INDEXTEN PRIVACY POLICY
A product of That Music Teacher, LLC, d/b/a Tarbet Education Network Website: indexten.app Effective Date: July 27, 2026
This Privacy Policy explains how That Music Teacher, LLC, an Ohio limited liability company doing business as Tarbet Education Network ("Company," "we," "us," or "our"), collects, uses, discloses, and protects information in connection with IndexTEN, our Kodály-based repertoire management application (the "Service"). It applies to visitors to our marketing site and to registered users of the Service ("you," "Teacher," or "user").
By creating an IndexTEN account or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy. This Policy is incorporated by reference into our Terms and Conditions, available at indexten.app/terms. Capitalized terms not defined here have the meanings given in the Terms.
Where we operate. We are a United States company based in Ohio. The Service is operated from the United States and is currently offered only to users located in the United States. Information you submit is processed and stored in the United States and in other countries where our service providers operate.
Adults only. IndexTEN is designed and marketed exclusively for use by adult educators. It is not directed to children, and it is not designed or authorized to store information about students. See Section 10.
1. Information We Collect
We collect information in three ways: information you provide directly, information generated through your use of the Service, and information collected automatically by the technical infrastructure that runs the Service.
1.1 Information You Provide Directly
Account information. Your email address and password (processed and securely hashed via our authentication provider, Supabase), and any display name you choose to add to your profile.
Billing information. When you subscribe, your email address is shared with our payment processor, Stripe, to create a matching Stripe Customer record. Full payment card details are entered directly into Stripe Checkout and are never transmitted to or stored on our servers. We receive only limited information from Stripe, such as subscription status, the last four digits of your card, and its expiration date.
Content you create or upload. Songs and repertoire records you add to your library, tags and taxonomy suggestions, saved lists, comments and free-text notes (such as a song's Comments field or Game/Formation teaching instructions), and any MusicXML files you upload or PDF exports you generate.
Support and feedback communications. If you submit a bug report through our in-app Bug Tracker, we post a notification to a private internal Slack channel using a Slack Incoming Webhook, so we can respond quickly. The notification includes the report's title and description, your display name, and a link for our team to open the report in our admin console. This is a one-way, internal notification only — it does not give Slack access to your library or any other account data, and your bug report is saved whether or not the notification is delivered. Feature suggestions are handled separately and are not sent to Slack.
Correspondence. If you email us or contact us through support channels, we retain that correspondence to respond to you and maintain a record of the interaction.
Marketing preferences. If you choose to opt in to marketing communications, we record that choice and the date it was made, and we record any later withdrawal of it.
1.2 Information Generated Through Use of the Service
Account and security logs. Audit and security log entries covering events such as login history, password changes, and account-level actions, maintained to secure your account and investigate misuse.
Subscription and billing history. Your subscription status, plan tier, renewal dates, and billing and receipt history, maintained through Stripe.
Export activity. When you use the self-service export function, we log the export event, including your account identifier, the date and time, and the volume of data exported. We also embed identifying information — your account identifier and an export timestamp — within export files. We do this to enforce the Terms, to detect misuse of the export function, and to identify the source of exported files if a rights holder raises a concern.
Legal and enforcement records. If we receive a copyright infringement notice or counter-notification relating to your account, or if we take enforcement action under our Terms, we retain records of that notice, our response, any content removed, and any strike or termination issued. These records contain information about both the user and the person submitting the notice, and are retained to comply with the Digital Millennium Copyright Act and to demonstrate consistent enforcement of our repeat infringer policy.
Acceptance records. When you accept our Terms and this Policy, we record your account identifier, the date and time, your IP address, and the version of the documents you accepted.
1.3 Information Collected Automatically
Usage analytics and session behavior. With your consent (see Section 3), we use Microsoft Clarity to understand how the Service is used, including clicks, scrolling, and aggregated heatmap-style behavior.
Error and performance data. We use Sentry to receive crash reports, stack traces, and request metadata (such as route and error context) when a technical error occurs. Our Sentry configuration does not attach your email address or user ID to these reports.
Infrastructure and traffic data. Our hosting provider, Vercel, processes network request data such as IP address and request metadata as a normal part of serving the application.
2. How We Use Information
We use the information described above to:
Create, authenticate, and maintain your IndexTEN account.
Provide the core functionality of the Service, including storing and organizing your repertoire library, saved lists, and uploaded files.
Process payments, manage subscriptions, and send billing communications such as receipts, renewal reminders, and payment failure notices.
Send transactional emails, including welcome emails, password reset links, one-time administrator-generated login links, renewal reminders, and notices about your account or these policies.
Send marketing communications about our other products and services, only if you have separately opted in (see Section 6).
Monitor, maintain, secure, and improve the Service, including diagnosing technical errors and understanding aggregate usage patterns.
Respond to support requests, bug reports, and other communications.
Detect, investigate, and prevent fraud, abuse, unauthorized access, infringement, or violations of our Terms.
Comply with legal obligations, including tax and accounting recordkeeping and copyright law requirements.
Aggregated and de-identified data. We may generate aggregated, de-identified, and statistical data derived from use of the Service — for example, aggregate counts of how frequently particular tags or taxonomy categories are used across all users — and use it to operate, analyze, improve, and market the Service. This data does not identify you, your account, or any individual, and does not include the substance of your content. We do not attempt to re-identify it, and we maintain it in de-identified form.
3. Cookies and Tracking Technologies
IndexTEN uses a limited set of tracking technologies.
Essential cookies. Used to maintain your login session and basic site functionality. These are necessary for the Service to work and are not subject to the consent banner.
Analytics (Microsoft Clarity). Clarity is an optional, consent-gated analytics tool that records session behavior such as clicks, scrolling, and heatmap-style interaction data. The Clarity script does not load unless you accept our cookie consent banner; if you decline or close the banner without accepting, the script never loads and no session data is recorded. Our Clarity project is configured with strict content masking, and we have additionally applied explicit masking to the two free-text fields most likely to contain sensitive or third-party information — the song Comments field and the Game/Formation teaching-instructions field — so that content typed into those fields is masked in recordings regardless of the project-level setting.
You can manage or withdraw cookie consent at any time through the cookie preference control in the Service, or through your browser settings. Because Clarity is consent-gated, declining does not affect your ability to use IndexTEN.
Global Privacy Control. We honor the Global Privacy Control (GPC) and similar browser-based opt-out preference signals. Where we detect such a signal, we treat it as a request to opt out of any sale or sharing of personal information and, where technically applicable, decline non-essential analytics.
Do Not Track. There is no common industry standard for responding to Do Not Track browser signals, and we do not respond to them. Our cookie consent control and GPC support serve the same purpose.
4. Service Providers and Subprocessors
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We use a small number of third-party service providers ("subprocessors") to operate the Service. Each is contractually and technically restricted to using data only to provide services to us.
A current list of our subprocessors, including what each receives and why, is maintained at indexten.app/subprocessors. We may add, remove, or replace subprocessors as the Service evolves, and we keep that list current.
As of the Effective Date, our subprocessors include Supabase (database, authentication, and file storage), Stripe (payment processing and billing), Postmark (transactional email), Microsoft Clarity (consent-gated session analytics), Sentry (error monitoring), Slack (internal bug report routing), and Vercel (hosting infrastructure).
We use commercially reasonable efforts to select reputable providers and to obtain contractual data protection commitments from them. We are not responsible for the independent acts or omissions of these providers beyond our agreements with them.
5. How We Share Information
Other than with the subprocessors described in Section 4, we share personal information only as follows:
Legal compliance and enforcement. If required by law, subpoena, court order, or other legal process, or where we believe in good faith that disclosure is necessary to protect our rights, protect the safety of any person, investigate fraud or abuse, or respond to a government request. This includes forwarding a counter-notification to a complaining party as required by the Digital Millennium Copyright Act.
Business transfers. If Company is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, personal information may be transferred as part of that transaction. We will notify you by email or notice on the Service of any resulting change in control of your personal information.
Professional advisors. To our accountants, auditors, insurers, and legal counsel, subject to confidentiality obligations.
With your direction or consent. In any other circumstance where you have directed us to share information.
Categories disclosed for a business purpose. In the preceding twelve months, we have disclosed the following categories of personal information to service providers for business purposes: identifiers (name, email address), account credentials, commercial information (subscription and billing history), internet or electronic network activity (session analytics, error and export logs), and user-generated content.
No sale or sharing. We do not sell personal information and have not done so, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended and comparable state laws. We do not knowingly sell or share the personal information of any consumer under 16 years of age.
6. Marketing Communications
Transactional email. Communications necessary to your account — receipts, renewal reminders, payment failure notices, password resets, security alerts, retention and deletion warnings, and notices about changes to these policies — are part of the Service. They are not marketing, and you cannot opt out of them while you maintain an account, because we need them to administer your subscription and meet our legal obligations.
Marketing email. We send marketing communications about our other products and services only if you separately opt in. Marketing consent is requested through a distinct, unchecked control that is separate from account creation and from acceptance of our Terms. You may withdraw it at any time using the unsubscribe link in any marketing message or by contacting us, and doing so will not affect your access to the Service or the transactional messages described above.
Withdrawing marketing consent does not suppress transactional email, and unsubscribing from marketing will not stop renewal reminders or other account notices.
7. Data Retention and Deletion
7.1 While Your Subscription Is Active
We retain your account information and content for as long as your subscription remains active.
7.2 When Your Subscription Ends
IndexTEN is a paid subscription service and does not offer a free tier. When you cancel, your access continues through the end of the billing period you have already paid for. After that period ends, your general access to the Service ends.
For ninety (90) days following the end of your paid access, we retain your content and you may sign in for the limited purpose of exporting it. If you resubscribe during this window, full access is restored and nothing is deleted.
We will send reminders before the export window closes so that you have an opportunity to retrieve your content.
7.3 Deletion
If the 90-day export window closes without resubscription, or if you request deletion of your account at any time, we take the following actions. The process is the same either way, except that a deletion request is processed promptly rather than waiting for the 90-day mark.
We permanently delete your songs, saved lists, uploaded files, recently-viewed history, and any taxonomy term suggestions you submitted.
We permanently delete your authentication credentials from our authentication provider.
We do not delete your account record outright. We anonymize it: your email address is replaced with a non-reversible placeholder and your display name is cleared. We retain this anonymized record, together with Stripe customer and subscription identifiers and subscription history, as a minimal billing record required for tax and accounting purposes.
Security and audit log entries, export logs, acceptance records, and any copyright enforcement records are retained in association with the anonymized account, to preserve the integrity of our security logs, to demonstrate consistent enforcement of our repeat infringer policy, and to establish what terms applied to the account.
Before requesting deletion, you may use the self-service export function to download your content, including your uploaded files.
7.4 Retention Criteria
Where information is not covered by a specific period above, we retain it for as long as reasonably necessary for the purpose for which it was collected, and then for any additional period required to comply with legal obligations, resolve disputes, enforce our agreements, or defend legal claims. Billing and tax records are generally retained for seven years. Copyright enforcement records are retained for as long as necessary to administer our repeat infringer policy.
7.5 Backups
Deleted data may persist for a limited additional period in routine system backups before those backups are cycled out, consistent with our standard backup retention practices.
8. Data Security
We maintain technical and organizational measures designed to protect information, including:
Encryption of data in transit (HTTPS/TLS) between your device and our servers.
Database-level access controls, including row-level security policies designed to restrict access to your data to your own account and authorized administrative functions.
Secure password hashing. We never store your password in plain text.
Audit logging of security-relevant account events.
Limiting subprocessor access to the minimum data reasonably necessary for each service to function.
These measures are designed to provide protection appropriate to the nature of the information and the size of our operations. No method of transmission or storage is completely secure, and we do not and cannot guarantee the security of any information. You are responsible for maintaining the confidentiality of your credentials and for maintaining your own copies of content important to you, as described in our Terms.
In the event of a security incident affecting your personal information, we will provide notification as and to the extent required by applicable law.
9. Your Privacy Rights
Depending on where you live, you may have rights regarding your personal information under laws such as the California Consumer Privacy Act as amended by the CPRA, and comparable laws in states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others. We extend the following rights to all IndexTEN users, regardless of state, though the availability of any particular right may depend on your jurisdiction.
Right to know and access. You may request confirmation of whether we process your personal information and a copy of it. You can self-serve this at any time through the in-app export function.
Right to correct. You may update inaccurate account information within the Service, or by contacting us.
Right to delete. You may request deletion of your account and associated data at any time, as described in Section 7. Consistent with legal recordkeeping obligations, we retain a minimal anonymized billing record, security and audit logs, and any copyright enforcement records after deletion.
Right to data portability. The export function provides your content in a structured, machine-readable format, including your uploaded files.
Right to opt out of sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising. Treat this Policy as our standing notice that no such activity occurs. We also honor Global Privacy Control signals as described in Section 3.
Right to opt out of targeted advertising or profiling. We do not engage in targeted advertising and do not use personal information for profiling that produces legal or similarly significant effects.
Right to withdraw consent. Where processing is based on your consent — such as Clarity analytics or marketing email — you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
Right to non-discrimination. We will not deny you the Service, charge a different price, or provide a different level of service because you exercised a privacy right.
9.1 How to Submit a Request
Email hello@thatmusicteacher.com with the nature of your request. We will verify your identity, typically by confirming the request comes from the email address associated with your account, and may request additional information where necessary to verify a request. We do not use verification information for any other purpose.
Response time. We will respond within forty-five (45) days. Where reasonably necessary, we may extend this by an additional forty-five (45) days, and will notify you of the extension and the reason within the initial period.
Fees. We do not charge for responding to requests, except that we may charge a reasonable fee or decline to act on requests that are manifestly unfounded, excessive, or repetitive, as permitted by law. We will explain the basis for any such decision.
9.2 Authorized Agents
You may designate an authorized agent to submit a request on your behalf. We will require written proof of the agent's authority — such as a signed permission or valid power of attorney — and may require you to verify your own identity directly with us and to confirm that you granted the agent permission.
9.3 Appeals
If we decline to act on your request, you may appeal. Send an appeal to hello@thatmusicteacher.com with the subject line "Privacy Request Appeal," together with the original request and the reason you believe our decision was incorrect.
We will review the appeal and inform you in writing of our decision, and the reasoning behind it, within forty-five (45) days of receipt. If we deny the appeal, we will provide a method for you to contact your state attorney general to submit a complaint.
Residents of California may also contact the California Privacy Protection Agency.
10. Children's and Student Privacy
IndexTEN is intended solely for use by adults. You must be at least 18 years old to create an account. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child, we will delete it.
No student data. As set out in our Terms, IndexTEN is not designed, intended, or authorized to store information about individual students, and entering, uploading, or importing Student Personal Information into the Service is prohibited. This includes student names, initials, identification numbers, photographs, contact information, assessment or grade data, behavioral or disciplinary records, and health or disability information.
We are not acting as a "school official" under the Family Educational Rights and Privacy Act (FERPA), and are not acting as a school service provider, operator, or contractor under any state student data privacy law. We do not knowingly collect, maintain, or process student education records, and we do not act as a service provider on behalf of any school or district.
If we become aware that content in an account contains Student Personal Information, we may remove it, require its removal, or suspend or terminate the account. You are responsible for the content you enter into the Service.
Masking of the Comments and Game/Formation fields in our analytics tooling (Section 3) reduces one avenue of exposure, but it is a safeguard and not a permission — the prohibition above applies regardless.
11. State Privacy Notices
This section supplements Section 9 for residents of states with comprehensive privacy laws.
Categories of personal information collected. Identifiers (name, email address); account credentials; commercial information (subscription and billing history); internet or electronic network activity (session analytics, error logs, export logs, audit logs); and user-generated content (your repertoire library and free-text fields). See Section 1.
Sources. Directly from you, automatically through your use of the Service, and from our payment processor in connection with billing. See Section 1.
Business purposes for collection. See Section 2.
Categories disclosed for a business purpose. See Section 5.
Sale or sharing. We do not sell personal information and have not done so in the preceding twelve months. We do not share personal information for cross-context behavioral advertising.
Sensitive personal information. We do not collect sensitive personal information as defined under the CPRA or comparable state laws, other than account login credentials, which are used solely to secure your account and are not used to infer characteristics about you.
Retention. See Section 7.
Notice at collection. This Policy, together with any notice presented at the point of collection, constitutes our notice at collection under the CCPA.
Residents of Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws have the rights described in Section 9, including the right to appeal a declined request under Section 9.3.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law.
Non-material changes take effect upon posting, indicated by an updated Effective Date.
Material changes — such as a change in the categories of information we collect, the purposes for which we use it, or the parties with whom we share it — will take effect no earlier than thirty (30) days after we provide notice by email to the address on your account or by in-app notice. Where required by law, we will obtain your consent before applying a material change to information already collected.
We retain prior versions of this Policy and can provide, on request, the version that applied to your account at any given time.
13. Contact Us
Questions, concerns, or privacy requests:
That Music Teacher, LLC, d/b/a Tarbet Education Network 5232 Norwich Street, Suite E Hilliard, Ohio 43026 United States Email: hello@thatmusicteacher.com Phone: +1 (614) 504-3994