LessonPad Privacy Policy
LessonPad is an app for instrumental music teachers. It records a teacher's spoken lesson notes, turns them into written homework, and lets the teacher send that homework to a student or parent as a PDF. This policy explains what data the app handles, why, and what your rights are. It is written for two groups of people: the teacher who holds the LessonPad account, and the students and parents whose details a teacher enters.
1. Who is responsible for your data
LessonPad is operated by Edita Stankeviciute trading as LessonPad, 203 Clarence Road, Windsor SL4 5AN, United Kingdom ("we", "us"). You can contact us at support@getlessonpad.com.
For the teacher's own account details, we are the data controller. For the student and parent details a teacher enters, and the recordings a teacher makes, the teacher is the data controller and we act as their processor: we store and process that information only on the teacher's instructions, in order to provide the service. Teachers are responsible for having a lawful basis to record lesson notes and to hold student and parent contact details, and for telling parents that they use LessonPad.
2. What data the app handles
Teacher account
- Email address and a password (the password is stored only as a secure hash by our authentication provider).
- Preferred homework language.
Students (entered by the teacher)
- Student name; optionally instrument, grade and lesson day.
- A contact email address for the student or their parent/guardian, used only to send homework.
Lessons and homework
- Audio recordings of the teacher's spoken notes. These are recordings of the teacher, made deliberately by tapping Record; the app does not listen in the background.
- The written transcript and the structured homework cards generated from each recording, including any edits the teacher makes.
- Short demonstration videos the teacher chooses to attach to a homework card.
- The homework PDF generated when the teacher taps Send, and a log that it was sent (date, recipient address, message id).
Technical data
- Standard server logs (request time, status codes, error messages) kept by our hosting providers for security and debugging. We do not run advertising or analytics trackers in the app.
3. How the data is used
- To sign the teacher in and keep their students, lessons and homework private to their account.
- To transcribe recordings and turn them into written homework (see section 4).
- To email the homework PDF, and a link to any demonstration video, to the address the teacher has saved for that student.
- To answer support requests.
We do not sell personal data, use it for advertising, or use lesson recordings, transcripts or homework to train AI models.
4. Service providers we use
The following providers process data on our behalf under contract:
- Supabase — database, sign-in and private file storage for recordings, videos and generated PDFs. Every file is stored privately and can be reached only by the signed-in teacher who owns it, or through a time-limited video link the teacher chooses to send.
- OpenAI — audio transcription and turning the transcript into homework cards. Only the audio of the teacher's spoken notes (or the text of the transcript) is sent; student contact details are not sent. Under OpenAI's API terms, data sent this way is not used to train their models.
- Resend — sending the homework email and PDF attachment to the recipient address saved by the teacher.
- Apple App Store / Google Play — app distribution and, where applicable, subscription billing. We never see your payment card details.
Some of these providers process data outside the UK. Where they do, transfers are covered by the UK International Data Transfer Agreement or Addendum, or by the provider's UK/EU standard contractual clauses.
5. How long data is kept
- Students, lessons, homework and videos stay in the teacher's account until the teacher deletes them. The app has explicit Delete lesson, Delete student and Archive student actions.
- Deleting a student or lesson permanently removes its homework, recordings and videos from storage and invalidates any video links that were sent.
- Audio recordings that were uploaded but never turned into homework are removed automatically by a scheduled clean-up.
- When a teacher deletes their account (Settings → Delete account), every recording, video, PDF, lesson, student and the account itself are permanently deleted. This cannot be undone.
- Emails already delivered to a parent are in that parent's mailbox and are outside our control.
6. Children
Many students of instrumental music are under 18. LessonPad is a tool for the teacher, not for children: children do not create accounts or use the app. Teachers should enter a parent or guardian's email address for any student under 16 and should only record their own spoken notes, not the child.
7. Security
All connections use HTTPS. Data is separated per teacher at the database level (row-level security), files are held in private storage buckets with per-teacher access rules, and server functions require a signed-in teacher and check that the lesson or student belongs to that teacher before acting. Keys for our service providers are held only on our servers, never in the app.
8. Your rights
Under UK GDPR you can ask to access, correct, delete or export personal data we hold, object to or restrict certain processing, and complain to the Information Commissioner's Office (ico.org.uk). Teachers can do most of this directly in the app. Parents and students should contact their teacher first, as the teacher controls those records; if you cannot reach the teacher, contact us at support@getlessonpad.com and we will help.
9. Changes
If we change this policy we will update the date at the top and, for significant changes, tell teachers in the app or by email.