Privacy policy

Last updated 29 August 2026. Applies to the BandBox app for iPhone.

The short version

BandBox stores your band's inventory so it appears on every device your band signs in on. It collects your email address, your name, your band's details, and the inventory you type in — including the name of whoever an instrument is signed out to. There is no advertising, no analytics, no tracking, and no third-party code in the app. Nothing is ever sold. Deleting your account in Settings deletes all of it.

Who we are

BandBox is an independently developed app for band directors. "BandBox", "we", and "us" mean Derrick McGuire, the developer of the app; "you" means the person signed in to it. Questions, requests, or anything that reads wrong to you: julianmcg08@gmail.com.

What BandBox collects

Your account

To sign in, BandBox needs an identity to attach your band's inventory to. Depending on the button you press, that is:

We also keep the display name you type during setup and which of the three methods you used, so Settings can show it.

Your band

The band's name, its two-to-five-letter label prefix, its six-character join code, and the list of accounts in it with their roles and the dates they joined. Every member of a band can see the names and email addresses of the other members on the People screen — that's the point of a shared band, and it's worth knowing before you invite someone.

Your inventory

Everything you type about an item: its label code, name, whether it's an instrument or a uniform, its category, serial number, size, notes, who it's currently signed out to, and when.

Your sign-out history

Each time an item is added, signed out, signed back in, or deleted, BandBox records what happened, when, the item's name and code, and the name of the student involved. History is the feature — it's what lets you answer "who had this trumpet in October" — so it's kept until you delete the account.

Technical data

Reaching our server means your device's IP address is visible to it, as it is to any website you open. Our hosting provider keeps ordinary short-term server logs. We don't build profiles from them, and no analytics product receives them. If you have separately agreed to share diagnostics with Apple, Apple may pass us anonymised crash reports; those come from Apple rather than from code in our app, and they contain stack traces rather than your inventory.

What BandBox does not collect

The camera

BandBox asks for camera access for one reason: reading the QR sticker on an instrument case. Recognition happens on your device using Apple's built-in scanner. BandBox receives only the short text the sticker encodes — something like RVHS-K7P2QX — and looks it up in your inventory. No photo or video is saved, and no camera frame ever leaves your device.

Student information

This deserves its own section, because it's the most sensitive thing in the app and it doesn't come from the student.

When you sign an instrument out, BandBox stores the name you type in the "signed out to" field and keeps it in that item's history afterwards. In practice that name usually belongs to a minor. BandBox collects nothing else about them: no email address, no phone number, no date of birth, no grades, no photograph. Students have no accounts and never use the app.

What we do with that name is exactly one thing: show it back to the members of your band. It is never used for advertising, never shared with anyone outside your band, and never analysed. It is stored in the same database row as the instrument, protected by the same rules, and deleted with the account.

A few practical notes for directors:

BandBox is a tool for the adults who run band programs. It is not directed to children, and we do not knowingly allow anyone under 13 to create an account.

Where the data lives, and who else touches it

Your inventory is stored in two places: on each device that signs in, and in our hosted database so those devices can agree with each other. We use a small number of providers to run that, and no one else.

Supabase (supabase.com)

What it does: hosts the database, handles sign-in, and sends the six-digit sign-in emails.

What it sees: everything described above.

Apple

What it does: Sign in with Apple; App Store distribution.

What it sees: that you signed in with Apple. Apple does not receive your inventory.

Google

What it does: Google sign-in, only if you use that button.

What it sees: that you signed in to BandBox with Google. Google does not receive your inventory.

Our database runs in a single region chosen when the project was created. If you use BandBox from elsewhere in the world, your data is transferred to and stored in that region.

Beyond those providers, we disclose data in only two situations: to the other members of your own band, which is the feature working as designed; and where we're required to by valid legal process. If BandBox were ever transferred to someone else, this policy would travel with the data, and we'd say so in the app before the change took effect.

How it is protected

No system is perfectly secure and we won't pretend otherwise. If you find a weakness in BandBox, please write to julianmcg08@gmail.com and we'll take it seriously.

How long it is kept

Your choices

Depending on where you live, you may have rights to access, correct, port, or erase your personal data and to object to how it's handled. We honour those requests regardless of where you live, and the same email address is how to make one. We'll never charge you for a request or treat you differently for having made one. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Changes to this policy

If we change how BandBox handles data, we'll update this page and the date at the top. If the change is significant, we'll tell you in the app before it takes effect rather than hoping you re-read this page.

Contact

julianmcg08@gmail.com