Student Data Privacy Policy
1. Who this covers
Adults (teachers, parents, studio owners, and adult learners) create accounts and run classes. Students join by typing a code — a class code from the board, or their own personal practice code in a private studio or homeschool — and they have no accounts and are never asked to agree to anything. A school classroom, a homeschool family, and a private studio all work the same way: the adult is the account, the learner is a label.
2. What we collect
| From | Data | Why |
|---|---|---|
| Teachers | Name, email, school, login records | Account, license, security |
| Students | A display label (teacher-controlled, first name or nickname only), an optional 4-digit PIN, a teacher-issued join or practice code, and lesson results (score, accuracy, grade, stars, practice minutes) | So the teacher can record a music grade and the student can resume their work |
We do not collect from students: email, last name (not required), passwords, address, phone, photos, biometrics, location, contacts, or advertising identifiers. Teacher card payments are handled entirely by Stripe — we never see card numbers.
3. What we never do
- No advertising, ad networks, or ad trackers.
- No sale, rent, or trade of any data.
- No marketing or behavioral profiles of students — results are grades, nothing more.
- No use of any user data to train AI or machine-learning models. Grading is deterministic software, not AI, and student pages involve no AI at all.
- No change to any of these commitments without advance notice to account holders (see section 11).
4. Who can see the data
A teacher sees only their own students' results, enforced by database-level row security — not just the user interface. Vendor staff access production data only for support or security, under logging.
5. Infrastructure providers (subprocessors)
| Provider | Role | Student data? |
|---|---|---|
| Supabase (US region) | Database, authentication, server functions | Labels + results |
| Stripe | Teacher billing only | No |
| Vercel | Serving the app over HTTPS | Request logs only |
6. Retention & deletion
- Student results are automatically deleted 365 days after the class session closes (configurable per district).
- Audit logs are kept 18 months for security review, then deleted.
- Teachers can delete any session and all its results from the dashboard, instantly.
- Account holders can delete their entire account self-serve (dashboard, "Delete my account"): every class, roster label, session, grade, and uploaded piece is erased from production immediately, and storage backups age out within 7 days.
- A school or teacher may request full deletion; we complete it within 30 days.
7. Security
HTTPS everywhere; encryption in transit and at rest; teacher-only accounts; server-side license checks; row-level security; and audit logging of logins, session creation, and exports. There is no offline mode and no downloadable copy of the application.
8. Parents
Schools typically cover classroom tools under their existing technology notices. Where direct parent consent is required, we provide sample notice language, and any student can complete the same learning objective in a no-record guest mode where nothing is stored.
9. Compliance posture
COPPA (Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506): Piano Professor is used by students under the school-authorization model recognized in FTC guidance. Students are never asked for personal information: no account, no email, no last name, no photo, no location, and no advertising identifiers. The only student-side data is a teacher-controlled display label and lesson scores. The routine technical identifiers any website receives (such as an IP address in server logs) are used solely to operate and secure the service, consistent with COPPA's support-for-internal-operations exception, and never for contact, profiling, or advertising.
FERPA (Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g): lesson results are education records that belong to the school. We operate as a school official with a legitimate educational interest, under the school's direct control with respect to those records: we use them only to provide the service, never for any other purpose, and we delete them at the school's direction.
New York Education Law § 2-d: our practices are built to satisfy 2-d's requirements for third-party contractors, including: student data is never sold or released for any commercial purpose; no marketing or advertising use; encryption of data in transit and at rest; limited retention with deletion on request; parents may review their child's data through the school and challenge its accuracy. We will sign a New York district's Data Privacy Agreement, including the district's Parents' Bill of Rights supplement, as part of any New York purchase.
Maryland (Student Data Privacy Act, Md. Code, Educ. § 4-131): no targeted advertising to students, no student profiling for non-educational purposes, no sale of covered information, and deletion at the school's request. This is the law of our home state, and the product was designed under it from day one.
Data Privacy Agreements: we will sign your district's DPA, including state riders and the national Student Data Privacy Consortium (SDPC / NDPA) standard form where your district uses it.
Breach notification: in the event of a breach affecting student data, we notify the affected school or district without unreasonable delay after discovery, with what happened, what data was involved, and what we are doing about it, so the district can meet its own notification obligations.
10. Your rights and how to exercise them
- Parents and students: review, correction, and deletion run through the school or the account-holding adult — because we cannot identify students (labels only), your teacher or parent is the one who can look up, export, correct, or erase a record, and the dashboard gives them one-tap tools to do it. Ask them first; ask us if you get stuck.
- Teachers and account holders: export everything to CSV any time; delete any student, class, or session instantly; delete your entire account self-serve.
- Districts: deletion certifications within 30 days of request, and our current compliance documentation on request.
- Anyone: write to the contact address above with any privacy question; we answer within one business day.
11. Changes to this policy
If we make a material change to what we collect or how we use it, account holders are notified by email before the change takes effect, and this page's version number and date change. We never weaken a commitment in section 3 retroactively: data collected under a promise stays under that promise.
12. For your district's review checklist
| Review question | Answer |
|---|---|
| Student accounts, email, or passwords required? | No. Join code + teacher-controlled first-name label only |
| Personal information collected from children? | No. Students are never asked for any |
| Targeted advertising, ever? | No. No ads anywhere a student plays, no ad identifiers, no pixels on student pages |
| Student data sold, rented, or shared for commercial purposes? | No, never. |
| Student profiles built for non-educational purposes? | No. Results are grades, nothing more |
| Student data used to train or improve the product? | No. Refused on principle |
| Chat, messaging, or social features? | None. Students cannot contact or be contacted by anyone |
| Encryption | In transit (TLS) and at rest |
| Access controls | Database-level row security; teachers see only their own students; vendor access logged |
| Data location | United States |
| Retention | Results auto-delete 365 days after a session closes (configurable per district); full deletion on request within 30 days |
| Subprocessors | Listed in section 5 of this policy |
| Will sign a DPA / NDPA / Ed Law 2-d rider? | Yes. |
| Breach notification to the district? | Yes, without unreasonable delay |
| Alternate activity for students without consent? | Yes. No-record guest mode stores nothing |