← Back to ChoralHub

Privacy Policy

What ChoralHub stores about you, who can see it, and how to remove it. Written to be read, not to be skimmed past.

Last updated 2026-10-04

Who is responsible for your data

ChoralHub is operated by the people named in the footer of this site, who act as the data controller for the account you create.

Your choir's owner and administrators decide who joins the choir and what they can see inside it. For that part, they act as controllers too — if you want your membership of a choir ended, they are the people to ask.

Questions about any of this can go to the contact address in the site footer.

What we store

Only what you or your choir enters. There is no tracking, no advertising and no analytics profile.

•Account: your email address and an encrypted password, handled by Supabase Auth. We never see your password.

•Profile: your name, voice part, and optionally a photograph.

•Contact and logistics: optionally your phone number, address, height, and whether you have a car. Height and car availability exist because they are used to arrange people on a stage and to organise lifts to concerts.

•Emergency contacts: optionally up to two people to call if something happens to you at a rehearsal or concert: their name, phone number and how they are related to you. Please make sure they agree to be listed.

•Choir activity: your attendance at rehearsals, recordings you upload, comments you write, and which choirs you belong to.

•Health and diet: optionally your blood group, known illnesses or medical conditions, medicines you take regularly, allergies, and your diet (for example vegetarian, vegan, gluten-free, or anything you write yourself). This is treated separately — see below.

Everything except your email is optional. You can leave any of it blank and use the app.

Your health and diet information is treated differently

Blood group, illnesses, medicines and allergies are health data. Under Turkish law (KVKK, Law 6698) they are special category personal data, and under the GDPR they fall under Article 9. Diet can reveal religious belief, which is a special category too. Both laws require consent that is explicit and specific to that data, rather than bundled into a general agreement.

So all of it sits under one consent of its own, separate from these terms. It is off by default, you are asked for it in your own profile, and every field under it is optional.

Withdrawing that consent deletes all of it. It does not merely hide it. You can withdraw at any time by unticking the box in your profile.

It is visible only to you and to the owners and administrators of your own choirs, and only while your consent stands. This is enforced by the database itself, which keeps health data in a separate, locked table, not merely by the app. It is never shown to other singers, never used for anything except emergencies and planning meals and travel, and never shared outside your choir.

You do not have to provide any of it. Nothing in the app stops working if you leave it blank.

Who can see what

Choirs are isolated from one another at the database level, not merely in the interface. A member of one choir cannot read another choir's data even if they try to reach it directly.

•Other members of your choir see your name, voice part, photo and attendance.

•Your choir's owner and administrators additionally see your contact details and emergency contacts, and — if you have consented — your health and diet information.

•Members of other choirs see nothing about you at all.

•We can technically reach the database to operate and repair the service, and do so only for that.

Where it is stored

In Supabase, which hosts the database and file storage, and on Vercel, which serves the application. Email is sent through Resend.

When something breaks, a technical error report (what failed, on which page, which browser) goes to Sentry so we can fix it. It carries no account details, IP address or content you entered. If you turn on browser notifications, they travel through your browser maker's push service (Google, Mozilla or Apple), encrypted so that service cannot read them.

These providers process data on our behalf and may store it outside your country, including in the European Union and the United States.

How long it is kept

Your profile is kept while your account exists. Delete your account and it goes.

Content you created inside a choir — attendance records, recordings, comments — belongs to that choir's history and may remain after you leave it, in the same way minutes of a meeting outlive the people at it. Ask your choir's administrators if you want it removed.

If a choir is deleted, its data is deleted with it.

Your rights

You can ask what is held about you, correct it, delete it, or object to it being held at all. Most of it you can do yourself from your profile page, which is faster than asking.

Where we rely on your consent — health and diet information is the clear case — you can withdraw it at any time without giving a reason, and withdrawing is as easy as giving it was.

Under KVKK you may also apply to the Turkish data protection authority, and under the GDPR to your local supervisory authority, if you think something is wrong.

Cookies

Only what is needed to keep you signed in. No advertising cookies, no third-party trackers, no analytics that follow you elsewhere.

Changes

If this document changes materially, the date at the top changes and you will be asked to read it again. Small corrections that do not change what we do will not interrupt you.