Privacy Policy
Version 2026-09-09 · Effective 2026-09-09
BellChord is software that choruses use to run themselves — sheet music, rehearsals, membership, and payments. We hold personal information because your chorus asked us to. We do not sell it, we do not use it to train AI models, and we do not use it for advertising.
Who we are
BellChord is operated by Artisan Software Consulting (“BellChord”, “we”, “us”). You can reach us about anything in this document at privacy@bellchord.com.
Who controls your information
This matters more than it sounds, because it determines who you ask when you want something changed or deleted.
- Your chorus or organization is the controller of the information it puts into BellChord about its members — your name, voice part, attendance, dues status, and so on. They decide what to collect and how long to keep it. We process it on their instructions.
- We are the controller of the information we need to run BellChord itself: your login credentials, your security settings, our billing relationship with the organization, and our own security and audit logs.
If you are a member of a chorus and you want your data corrected or removed, start with an administrator of that chorus. If they cannot help, or you are not getting a response, contact us directly.
Information we collect
- Account information. Your email address, your name, and — if you set one — a password stored only as a bcrypt hash. We never store your password itself.
- Sign-in provider information. If you sign in with Google or another provider, see the dedicated section below.
- Membership information. Your role, voice part, section, and status within each chorus you belong to, plus anything an administrator records about you such as attendance, availability responses, and dues enrolment.
- Content you create. Practice recordings you upload, comments, poll answers, RSVPs, and your self-assessed learning progress on individual songs.
- Security and activity records. An append-only audit log of significant actions — file downloads, permission changes, deletions — recording who did what and when.
- Multi-factor authentication data. If you enable MFA, an encrypted authenticator secret and hashed backup codes.
- Payment information. Handled by Stripe. Card numbers never reach our servers; we retain only the identifiers and amounts needed to reconcile a payment.
- Connected services. If an administrator connects your chorus to an outside service such as Meetup, we store the access credentials that connection issues — encrypted — together with the identifier of the account that authorized it and of the group it points at. We do not receive contact details for that service’s other members, and we do not ask for them.
Google Sign-In, and what we do with Google user data
When you choose “Continue with Google”, we request three standard scopes: openid, email, and profile. These are Google’s non-sensitive scopes. We do not request access to your Gmail, Drive, Calendar, Contacts, or any other Google service, and we cannot read them.
- What we access. Your email address, your name, your profile picture URL, and the stable identifier Google uses for your account.
- How we use it. Solely to create and sign you into your BellChord account, and to match you to an invitation a chorus administrator has already sent to that email address.
- How we store it. Your email, name and picture URL are stored on your BellChord user record. The identifier and the access tokens Google issues are stored so the sign-in link persists between visits.
- How we share it. We do not share Google user data with anyone. It is not sold, not disclosed to advertisers, and not passed to any third party except the infrastructure providers listed below that store our database on our behalf.
You can disconnect BellChord from your Google account at any time at myaccount.google.com/permissions. Doing so stops future Google sign-ins; it does not by itself delete your BellChord account, which you can request as described below.
Watermarking: please read this one
BellChord exists in large part to let choruses distribute licensed music responsibly. Every PDF you download is stamped with your name on each page, and carries your name, your user identifier, the chorus identifier, and the download timestamp inside the file’s metadata. Audio downloads carry the same details in their ID3 tags.
The purpose is to make a leaked copy traceable to the account that downloaded it. The consequence you should understand is that if you send that file to somebody else, your identity travels with it, and it remains in the file after your BellChord account is deleted, because the copy is no longer ours to reach. We record each download in the audit log so an administrator can answer “who downloaded this?”
Who we share information with
We do not sell personal information, and we do not share it for advertising. We use the following processors to operate the service:
- Stripe — payment processing for subscriptions, tickets, member dues, and donations.
- Resend — delivery of transactional and chorus-broadcast email.
- Anthropic — powers the in-app help assistant and the automatic music-tagging feature. Questions you type into the help assistant, and song metadata such as titles and composers, are sent to Anthropic to generate a response. Anthropic does not use this data to train its models.
- Object storage and hosting providers — store uploaded files and run the application servers.
Separately from those processors, an administrator can connect your chorus to an outside service so that BellChord publishes to it. Today that means Meetup: when an event is marked public, its title, description, date and time, venue name and street address are published to your chorus’s Meetup group, along with a link back to the event’s page on this site. Only events an administrator has marked public are ever sent — rehearsals, sectionals and everything else stay here.
This is publication rather than processing: the information is already public on your chorus’s own page, your administrator chose the destination, and once it reaches Meetup it is covered by Meetup’s own privacy policy. BellChord uses the Meetup API and is not verified by Meetup.
We will also disclose information where we are legally required to, or where it is necessary to investigate a credible security or copyright issue. If BellChord is ever acquired, personal information would transfer as part of that transaction, and we would say so before it took effect.
Where your information is held
BellChord’s servers and storage are located in the United States. If you are in the United Kingdom, the European Economic Area, or Switzerland, using BellChord means your information is transferred to and processed in the United States.
How long we keep it
Retention is described in detail in our Data Retention Policy, which forms part of this privacy policy. In short: most information lives as long as your membership does, audit records are kept longer because they are a security control, and some financial records are kept for as long as tax and accounting rules require.
Credentials for a connected service are kept until an administrator disconnects it or the service revokes them, and are deleted at that point. We also keep a record linking each published event to its copy on the outside service, for as long as that copy exists, so that changes and cancellations can follow it.
One honest limit. Information already published to an outside service is no longer only ours to remove. We will unpublish what we published if you ask, but we cannot reach copies that service or its members have made.
Your rights
Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, object to or restrict how we use it, receive it in a portable format, and complain to a data protection regulator. Where we rely on consent, you may withdraw it at any time.
Exercise any of these by emailing privacy@bellchord.com. We will respond within 30 days. We will not discriminate against you for exercising a right.
Two honest limits. Where your chorus is the controller, we may need to refer your request to them or act on their instruction. And we cannot remove your identity from a watermarked file that has already been downloaded and passed on, because we do not hold that copy.
Where your chorus has connected an outside service, an administrator can disconnect it at any time, which deletes the stored credentials. Events BellChord already published stay where they are by default, because people may have planned around them; an administrator can choose to withdraw future ones at the same time.
Security
Passwords are stored as bcrypt hashes. Authenticator secrets are encrypted at rest. Traffic is served over HTTPS. Access to member data is constrained by role, and significant actions are written to an append-only audit log. No system is perfectly secure, but we would rather tell you what we actually do than make a broad promise.
Children
Choruses often include young singers. BellChord is designed to be used by the adults who run a chorus, and accounts are created by administrators or by adults signing themselves up. We do not knowingly create accounts for children under 13, and we do not direct BellChord at them. If you believe a child under 13 has an account, contact us and we will remove it.
Changes to this policy
Each version of this document carries a version date. If we make a material change, we will publish a new version and ask you to accept it the next time you sign in. Minor corrections that do not change what we do with your information may be made without re-prompting.
Other documents
These documents are published in English. BellChord’s interface is available in several languages; where a translation of this document is offered, the English text is the version that governs.