it is a teacher's.
4. Progress and exercises
We record each exercise attempt (the lesson, the exercise, what was asked, the result, the hint you asked for, whether you answered on screen or by playing, and when), the lessons completed or skipped, the times you tell us the microphone did not hear what you played, and how well you know each topic. From these we work out your progress, your streak, your certificates and what to review next. We also keep the chord progressions you save.
If you use the "Still not clear?" field, we keep what you write, with the lesson and exercise it came from, to improve the course. Do not write personal data there.
In the played exercises and in the tuner, the microphone's sound is analyzed in your own browser to recognize the notes. The sound is not sent to us or to anyone and is not kept: what reaches our database is only the attempt's result. Your browser asks for your permission before opening the microphone, and every played exercise can be answered on screen.
If you turn on "Record my attempt" in Account, your browser keeps your last played attempt in the page's memory, only so you can listen back. It is not sent to any server and is gone when you close the page.
When the plans screen appears, we record that it appeared, in which currency, which plan you tapped and, if you choose to tell us, the reason for not subscribing now, picked from a list. We use this only to understand the offer.
5. Certificates
When you ask for the certificate of a completed level or of the course, it keeps your profile name on that day, what was completed and the date. It never shows your email or details of your progress. The certificate has its own address, hard to guess: anyone with the link can see it, and it is marked to stay out of search engines. It is the only place we keep a name, and it exists because a certificate's purpose is to be shown. Deleting the account deletes the certificates, and their links stop working.
6. Payment
Payments are made through Stripe, on its payment page. Stripe receives the card details and what you enter at checkout, such as your email, and also handles them on its own account to meet its obligations, such as fraud prevention and financial records, under its own privacy policy. We never see or keep the card number. We keep the plan type, how it is billed (annual or one-time), the billing status, whether a cancellation is scheduled, the amount and currency charged, the customer and subscription identifiers at Stripe and the record of refunds. Stripe sends receipts to you directly.
7. Classes
The teacher area may not be open yet when you read this. What follows applies once it is open.
When you join a class with the code the teacher gave you, that class's teacher can see: your profile name (or "No name on profile" when it is empty), the level and lesson you are on, how many course lessons you have completed, the day you last studied, your streak and the date you joined. The teacher does not see your email, your answers, your questions or your plan. The joining screen shows this list, with your name, before the confirm button, and joining is your authorization. You can leave the class whenever you want, on the same screen: once you leave, the teacher stops seeing anything about you at once. When the teacher opens the class, nothing is written to your account.
If you are a teacher, we keep the classes you created (name, join code and date) and who joined each one, by account identifier and joining date. Each student's name is read from Clerk when you open the class and is not kept by us.
Live observation (a teacher watching your study session) is not open yet. When it is, it will only work with your explicit permission, given per class and which you can withdraw at any time; every permission, request and withdrawal is recorded and is part of your data export.
8. Messages through the contact form
Anyone can write to us through the contact form, with or without an account. With your account signed in, we keep the topic, the text (up to 2000 characters) and the date, linked to your account. Your email is not kept with the message: it is read from Clerk to show you where the reply goes and for us to reply. These messages stay as long as the account exists, are part of your data export and are deleted with the account. Only the person who makes Solmiza reads the messages; teachers and other accounts do not see them.
Without an account, we keep the email you type, the topic, the text and the date, only to reply, and the message is deleted automatically 12 months after it was sent. To keep out automated messages, the form has a hidden field and a minimum time to fill it in, with no third-party captcha and no cookie. Your IP address is not kept: it stays briefly in the server's memory only, to limit how many messages come from the same address (5 per hour), with a limit for all visitors together as well.
Each message also reaches the person who makes Solmiza by email, sent through Mailtrap, with the topic, the email for the reply (and, with an account, the account's identifier), the date and the full text. A copy of that notice stays in that inbox and at Mailtrap, outside our database. Never send card numbers or passwords through the form.
9. Emails we send
We may send you an email reminder when your streak is about to be lost, through Mailtrap, in your account's language and time zone. Your email is looked up at Clerk when the reminder is sent and is not kept in our database. You can turn this reminder off whenever you want, in Account, on the Study tab, or from the link in every reminder, which works without signing in. That choice is kept on your account, is part of the export and is deleted with it. We do not send advertising. Clerk sends the sign-in codes and Stripe the payment receipts, each on its own.
10. What we use the data for and on what legal basis
To perform our contract with you (LGPD, art. 7, V): creating and keeping the account, keeping your progress, issuing certificates, charging for and granting the plan, making classes work, answering your messages and handling export and deletion requests.
To meet legal obligations (art. 7, II): keeping the access records Brazil's Internet Civil Framework (Marco Civil da Internet) requires (section 17), keeping the payment and refund records the law requires and answering requests from authorities when the law requires it.
On our legitimate interest (art. 7, IX), within what you would expect from a course: knowing when something breaks (section 14), limiting abuse, understanding why someone does not subscribe (the plans screen records), improving lessons from the questions you write and sending the streak reminder, which you can turn off whenever you want. You can object to these uses through the contact form.
With your consent (art. 7, I): the teacher seeing your name and progress when you join a class, consent you withdraw by leaving it, and, once it exists, live observation, with its own permission per class. The microphone only opens with your permission in the browser, and the sound does not leave your device.
11. Who we share with
We do not sell or rent personal data. It passes only through these service providers, each with what its job needs: Hetzner (the app and database servers), Clerk (sign-in), Stripe (payment), Sentry (error alerts), Mailtrap (sending email) and Google Cloud (keeping the access records). Signing in with Google involves Google only if you choose to sign in with it. Beyond that, the teacher of a class you joined sees what section 7 describes, anyone with a certificate's link sees the certificate, and we may hand data to authorities when the law or a court order requires it.
12. Data outside Brazil
The app and the database run on Hetzner servers in Helsinki, Finland (European Union). Clerk, Stripe, Sentry and Mailtrap have servers outside Brazil, mostly in the United States. So the data each one receives is transferred to another country. That transfer is needed to provide the service you signed up for (LGPD, art. 33, IX) and rests on the data protection safeguards these providers commit to by contract. The access records stay at Google Cloud, in São Paulo, Brazil.
13. Where the data is and how we protect it
The app and the database run on servers rented from Hetzner, in Finland, which we manage ourselves, and the connection to the site is always encrypted (HTTPS). The app reaches the database with limited permissions (the attempt record, for instance, cannot be changed once written), each query reaches only the data of the account that made it, the admin screens are limited to authorized accounts, card details never pass through our servers and there are usage limits against abuse.
No system is fully immune. If a security incident happens that may bring you relevant risk or harm, we tell you and Brazil's National Data Protection Authority (ANPD), as the law requires.
14. Error reports
We use Sentry to know when something breaks. An error report carries the technical description of the error, the page, the browser and the device's system and, when you are signed in, your account identifier. It does not carry your email, your name or the content of what you send, and Sentry is set not to store your IP address. Reports stay at Sentry for that service's retention period.
15. Cookies and browser storage
We use only cookies the site needs to work: Clerk's session cookies, which keep you signed in, one that remembers the language you chose and one that remembers how you want to read notes before you sign in. We use no advertising cookies and no third-party analytics cookies. Some choices are kept only in your browser, on this device, and are not sent to us: the light or dark theme, auto-advance, recording the attempt, answering by playing or on screen, and whether you have seen the invitation to use the microphone.
16. IP address
Our database does not record your IP address. It goes only into the access records the law requires (section 17), kept outside the database, and stays briefly in the server's memory when you write through the contact form without an account (section 8). To show prices in your currency, we use the country the visit comes from, when the network reports it, or the browser's language, only while building the page; the currency is recorded only when you open the plans screen or buy. Clerk records the IP address and browser of each sign-in session, under its own policy.
17. Access records
Brazil's Internet Civil Framework (Marco Civil da Internet, Law 12.965/2014, art. 15) requires anyone offering an internet application to keep access records for 6 months. So we record the date and time Solmiza was used, the IP address the access came from and, when you are signed in, your account's internal identifier. There is at most one record per IP address and account every 15 minutes. We do not record the pages you open, the browser, the device, the email, the name or the connection's port.
These records are kept apart from our database, at Google Cloud, in the São Paulo region, Brazil, with Google as processor. They are kept for 6 months and then deleted automatically. The legal basis is meeting a legal obligation (LGPD, art. 7, II). They are looked at only to hand over records when a court order asks for them (Marco Civil, arts. 15 and 22) and are never used for statistics, marketing or profiling. Because the law requires them to be kept for the whole period, they cannot be deleted earlier on request, not even when you delete the account.
18. How long we keep data
We keep the data as long as your account exists. When you delete the account, we immediately erase everything in our database (progress, choices, progressions, questions, contact messages, certificates, classes, plan and refund records) and ask Clerk to delete your sign-in. Database backups keep what was in it for up to 7 days, to restore the service after a failure, and are then deleted; in that time no one uses that data for anything else. If you are a teacher, your classes are deleted with it, and the students are no longer in them. A message sent through the form without an account belongs to no account and is deleted automatically 12 months after it was sent.
Some data sits outside our database and follows each provider's rules: the access records, at Google Cloud, for the 6 months the law requires (section 17); payment records at Stripe, kept for the period financial laws require; the copies of contact message notices, in the inbox of the person who makes Solmiza and at Mailtrap; and error reports at Sentry, until its retention period ends.
19. Your rights
The LGPD (art. 18) gives you the right to: confirm that we handle your data and access it; correct incomplete, wrong or outdated data; ask for unnecessary, excessive or unlawfully handled data to be anonymized, blocked or erased; portability; erasure of data handled with your consent; know who we share with; know that you may withhold consent and what happens if you do; withdraw consent; and object to a use made without consent, if it breaks the law.
In practice: in Account, on the Data tab, you download at once a copy of everything our database keeps about you, in a JSON file that also works to take to another service. In Account, on the Account tab, you delete the account. You correct your name, email and photo in your profile, from the menu on your photo at the top of the screen; the language and note names, in Account. You turn off the streak reminder in Account, on the Study tab, or from the link in the email itself. To withdraw the consent given to a teacher, leave the class. For any other request, use the contact form, with or without an account, with the topic "Account or data"; we reply within the periods the law sets. You can also file a complaint with the ANPD.
20. Children
Solmiza has no minimum age and does not ask for a date of birth. Under the LGPD (art. 14), the data of a child, under 12, may only be handled with the specific consent of a parent or legal guardian. So a parent or guardian who creates a child's account or lets the child use Solmiza gives that consent. If you are a parent or guardian and want a child's account deleted, write through the contact form.
21. Changes to this policy
We may update this policy as Solmiza changes. The date at the top shows the current version. If a change would use your data in a way that depends on your consent, we ask first.
22. Contact and data protection officer
The channel to talk about your data, exercise your rights or reach the data protection officer is the contact form, open to anyone, with or without an account. With your account signed in, the reply goes to your account's email; without an account, to the email you give. See also the Terms of use.