Even with a class connection, the framing sentence from your self-service data page still holds word for word: "Your practice, pieces and profiles live only on your device — we don't have them." A class doesn't change that — it only adds one voluntary, very narrow daily summary.
Gets
- Practice days — whether anything at all was practised that day
- Scores & levels — the day's best score per exercise/piece, rounded
- up to 3 sticking points — only as an axis + bar number (e.g. "Rhythm, bar 12")
Never
- your sheet music, MusicXML or own pieces
- recordings or a microphone signal
- an exercise or piece title as its own field — only a technical identifier
- your email address — lives, if linked at all, in a separate encrypted silo
Enforced technically, at most once an hour
The daily sync summary's data format allows exclusively the three fields above — any extra field is strictly rejected. With no event on a given day (neither played nor listened to acoustically), simply nothing is sent for that day, and the push itself is throttled to at most once an hour.
A technical identifier is not a title
The server never stores a piece's real title — only an anonymous identifier. For a piece your child imported themselves, that identifier stays meaningless to the school forever — the file itself lives only in the child device's own browser storage and never leaves it.
The device secret, only as a hash
The secret a device uses to identify itself to the server stays in plain text exclusively on that device — the server only ever knows a password hash (argon2id) of it, never the plain text. This access data also travels inside the full backup — hence its literal warning line: "The file also contains your access data (e.g. class connection) — keep it safe."
Email: separate, encrypted, voluntary
A linked email address serves only profile recovery, your optional weekly review and the optional weekly parent update — it lives in its own encrypted silo and never reaches the school.
The two opt-in emails in detail
Weekly review and parent update work independently of each other: you switch each one on or off separately, both arrive at most once a week, and every single email carries an unsubscribe link. Your device puts the content together locally before it's sent — the server never stores a single practice note in the process.
A family connection shares the same narrow summary
A family connection uses exactly the same daily summary as a class — the receives/never list above holds word for word for a family device too. The only difference is WHO follows along: a parent's device instead of a teacher. Here too, nothing is assigned, only read along.
For parents
Without tapping "Allow connection", technically nothing is sent at all — the consent gate is the only place in the code that can ever trigger the first sync. Declining costs no functionality: your child keeps practising just as fully without a class.
Your data:
Word for word in settings (Data & Privacy): "Pieces, plans, results, sounds — everything lives on this device. There's no account and no server that can read your music — if you use device sync, only an encrypted container for your own devices lives there." The class connection is a deliberate exception, limited to exactly the narrow content listed here.
