Privacy policy

Last updated: 23 July 2026

BandBook is a private, invite-only app for bands: a director publishes sheet music and set lists, and members read their parts, mark them up, and follow along during performances. This policy covers the BandBook mobile app and the organizer web app at admin.bandbook.band, together "BandBook".

BandBook is operated by Jeremy Ketterer, who is the data controller for the information described here. For any question about this policy or your data, write to privacy@bandbook.band.

BandBook shows no advertising, contains no advertising or analytics SDKs, does not track you across other apps or websites, and does not sell or share your personal information.

What we collect

DataWhy
Email address Your sign-in identity, password resets, and band invitations. Visible to the organizers of bands you belong to.
Display name Identifies you to other members of your band. You choose it and can change it in Settings.
Band membership Which bands you belong to, and whether you are an organizer or conductor in each.
Notification token A device identifier issued by Firebase Cloud Messaging so the app can alert you when a performance starts or the set changes. Collected only while the app is installed on that device.
Your markings Annotations you draw on parts, personal tags, and per-chart preferences. Stored per band, and private to you — see below.
Performance activity Which performance you are currently following, so the app can send you the right cues and show the band who is present.
Bug reports If you use "Report issue", we store the chart name, your notes, your user id, and the time. Readable by your band's organizers.
Crash diagnostics Via Firebase Crashlytics: device model, operating system version, app version, and the error and stack trace. Attached to each report are your user id, the band you were in, the screen you were on, and recent non-personal app log messages.
Administrative records Organizer actions in a band — invitations, role changes, member removals, content changes — recorded with who did what, to whom, and when.

We do not collect your location, contacts, photos, microphone or camera input, advertising identifiers, or browsing activity. We do not ask for a payment method; BandBook is free.

Who can see your markings

Annotations and personal tags are stored per band and are readable only by you. Your band's organizers cannot read them.

There is one narrow exception. If you ask for help with a problem in your own data, the operator can open a time-limited support session that grants read-only access to one member's markings in one band, for a period that is always under two hours and expires automatically. Opening and closing such a session is recorded in that band's administrative records along with a stated reason. Support sessions never permit writing to or deleting your data.

What your band can see

Bands are closed groups. Members of a band can see the display names of other members. Organizers of a band can additionally see members' email addresses, manage roles, and remove members. Nobody outside a band can see its roster, its library, or anything you do in it.

How long we keep it

DataRetention
Account, display name, markings Until you delete your account. Leaving a single band removes your membership of it.
Notification token Until you sign out, uninstall the app, or delete your account.
Bug reports Kept with the band they were filed in, so an organizer can act on them, until the band is deleted.
Administrative records 90 days, then deleted automatically.
Crash diagnostics 90 days, per Firebase Crashlytics' retention.

Your choices and rights

If you are in the European Economic Area or the United Kingdom, we process your data to provide the service you signed up for (contractual necessity), and, for crash diagnostics and administrative records, on the basis of our legitimate interest in keeping the app working and its bands accountable. You have the right to access, correct, export, restrict, or erase your data, and to complain to your local supervisory authority. Write to privacy@bandbook.band and we will respond.

Who processes data for us

BandBook runs on Google Firebase, which provides authentication, the database, file storage, notifications, crash reporting, and hosting. Data is stored on Google Cloud infrastructure in the United States. Organizer invitation emails are sent through Resend. Both act as processors on our behalf and are not permitted to use your data for their own purposes.

Children

BandBook is not directed to children under 13 and we do not knowingly collect personal information from them. Accounts are created by invitation from a band organizer. If you believe a child under 13 has an account, write to privacy@bandbook.band and we will delete it.

Security

Traffic between the app and our servers is encrypted in transit, and data is encrypted at rest by Google Cloud. Access to every record is enforced server-side by rules scoped to your band and your account, so one band cannot reach another band's data and one member cannot reach another member's markings. No system is perfectly secure, but we keep the permitted access as narrow as the app allows.

Changes

We may update this policy. The date at the top reflects the most recent revision, and material changes will be posted on this page.

Contact

Jeremy Ketterer — privacy@bandbook.band