Privacy Policy
Last updated: August 2026
MusicFlow is a self-managed application for managing sheet music, practice tracks, and performances for bands and choirs. This policy explains what data we collect and how we use it.
What data we collect
- Account information: your name and email address
- Your instrument selections in your profile
- Content you interact with: favorites, setlists, annotations
- Files you upload: sheet music, practice tracks, and source files
Why we collect this data
All data is collected solely to provide the MusicFlow service: showing you the right practice materials, managing group repertoires, and enabling collaboration with your band or choir.
Who can see your data
- Group members can see your name and assigned instruments within shared groups
- Group organizers can manage group membership and event plans
- System administrators can manage accounts and roles
Data storage
Your data is stored on servers inside the European Economic Area (Germany). We take daily backups; the copy held off our own server is encrypted before it leaves. We do not sell your data and do not use it to build profiles or train models.
Third parties
To run the service we engage a small number of parties: our hosting provider in Germany and our email provider in the Netherlands. Notifications via Telegram or your browser are used only if you enable them yourself; the same goes for signing in with a Google or Microsoft account, where that provider handles the sign-in under its own privacy terms. The parties that process data on our behalf are listed on the Subprocessors page. For invoicing we use Moneybird (the Netherlands), which holds your organisation's billing details, including any contact person you enter yourself.
Some things that are often a third-party service are not, with us: usage statistics (Umami) and our monitoring and logging run on our own servers, and sheet music and audio are rendered in your own browser. No Google Analytics, no third-party trackers, and no music sent to an external service.
Data deletion
To request deletion of your account and associated data, contact a system administrator.
An organisation can remove you from its roster. Doing so permanently deletes the data you created inside that organisation — your annotations, favourites, personal setlists, practice recordings and quick-arrange versions — along with your access to its material.
Your contributions to an organisation's own content stay with that organisation as its records, so your name can remain visible there for as long as your account exists.
An organisation's activity log keeps a record that the change happened. Once your account is deleted, those entries no longer identify you.
Changes to this policy
This policy may be updated from time to time. In case of significant changes, you'll be notified and asked to accept the updated policy.