Skip to content
Security & privacy

Each studio is an island

Harmony isolates every studio’s data, enforces roles server-side, and only lets platform support in with a consent-gated, time-boxed grant you control — every visit audited.

Per-studio isolation

Every record — lessons, availability, policy, members, notifications — is scoped to one studio. Queries are filtered by your studio on every request, so one studio can’t see another’s data.

Role-based access

Admins, teachers, and students each see only what their role allows, enforced server-side on every page and action. Teachers manage their own lessons; students act only on their own.

Authenticated sessions

Sign-in is email and password, with optional Continue with Google when configured. Credentials are stored hashed, never in plain text. Sessions expire after seven days and refresh while you’re active.

Two-factor authentication

Admins must enroll in 2FA (email code or authenticator app) unless they sign in with Google, which already provides MFA. Teachers can opt in from Security settings. Trusted devices can skip the prompt for 90 days.

Audit trails

Support visits log who entered and when. Mutating actions taken during a support session — lesson changes, availability, policy — are recorded alongside enter/exit, and every notification email is kept in the outbox.

Notification privacy

People control what reaches their inbox. Each user can opt out of new-lesson, reschedule, cancellation, and reminder emails independently.

The standout

Consent-gated, time-boxed support access

Most SaaS support can quietly read your data. Harmony flips that: a platform administrator can only enter your studio when you grant access, only for as long as you allow, and every visit is recorded where you can see it.

  1. 1

    You grant access

    An admin enables support access for a set window — say, seven days. Nothing is open until you do this.

  2. 2

    Support enters — and it’s logged

    A support visit is recorded the moment it starts, acting only as your studio’s admin, with a clear support-session banner.

  3. 3

    It auto-revokes

    When the window expires or you switch it off, access ends automatically. Support sessions can’t extend their own grant.

  4. 4

    You see everything

    Every enter and exit appears in your studio’s audit log, along with lesson and settings changes made during the visit.

Default grant windows are short and expire on their own — access is the exception, not the rule.
How we build

Honest about what we do — and don’t — claim

We’d rather describe what the software actually enforces than wave compliance badges. Here’s where things stand.

Data is isolated per studio and access is checked on the server for every request.

Passwords are hashed; we never store them in plain text. Optional Google sign-in is available when configured.

Admin 2FA is mandatory (email or authenticator); Google sign-in satisfies the MFA requirement. Teachers can opt in.

Support access is opt-in, time-boxed, and fully logged — including mutating actions during the visit.

We do not yet carry formal certifications (e.g. SOC 2), and we don’t claim otherwise.

Infrastructure

Subprocessors we may use

These providers process data on our behalf when the related feature is enabled for a deployment. Optional services are off until configured.

  • Microsoft Azure

    Application hosting (Azure Container Apps) in the United States.

  • Neon

    Managed PostgreSQL for studio and account data.

  • Google

    Optional Sign in with Google; optional free/busy, Calendar sync, Contacts, website Analytics, and Ads conversion measurement when enabled.

  • Stripe

    Optional payment processing and subscription management for per-teacher billing.

  • Azure Communication Services Email

    Optional transactional email delivery when configured.

  • Anthropic

    Optional AI student assistant responses when configured.

Found something? Tell us.

We welcome responsible disclosure. If you believe you’ve found a security issue, email us and we’ll work with you to confirm and resolve it.

support@harmonyscheduling.com

For how we collect and use personal information, see our Privacy Policy. Service use is governed by our Terms of Service.

FAQ

Security questions

Can one studio see another studio's data?
No. Every record is scoped to one studio, and queries are filtered by studio on every request. Multi-studio users switch context; data never crosses studios.
How does platform support access a studio?
Only with a consent-gated, time-boxed support grant from the studio. Every support visit is audited and visible to the studio — support cannot browse tenant data by default.
Is two-factor authentication required?
Yes for studio admins (email OTP or authenticator app). Teachers may opt in. Students sign in with email and password (or Google when configured).

Run your studio with confidence

Isolation, role-based access, and audited support — from day one.

Start your studio