Varius
PricingFAQContactSign In

Privacy Policy

Effective date: July 27, 2026 ·  Questions: support@varius.music

Overview

Varius is a score annotation and version-control platform for orchestra programs. This policy explains what data we collect when you use the Varius mobile app (iOS/iPadOS) or web dashboard, how we use it, and your rights over it.

We collect only what we need to operate the service. We do not sell your data. We do not use your score files or annotations for advertising.

1. Who we are

Varius is operated by Neel Krishnan, doing business as Varius (“Varius,” “we,” “us”), based in Atlanta, Georgia. Our primary contact address is support@varius.music.

2. Data we collect

Account information. When you create an account we collect your email address and a hashed password (managed by Supabase Auth). Librarian accounts also include an organization name. We do not collect your legal name unless you provide it.

Score files and annotations. PDFs you upload are stored in Supabase Storage and are private to your organization. Annotation data (bounding boxes, tags, comments, stroke coordinates) is stored as structured data in our database, scoped to your organization.

Roster and membership data. Librarians may enter player names and email addresses to build an ensemble roster. This data is stored in our database and is visible only to members of the same organization.

Usage data. We collect basic server logs (IP address, request timestamps, HTTP status codes) for security monitoring and debugging. These logs are retained for 30 days and are not used for analytics or advertising.

Push notification tokens.If you enable push notifications on the iOS app, we store your Expo push token and (for iOS Live Activities) an APNs device token in our database. These are used solely to deliver score-update notifications from your own organization’s librarian.

Device information. The iOS app collects device type (iPad vs. iPhone) to adapt the interface. We do not collect device identifiers (IDFA, IDFV) or advertising IDs.

AI processing.Crops of detected score changes are sent to Anthropic’s Claude API for automatic marking classification (e.g., “down-bow,” “fp”). These crops are small image fragments from PDFs your organization has already uploaded. Anthropic’s API usage policy governs how they handle data on their end — see anthropic.com/legal/privacy.

3. How we use your data

  • To provide, maintain, and improve the Varius service
  • To authenticate users and enforce access controls between organizations
  • To deliver push notifications about score updates within your organization
  • To run the automated diff and marking-classification pipeline on uploaded PDFs
  • To respond to support requests sent to support@varius.music
  • To detect and prevent unauthorized access or abuse

We do not use your data to train AI models. We do not use your data for advertising or behavioral targeting.

4. Data sharing

We share data with a small number of third-party services necessary to operate the platform:

Supabase— database, authentication, file storage, and real-time sync. Data is stored in US-East-1 (AWS). Privacy policy →

Vercel— hosting and serverless API functions for the web app. Privacy policy →

Anthropic— Claude API for automatic marking classification. Receives small PDF crops only. Privacy policy →

Expo / EAS— push notification delivery for the iOS app. Receives push tokens. Privacy policy →

Resend— transactional email (account invitations, password resets). Receives email addresses. Privacy policy →

We do not sell, rent, or share your data with any other third parties. We do not share data across organizations — your ensemble’s scores, annotations, and roster are not visible to other Varius customers.

5. Data retention

We retain your data for as long as your account is active. This includes score files, annotation data, roster information, and account credentials.

If you wish to have your data deleted, contact us at support@varius.musicand we will handle the request manually. We will confirm receipt within 7 days and complete the deletion within a reasonable timeframe. Note that some data may be retained where necessary to comply with legal obligations or to resolve disputes.

Server logs generated by our hosting infrastructure (Vercel, Supabase) are retained per those platforms’ default policies, which we do not control.

6. Your rights

You may request access to, correction of, or deletion of your personal data at any time by emailing support@varius.music. We handle these requests manually and will confirm receipt within 7 days.

7. Children

Varius is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data without appropriate consent, contact us at support@varius.music and we will delete it.

Ensemble programs that include minor players (e.g., youth orchestras) should ensure that parental consent is obtained before adding those players to the Varius roster, in accordance with applicable law.

8. Security

All data is transmitted over HTTPS. PDFs and annotation data are stored in Supabase with row-level security (RLS) policies that enforce organization-level isolation. Push notification tokens are scoped to individual user accounts.

We conduct periodic security reviews of our database policies and API authorization. If you discover a security vulnerability, please disclose it responsibly to support@varius.music.

9. Changes to this policy

We may update this policy when we add new features or change how we handle data. Material changes will be communicated by email to the librarian account on file. The effective date at the top of this page reflects the date of the most recent update.

10. Contact

Questions about this policy or your data: support@varius.music

© 2026 Neel Krishnan
PrivacyTermsContact