Privacy Policy
Effective and last updated: 4 October 2026
This policy explains how Aeolian, operated by Kelvin Wong, handles personal information when you use the piano studio management service. Contact kaiwey6160@gmail.com with privacy questions or requests.
Information we handle
- Account information: your sign-in email, account identifier, and the basic identity information supplied by your sign-in provider. Authentication is handled through Supabase.
- Studio records: student and parent names and contact information you enter, lesson dates and locations, attendance, notes, repertoire and progress, class balances, payments, expenses, and invoice information.
- Integration information: connected account identifiers, selected organisations and calendars, encrypted authorization tokens, remote record identifiers, and synchronization state and errors.
- Technical information: essential session cookies, saved preferences, and operational information such as request times, IP addresses, browser information, and error logs processed by our hosting and service providers.
Aeolian records payment information you enter; it is not a payment-card processor. Do not put card numbers, passwords, or unnecessary sensitive information in student notes.
How information is used
We use information to authenticate you, provide your studio tools, calculate class balances, create requested invoices and exports, operate optional integrations, troubleshoot problems, secure the service, and respond to support requests. You control which studio records you enter and which integrations you connect.
Google sign-in and Calendar data
Google sign-in supplies basic account identity information. It does not connect Google Calendar. Calendar access requires separate permission and may use a different Google account.
When Calendar sync is enabled and you connect it, Aeolian requests permission to create secondary calendars and manage events in calendars created by the app, together with account-identification permissions. We store the connected Google account identifier and email, encrypted access and refresh tokens, the dedicated calendar identifier, event mappings, and sync state. Tokens allow background synchronization and renewal of access when an access token expires.
Aeolian sends student names, lesson times and duration, location where provided, attendance or replacement status, reminders, and a link to the lesson to the dedicated Aeolian Google calendar. It reads that calendar’s events to reconcile managed copies. Private lesson notes, payment details, and student contact information are excluded from Calendar events. It does not invite students or send invitation emails. Access to your other personal calendars is not requested by this integration.
This is one-way synchronization: Google changes do not update Aeolian, and reconciliation can restore Aeolian’s managed event details. Events you add independently are left alone. Google applies its own privacy policy to information stored in Google Calendar.
Aeolian’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used for advertising, sold, supplied to data brokers, or used to train general-purpose AI models. We access it to provide the connected features you request. Human access is limited to support you authorize, security or abuse investigations, legal obligations, or other access allowed by that policy.
Zoho and sharing you request
If you connect Zoho Invoice, Aeolian exchanges the customer, invoice, item, amount, payment, and status information needed for the invoice actions you request with your selected Zoho organisation. Zoho applies its own privacy policy. Downloading or sharing an invoice or export sends the information in that file to the destination you choose, such as WhatsApp. Check the recipient before sharing.
Service providers and storage
Vercel hosts the application, Supabase provides authentication and database storage, and Google and Zoho provide their optional connected services. These providers process information needed to deliver their services, which may involve processing outside your country. We may also disclose information when required by law or reasonably necessary to protect security and prevent abuse. We do not sell your personal information.
Account ownership checks restrict access to studio records. Integration tokens are encrypted on the server and are not returned to the browser by integration-status endpoints. No security measure can guarantee complete protection. Protect your account and the devices you use.
The AI assistant is currently disabled. Google Calendar sync does not require AI processing. Any future material change to data use will be reflected in this policy before that use begins.
Retention, choices, and deletion
Studio records remain stored while you use the service until you delete them or request removal, subject to legal or operational retention needs. Operational logs and provider backups may persist under the providers’ retention processes; removing an active record does not guarantee immediate removal from every backup.
You can edit records, download the available CSV exports, disconnect Google Calendar in Settings, and revoke access through your Google Account permissions. Disconnecting removes the stored Google credentials and stops synchronization, but leaves the calendar and events in Google. Delete those copies in Google Calendar if you no longer want them.
Settings → Reset All Data removes your studio records and local integration connections. It does not delete your sign-in account, Google Calendar copies, or remote Zoho records. Contact us to request account deletion or assistance with access, correction, or removal. We may need to verify your identity before acting.
Students and children
Aeolian is intended for teachers, not for children to create accounts. Teachers may enter records about students who are children. Only enter information you are entitled to use, obtain any required parent or guardian permission, and avoid unnecessary sensitive details.
Updates and contact
We will update the date on this page when the policy changes and provide notice of material changes through the service or your account contact where appropriate. Direct questions and requests to Kelvin Wong at kaiwey6160@gmail.com.