Nutmeg
Privacy Policy
Effective 2026-09-13 · Version 2026-09-13
1. Who operates Nutmeg
Nutmeg is operated by Marcin Sobieraj, a sole trader registered in Poland, NIP 7831900655, at Piaskowa 6 lok. 26, 61-753 Poznań, Poland. Privacy questions and requests may be sent to hello@usenutmeg.com.
2. What Nutmeg does
Nutmeg helps music teachers, teaching studios and similar professional teaching users organise students, lessons, practice work, communication, media and lesson-payment records. Teachers create or prepare student records. Students may receive a teacher invitation to log in; they cannot register independently. Parent access is not part of the current beta.
3. Nutmeg's role
For teacher account administration, security, service communications, optional analytics, support and compliance, the Nutmeg operator decides why and how information is used and acts as a controller. A sole-trader teacher normally contracts with Nutmeg directly. When a person uses Nutmeg on behalf of a studio or another organisation, that organisation may be the contracting party and Nutmeg processes the representative's details to administer that relationship.
For studio and student information a teacher enters and manages for their teaching activity, the teacher will usually decide the purpose and Nutmeg is intended to process that information for the teacher. Some operations, including account security and legal compliance, remain Nutmeg's own controller activities. The exact allocation depends on the processing purpose and is described in the Data Processing Agreement, which is incorporated into the Terms and applies automatically where this controller–processor relationship exists.
4. Information processed
- Accounts: Supabase identifier, email address, name, avatar, role, locale, timezone and authentication records, plus teachers' versioned agreement to the Terms (including the incorporated DPA where applicable), acknowledgment of the Privacy Policy and server timestamp.
- Teacher and studio settings: instrument, teaching preferences, notification settings, rates, currency and Stripe sandbox account status.
- Student records: name, email where login is enabled, instrument, optional teacher-entered birthday and student-since date, teacher notes and the teacher relationship.
- Teaching activity: pieces, lessons, schedules, assignments, practice progress, ratings, goals, todos, comments and annotations.
- Communications and media: messages and uploaded images, documents, audio and video, which may include a student's voice or appearance.
- Calendar: Google access and refresh tokens, selected calendar, event identifiers, summaries and student mappings when a teacher connects Calendar.
- Payments: manual payment records and Stripe identifiers/status from sandbox testing. Nutmeg does not currently enable real-money Stripe payments.
- Technical data: IP/network and device information, requests, security challenges, consent choice, error diagnostics and operational logs.
Teachers and students should avoid placing unnecessary health information or private details about family circumstances in free-text notes, messages or uploads. Ordinary family information is not automatically special-category data; some health information and other data identified by law may be.
Required and optional information. An email address, authentication identifier and account role are required for a login-enabled account. A versioned agreement/acknowledgment record is required only for a teacher account; it evidences the accepted Terms and same-version DPA where applicable, the Privacy Policy version and the server time, and Nutmeg does not create such a record for a student. A student name is required for a teacher-managed record; an email address is required only if the student will receive login access. Information labelled optional in Nutmeg, including an avatar, birthday, studio settings, profile details and optional integrations, does not have to be provided. Without required information Nutmeg cannot create or secure the relevant account or record. Without optional information only the related optional feature or personalisation is unavailable.
5. Sources
Information comes from the teacher, an invited student when they use Nutmeg, Google when Google sign-in or Calendar is used, payment and delivery providers, the user's browser/device and service-security/diagnostic systems.
6. Purposes, roles and legal bases
| Purpose | Nutmeg's role | Legal basis or instruction |
|---|---|---|
| Create and operate a teacher account, provide the teaching workspace and administer the Terms | Controller | For a sole-trader teacher contracting personally: steps requested before a contract and performance of the service contract (GDPR Article 6(1)(b)). For a studio representative: Nutmeg's legitimate interest in entering into and administering the service relationship with the represented organisation (Article 6(1)(f)). |
| Host and process studio, lesson and student information entered for a teacher's teaching activity | Normally processor for the teacher or represented teaching organisation; controller only for Nutmeg's separate security and legal operations | The customer's documented instructions and the DPA incorporated into the accepted Terms. The customer, as controller, determines and documents the lawful basis for the teaching records. |
| Authenticate users, prevent abuse, diagnose failures and protect the service | Controller | Nutmeg's legitimate interests in a secure and reliable service (Article 6(1)(f)); Article 6(1)(c) where a specific legal duty applies |
| Send login, invitation, service, reminder and support email | Controller for Nutmeg account, legal and support messages; processor when delivering a teacher-directed message about the teacher's studio | Contract performance (Article 6(1)(b)), legitimate interests in service communication (Article 6(1)(f)), or the teacher's documented instructions |
| Provide teacher-selected Google Calendar, media and Stripe sandbox functions | Controller for connection/account administration; normally processor for teaching content handled on the teacher's instructions | For a sole-trader teacher contracting personally: contract performance at the teacher's request (Article 6(1)(b)). For a studio representative: Nutmeg's legitimate interest in administering the selected service connection (Article 6(1)(f)). The teacher's documented instructions apply to studio data. |
| Meet legal duties, respond to rights requests and establish, exercise or defend claims | Controller | Compliance with a legal obligation (Article 6(1)(c)) or Nutmeg's legitimate interests in handling and defending claims (Article 6(1)(f)) |
| Optional product analytics for public visitors and teachers | Controller; PostHog acts as provider for the analytics data | Consent (Article 6(1)(a)). Analytics is disabled for every student and parent account, even if that browser previously recorded an opt-in. |
Consent may be withdrawn without affecting processing that took place before withdrawal. Refusing analytics has no effect on access to Nutmeg. Blocking technical information needed for authentication or security may prevent the relevant sign-in, protected form or connected feature from working.
7. Children and students
Nutmeg processes information about students, who may be children, because teachers maintain studio records. Direct or login-enabled Nutmeg accounts are prohibited for anyone known to be under 13, regardless of country. Nutmeg does not ask for date of birth solely to enforce this rule. If an existing record shows the person is under 13, login activation is blocked; if Nutmeg later learns that a login-enabled user is under 13, access will be disabled and the record reviewed.
A teacher may maintain a limited non-login record for a student under 13 only when the teacher has appropriate authority and supplies only information needed for teaching. A teacher who invites a student confirms that the student is not known to be under 13 and that the teacher has authority to issue the invitation. This product restriction does not mean that Nutmeg processes no children's information.
8. Providers and other recipients
Nutmeg uses Supabase for authentication, database and uploaded-media storage; Vercel for hosting and operational logs; Resend for authentication and transactional email; Cloudflare for Turnstile and inbound email routing; Sentry for error monitoring; bunny.net for beta video processing, storage and delivery; and Google for sign-in and, when selected, Calendar. Messages sent to Nutmeg's support address are ultimately delivered to Google/Gmail, which acts as an independent recipient under Google's consumer-service terms. Stripe receives connected-account and payment-flow test data in sandbox mode but moves no real money. PostHog processes optional analytics for opted-in public visitors and teachers only; it does not receive analytics from student or parent accounts. Proton and Anthropic are dormant and receive no beta account data. The Service Providers, Subprocessors and Other Recipients page describes each provider according to its actual role.
Optional DiceBear avatar images and teacher-added YouTube or Vimeo content can cause the browser to contact those services and disclose ordinary request data such as the IP address and browser headers. Nutmeg does not sell personal information and does not use behavioural advertising.
9. International processing
Nutmeg's primary Supabase project data is hosted in Ireland. Other providers may process information in the United States or through global delivery networks, as described on the Service Providers, Subprocessors and Other Recipients page. Where Chapter V of the GDPR applies to a transfer by Nutmeg, the applicable provider agreement must supply a valid transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses. Providers acting as independent controllers, including Google or Stripe for some activities, describe their own international-processing arrangements in their notices and agreements. The Article 28 controller-processor clauses are not by themselves an international-transfer mechanism.
10. Cookies and analytics
Necessary storage supports authentication, security, locale and requested features. For public visitors and teachers, PostHog is not initialised until “Accept analytics” is selected. Analytics remains disabled for every student and parent account regardless of the browser choice. A refusal is remembered, and teachers can withdraw a previous choice in Settings. Withdrawal stops future capture, resets the PostHog browser identity and stored analytics properties, and records an opt-out; a small opt-out marker or newly generated anonymous value may remain until site data is cleared. Session replay is disabled and Nutmeg masks or removes configured content. Details appear in the Cookie Policy.
11. Retention and deletion
Account and teaching content is kept while the relevant account and service relationship remain active. After an approved deletion request, Nutmeg removes active account data promptly, normally within 30 days. Authentication and invitation intents stop being usable after their stated short expiry; security and diagnostic records are kept only for as long as they are needed to investigate abuse, maintain reliability or handle a specific claim. Legal-acknowledgment and complaint records are kept only for as long as needed to evidence the agreement, resolve the matter and meet an applicable limitation period.
Google tokens may expire or be revoked. Nutmeg deletes its stored Google tokens when the teacher disconnects the integration or the relevant account is deleted. Deleted data may remain temporarily in database backups, where configured, or in provider recovery systems, caches and logs until it is overwritten or deleted under each system's normal operating cycle. These systems differ by provider and configuration, are not used for ordinary product access, and must not be used deliberately to restore data deleted from the active service. Shared teaching records and Stripe sandbox records are reviewed according to their purpose and the role of the relevant controller.
12. Security
Nutmeg uses access controls, authenticated role checks, transport encryption, secret hashing, rate limits, anti-bot controls, restricted provider references and diagnostic scrubbing. No internet service can promise absolute security.
13. Rights and complaints
Depending on the applicable law and Nutmeg's role, a person may request access, correction, deletion, restriction, portability, objection or withdrawal of consent. Send requests to hello@usenutmeg.com. Nutmeg may need reasonable identity or authority verification. When the teacher is the controller, Nutmeg may refer the request to or assist that teacher.
EEA users may complain to a supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), uodo.gov.pl.
14. California information
Nutmeg does not sell personal information or share it for cross-context behavioural advertising. Where California law gives a person a privacy right in relation to Nutmeg, that person may submit a request using the contact details in section 1.
15. Changes and contact
Current version and effective date: 2026-09-13. Material changes will be communicated by email and/or in-app notice, as appropriate. A new Terms acceptance will be requested only when the change requires it. Questions may be sent to hello@usenutmeg.com or to the postal address in section 1.