Last updated: September 10, 2026 · Operated by: PracticeXP LLC, a Wisconsin limited liability company
PracticeXP is practice-tracking software used by K–12 school music programs. This policy explains what we collect, why, who it goes to, and how long we keep it. A school district signing with us also receives a full Data Privacy Agreement, a COPPA notice, and a data retention policy; those documents control where they are more specific than this page.
Our customer is the school, not the student and not the parent. A school purchases a license for its music program. Students use the service because their school directed them to. Students and parents never pay us and never enter payment details.
| Category | What it is |
|---|---|
| Account | Name, school-issued email address, grade level, primary instrument or voice part, role (student or director) |
| Practice logs | Practice duration, date, and — only if the student chooses to write one — a free-text practice note |
| AI responses | The coaching response generated for a practice note, stored with that entry |
| Director feedback | Notes a director writes about a practice entry |
| Goals | Practice-minute targets set by the director or the student |
| Roster | Student name, school email, grade, instrument or voice part, and optionally a parent/guardian email address supplied by the director |
| Technical | The IP address a practice entry was submitted from, to prevent abuse |
| Billing | The school's billing contact and payment details — handled by Stripe, never containing student data |
We do not collect grades, discipline records, health information, biometrics, government identifiers, precise location, or photos and video.
This marketing site — the pages at practicexp.com — uses
Cloudflare Web Analytics to count
page views. It sets no cookies, does not fingerprint your browser, stores no
personal data, does not follow you to other sites, and cannot identify you. We use it to see
which pages directors read before getting in touch. That is why this site has no cookie
banner: there is nothing to consent to.
The application at app.practicexp.com carries no analytics at all.
Everyone signed in there is a K-12 student or their teacher, and we are not willing to hand a
third party a record of what children do inside the service. This is enforced in our build,
not just intended: a check fails the release if any tracking code reaches the app.
We operate as a school official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)), performing a service the school would otherwise perform itself. Schools retain ownership and control of their education records.
Where they apply, we adhere to SOPIPA-type statutes (including the California Student Online Personal Information Protection Act) and to New York Education Law § 2-d with 8 NYCRR Part 121, and will execute a district's own rider on request.
We are a Wisconsin company and most of our schools are here. Wisconsin has no separate student-online-privacy statute; for a Wisconsin district the governing law is Wis. Stat. § 118.125 on pupil records, together with FERPA. We treat practice records as pupil records under that section and do not re-disclose them except as it and FERPA allow.
Music programs include students under 13. Student accounts are created within a school's program at the school's direction, and we rely on the school-consent mechanism recognized by FTC guidance: the school may consent on parents' behalf for a school-authorised educational purpose, and not for any commercial purpose independent of it. Parents receive a direct notice describing what is collected and how it is used, including the AI features below.
| Provider | Purpose | What they receive |
|---|---|---|
| Google Cloud / Firebase | Hosting, authentication, database | All data above, to operate the service (United States) |
| Google Gemini API | AI features (see below) | Varies by feature; two features receive student-written text |
| Stripe | Subscription payments | The school's billing contact and payment details. No student data. |
Each is contractually restricted to using the data only to provide their service to us.
Some features generate a response by sending information to Google's Gemini API. Two of them send text a student wrote. We think that deserves to be stated precisely rather than summarized:
| Feature | Model | What is sent | Written by |
|---|---|---|---|
| AI practice coach | gemini-3.1-flash-lite | The practice note text, plus instrument and grade level | The student |
| AI Music Librarian | gemini-3-flash-preview | The question the student types | The student |
| Scale coach | gemini-3.1-flash-lite | A scale name and instrument name | Selected from a list |
| Lesson plan generator | gemini-3-flash-preview | Grade, instruments, and the director's own goals text | The director |
| Instrument care tips | gemini-3-flash-preview | An instrument name only | Selected from a list |
We do not direct Google to use this content for advertising or to train its publicly available models on identifiable student content, and our use is governed by Google's terms for API customers rather than its consumer terms. AI output can be wrong; students and directors should treat it as a suggestion, not authoritative instruction.
The librarian answers questions about music and instruments, and refuses anything else. Every question a student submits is stored, along with which account asked it and whether it was refused, and the director at that school can read it. Questions are kept for 90 days and then deleted.
We record them because the alternative is worse: a school would be sending its students' typed questions to an AI service with no record of what was asked and no way for anyone at the school to check. Only a teacher at that school can read the log — students cannot, and no account can write to or delete from it. A director who would rather the feature not run at all can switch it off from their dashboard, and that refusal is enforced on our server.
Every feature above starts switched off, and your school decides whether to turn any of them on. When a school is set up, no AI feature is active and nothing is sent to Google at all. A director can enable a feature from the Teacher Dashboard without asking us, and switch it back off the same way; both take effect immediately for everyone at the school. Whenever a feature is off, our server refuses the request, so nothing is sent to Google for it.
The two features that send something a student wrote — the practice coach and the music librarian — need a second step. The director must also say which classes may use them, so a school can allow the librarian for its high school ensemble and not for its fifth graders. A feature that has been enabled but has no class named against it stays off for everyone.
Before that text is sent, we automatically strip the identifiers most likely to appear by accident: email addresses, web links, phone numbers, long runs of digits, and the student's own name. This is not anonymization and we do not claim it is — the writing still reaches Google as something written by an identified student at an identified school, and a child can describe themselves in ways no automatic filter catches. It reduces accidental disclosure. That is all it does.
Turning a feature off does not delete AI responses already saved against past practice entries; email us and we'll purge those. Everything else in PracticeXP — practice logging, the timer, goals, streaks, fingering charts, practice resources, reports, and the monthly parent summaries — works exactly the same with AI off entirely, which is how it is delivered. See Security for more.
If a director has a parent's email address on the class roster, that parent may receive a monthly summary of their own child's practice — total time, sessions, days practiced, and how that compared to the goal the director set. It never includes the text of a student's practice notes, and it never ranks children against each other.
The school chooses how it is sent. By default the director sends it themselves and we transmit nothing. A director can instead switch on an automatic monthly send, in which case we send it on their behalf: the message carries their name, replies go to their school address, and every message has a one-click unsubscribe that needs no account and is permanent. We send parents nothing else, and we never email students.
Weekly director report. Each director can receive a weekly email listing their own students' names and practice totals for the week. It goes only to the director's school-issued address, never includes practice-note text, and the director can switch it off in the app.
Student practice reminders. Off unless a school's director turns them on. When on, a student who has logged nothing for seven days gets one short reminder at their school-issued address. It contains the student's first name and no practice data, and every message has a one-click unsubscribe that needs no account and is honoured permanently. We send nothing else to students.
The built-in tuner and metronome ask for the device microphone so the tuner can hear the note being played. Audio is analysed on the device in real time. No sound is recorded, stored, or sent anywhere, by us or by any service provider.
| Data | Retention |
|---|---|
| While a student is active in the program | Kept, so progress carries across the year |
| After a student leaves or graduates | No more than 90 days |
| After a school's contract ends | No more than 30 days, to allow export |
| Server logs and submission IP addresses | No more than 60 days |
| Backups | Overwritten on a rolling 35-day cycle |
Because backups are point-in-time snapshots, deleted data can persist in a backup for up to that window before it is fully gone. Earlier deletion is available on request at any time.
Parents and eligible students may request to access, correct, export, or delete their data. Because the school controls its education records, we handle these requests through the school — contact your director first, as they can correct names, grades, instruments, and practice entries directly. For anything they can't resolve, write to us at the address below and we will coordinate with the school.
Directors can export their program's full data at any time from the dashboard; you do not need to ask us for routine access.
Data is stored in the United States on Google Cloud infrastructure. Each school's data is isolated by a tenant identifier and enforced server-side, so one school cannot read another's. Access to student data is limited to those with a legitimate need to operate the service.
If we change this policy materially — including adding a service provider or changing which AI model receives student writing — we will update this page and notify schools under contract in advance, as their Data Privacy Agreement requires.
support@practicexp.com
PracticeXP · 421 N Elizabeth Ave, Apt 1, Jefferson, WI 53549 · United States