Privacy

Last updated 10 September 2026

Doublesharp is a music theory practice app for anyone working through ABRSM theory grades 1 to 5. It is run by a single small operator (not a large company), so this policy is short and direct. We collect the minimum we need to make the app work, and you can ask us to delete everything we hold at any time.

Who runs Doublesharp

Doublesharp is operated by an individual UK-based operator trading as Doublesharp. For privacy questions, data deletion requests, or anything else covered by this policy, email hello@doublesharp.co.uk.

What we collect, and why

For adult (parent) accounts:

  • Email address used to send the magic sign-in link and (rarely) account-related notifications. No marketing emails without separate explicit opt-in.
  • Display name optional. Shown in the dashboard so an adult with multiple devices recognises their own account.
  • Sign-in cookies a JWT session cookie after sign-in. Cleared on sign-out. Used only to keep you signed in across pages.

For child accounts:

  • First name what the parent typed when they added the child. Shown only on that child’s own screen and in the parent’s dashboard.
  • A globally-unique handle (e.g. tiger.river.galaxy). Three random words from a curated list, auto-generated. Used to sign in. The child’s display name is not in the handle, so it doesn’t identify them outside their family context.
  • A bcrypt hash of the child’s 4-digit PIN — we never store the PIN itself. The hash is used to verify sign-in.
  • Answers and session records which questions the child answered, whether they got each right, how long they took, plus session-level summaries (grade, topic, score). This is what makes the practice reports and the placement test useful. Without it we can’t show progress or pitch questions at the right level.
  • A child sign-in cookie random token, 1-year expiry, HttpOnly. Cleared on sign-out, or any time the parent revokes the session from the dashboard.

For teacher (instrumental tutor) accounts:

  • Email address the same magic-link sign-in used for a parent account.
  • A pupil list the teacher’s own record of the pupils they have set up or been linked to on Doublesharp. Each pupil entry holds the same first name, handle, PIN hash and answers/session records described above, not a separate copy of it.

What we don’t collect. No date of birth and no age. Where a learner profile is set up for someone else, we ask the adult to confirm they have the right to do that, and we don’t store the answer. No location. No device fingerprinting. No behavioural-advertising signals. No third-party social sign-in.

Marketing-page measurement. The public marketing pages (the homepage, this privacy page, /terms, /contact) load Google Analytics 4 and the Google Ads conversion tag only so we can see whether advertising spend brings in real visitors. IP addresses are anonymised at collection. The tag is never loaded on the part of Doublesharp your child uses (everything under /play, /profiles, /dashboard, or /invite) and we never send personal data through it. If you’d rather opt out of advertising measurement entirely on the marketing pages, browser-level "Do Not Track" + ad blockers work; we don’t fight either.

Legal basis

Adult accounts: contract (UK GDPR Art. 6(1)(b)). We need the email to provide the sign-in service the adult asked for.

Learner profiles set up for someone else: parent-mediated consent (UK GDPR Art. 6(1)(a) + Art. 8). The adult who creates the profile confirms they have the right to do so on that person’s behalf (parent, legal guardian, or authorised teacher). We don’t collect age verification beyond that confirmation, and we don’t ask for a date of birth. We don’t use learner data for any purpose other than running the practice questions, the placement test and practice papers, and showing the adult who set it up (and, where a teacher is linked, that teacher) what the learner has been doing.

A learner profile you create for yourself is just your own account: contract (Art. 6(1)(b)), the same as the adult account it sits on, with no third party involved and nobody else able to see it.

On age. We don’t set an age range, because the syllabus doesn’t have one: grade 5 theory is the same paper whoever sits it. We design the whole learner surface to the standard the ICO’s Children’s Code asks for regardless of who is using it: no advertising profiles, no behavioural tracking, no nudges to stay longer, no public sharing, no contact between users, and no analytics of any kind on the pages a learner sees. Anyone under 18 reaches Doublesharp through an adult’s account, and that adult can read, export or delete everything at any moment.

How long we keep it

Your data lives in our database for as long as your account does. When you delete an account or a child:

  • The account / child row is removed immediately.
  • All linked data (sessions, attempts, flags) cascades and is removed at the same time.
  • Database backups (daily) retain a copy for up to 30 days; after that point all traces are gone.
  • An entry in our audit_log table records that a deletion happened, but contains no personal data beyond the event timestamp and the account / child id.

Your rights

Under the UK GDPR you have the right to:

  • See what we hold the parent dashboard has a “Download data” button per child that produces a JSON export of everything we have on that child. Email us if you want your own adult-account export.
  • Ask us to delete it there’s a delete button on the dashboard, or you can email us and we’ll do it within 7 days.
  • Ask us to correct it most child-facing fields (name, settings) you can edit yourself from the child’s settings page. For anything else, email us.
  • Complain to the regulator — the UK Information Commissioner’s Office at ico.org.uk.

Where the data lives

Doublesharp uses four sub-processors. None hold or process data on our behalf in a way the operator doesn’t control. All have UK GDPR-compliant data processing agreements in place.

  • Vercel Inc. — runs the app servers and serves static assets. Hosting region: EU (Frankfurt). DPA.
  • Neon Inc. — hosts the Postgres database that holds all account / child / session data. Region: EU (eu-west-2, London). DPA.
  • Resend Inc. — sends the magic sign-in emails to adults. Receives the recipient email address and a one-time link. Doesn’t store email content beyond delivery diagnostics. DPA.
  • Cloudflare Inc. — CDN in front of Vercel. Sees IP addresses and request paths in transit; doesn’t persist them. DPA.

We never sell or rent personal data. We never share it with advertisers, data brokers, or analytics platforms.

Cookies

Doublesharp uses two cookies, both first-party and both necessary for sign-in to work:

  • authjs.session-token — adult sign-in (Auth.js JWT). HttpOnly, Secure, SameSite=Lax. Cleared on sign-out.
  • doublesharp_kid_session — child sign-in. HttpOnly, Secure, SameSite=Lax, 1-year expiry by default. Cleared on sign-out or when the parent revokes from the dashboard.

On the public marketing pages (NOT on /play, /profiles, /dashboard, or /invite), Google Analytics 4 and Google Ads conversion measurement set first-party cookies (_ga, _gid, _gcl_*). These are used solely to see whether advertising spend brings in real visitors and never on pages your child uses.

The same marketing pages also load GoatCounter, a privacy-focused page-view counter. It sets no cookies, stores no personal data and does not follow you between sites, which is why it runs without asking; it tells us how many people read a page, nothing about who they are. It never loads on the pages your child uses.

On those marketing pages we show a cookie banner the first time you visit. Choosing Reject means no Google Analytics or Google Ads cookies are set on your device, ever. Choosing Accept remembers your decision for a year via a strictly-necessary doublesharp-consent cookie (no third party — set by us, used only to remember your choice). You can change your mind by clearing site data in your browser; the banner reappears.

No third-party tracking cookies on any child-facing surface, ever, regardless of consent. The banner only appears on marketing pages because that’s the only place gtag could possibly load.

Security

Adult passwords don’t exist. Sign-in is magic-link only, so there’s no password to leak. Child PINs are stored as bcrypt hashes (cost 10), so even a full database leak doesn’t expose the PIN itself. All traffic is HTTPS. Database is in a private network and accessed only over TLS.

Changes to this policy

If we change something material, we’ll bump the “Last updated” date at the top and add a one- line summary explaining what changed.

Questions, concerns, or want a copy of your data? Email hello@doublesharp.co.uk.

Contact form →