Tenuti
Last updated 30 August 2026
Tenuti is a tool for music teachers and their students. It holds records about people's music education, including children's. This page says exactly what is collected, why, who else can see it, and how long it is kept. It describes what the software actually does — nothing here is aspirational.
Chris Jepson is the data controller and can be reached at cjepson@me.com.
As institutions begin using Tenuti, each institution will become the controller for its own students' and teachers' records, and responsibility for those records will pass to them. You will be told before that happens to any account of yours.
Your account. Name, email address and password (stored only as a cryptographic hash — nobody, including us, can read it). Optionally a short bio, instruments, location, website, date of birth, and for teachers a profile photo. We also record how many times you have signed in and when you last did, to tell active accounts from abandoned ones.
Lessons. Times, durations, locations, who taught whom, any notes you attach when booking, and whether an accompanist was requested.
Students' work. Practice sessions a student logs (what they practised, for how long, their own notes and difficulty rating), repertoire, and course or festival participation.
Teachers' records about students. Written lesson notes and end-of-term assessments with a rating and comments.
Lesson notes and assessments are visible only to the teacher who wrote them. Students do not see them, and there is no mechanism for sharing them with anyone else.
Your teacher can see your practice log, repertoire and lessons — that is the point of connecting to them, and it only begins once both of you have accepted the connection. A teacher only ever sees students on their own roster.
Other students can see your first and last name against a booked lesson time with a shared teacher, so that lesson swaps can be arranged. They cannot see your email address, your practice, your repertoire, or anything a teacher has written.
Institution administrators can see which courses run under their institution and how many people are enrolled, but not individual students' practice, repertoire or lesson notes.
We do not sell data, we do not show advertising, and we do not use anything here to build profiles or train machine-learning models.
Vercel hosts the application, the database and uploaded files. All data lives on their infrastructure.
Resend delivers email — invitations and password resets. They see the recipient address and the message.
Anthropic reads timetables, and only that. If a teacher uploads a photo, PDF or pasted note of an existing schedule to import it, that file is sent to Anthropic to extract the dates and times. It is not stored there and is not used for training. Nothing else in the app is sent to any AI service — lessons are never recorded or transcribed.
Your browser's speech service. Teachers can dictate lesson notes instead of typing. This uses your browser's own speech recognition, which in Google Chrome sends the audio to Google to convert it to text. If you would rather that did not happen, type the note instead — the feature is entirely optional.
Practice logs, written lesson notes and assessments are deleted automatically after 24 months. A teacher can mark an individual assessment to be kept for longer where there is a reason to — a reference for a conservatoire application, for instance.
Lesson bookings themselves are kept as a record of teaching done, but the written notes inside them are cleared on the same 24-month schedule. Repertoire lists are kept, since they are a record of what someone has played rather than an observation about them.
Your account and everything attached to it is kept until you close it.
Many students here are under 16. Accounts are created by invitation from a teacher, not by children signing themselves up, and by sending that invitation the teacher confirms they have the consent they need from a parent or guardian.
A parent or guardian can ask that teacher, or us, for a copy of their child's data or for it to be deleted, and we will act on it.
Students cannot upload photographs or files. This is deliberate — it keeps the service from holding images of children.
You can download everything held about you at any time from Profile & Settings, as a file you can keep or take elsewhere. You can correct your details on the same page, and you can close your account, which deletes your records.
Under the GDPR you also have the right to object to processing, to ask us to restrict it, and to complain to your national data protection authority if you think we have handled your data badly. You are welcome to raise it with us first at cjepson@me.com.
Passwords are hashed, never stored as text. Access to student records is checked on every request against the actual teaching relationship, not merely hidden in the interface.
If a breach occurs that puts anyone at risk, we will tell those affected and the relevant authority within 72 hours of becoming aware of it.
If this notice changes in a way that affects what happens to your data, you will be told rather than left to notice the date at the top.