Praxis Percussion

Privacy statement

Version 15 · Effective August 28, 2026 · Backwerd Rimshot, LLC · taylor@backwerdrimshot.com
Version 15 corrects the calendar-permission and disconnect descriptions. Google limits Praxis to calendars Praxis creates. Microsoft grants delegated read/write permission across the signed-in user's calendars because it offers no equivalent app-created-calendar scope; Praxis's software nevertheless uses only the dedicated Praxis calendar. On disconnect Praxis always destroys its stored credential, first attempts to delete that dedicated calendar, and asks Google to revoke its grant; Microsoft access can also be removed in Microsoft account settings.
Version 14 corrected two disclosures to match the service already deployed. While a Studio calendar connection remains active, closing a student record now causes Praxis to ask Google or Microsoft to delete the linked events and to retry a provider failure on a later sync. Copies made outside the separate calendar Praxis created can remain beyond our reach. Version 14 also names Stripe for both Praxis Percussion Studio and Praxis Tech subscription Checkout, and distinguishes the payment credentials Stripe handles from the Studio lesson-invoicing records that never accept a card or bank credential.
Version 13 replaces the "Staff and support access today" disclosure with the built control: support access now requires the organization owner's approval, is limited to one stated reason, expires after 72 hours or on revocation, and every read under it is logged where the owner can see it.
Version 12 changes who turns real records on: a private studio's owner activates them by completing the recorded attestation-and-acceptance step, and enables under-13 records by separately accepting the new Under-13 Records Addendum. Praxis no longer reviews each studio's activation individually — a recorded operator risk posture — while the transition stays one-way and audited, and schools and districts keep their separately reviewed path.
Version 11 changes what this page says about children under 13, because the software changed the same day: a private studio or independent teaching practice may now keep teacher-entered records about students of any age, subject to each organization's own recorded approval. The student still holds no account and cannot sign in — that is enforced in the software — and the optional guardian confirmation stays available without being a requirement. Version 11 also corrects the Praxis Tech description: an authorized director may hold narrow, explicitly enabled access to the Tech Director Portal, so "no client portal" was no longer accurate as an absolute.
Version 10 corrects three things Version 9 got wrong. It said a genuinely independent erasure reviewer would be in place before any organization other than our own was activated for real records — one was activated on August 13, 2026, the same day Version 9 published, and no independent reviewer existed then or now. It named Cloudflare as our email delivery provider, when the mail you actually receive goes through Resend, and then closed the list of other providers without Resend on it. And it described how we use information as a closed list that did not mention the AI drafting available inside Praxis Tech. All three are corrected below. Nothing about what the software does changed in any of them: the software was already working this way and the page had not caught up.
Version 9 accurately discloses the present operator-access limitation and the controlled 13-and-older founding-teacher activation path. It replaced Version 8 of August 11, 2026.
Version 8 added the limited public-site analytics disclosure below.
Version 7 replaced Version 6 of August 6, 2026, which described no billing at all while the service stored lesson rates, invoices, recorded payments, and a paying adult's contact details — and told a reader in the same breath that we hold no financial information. Both are corrected below; nothing about what the software does changed.
Version 6 replaced Version 5 of the same date, which said without qualification that we do not put a student's name in a calendar; that is now true of schools and districts, and a private teacher's own calendar shows the names they entered. Replaces the beta privacy notice of July 29, 2026.

Praxis Percussion is operated by Backwerd Rimshot, LLC. This statement describes, plainly and completely, what the service collects and why. The separate, free Backwerd Rhythm Shop apps are account-free and store progress locally in your browser unless you deliberately use a clearly identified hosted mode.

Check the workspace label. Every organization workspace is labeled. A workspace marked fictional-records-only — the default for every organization — accepts fictional example records ONLY: do not enter real student names, identifiers, or records there, including in free-text fields.

Real student records exist only by recorded decision. A private studio's own authorized owner activates real records by completing a deliberate, recorded step — attesting to their authority and accepting the published activation disclosure — and that acceptance is stored with the exact document versions it covered. The transition is one-way and audited, the workspace is then labeled "Real student records," and the server enforces the boundary per organization. Schools and districts cannot self-activate; their path remains separately reviewed.

Children under 13

Praxis Percussion may hold records about children under 13 when a private studio or independent teaching practice keeps them. Those records are entered by the adult teacher who teaches the child — about their own student, for their own teaching and administration. Scheduling a lesson, invoicing the responsible adult, and noting what to practise are the reasons they exist. Activation alone covers students 13 or older; records about younger students require the studio to separately accept the published Under-13 Records Addendum, and until it has, younger students' records stay out of Praxis Percussion entirely — enforced in the database, not only stated here.

The child has no Praxis Percussion account. They cannot sign in, and they submit nothing to us directly. That is enforced in the software, not only stated here: student sign-in and access codes are refused for these organizations, in every mode.

The teacher enters and maintains these records, including the student's name. The lessons are a service the teacher provides to the family, under their own agreement with that family, and we act on the teacher's instructions. What the teacher promises us about having the family's permission is set out in the Terms, not here. We do not advertise to anyone, we do not sell these records, and we do not train general-purpose AI on them.

A parent or guardian may ask what we hold about their child, ask for it to be corrected, or ask for it to be deleted, by writing to taylor@backwerdrimshot.com. We will act on that request whether or not their child's teacher still subscribes.

A teacher may also invite a parent or guardian into a record directly, and we keep that available. It is not a requirement for keeping a record, and we do not present it as one.

We have not received a fact-specific legal opinion clearing this arrangement under children's privacy law. It follows the published practice of comparable studio-management services. We do not claim to go further than they do on this point, and this statement will be corrected if that assessment changes.

What we collect from adults

Student records in an activated workspace

An organization activated for real records holds only what a teacher enters and the service derives from it: a learner name or label, an internal identifier, class or program membership, coursework attempts and evidence, teacher verification and retention events, lesson scheduling and teaching records the teacher maintains, and limited equipment-custody history.

We do not ask for and do not need: student email addresses, school-issued IDs, birth dates, student contact details, the student's own home address, precise location, health or disability information, discipline records, a student's or family's financial circumstances — household income, fee assistance, or free-and-reduced-price meal status — photos, audio, video, biometric data, advertising identifiers, or social-media data. In a private-studio workspace, students do not sign in and receive no accounts or credentials.

One item on that list needs a plain qualification rather than a flat denial, because a flat denial would be wrong. A private studio's teacher may bill for lessons, and where they do we hold what "Studio billing" above describes: rates, invoice amounts, recorded payments, and the paying adult's name, email, and optional address note. That adult is usually the student's parent, so in practice we may hold a household's contact details even though we hold none for the student. The Praxis application does not receive or store the payment credential an adult enters in Stripe-hosted Checkout to buy a Studio or Tech subscription; Stripe does. We would rather say this here than let a reader infer from the words "financial information" that a studio's invoices or Praxis subscription billing do not exist.

How we use it

To operate your account and workspace, deliver sign-in links and invitations you request, create the records and exports your organization authorizes, administer a Praxis subscription you choose through Stripe Checkout, respond when you contact us, and keep the service secure. That is the whole list. We do not sell personal information, show ads, share information for marketing, build unrelated commercial profiles, or train general-purpose AI models on covered records.

One use belongs on that list by name rather than tucked inside "create the records your organization authorizes". Praxis Tech can draft a service note or a client recap for the adult contractor whose work it describes, using an AI model run by Cloudflare — already our host, so no new company receives anything. Every draft is private until a person edits it and chooses to use it; nothing is sent, published, or shared from one on its own. It runs on a contractor's own record of their own work. It is not available anywhere student records live, and it is never given one. The sentence above still holds exactly as written: we do not train general-purpose AI models on covered records, and drafting is not training.

Who else touches the data

Praxis Percussion runs on Cloudflare (hosting, database, and security challenges), primarily in the United States. Cloudflare processes data on our behalf under its customer data protection agreement. We monitor Cloudflare's published list of sub-processors for changes.

Other service providers can receive limited information only to provide the feature you choose: Google LLC receives limited technical and page-visit information through Google Analytics on the public pages described above; Google LLC or Microsoft Corporation receives calendar information only when a teacher in your organization deliberately connects a Studio calendar; and Stripe, Inc. processes Praxis Percussion Studio and Praxis Tech subscription billing when you choose Checkout, including the account email, internal organization reference, plan, billing address, and payment credential used for that purchase; and Resend, Inc. delivers the email we send you — sign-in links, invitations, and notices — which means it receives the address the message goes to and what the message says. The Praxis application and server do not receive or store Studio or Tech subscription card or bank credentials; Stripe does. Google Analytics does not receive learner records, workspace content, or URL query strings from Praxis. Apart from those, no third party receives your information, except when disclosure is legally required or necessary to protect the service and its users.

Versions 6 through 9 of this statement attributed email delivery to Cloudflare and did not name Resend at all. Cloudflare's own routing is still there as a fallback, but the mail that reaches a real person goes through Resend, and Version 9 made this worse rather than better: it replaced a vague sentence with the closed list above, which was more precise and still missing a company. It is named here now.

Calendar connections you choose

This section describes Studio calendar connections, not Praxis Tech. A teacher can connect a Google or Microsoft calendar so their lesson schedule appears alongside the rest of their week. This is off until they connect it, it is per teacher and per organization, and nothing reaches either company before that. When it is connected, Google LLC or Microsoft Corporation receives what we write. Praxis Tech does not currently offer an internal calendar, Google/Outlook calendar connections, or other external calendar integrations.

What we write is a lesson time, how long it lasts, and who the lesson is with. We never write notes, observations, assignments, evidence, reports, or amounts.

Who the lesson is with depends on the kind of organization, and the difference is deliberate:

We ask each provider for the narrowest permission it offers. Google limits Praxis to secondary calendars Praxis creates. Microsoft does not offer an equivalent app-created-calendar permission: its delegated Calendars.ReadWrite grant allows access to the signed-in user's calendars. Praxis's software narrows that broader grant by creating a separate Praxis calendar and reading, changing, and deleting events only there; it does not read or change events in the teacher's other calendars.

The retraction applies to the linked event in the separate calendar Praxis created, while the connection remains active. A provider response that the event is already gone completes the retraction; another provider failure leaves the link in place for the next sync to retry. It is not a guarantee of immediate provider action, and it cannot reach an event copied, exported, or shared outside that calendar. A teacher can disconnect at any time from their schedule screen, without contacting us. Praxis first attempts to delete the dedicated calendar and its events, then always destroys the stored connection credential. For Google, Praxis also asks Google to revoke the grant. Microsoft access can be removed from the teacher's Microsoft account settings. A provider outage or expired permission can leave the dedicated calendar behind; once the credential is destroyed, Praxis can no longer retract it or its events. That residual limit is why a school or district calendar receives no student name or label even though Praxis now retracts linked events while the connection remains active.

Praxis Percussion's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use that information only to provide the calendar feature you asked for; we do not transfer it except as necessary to provide that feature, to comply with applicable law, or in a merger or acquisition with the notice and consent required; we do not use it for advertising; and we do not allow humans to read it except with your explicit consent for specific data, for security purposes, to comply with applicable law, or where the information is aggregated and de-identified.

Staff and support access

Praxis follows an operating policy of no routine staff access to another teacher's student records, and support access is now a product control you hold: Praxis asks naming one stated reason, nothing is readable until your organization's owner approves the request in their portal, an approval ends by itself after 72 hours or the moment the owner revokes it, and every read performed under it is written to a log the owner can open. Praxis's policy is that support access to your records happens only through that mechanism.

The owner-operator can still technically reach production systems when necessary to operate, secure, restore, or erase the service, as every hosted provider can. That remains a disclosed limitation, not a claim that access is technically impossible — but where this section once promised discipline alone, the approval, the expiry, and the log are now yours. The separate Platform Operations console displays student records only under a live grant approved this way.

Security

We use encrypted transit and provider-managed encryption at rest, hashed credentials, secure HTTP-only session cookies, time-limited sessions, per-organization and per-capability access controls, append-only audit events, rate limiting, and the server-enforced per-organization release gate described above. No system is guaranteed secure, and we describe our controls honestly rather than claim certifications we do not hold.

Where we hold a credential to another service on your behalf — today only a calendar connection a teacher chose to make — we protect it beyond the storage encryption above. We encrypt it separately with a key kept outside the database that we can rotate without interrupting the service, we exclude it by design from logs, exports, error messages, and our own interfaces, and we destroy it outright rather than mark it deleted when a teacher disconnects, when their access to the organization ends, or when the organization is deleted. We record that a credential was destroyed; we never record its value.

Retention and deletion

We keep information only while it is needed for its purpose, agreement, security, or a legal obligation. Sessions and sign-in links expire automatically. Two different things are called deletion here and we keep them apart: ordinary deletion in the product closes access immediately and keeps governed history, so a teacher's past decision can still be explained; erasure is a separate, documented procedure that physically removes records. Erasure cannot be performed as a single action: it requires a preview of exactly which records would be removed, a distinct approval step against that preview, and a permanent record of who did each part. See "Review status" below for who performs those steps today. The periods below are erasure periods.

How long we keep the main categories:

Where Texas Education Code §32.156 applies, a district-directed deletion is completed no later than 60 days after the request unless the agreement sets a shorter period, which it may. Evaluation and staging environments may still be reset as the product evolves; activated production workspaces are not treated as disposable.

Access, correction, and deletion requests

To access, correct, or delete your information, email taylor@backwerdrimshot.com. When we hold education records for a school, requests should normally go through that school so it can verify authority and direct us; for a private studio, requests go to the studio's teacher or to us directly. Deletion requests are honored except where a record must be retained for security or legal reasons, and we will tell you if that applies. We will not use a rights request as a reason to collect unnecessary identity documents.

A deletion request is an email. You do not need an account, a login, a portal, or a support ticket, and you do not need your organization's agreement with us to still be in effect. If your school or studio has stopped using Praxis Percussion and you want the records gone, email the address above and we will erase them within the period stated above. We mention this because losing access to a system is a common reason people never manage to get their data deleted from it.

Review status

This statement is maintained directly by the owner-operator and has not yet had independent legal review. Records for private studios and independent teaching practices are teacher-maintained, and since Version 11 they may concern students of any age. Since Version 12, a private studio's owner activates real records themselves by completing the recorded attestation-and-acceptance step, and enables under-13 records by separately accepting the Under-13 Records Addendum; Praxis no longer reviews each studio's activation individually, which is a risk posture the operator has recorded and accepted. The transition remains one-way and audited. Schools and districts remain a separate path with their own requirements and their own review.

The same is true of erasure, and we would rather say so than let the word "approval" imply more than it currently means. The erasure procedure requires a preview, a separate approval against that preview, and an execution step, and the system refuses to let one account perform two of them. Today all three steps are performed by the owner-operator using separate accounts, so the approval is a check against mistakes and a permanent record of what was done — it is not an independent second person reviewing the decision.

Version 9 of this statement said a genuinely independent reviewer would be in place before any organization other than our own was activated for real records. That is not what happened. One was activated on August 13, 2026, and the arrangement described above — one person holding two accounts — has governed erasure since. We are correcting that sentence here rather than deleting it, because a reader who relied on it should be able to see that it was wrong and for how long. An independent reviewer is still the intended end state. We are not pinning it to another milestone until something other than our own memory is holding it there.

Meanwhile the 60-day period above is a commitment we can and do meet; the word "approval" simply describes a control, not an outside opinion. If you are ever asked, in a contract or a questionnaire, whether deletions at Praxis require independent approval, the honest answer today is no.

Changes

If this statement changes, the new version will be posted here with a new version number and effective date. Material changes involving student information, purposes, disclosure, or retention follow the applicable agreement and a notice process before taking effect.