Praxis Percussion

Privacy statement

Version 9 · Effective August 13, 2026 · Backwerd Rimshot, LLC · taylor@backwerdrimshot.com
Version 9 accurately discloses the present operator-access limitation and the controlled 13-and-older founding-teacher activation path. It replaces Version 8 of August 11, 2026.
Version 8 added the limited public-site analytics disclosure below.
Version 7 replaced Version 6 of August 6, 2026, which described no billing at all while the service stored lesson rates, invoices, recorded payments, and a paying adult's contact details — and told a reader in the same breath that we hold no financial information. Both are corrected below; nothing about what the software does changed.
Version 6 replaced Version 5 of the same date, which said without qualification that we do not put a student's name in a calendar; that is now true of schools and districts, and a private teacher's own calendar shows the names they entered. Replaces the beta privacy notice of July 29, 2026.

Praxis Percussion is operated by Backwerd Rimshot, LLC. This statement describes, plainly and completely, what the service collects and why. The separate, free Backwerd Rhythm Shop apps are account-free and store progress locally in your browser unless you deliberately use a clearly identified hosted mode.

Check the workspace label. Every organization workspace is labeled. A workspace marked fictional-records-only — the default for every organization — accepts fictional example records ONLY: do not enter real student names, identifiers, or records there, including in free-text fields.

Real student records exist only by recorded decision. An organization may hold real student records only after a deliberate, recorded, audited activation decision by its authorizing party. Its workspace is then labeled "Real student records." The server enforces this boundary per organization; no setting or button turns it on.

Children under 13

Praxis Percussion does not knowingly hold records about children under 13. An organization may be activated for real records only while it attests that the records it keeps here are about students 13 or older. A teacher whose studio also serves younger students keeps those students' records out of Praxis Percussion entirely. Records about a child under 13 will not be accepted until a verifiable parental-consent path exists and is approved; if we learn such a record was entered without that path, we will delete it through our documented erasure procedure.

What we collect from adults

Student records in an activated workspace

An organization activated for real records holds only what a teacher enters and the service derives from it: a learner name or label, an internal identifier, class or program membership, coursework attempts and evidence, teacher verification and retention events, lesson scheduling and teaching records the teacher maintains, and limited equipment-custody history.

We do not ask for and do not need: student email addresses, school-issued IDs, birth dates, student contact details, the student's own home address, precise location, health or disability information, discipline records, a student's or family's financial circumstances — household income, fee assistance, or free-and-reduced-price meal status — photos, audio, video, biometric data, advertising identifiers, or social-media data. In a private-studio workspace, students do not sign in and receive no accounts or credentials.

One item on that list needs a plain qualification rather than a flat denial, because a flat denial would be wrong. A private studio's teacher may bill for lessons, and where they do we hold what "Studio billing" above describes: rates, invoice amounts, recorded payments, and the paying adult's name, email, and optional address note. That adult is usually the student's parent, so in practice we may hold a household's contact details even though we hold none for the student. What we do not hold, for anybody, is a payment instrument. We would rather say this here than let a reader infer from the words "financial information" that a studio's invoices do not exist.

How we use it

To operate your account and workspace, deliver sign-in links and invitations you request, create the records and exports your organization authorizes, respond when you contact us, and keep the service secure. That is the whole list. We do not sell personal information, show ads, share information for marketing, build unrelated commercial profiles, or train general-purpose AI models on covered records.

Who else touches the data

Praxis Percussion runs on Cloudflare (hosting, database, security challenges, and email delivery), primarily in the United States. Cloudflare processes data on our behalf under its customer data protection agreement. We monitor Cloudflare's published list of sub-processors for changes.

Other service providers can receive limited information only to provide the feature you choose: Google LLC receives limited technical and page-visit information through Google Analytics on the public pages described above; Google LLC or Microsoft Corporation receives calendar information only when a teacher in your organization deliberately connects a Studio calendar; and Stripe, Inc. processes Praxis Tech membership billing when you choose to provide a payment method. Praxis does not store Tech membership card details. Google Analytics does not receive learner records, workspace content, or URL query strings from Praxis. Apart from those, no third party receives your information, except when disclosure is legally required or necessary to protect the service and its users.

Calendar connections you choose

This section describes Studio calendar connections, not Praxis Tech. A teacher can connect a Google or Microsoft calendar so their lesson schedule appears alongside the rest of their week. This is off until they connect it, it is per teacher and per organization, and nothing reaches either company before that. When it is connected, Google LLC or Microsoft Corporation receives what we write. Praxis Tech does not currently offer an internal calendar, Google/Outlook calendar connections, or other external calendar integrations.

What we write is a lesson time, how long it lasts, and who the lesson is with. We never write notes, observations, assignments, evidence, reports, or amounts.

Who the lesson is with depends on the kind of organization, and the difference is deliberate:

We ask each provider for the narrowest permission it offers — access limited to a calendar our application creates — so we can neither read nor change anything already in that teacher's own calendar. We create a separate calendar and write only there.

We are deliberate about this because a calendar entry, once written, leaves our reach: our deletion and erasure procedures cannot remove it, and sharing that calendar copies it further. That is exactly why no student name goes into one. A teacher can disconnect at any time from their schedule screen, without contacting us; disconnecting destroys the stored connection credential immediately and asks the provider to revoke it.

Praxis Percussion's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use that information only to provide the calendar feature you asked for; we do not transfer it except as necessary to provide that feature, to comply with applicable law, or in a merger or acquisition with the notice and consent required; we do not use it for advertising; and we do not allow humans to read it except with your explicit consent for specific data, for security purposes, to comply with applicable law, or where the information is aggregated and de-identified.

Staff and support access today

Praxis follows an operating policy of no routine staff access to another teacher's student records. Today that policy depends on operator discipline. There is not yet a product control that requires the organization's approval, limits support access to a stated purpose and expiration, or separately logs each support-access session.

The owner-operator can technically reach production systems when necessary to operate, secure, restore, or erase the service. This is a disclosed limitation, not a claim that routine access is technically impossible. The separate Platform Operations console does not display student records; a future delegated support-access workflow will require its own reviewed decision and implementation.

Security

We use encrypted transit and provider-managed encryption at rest, hashed credentials, secure HTTP-only session cookies, time-limited sessions, per-organization and per-capability access controls, append-only audit events, rate limiting, and the server-enforced per-organization release gate described above. No system is guaranteed secure, and we describe our controls honestly rather than claim certifications we do not hold.

Where we hold a credential to another service on your behalf — today only a calendar connection a teacher chose to make — we protect it beyond the storage encryption above. We encrypt it separately with a key kept outside the database that we can rotate without interrupting the service, we exclude it by design from logs, exports, error messages, and our own interfaces, and we destroy it outright rather than mark it deleted when a teacher disconnects, when their access to the organization ends, or when the organization is deleted. We record that a credential was destroyed; we never record its value.

Retention and deletion

We keep information only while it is needed for its purpose, agreement, security, or a legal obligation. Sessions and sign-in links expire automatically. Two different things are called deletion here and we keep them apart: ordinary deletion in the product closes access immediately and keeps governed history, so a teacher's past decision can still be explained; erasure is a separate, documented procedure that physically removes records. Erasure cannot be performed as a single action: it requires a preview of exactly which records would be removed, a distinct approval step against that preview, and a permanent record of who did each part. See "Review status" below for who performs those steps today. The periods below are erasure periods.

How long we keep the main categories:

Where Texas Education Code §32.156 applies, a district-directed deletion is completed no later than 60 days after the request unless the agreement sets a shorter period, which it may. Evaluation and staging environments may still be reset as the product evolves; activated production workspaces are not treated as disposable.

Access, correction, and deletion requests

To access, correct, or delete your information, email taylor@backwerdrimshot.com. When we hold education records for a school, requests should normally go through that school so it can verify authority and direct us; for a private studio, requests go to the studio's teacher or to us directly. Deletion requests are honored except where a record must be retained for security or legal reasons, and we will tell you if that applies. We will not use a rights request as a reason to collect unnecessary identity documents.

A deletion request is an email. You do not need an account, a login, a portal, or a support ticket, and you do not need your organization's agreement with us to still be in effect. If your school or studio has stopped using Praxis Percussion and you want the records gone, email the address above and we will erase them within the period stated above. We mention this because losing access to a system is a common reason people never manage to get their data deleted from it.

Review status

This statement is maintained directly by the owner-operator and has not yet had independent legal review. The owner first proceeded for the owner's own studio, then recorded a narrow decision permitting two named, non-operator founding-teacher studios to seek individual activation for teacher-maintained records about students age 13 or older. Each still requires a written pilot agreement, an accepted organization-specific decision, and the reviewed one-way activation procedure. This is not a general public activation rule.

Schools, districts, learner accounts, and all records about children under 13 remain outside that decision. The approved under-13 product direction is direct guardian notice and authorization through a future guardian-consent workflow; no under-13 record is accepted until that workflow, its notice and verification method, and the applicable legal review are complete.

The same is true of erasure, and we would rather say so than let the word "approval" imply more than it currently means. The erasure procedure requires a preview, a separate approval against that preview, and an execution step, and the system refuses to let one account perform two of them. Today all three steps are performed by the owner-operator using separate accounts, so the approval is a check against mistakes and a permanent record of what was done — it is not an independent second person reviewing the decision. A genuinely independent reviewer arrives at the same point independent legal review does: before any school or third-party organization is activated. Until then, the 60-day period above is a commitment we can and do meet; the word "approval" simply describes a control, not an outside opinion.

Changes

If this statement changes, the new version will be posted here with a new version number and effective date. Material changes involving student information, purposes, disclosure, or retention follow the applicable agreement and a notice process before taking effect.