Privacy policy
The short version
BandBox stores your band's inventory so it appears on every device your band signs in on. It collects your email address, your name, your band's details, and the inventory you type in — including the name of whoever an instrument is signed out to. There is no advertising, no analytics, no tracking, and no third-party code in the app. Nothing is ever sold. Deleting your account in Settings deletes all of it.
Who we are
BandBox is an independently developed app for band directors. "BandBox", "we", and "us" mean Derrick McGuire, the developer of the app; "you" means the person signed in to it. Questions, requests, or anything that reads wrong to you: julianmcg08@gmail.com.
What BandBox collects
Your account
To sign in, BandBox needs an identity to attach your band's inventory to. Depending on the button you press, that is:
- Email — your email address. BandBox emails you a six-digit code and you type it back in. There is no password to store, so we don't store one.
- Sign in with Apple — the identifier Apple gives us, plus your name and email address if you choose to share them. If you use Apple's Hide My Email, we only ever see the relay address, and we don't try to look behind it.
- Google — your Google account's email address and name.
We also keep the display name you type during setup and which of the three methods you used, so Settings can show it.
Your band
The band's name, its two-to-five-letter label prefix, its six-character join code, and the list of accounts in it with their roles and the dates they joined. Every member of a band can see the names and email addresses of the other members on the People screen — that's the point of a shared band, and it's worth knowing before you invite someone.
Your inventory
Everything you type about an item: its label code, name, whether it's an instrument or a uniform, its category, serial number, size, notes, who it's currently signed out to, and when.
Your sign-out history
Each time an item is added, signed out, signed back in, or deleted, BandBox records what happened, when, the item's name and code, and the name of the student involved. History is the feature — it's what lets you answer "who had this trumpet in October" — so it's kept until you delete the account.
Technical data
Reaching our server means your device's IP address is visible to it, as it is to any website you open. Our hosting provider keeps ordinary short-term server logs. We don't build profiles from them, and no analytics product receives them. If you have separately agreed to share diagnostics with Apple, Apple may pass us anonymised crash reports; those come from Apple rather than from code in our app, and they contain stack traces rather than your inventory.
What BandBox does not collect
- No tracking. Nothing about you is linked with data from other companies' apps or websites, for advertising or anything else. The app contains no advertising identifier.
- No analytics or third-party SDKs. The app ships no third-party code at all — no Firebase, no Google Analytics, no advertising or social SDKs, no crash reporter of our own.
- No location, contacts, photo library, microphone, or health data. The app never asks, because it never needs them.
- No photographs. See the camera section below.
- No sale of data, ever. Not to advertisers, not to data brokers, not to anybody. There is no version of this app in which your students' names are a product.
The camera
BandBox asks for camera access for one reason: reading the QR sticker on an
instrument case. Recognition happens on your device using Apple's built-in scanner.
BandBox receives only the short text the sticker encodes — something like
RVHS-K7P2QX — and looks it up in your inventory. No photo or video is
saved, and no camera frame ever leaves your device.
Student information
This deserves its own section, because it's the most sensitive thing in the app and it doesn't come from the student.
When you sign an instrument out, BandBox stores the name you type in the "signed out to" field and keeps it in that item's history afterwards. In practice that name usually belongs to a minor. BandBox collects nothing else about them: no email address, no phone number, no date of birth, no grades, no photograph. Students have no accounts and never use the app.
What we do with that name is exactly one thing: show it back to the members of your band. It is never used for advertising, never shared with anyone outside your band, and never analysed. It is stored in the same database row as the instrument, protected by the same rules, and deleted with the account.
A few practical notes for directors:
- You decide how much to type. "A. Nguyen" or a locker number works as well as a full legal name, and we'd encourage the shorter form.
- If your school or district has a policy about student information in third-party apps, that policy governs. Please check it before entering student names.
- Signing an item back in clears the current holder, but the history entry remains, so the record of who had it stays readable. To remove a name from history entirely, delete the item, or delete the account.
BandBox is a tool for the adults who run band programs. It is not directed to children, and we do not knowingly allow anyone under 13 to create an account.
Where the data lives, and who else touches it
Your inventory is stored in two places: on each device that signs in, and in our hosted database so those devices can agree with each other. We use a small number of providers to run that, and no one else.
Supabase (supabase.com)
What it does: hosts the database, handles sign-in, and sends the six-digit sign-in emails.
What it sees: everything described above.
Apple
What it does: Sign in with Apple; App Store distribution.
What it sees: that you signed in with Apple. Apple does not receive your inventory.
What it does: Google sign-in, only if you use that button.
What it sees: that you signed in to BandBox with Google. Google does not receive your inventory.
Our database runs in a single region chosen when the project was created. If you use BandBox from elsewhere in the world, your data is transferred to and stored in that region.
Beyond those providers, we disclose data in only two situations: to the other members of your own band, which is the feature working as designed; and where we're required to by valid legal process. If BandBox were ever transferred to someone else, this policy would travel with the data, and we'd say so in the app before the change took effect.
How it is protected
- Every request between the app and the server uses HTTPS.
- The database enforces band membership on every row. A signed-in account can only read and write rows belonging to a band it's a member of, and that check happens inside the database rather than in the app — so a modified copy of the app can't talk its way past it.
- Sign-in tokens are held in the iOS keychain rather than ordinary app storage.
- Your join code is the one credential you hand out. Anyone with it can join your band and see the inventory, so treat it like a key to the uniform closet. If it gets out, Settings > People lets you generate a new one, which stops the old one working immediately.
No system is perfectly secure and we won't pretend otherwise. If you find a weakness in BandBox, please write to julianmcg08@gmail.com and we'll take it seriously.
How long it is kept
- Account, band, inventory, and history are kept for as long as the account exists.
- When you delete an item, the app keeps a hidden marker for it so your other devices find out it's gone. That marker still contains the item's details; it's removed from each device about a week later, and it remains on the server until the account or band is deleted.
- Deleting the app from a device removes that device's local copy. It does not delete the account — sign in again anywhere and the inventory comes back.
Your choices
- Correct or change your details. Your name, band name, and label prefix are all editable in Settings at any time.
- Leave a band. Members can leave; the band's inventory is unaffected.
- Delete everything. Settings > Delete Account removes your account, your membership, and the inventory and history belonging to any band you created. If you created the band, deleting your account deletes that band and its entire inventory for every member of it. There's no undo and no backup we can restore from, so print or export anything you want to keep first.
- Get a copy of your data. Email julianmcg08@gmail.com from your account's address and we'll send you your band's records.
Depending on where you live, you may have rights to access, correct, port, or erase your personal data and to object to how it's handled. We honour those requests regardless of where you live, and the same email address is how to make one. We'll never charge you for a request or treat you differently for having made one. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Changes to this policy
If we change how BandBox handles data, we'll update this page and the date at the top. If the change is significant, we'll tell you in the app before it takes effect rather than hoping you re-read this page.