Privacy Policy

Effective August 8, 2026

Who We Are

CogNote Studio (“CogNote”, “we”, “us”) is operated by Morales Piano Studio LLC, doing business as CogNote Studio. This policy covers the hosted service at cognote.studio. If your teacher runs their own self-hosted copy of the CogNote software, that deployment is operated by them, not by us, and this policy does not apply to it.

Information We Collect

Teacher accounts. When a teacher signs up we collect an email address, a display name, an optional profile photo, and a timezone. If a teacher subscribes to a paid plan, our payment processor (Stripe) collects billing details; we store only subscription status and Stripe identifiers, never card numbers.

Student and family records entered by teachers. Teachers add records about their students and families to run their studios: names, optional birthdates, parent contact information, lesson schedules, attendance, lesson notes, invoices, and assigned sheet music. The teacher is the data controller for these records; we process them on the teacher's behalf to provide the service.

Practice activity. When a student uses a practice link, we record quiz answers, scores, and flashcard progress tied to that student's record so their teacher can track progress. Practice links and family portals do not require accounts, passwords, or email addresses from students or parents.

Technical data. We keep standard server logs (IP address, request time, user agent) for security and abuse prevention. We use cookies only to keep teachers signed in; we do not use advertising or cross-site tracking cookies.

Children's Privacy

CogNote is a tool for teachers and parents. Students, including children under 13, never create accounts, and we do not knowingly collect personal information directly from children. Student records are created and controlled by the teacher, who is responsible for having the family's permission to store them. Practice links collect only the practice activity described above. Parents who want a student's records corrected or deleted should contact their teacher, who can edit or delete them at any time; you can also contact us directly.

How We Use Information

We use the information above solely to provide and secure the service: showing teachers their studio data, delivering emails the teacher initiates (practice links, lesson notes, invoices, reminders), processing subscription payments, and preventing abuse.

We do not sell personal information, we do not use it for advertising, and we do not use student records to train AI models. If a teacher connects their own optional AI key, requests they initiate are sent to their chosen provider under that provider's terms.

Service Providers

We rely on a small set of subprocessors to run the service:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting.
  • Stripe — payment processing for CogNote subscriptions, and for lesson tuition when a teacher connects their own Stripe account.
  • Resend — transactional email delivery.

Each provider receives only the data needed to perform its function.

Security

All traffic is encrypted in transit (TLS). Studio data is isolated per teacher account with database-level row security. Sensitive credentials that teachers store with us (such as their own Stripe or AI keys) are encrypted at rest and are never included in data exports.

Retention, Export, and Deletion

We keep studio data for as long as the teacher's account is active, on any plan. Teachers can export their full studio data as a JSON file at any time from Account settings. When a teacher deletes their account, or asks us to, we delete the account and its studio data, minus records we must keep for legal or accounting reasons (such as subscription payment history), within 30 days.

Changes and Contact

If we make material changes to this policy we will update the effective date above and notify teachers by email or in the app. Questions and requests: support@cognote.studio.