Privacy policy — draft
Draft for the PianoNear pilot, 14 September 2026. This is not a finalized legal notice. The operator's legal identity, contact address and privacy email have not yet been supplied. The draft describes the implementation and records what must be completed before opening the service beyond controlled operator tests. GDPR applies to a free pilot too.
1. Who is responsible
PianoNear is operated from France. Operator name, legal status, postal address, registration details where applicable, and privacy contact: to be completed. Until these fields are supplied, this document must not be represented as a completed GDPR notice or proof of compliance. A separate French legal notice and subscription terms must also be completed before real sales.
2. Information used to provide lessons
- Camera, microphone and MIDI: the browser asks for the relevant permissions. Audio, video and MIDI are sent to the other participant using encrypted WebRTC. PianoNear does not provide server-side recording or store lesson content. Another participant may independently record or capture what they receive.
- Network information: signaling uses room identifiers, participant roles, connection descriptions and network candidates. Direct WebRTC can disclose your public network address to the other participant. When direct connectivity fails, coturn relays encrypted traffic and processes connection metadata. Encryption does not hide all network metadata from participants, hosting or relay operators.
- Room details: the optional session name, room code and timer state are held in server memory while the room exists. A disconnected host's room normally remains available for up to five minutes; ending the lesson removes it immediately. The session name can be included in an invitation URL, so anyone receiving the link can read it. Do not use confidential details in invitation names.
- Sign-in: when you choose to sign in, Auth0 and the selected provider (currently Google) authenticate you. PianoNear stores a random account ID, the identity's issuer/subject, email and verification status if supplied, and account timestamps. PianoNear does not receive your Google password or request access to your contacts, Drive files or calendar. Guest participants do not need an account.
- Usage accounting: SQLite contains daily aggregate counts of rooms, joins, resumes and paired signaling presence time. The usage database does not contain room names/codes, IPs, account IDs, MIDI or media. These counts are not unique-person analytics and do not prove a successful media connection.
- Operational logs: application, relay and hosting systems may process network addresses, timestamps and errors for operation and security. The exact retention configuration and hosting-provider retention must be confirmed before this policy is finalized; we do not promise a deletion period that has not been implemented.
3. Purposes and proposed legal bases
Subject to confirmation by the identified operator: providing the requested account and lesson service relies on Article 6(1)(b) GDPR; proportionate security, operational diagnostics and service accounting rely on legitimate interests under Article 6(1)(f). Any future statutory financial records will have their applicable legal-obligation basis and retention period specified before live payments. Browser device permission is a technical authorization, not blanket consent to unrelated processing.
There is no advertising, sale of personal data, behavioural profiling or third-party analytics added to the landing page. No marketing consent is bundled with sign-in.
4. Cookies and storage on your device
| Storage | Purpose | Lifetime / control |
|---|---|---|
__Host-pianonear-session cookie on the app |
Essential authenticated session, HttpOnly/Secure/SameSite=Lax | Up to 7 days; revoked on local sign-out |
__Host-pianonear-login cookie |
Bind an OIDC login attempt to the initiating browser | Up to 10 minutes; consumed after callback |
piano-tutor.host-settings in localStorage |
Remember session name and timer defaults | Until cleared in the app/browser |
piano-tutor.host-sessions in localStorage |
Up to 12 saved invitations and secret host-resume tokens | Until forgotten/cleared or displaced by newer entries |
| Browser HTTP cache and service worker | Load application assets | Managed by the browser; clear site data to remove |
The app has a Clear saved lessons control. It clears PianoNear's saved lesson settings and invitations in that browser; it does not delete your server account, end a live lesson, erase other participants' copies or revoke every previously issued host token. Full browser site-data removal also clears cached assets and cookies.
Auth0 and Google may set their own authentication cookies when you visit their login pages. Signing out of PianoNear revokes its local session, not necessarily your Google or Auth0 SSO session. Admin Basic Auth credentials may be cached by the browser; the admin panel does not create an analytics cookie.
Necessary authentication/session storage is used to provide the requested service. There is no catch-all consent banner for non-existent advertising cookies. The necessity/exemption of every retained preference must be reviewed before finalization; non-essential tracking, if introduced, must wait for a separate valid choice.
5. Providers and other recipients
- The other lesson participant receives the media/MIDI and relevant connection information necessary for the lesson.
- netcup hosts the application, databases and coturn relay on the existing German VPS. The operator administers these services.
- Auth0 / Okta, using an EU tenant and
auth.pianonear.com, supplies authentication. Google is the currently configured social identity provider. - Google STUN is presently used for network discovery (
stun.l.google.com). - GitHub Pages (
smpldsnds.github.io) supplies piano samples when optional software piano playback is initialized. Such requests reveal network information to the sample host; they are not needed to browse the landing page. Software piano is the default remote-note output mode in a lesson and can be changed in the call controls. - Namecheap provides domain/DNS services. Hosting in Europe does not imply that every DNS, authentication or third-party operation takes place only in Europe.
- Paddle sandbox, when configured and explicitly opened for a test checkout, processes test customer/payment information. Use test details and test cards only. Paddle.js is loaded only when checkout is requested. No live payments are enabled.
Processor agreements, provider legal entities, subprocessors and any transfers outside the EEA still require an operator review. Applicable adequacy decisions, Standard Contractual Clauses and other safeguards must be identified before this draft is finalized. We do not claim that selecting an EU Auth0 tenant alone settles all international-transfer obligations.
6. Retention
Live room state is ephemeral as described above. Browser-saved invitations/settings remain until cleared. Local account records remain until the operator processes a deletion request; an inactivity-retention policy is still to be set. Login attempts expire after 10 minutes; local sessions after 7 days. Expired database entries are periodically removed while the service runs.
Aggregate daily usage rows are retained for all-time totals; the dashboard displays the latest 30 days. They are stored separately from accounts. Sandbox transaction references/statuses remain associated with the test account until deletion; their production replacement and retention rules are not yet enabled.
Operational-log limits, Auth0/Paddle retention and a complete backup/deletion schedule must be documented and implemented before a final policy is published. A persistent database volume is not itself a backup.
7. Your rights
Depending on the applicable conditions, you may request access, correction, deletion, restriction and portability of your personal data, and object to processing based on legitimate interests. Where processing relies on consent, it may be withdrawn without affecting prior lawful processing. Requests may require proportionate identity verification. The usual GDPR response period is one month, subject to the permitted extensions and exceptions.
Privacy request address: to be supplied by the operator. Account data and Auth0-held identity data may require coordinated deletion; signing out or clearing browser storage does not perform that deletion.
You may lodge a complaint with the French CNIL or another competent data-protection authority.
8. Students and minors
Guest access does not require registration. Teachers/organizers should explain the service to their students and, where appropriate, parents or guardians. A policy for minors and the roles of independent teachers still needs to be finalized. Do not assume that collecting a teacher's consent substitutes for every student's rights.
9. Before this becomes a final policy
The operator must complete its identity/contact information, choose and implement retention/deletion procedures, review providers and transfer safeguards, assess local-storage purposes, and finalize the rules for minors and paid subscriptions. The privacy requirements apply before onboarding real pilot users, not only before charging them. The document will be updated when those decisions or the actual service change.