Piano Professor — School Edition

Student Data Privacy Policy

Version 2 · Effective August 17, 2026 (v1 June 2026) · Vendor: Piano Professor, a product of Find a Way or Make One, LLC (Maryland, USA) · Contact: iwillfindawayormakeone@gmail.com

The short version: students never create accounts, never enter an email, and never accept any terms. The only student data stored is a class label the teacher controls (like "Student 12") and the scores earned on lessons. No ads. No selling of data. Ever.
About the student experience and our marketing pages: the pages a student ever loads — the class-join page and the lessons themselves — contain no ads, no third-party trackers, and no advertising pixels of any kind. Our public marketing pages (the homepage and pricing pages, which a student never uses) do use standard advertising measurement, like most websites, so we can run ads to teachers and parents. That measurement never runs during a class and never involves a child.

1. Who this covers

Adults (teachers, parents, studio owners, and adult learners) create accounts and run classes. Students join by typing a code — a class code from the board, or their own personal practice code in a private studio or homeschool — and they have no accounts and are never asked to agree to anything. A school classroom, a homeschool family, and a private studio all work the same way: the adult is the account, the learner is a label.

2. What we collect

FromDataWhy
TeachersName, email, school, login recordsAccount, license, security
StudentsA display label (teacher-controlled, first name or nickname only), an optional 4-digit PIN, a teacher-issued join or practice code, and lesson results (score, accuracy, grade, stars, practice minutes)So the teacher can record a music grade and the student can resume their work

We do not collect from students: email, last name (not required), passwords, address, phone, photos, biometrics, location, contacts, or advertising identifiers. Teacher card payments are handled entirely by Stripe — we never see card numbers.

3. What we never do

4. Who can see the data

A teacher sees only their own students' results, enforced by database-level row security — not just the user interface. Vendor staff access production data only for support or security, under logging.

5. Infrastructure providers (subprocessors)

ProviderRoleStudent data?
Supabase (US region)Database, authentication, server functionsLabels + results
StripeTeacher billing onlyNo
VercelServing the app over HTTPSRequest logs only

6. Retention & deletion

7. Security

HTTPS everywhere; encryption in transit and at rest; teacher-only accounts; server-side license checks; row-level security; and audit logging of logins, session creation, and exports. There is no offline mode and no downloadable copy of the application.

8. Parents

Schools typically cover classroom tools under their existing technology notices. Where direct parent consent is required, we provide sample notice language, and any student can complete the same learning objective in a no-record guest mode where nothing is stored.

9. Compliance posture

COPPA (Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506): Piano Professor is used by students under the school-authorization model recognized in FTC guidance. Students are never asked for personal information: no account, no email, no last name, no photo, no location, and no advertising identifiers. The only student-side data is a teacher-controlled display label and lesson scores. The routine technical identifiers any website receives (such as an IP address in server logs) are used solely to operate and secure the service, consistent with COPPA's support-for-internal-operations exception, and never for contact, profiling, or advertising.

FERPA (Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g): lesson results are education records that belong to the school. We operate as a school official with a legitimate educational interest, under the school's direct control with respect to those records: we use them only to provide the service, never for any other purpose, and we delete them at the school's direction.

New York Education Law § 2-d: our practices are built to satisfy 2-d's requirements for third-party contractors, including: student data is never sold or released for any commercial purpose; no marketing or advertising use; encryption of data in transit and at rest; limited retention with deletion on request; parents may review their child's data through the school and challenge its accuracy. We will sign a New York district's Data Privacy Agreement, including the district's Parents' Bill of Rights supplement, as part of any New York purchase.

Maryland (Student Data Privacy Act, Md. Code, Educ. § 4-131): no targeted advertising to students, no student profiling for non-educational purposes, no sale of covered information, and deletion at the school's request. This is the law of our home state, and the product was designed under it from day one.

Data Privacy Agreements: we will sign your district's DPA, including state riders and the national Student Data Privacy Consortium (SDPC / NDPA) standard form where your district uses it.

Breach notification: in the event of a breach affecting student data, we notify the affected school or district without unreasonable delay after discovery, with what happened, what data was involved, and what we are doing about it, so the district can meet its own notification obligations.

10. Your rights and how to exercise them

11. Changes to this policy

If we make a material change to what we collect or how we use it, account holders are notified by email before the change takes effect, and this page's version number and date change. We never weaken a commitment in section 3 retroactively: data collected under a promise stays under that promise.

12. For your district's review checklist

Review questionAnswer
Student accounts, email, or passwords required?No. Join code + teacher-controlled first-name label only
Personal information collected from children?No. Students are never asked for any
Targeted advertising, ever?No. No ads anywhere a student plays, no ad identifiers, no pixels on student pages
Student data sold, rented, or shared for commercial purposes?No, never.
Student profiles built for non-educational purposes?No. Results are grades, nothing more
Student data used to train or improve the product?No. Refused on principle
Chat, messaging, or social features?None. Students cannot contact or be contacted by anyone
EncryptionIn transit (TLS) and at rest
Access controlsDatabase-level row security; teachers see only their own students; vendor access logged
Data locationUnited States
RetentionResults auto-delete 365 days after a session closes (configurable per district); full deletion on request within 30 days
SubprocessorsListed in section 5 of this policy
Will sign a DPA / NDPA / Ed Law 2-d rider?Yes.
Breach notification to the district?Yes, without unreasonable delay
Alternate activity for students without consent?Yes. No-record guest mode stores nothing