Privacy Policy

Last updated: 10 September 2026 · Application: MySwara

MySwara is an invite-only portal for music teachers and students (any instrument or style), operated by Sound of Carnatic. This policy explains what information we collect, how we use it, and your choices when you use MySwara. Related: Terms of Service (including Stripe subscriptions).

Who we are

MySwara is operated by Sound of Carnatic (“we”, “us”), the data controller for personal data processed in MySwara. Contact: info@soundofcarnatic.com or soundofcarnatic@gmail.com. If you have a privacy request (access, correction, or deletion), email us at that address.

What MySwara is

MySwara is an invite-only web application for music teachers (gurus) and students (sishyas) — any instrument or style — to share learning materials, assign practice to-dos (including bulk assign and “Needs practice” follow-ups), track practice, submit audio/video/text work for review, manage unlocks and progress, organise students into groups, record lesson notes, receive practice-related email notifications, and (for paid plans) manage a subscription. Prospective teachers may request access via a Clerk-hosted waitlist. Teachers may optionally log lessons through a MySwara Telegram bot; the durable lesson record is stored in MySwara’s database (not only in the chat).

Invitations and account creation

Access starts with a personal invitation, or (for teachers) a waitlist request that we later convert into an invite. An administrator or a linked teacher enters the invitee’s email address into MySwara. We store that email as a pending invite and ask Clerk (our authentication provider) to send an invitation email with a link to accept and sign in. Waitlist requests are collected by Clerk and reviewed by us before an invite is issued.

  • The invitation email is sent by Clerk on our behalf and typically includes your name (if provided) and the invite link.
  • When you accept and sign in (for example with Google via Clerk), we create or link your MySwara account using your name, email, and Clerk user id.
  • Inviting someone means the inviter already has that email (they typed it). We use it only to create the invite and allow access to MySwara.

Information we collect

  • Account information — name, email, and sign-in details via Clerk (including Google sign-in if you choose it), plus a Clerk user id linked in our database
  • Invite and waitlist records — email addresses entered for invitations, and emails submitted on the teacher waitlist before an invite is issued
  • Profile and role data — admin, guru, or sishya; teacher–student links; optional student groups; invite status; and optional teacher-facing portal display names for students
  • Learning content — curriculum levels/sections and special-practice materials, practice submissions (including uploaded audio/video/files and written notes; we may keep a short recent history of submissions per material for review), grades/reviews (including “Needs practice”), unlocks, pitch/key assignments used in teaching, practice to-dos, and progress
  • Lesson records — lesson dates, topics, notes, practice text, hours, price (generic currency amount), and lesson payment status entered by teachers in MySwara or via the optional Telegram lesson bot (separate from Stripe subscriptions). The authoritative copy of each lesson is stored in our Supabase Postgres database.
  • Optional Telegram link (teachers only) — if a guru connects the MySwara lesson bot, we store their Telegram user id on their MySwara account so we can match chat actions to that teacher. Lesson fields typed or selected in Telegram for logging are received by our servers and then saved as normal lesson rows in Supabase.
  • Practice notification emails — we send transactional messages about teaching events (for example a new to-do, a submission for review, or a “Needs practice” grade). Those emails use your MySwara account name/email and short details about the relevant material (title/path), delivered via Resend.
  • Billing and subscription data — when you start a trial or subscribe, we create or update a Stripe Customer using your account email (and billing details you enter in Stripe Checkout, such as name and address for invoices/tax). Stripe stores card and payment data; we store Stripe customer id and subscription status in our database. We do not store full card numbers.
  • Session / security signals — authentication tokens (Clerk) and a browser activity timestamp used only for idle sign-out on this device
  • Technical logs needed to run and secure the service (for example API and hosting logs)
  • Aggregate website usage signals via Vercel Web Analytics (page views and similar high-level visit metrics). This is privacy-oriented product analytics, not advertising; it is not used to build marketing profiles or sell data

How we use information

  • To operate MySwara and show each user the content they are allowed to see
  • To send and process invitations and authenticate users (via Clerk)
  • To enforce invites, roles, teacher–student links, and student groups
  • To enable teaching, practice, review, and progress workflows
  • To provide each new teacher a starting copy of the admin library template (curriculum and special-practice structure). Edits to that template do not rewrite existing teachers’ private libraries.
  • To send transactional practice emails (to-do assigned, submission received, Needs practice) via Resend
  • To let teachers optionally log lessons through Telegram into the same MySwara lesson ledger stored in Supabase
  • To start trials, process subscriptions, invoices, and tax where enabled (via Stripe), including creating a Stripe customer record with your email when you begin checkout
  • To maintain security and prevent abuse
  • To understand aggregate use of the site (for example which public pages are visited) via Vercel Web Analytics, so we can operate and improve MySwara
  • Administrators may access accounts, learning content, and stored media when needed to operate, support, and secure MySwara (for example storage cleanup or troubleshooting)

We do not sell your personal information. We do not use MySwara data for advertising.

Legal bases (EEA / UK)

Where GDPR / UK GDPR applies, we process personal data on these bases:

  • Contract — to provide MySwara after you accept an invite and use the service (account, learning workflows, subscription you request)
  • Legitimate interests — to secure the service, prevent abuse, support accounts, send operational practice notifications, measure aggregate website usage (Vercel Web Analytics), and operate an invite-only learning portal (balanced against your rights)
  • Legal obligation — where we must keep payment or tax-related records (often held by Stripe)

Google sign-in

If you sign in with Google, MySwara (via Clerk) receives basic profile information such as name and email to create or link your account. This is used only for authentication and account display. You can revoke access in your Google Account settings.

Telegram lesson bot (optional, teachers)

Teachers may connect an official MySwara Telegram bot from the Lessons page to log lessons by chat. This is optional and is only a logging medium: after you confirm a lesson in Telegram, MySwara writes the lesson into the same Supabase database used by the web app (student, date, hours, topic, notes, practice, price, payment status). Students do not need Telegram to use MySwara.

To connect, the teacher generates a short-lived link code in MySwara and sends it to the bot. We then store the teacher’s Telegram user id on their MySwara account. Unlinking clears that id; you can also use the bot’s unlink command.

GDPR note: Telegram is a third-party messaging service. Messages and button taps you send to the bot travel through Telegram’s infrastructure under Telegram’s privacy policy before our servers receive the webhook update. Telegram may process that chat traffic outside the EEA depending on their operations; we do not control Telegram’s platform. What MySwara keeps as the source of truth for teaching records is the lesson row (and related account link) in Supabase. Do not put sensitive data in Telegram that you would not put in a lesson note on MySwara. If you prefer not to use Telegram, log lessons only in the MySwara web app.

Practice notification emails (Resend)

When practice events happen (a teacher assigns a to-do, a student submits work, or a submission is marked Needs practice), MySwara may email the relevant teacher(s) or student using Resend. Emails are transactional only (not marketing). Content typically includes names already on the account, a short description of the material, and a link back to MySwara.

Resend processes these sends for us. Our Resend region is Ireland (eu-west-1). From address defaults to notify@myswara.soundofcarnatic.com (or another address we configure). See also Resend’s own documentation and privacy terms.

Cookies and similar technologies

Sign-in is handled by Clerk, which uses cookies or similar session storage to keep you logged in. We also store a last-activity timestamp in your browser’s local storage for idle sign-out. Stripe Checkout / Customer Portal may set cookies needed for payment security. We use Vercel Web Analytics to collect aggregate page-view style metrics; Vercel’s Web Analytics is designed to work without advertising cookies and is not an ad network. We do not use advertising trackers or third-party ad pixels on MySwara.

Service providers (processors)

  • Clerk — authentication, session management, invitation emails, and the optional teacher waitlist
  • Stripe — Checkout, trials, subscriptions, customer portal, invoices, tax calculation where enabled, and storage of customer/billing records (including your email in Stripe’s Customers list when you start a trial or subscribe)
  • Supabase — database and private media storage (including lesson ledger rows)
  • Resend — transactional practice notification emails (region: Ireland / eu-west-1)
  • Telegram — optional message transport for the teacher lesson-logging bot (independent platform; see section above). Not used for student practice media.
  • Vercel — website and API hosting, plus Web Analytics for aggregate visit metrics

These providers process data on our behalf (or as independent controllers for parts of payment compliance, in Stripe’s case, and as a messaging platform in Telegram’s case) to run the service. Their privacy policies also apply. Some providers may process data outside the EEA/UK; they use appropriate safeguards (such as standard contractual clauses) as described in their documentation where they act as processors.

Retention and deletion

We keep account and learning data while your account is active so teachers and students can use MySwara. Pending invite emails are kept until the invite is accepted, cancelled, or cleaned up by an admin. When an administrator deletes an account, we remove the user from our database, clean up linked teaching data and media where our systems support it, clear any Telegram link id on that account, and remove the related Clerk sign-in and Stripe customer record when possible. Stripe may still retain invoices or payment records as required for payments and accounting. Copies of messages that remain in a user’s Telegram chat history are controlled by Telegram / the user’s Telegram account, not by MySwara deletion alone.

To request deletion or a copy of your data, email info@soundofcarnatic.com or soundofcarnatic@gmail.com with the subject “Privacy request” and the email address on your MySwara account. We aim to complete straightforward deletion or access requests within 30 days.

Security and breaches

We use authenticated access, role checks, and private media storage to protect data. If we become aware of a personal data breach that is likely to risk your rights, we will assess it and notify the relevant authority and affected users when the law requires.

Your choices (EEA / UK)

Depending on where you live, you may have rights to access, correct, or delete personal data we hold about you, to restrict or object to certain processing, and to data portability where applicable. You may also contact your local data-protection authority (in the Netherlands: Autoriteit Persoonsgegevens). Teachers who connected Telegram can unlink the bot at any time and continue logging lessons only on the web.

Children

MySwara is used in a teaching context and may include younger students invited by a teacher or parent/guardian. Accounts are created only via invitation. If you believe we hold data about a child without appropriate permission, contact us and we will address it.

Contact

info@soundofcarnatic.com
soundofcarnatic@gmail.com
Application: MySwara