Privacy statement
Praxis Percussion is operated by Backwerd Rimshot, LLC. This statement describes, plainly and completely, what the service collects and why. The separate, free Backwerd Rhythm Shop apps are account-free and store progress locally in your browser unless you deliberately use a clearly identified hosted mode.
Check the workspace label. Every organization workspace is labeled. A workspace marked fictional-records-only — the default for every organization — accepts fictional example records ONLY: do not enter real student names, identifiers, or records there, including in free-text fields.
Real student records exist only by recorded decision. A private studio's own authorized owner activates real records by completing a deliberate, recorded step — attesting to their authority and accepting the published activation disclosure — and that acceptance is stored with the exact document versions it covered. The transition is one-way and audited, the workspace is then labeled "Real student records," and the server enforces the boundary per organization. Schools and districts cannot self-activate; their path remains separately reviewed.
Children under 13
Praxis Percussion may hold records about children under 13 when a private studio or independent teaching practice keeps them. Those records are entered by the adult teacher who teaches the child — about their own student, for their own teaching and administration. Scheduling a lesson, invoicing the responsible adult, and noting what to practise are the reasons they exist. Activation alone covers students 13 or older; records about younger students require the studio to separately accept the published Under-13 Records Addendum, and until it has, younger students' records stay out of Praxis Percussion entirely — enforced in the database, not only stated here.
The child has no Praxis Percussion account. They cannot sign in, and they submit nothing to us directly. That is enforced in the software, not only stated here: student sign-in and access codes are refused for these organizations, in every mode.
The teacher enters and maintains these records, including the student's name. The lessons are a service the teacher provides to the family, under their own agreement with that family, and we act on the teacher's instructions. What the teacher promises us about having the family's permission is set out in the Terms, not here. We do not advertise to anyone, we do not sell these records, and we do not train general-purpose AI on them.
A parent or guardian may ask what we hold about their child, ask for it to be corrected, or ask for it to be deleted, by writing to taylor@backwerdrimshot.com. We will act on that request whether or not their child's teacher still subscribes.
A teacher may also invite a parent or guardian into a record directly, and we keep that available. It is not a requirement for keeping a record, and we do not present it as one.
We have not received a fact-specific legal opinion clearing this arrangement under children's privacy law. It follows the published practice of comparable studio-management services. We do not claim to go further than they do on this point, and this statement will be corrected if that assessment changes.
What we collect from adults
- Account information: your name and email address, used to sign you in with single-use email links and to operate your account.
- Director access requests: the information you submit on the request form — your name, email, role, organization name and type, location, site descriptions, grade bands, estimated student count, under-13 status, and intended use.
- Workspace content you create: organizations, sites, class names, paths, invitations to other adults, and library, inventory, and repertoire records. In a fictional-records-only workspace this content must not include real student information.
- Studio lesson invoicing, if a teacher keeps it: lesson rates,
invoices and their lines, payments the teacher records as received (an
amount, a date, and a free-text method such as "check 1042"), and a billing
contact for a student's lessons — the paying adult's name, email address,
and an optional note used as an address line. In a private studio that
paying adult is usually a parent, who may have no account here and may never
visit the site.
The Studio lesson-invoicing feature never accepts or processes a payment instrument. There is no card handling, no stored card or bank detail, no payout, and no platform fee in that feature; a request carrying a card number, a CVV, an account or routing number, or a payment-processor token is refused outright rather than quietly dropped. Billing records are erased with the student's records, including the billing contact. - Praxis subscription billing: when an adult chooses to buy Praxis Percussion Studio or Praxis Tech through Checkout, Praxis sends Stripe the adult account email, an internal organization reference, and the selected plan. Praxis stores Stripe customer and subscription identifiers, the price reference, subscription status and period timestamps, and a minimized record of billing-provider events and reconciliation. Checkout is hosted by Stripe: the card or bank credential is entered directly with Stripe, and the Praxis application or server does not receive or store that credential. Stripe also collects the billing address used for tax and payment processing.
- Operational records: essential session cookies, security and audit logs, and short-lived infrastructure logs (such as IP addresses and request metadata) used to keep the service working and secure.
- Praxis Tech Workspace records: adult operational information an independent technician enters for a service relationship: client organizations, adult client contacts, service offerings and availability, booking requests, confirmed services, private notes, selected adult recap recipients, and invoice-record status. Praxis Tech is not for student-private information. A public Tech profile is optional and shows only the provider information, services, and availability the provider chooses to publish; client organizations, private notes, invoice records, and unpublished recaps are not public. A recap is shared only when the provider deliberately publishes it to a selected adult recipient. Praxis Tech provides no general client account or portal; an authorized adult director a provider explicitly invites may hold access to the Tech Director Portal, limited to the records and actions we explicitly enable there, and that invitation and its acceptance are recorded against the client contact they concern.
- Public-site analytics: on a limited set of public marketing and sign-up pages, we use Google Analytics to understand aggregate traffic, referral sources, and which public pages lead to a sign-up. The tag is not loaded on learner pages, authenticated workspaces, or operational tools. It records the page path without its query string and is configured not to store an Analytics cookie in your browser. We do not use it for advertising, cross-site targeting, or to identify a person.
Student records in an activated workspace
An organization activated for real records holds only what a teacher enters and the service derives from it: a learner name or label, an internal identifier, class or program membership, coursework attempts and evidence, teacher verification and retention events, lesson scheduling and teaching records the teacher maintains, and limited equipment-custody history.
We do not ask for and do not need: student email addresses, school-issued IDs, birth dates, student contact details, the student's own home address, precise location, health or disability information, discipline records, a student's or family's financial circumstances — household income, fee assistance, or free-and-reduced-price meal status — photos, audio, video, biometric data, advertising identifiers, or social-media data. In a private-studio workspace, students do not sign in and receive no accounts or credentials.
One item on that list needs a plain qualification rather than a flat denial, because a flat denial would be wrong. A private studio's teacher may bill for lessons, and where they do we hold what "Studio billing" above describes: rates, invoice amounts, recorded payments, and the paying adult's name, email, and optional address note. That adult is usually the student's parent, so in practice we may hold a household's contact details even though we hold none for the student. The Praxis application does not receive or store the payment credential an adult enters in Stripe-hosted Checkout to buy a Studio or Tech subscription; Stripe does. We would rather say this here than let a reader infer from the words "financial information" that a studio's invoices or Praxis subscription billing do not exist.
How we use it
To operate your account and workspace, deliver sign-in links and invitations you request, create the records and exports your organization authorizes, administer a Praxis subscription you choose through Stripe Checkout, respond when you contact us, and keep the service secure. That is the whole list. We do not sell personal information, show ads, share information for marketing, build unrelated commercial profiles, or train general-purpose AI models on covered records.
One use belongs on that list by name rather than tucked inside "create the records your organization authorizes". Praxis Tech can draft a service note or a client recap for the adult contractor whose work it describes, using an AI model run by Cloudflare — already our host, so no new company receives anything. Every draft is private until a person edits it and chooses to use it; nothing is sent, published, or shared from one on its own. It runs on a contractor's own record of their own work. It is not available anywhere student records live, and it is never given one. The sentence above still holds exactly as written: we do not train general-purpose AI models on covered records, and drafting is not training.
Who else touches the data
Praxis Percussion runs on Cloudflare (hosting, database, and security challenges), primarily in the United States. Cloudflare processes data on our behalf under its customer data protection agreement. We monitor Cloudflare's published list of sub-processors for changes.
Other service providers can receive limited information only to provide the feature you choose: Google LLC receives limited technical and page-visit information through Google Analytics on the public pages described above; Google LLC or Microsoft Corporation receives calendar information only when a teacher in your organization deliberately connects a Studio calendar; and Stripe, Inc. processes Praxis Percussion Studio and Praxis Tech subscription billing when you choose Checkout, including the account email, internal organization reference, plan, billing address, and payment credential used for that purchase; and Resend, Inc. delivers the email we send you — sign-in links, invitations, and notices — which means it receives the address the message goes to and what the message says. The Praxis application and server do not receive or store Studio or Tech subscription card or bank credentials; Stripe does. Google Analytics does not receive learner records, workspace content, or URL query strings from Praxis. Apart from those, no third party receives your information, except when disclosure is legally required or necessary to protect the service and its users.
Versions 6 through 9 of this statement attributed email delivery to Cloudflare and did not name Resend at all. Cloudflare's own routing is still there as a fallback, but the mail that reaches a real person goes through Resend, and Version 9 made this worse rather than better: it replaced a vague sentence with the closed list above, which was more precise and still missing a company. It is named here now.
Calendar connections you choose
This section describes Studio calendar connections, not Praxis Tech. A teacher can connect a Google or Microsoft calendar so their lesson schedule appears alongside the rest of their week. This is off until they connect it, it is per teacher and per organization, and nothing reaches either company before that. When it is connected, Google LLC or Microsoft Corporation receives what we write. Praxis Tech does not currently offer an internal calendar, Google/Outlook calendar connections, or other external calendar integrations.
What we write is a lesson time, how long it lasts, and who the lesson is with. We never write notes, observations, assignments, evidence, reports, or amounts.
Who the lesson is with depends on the kind of organization, and the difference is deliberate:
- A school or district. The event carries no student name and no student label at all — just a time. Praxis asks the provider to delete linked events when the student record is closed, but a shared or copied event can outlive that request. An institution should not put student names into a third-party calendar when the safer event works without them.
- A private studio or independent teacher. The event carries the student's name as the teacher entered it. This is a teacher's own calendar, in their own account, about students they already teach and whose names they already write on a lesson sheet — and a calendar full of codes is one they cannot read. While the connection remains active, Praxis asks the provider to delete linked events when the student record is closed or the lesson is marked as entered in error. Provider failures are kept for a later sync to retry.
- A workspace using fictional example records. The event carries the example label. Nothing real is disclosed.
We ask each provider for the narrowest permission it offers. Google limits
Praxis to secondary calendars Praxis creates. Microsoft does not offer an
equivalent app-created-calendar permission: its delegated
Calendars.ReadWrite grant allows access to the signed-in user's
calendars. Praxis's software narrows that broader grant by creating a separate
Praxis calendar and reading, changing, and deleting events only there; it does
not read or change events in the teacher's other calendars.
The retraction applies to the linked event in the separate calendar Praxis created, while the connection remains active. A provider response that the event is already gone completes the retraction; another provider failure leaves the link in place for the next sync to retry. It is not a guarantee of immediate provider action, and it cannot reach an event copied, exported, or shared outside that calendar. A teacher can disconnect at any time from their schedule screen, without contacting us. Praxis first attempts to delete the dedicated calendar and its events, then always destroys the stored connection credential. For Google, Praxis also asks Google to revoke the grant. Microsoft access can be removed from the teacher's Microsoft account settings. A provider outage or expired permission can leave the dedicated calendar behind; once the credential is destroyed, Praxis can no longer retract it or its events. That residual limit is why a school or district calendar receives no student name or label even though Praxis now retracts linked events while the connection remains active.
Praxis Percussion's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use that information only to provide the calendar feature you asked for; we do not transfer it except as necessary to provide that feature, to comply with applicable law, or in a merger or acquisition with the notice and consent required; we do not use it for advertising; and we do not allow humans to read it except with your explicit consent for specific data, for security purposes, to comply with applicable law, or where the information is aggregated and de-identified.
Staff and support access
Praxis follows an operating policy of no routine staff access to another teacher's student records, and support access is now a product control you hold: Praxis asks naming one stated reason, nothing is readable until your organization's owner approves the request in their portal, an approval ends by itself after 72 hours or the moment the owner revokes it, and every read performed under it is written to a log the owner can open. Praxis's policy is that support access to your records happens only through that mechanism.
The owner-operator can still technically reach production systems when necessary to operate, secure, restore, or erase the service, as every hosted provider can. That remains a disclosed limitation, not a claim that access is technically impossible — but where this section once promised discipline alone, the approval, the expiry, and the log are now yours. The separate Platform Operations console displays student records only under a live grant approved this way.
Security
We use encrypted transit and provider-managed encryption at rest, hashed credentials, secure HTTP-only session cookies, time-limited sessions, per-organization and per-capability access controls, append-only audit events, rate limiting, and the server-enforced per-organization release gate described above. No system is guaranteed secure, and we describe our controls honestly rather than claim certifications we do not hold.
Where we hold a credential to another service on your behalf — today only a calendar connection a teacher chose to make — we protect it beyond the storage encryption above. We encrypt it separately with a key kept outside the database that we can rotate without interrupting the service, we exclude it by design from logs, exports, error messages, and our own interfaces, and we destroy it outright rather than mark it deleted when a teacher disconnects, when their access to the organization ends, or when the organization is deleted. We record that a credential was destroyed; we never record its value.
Retention and deletion
We keep information only while it is needed for its purpose, agreement, security, or a legal obligation. Sessions and sign-in links expire automatically. Two different things are called deletion here and we keep them apart: ordinary deletion in the product closes access immediately and keeps governed history, so a teacher's past decision can still be explained; erasure is a separate, documented procedure that physically removes records. Erasure cannot be performed as a single action: it requires a preview of exactly which records would be removed, a distinct approval step against that preview, and a permanent record of who did each part. See "Review status" below for who performs those steps today. The periods below are erasure periods.
How long we keep the main categories:
- Student records — coursework, evidence, and teacher decisions. Kept for as long as the organization's agreement with us lasts. When that agreement ends, or when the teaching relationship ends, or on request — whichever comes first — we erase them within 60 days. If the organization asks for an export first, we provide it before erasing.
- Audit and security records. Kept for 13 months from the date of the event, so that a full school year plus the summer can be reconstructed if something is disputed or investigated. These records are how we can tell you what happened to an account, so we do not delete them when an individual record is erased — instead we remove the identifying information from them at that point, and the record itself expires on the 13-month clock.
- Backups. Our hosting provider keeps recovery copies on a rolling schedule that we do not control and cannot edit individually. Erased information stays in those copies until the cycle expires, and then it is gone. We state the current window in our data-processing agreements rather than here, so that a change of hosting plan does not silently make this page wrong. We would rather describe backup expiry accurately than claim immediate deletion from recovery media.
Where Texas Education Code §32.156 applies, a district-directed deletion is completed no later than 60 days after the request unless the agreement sets a shorter period, which it may. Evaluation and staging environments may still be reset as the product evolves; activated production workspaces are not treated as disposable.
Access, correction, and deletion requests
To access, correct, or delete your information, email taylor@backwerdrimshot.com. When we hold education records for a school, requests should normally go through that school so it can verify authority and direct us; for a private studio, requests go to the studio's teacher or to us directly. Deletion requests are honored except where a record must be retained for security or legal reasons, and we will tell you if that applies. We will not use a rights request as a reason to collect unnecessary identity documents.
A deletion request is an email. You do not need an account, a login, a portal, or a support ticket, and you do not need your organization's agreement with us to still be in effect. If your school or studio has stopped using Praxis Percussion and you want the records gone, email the address above and we will erase them within the period stated above. We mention this because losing access to a system is a common reason people never manage to get their data deleted from it.
Review status
This statement is maintained directly by the owner-operator and has not yet had independent legal review. Records for private studios and independent teaching practices are teacher-maintained, and since Version 11 they may concern students of any age. Since Version 12, a private studio's owner activates real records themselves by completing the recorded attestation-and-acceptance step, and enables under-13 records by separately accepting the Under-13 Records Addendum; Praxis no longer reviews each studio's activation individually, which is a risk posture the operator has recorded and accepted. The transition remains one-way and audited. Schools and districts remain a separate path with their own requirements and their own review.
The same is true of erasure, and we would rather say so than let the word "approval" imply more than it currently means. The erasure procedure requires a preview, a separate approval against that preview, and an execution step, and the system refuses to let one account perform two of them. Today all three steps are performed by the owner-operator using separate accounts, so the approval is a check against mistakes and a permanent record of what was done — it is not an independent second person reviewing the decision.
Version 9 of this statement said a genuinely independent reviewer would be in place before any organization other than our own was activated for real records. That is not what happened. One was activated on August 13, 2026, and the arrangement described above — one person holding two accounts — has governed erasure since. We are correcting that sentence here rather than deleting it, because a reader who relied on it should be able to see that it was wrong and for how long. An independent reviewer is still the intended end state. We are not pinning it to another milestone until something other than our own memory is holding it there.
Meanwhile the 60-day period above is a commitment we can and do meet; the word "approval" simply describes a control, not an outside opinion. If you are ever asked, in a contract or a questionnaire, whether deletions at Praxis require independent approval, the honest answer today is no.
Changes
If this statement changes, the new version will be posted here with a new version number and effective date. Material changes involving student information, purposes, disclosure, or retention follow the applicable agreement and a notice process before taking effect.