Effective Date: September 1, 2026
Last Updated: September 9, 2026
This Privacy Policy describes how Viddi Labs LLC, doing business as Practice Pulse ("Provider," "we," "us," or "our"), collects, uses, discloses, and protects information when schools, teachers, and students use the Practice Pulse educational software platform (the "Platform").
Provider Information
Viddi Labs LLC, doing business as Practice Pulse
13740 N Highway 183, Ste L2 #588
Austin, TX 78750
Email: help@joinpracticepulse.com
Students, parents, or guardians who wish to request deletion of a student's Practice Pulse account or associated Student Data should submit the request to the applicable School. Provider will process authorized deletion requests in accordance with the School's instructions, the applicable School Agreement, and applicable law.
Teachers, administrators, or other non-student users may contact help@joinpracticepulse.com regarding deletion of their own account information.
Practice Pulse is a school-directed educational technology service designed for use by K–12 schools, districts, teachers, and students pursuant to a written agreement with a school or district (each, a "School"). The Platform is not offered directly to the general public and is not intended for independent consumer use.
If a School has entered into a School Agreement or other written agreement with Provider that includes data privacy and data protection terms (a "Data Privacy Agreement" or "DPA"), that agreement governs the processing of Student Data and supersedes this Privacy Policy in the event of any conflict.
This Privacy Policy is provided solely for transparency and informational purposes. It does not create independent contractual obligations, third-party beneficiary rights, or direct consumer rights enforceable against Provider by students, parents, or guardians. All enforceable data protection obligations are governed exclusively by the applicable Terms of Service, School Agreement, Data Privacy Agreement, or other written agreement between Provider and the School.
"Student Data" means information that is directly related to an identifiable student and is maintained by Provider on behalf of a School, including information that constitutes "education records" under the Family Educational Rights and Privacy Act ("FERPA").
"User Content" means content submitted to the Platform by users, including videos, reflections, text responses, practice submissions, and other educational materials.
"Personal Information" means information treated as personal information, personal data, or a similar protected category under applicable privacy law.
"School" includes a school district, charter school, or other educational authority that has entered into a written agreement with Provider authorizing educational use of the Platform.
"School Agreement" means the Practice Pulse Pilot Program Agreement or Subscription Agreement between Provider and a School, including the Data Privacy Agreement terms contained in it.
For avoidance of doubt, "Student Data" as used in this Privacy Policy has the same meaning as "Student Data" as used in any applicable School Agreement or DPA.
On behalf of Schools, Provider may process Student Data including, but not limited to:
Provider collects and processes Student Data solely at the direction of and on behalf of the applicable School. Provider does not determine the purposes or means of processing Student Data except as necessary to provide and support the Platform in accordance with School instructions.
Where a student or teacher signs in with an email address and password, the password is transmitted directly to Firebase Authentication, which stores it as a salted cryptographic hash. Provider does not store, retain, or have access to user passwords. Where sign-in is through Google or Apple, no password is transmitted to Provider at any point.
Provider collects only the minimum technical identifiers necessary for Platform functionality. Provider provides the following information regarding the technical identifiers collected in connection with the Platform.
Identifiers We DO Collect:
Provider uses Google Analytics for Firebase to collect aggregate, pseudonymous information about how the Platform is used. This is used to operate and improve the educational service. It is not used for advertising, cross-application tracking, or profiling of individual students.
What is collected: counts and timing of product events — sign-in and account-creation outcomes, practice sessions saved (including session duration, instrument, and whether written reflections were added), practice sessions shared or removed, video submissions to assignments (including recording duration), and app open and engagement events generated automatically by the analytics service. Each event records the application version.
How it is grouped: analytics data is segmented only by user role (student, teacher, or administrator) and by school identifier. Neither identifies an individual person.
What is excluded, and how:
Persistent identifier. The analytics service assigns each app installation an instance identifier. This identifier is reset when a user signs out, so that usage on a shared school device does not accumulate against a single continuous identity. On a device where a user remains signed in, the identifier persists for that installation. It is not linked to a student's name or account and is not used to track a student across other applications or services.
Provider uses Firebase Crashlytics to detect and diagnose application failures. When the app crashes or encounters an error, the service records the device model and operating system version, the application version, the state of the application at the time of the failure, and a crash-reporting installation identifier. No student name, email address, or account identifier is attached to crash reports. Crash reports are used solely to identify and fix defects, and are retained for 90 days.
Identifiers We Do NOT Collect:
Purpose and Use:
All technical identifiers are collected and used solely for the educational purposes stated in this Privacy Policy. Provider does not use technical identifiers for advertising, marketing, cross-app tracking, or any non-educational commercial purpose. Provider has configured Firebase and all third-party services to disable advertising identifier collection, advertising personalization, and cross-application tracking. Analytics collection is limited to the aggregate operational data described above.
Data Minimization:
Provider applies the Student Data protections described in this Privacy Policy and the applicable School Agreement to these technical identifiers where they are associated with School-authorized student use.
Provider may collect information provided by teachers or School administrators, including:
Provider does not intentionally collect:
Provider processes Student Data exclusively on behalf of Schools and strictly for the school-authorized educational purposes stated below, and not for any independent commercial, consumer, or marketing purpose:
Provider does not:
To the extent Provider receives education records pursuant to FERPA's school-official exception, Provider acts as a school official with a legitimate educational interest and remains under the School's direct control with respect to the use and maintenance of those records.
For students under thirteen (13), Provider may rely on School authorization only to the extent permitted by COPPA for School-authorized educational use. The applicable School is responsible for providing any notices and obtaining any parental consent required of the School by applicable law or policy.
Provider does not independently verify parental consent and relies on the applicable School's authorization and representations regarding its authority to authorize student use.
Provider processes Student Data in accordance with the following laws to the extent applicable to Provider, the Platform, and the particular School relationship:
Provider may disclose information:
Subprocessors. Provider's current subprocessors are:
| Subprocessor | Role |
|---|---|
| Google Cloud Platform / Firebase | Authentication, database, file storage, backend functions, push notifications |
| Google Analytics for Firebase | Aggregate product analytics |
| Firebase Crashlytics | Crash and error reporting |
| Mailjet | Transactional email delivery for safeguarding notifications |
| Stripe | Payment processing where a School pays by card; receives billing contact and payment information, not Student Data |
Except as disclosed in this Privacy Policy or the applicable School Agreement, or as required or permitted by law, Provider does not disclose Student Data to third parties for their own commercial purposes.
Provider does not disclose Student Data in response to individual student or parent requests except as expressly authorized by the applicable School or required by law.
Provider maintains a Written Information Security Plan describing the administrative, technical, and physical safeguards protecting information against unauthorized access, disclosure, alteration, or misuse. It is available to Schools on request.
Security practices may evolve as the Platform develops. No method of transmission or storage is completely secure, and Provider does not guarantee absolute security.
Provider will notify the applicable School without undue delay following Provider's confirmation of unauthorized access to or acquisition of Student Data maintained on behalf of that School, in accordance with the notification provisions of the applicable School Agreement. This School-notification framework does not limit any separate reporting or notification obligation imposed by applicable law.
Provider has no obligation to notify individual students or parents directly except as required by applicable law.
Provider retains information only as long as reasonably necessary for the purpose for which it was collected. Provider does not retain Student Data indefinitely.
Student video and audio submissions are deleted at the conclusion of each school year — on July 31 annually — or within thirty days of the end of the School's agreement, whichever comes first.
The schedule below states, for each category, why the information is collected, the business need for retaining it, and the timeframe within which it is deleted.
| Category | Why collected | Business need for retention | Deletion |
|---|---|---|---|
| Video and audio submissions | Teacher review and feedback | Instructional reference within the school year in which the work was submitted | Deleted annually on July 31, covering all submissions from that school year, or within 30 days of the end of the agreement, whichever comes first |
| Practice and account records | Progress tracking; authentication and roster membership | Required for the duration of the School relationship | 30 days after account deletion or agreement end |
| Teacher feedback and assessments | Instructional record | Retained alongside the submission it relates to, for instructional reference within the school year. | Deleted annually on July 31 with the submissions they relate to, or within 30 days of the end of the agreement, whichever comes first |
| Technical logs | Security monitoring, abuse detection, support | Incident investigation requires recent history | 12 months |
| Crash and error reports | Diagnosing failures affecting students and teachers | Recurring crashes need history across occurrences to identify a pattern | 90 days |
| Product analytics data | Operating and improving the service | Comparison across equivalent points in successive school years | 14 months |
| Backups | Disaster recovery | Rolling recovery window | 90 days after deletion from active systems |
| Audit logs — administrative actions, membership decisions, data exports | Accountability record for access to and decisions about Student Data | Evidence for School inquiries, regulatory response, and incident investigation | 3 years |
| Security incident records | Legal and regulatory defense | Statutory limitation and regulatory response periods | 7 years |
| Safeguarding report records (report, notifications sent, actions taken, and outcome) | Recording that a student safety report was received and routed | Demonstrating the report was handled appropriately, and responding to School or regulatory inquiry | For the period reasonably necessary to document the report and its disposition, subject to applicable law, School instruction, and any legal hold. |
| Safeguarding report media (video + audio) | Preserving evidence for the School's safeguarding assessment | Retained while the matter is open so evidence remains available to the School and, where applicable, to law enforcement | Preserved while the matter remains open and deleted after the School confirms the matter is closed, subject to applicable law, School instruction, and any legal hold. |
Deletion on request or termination. Upon written request from a School, or upon termination of the applicable agreement, active Student Data is deleted within thirty (30) days and backup systems are purged within ninety (90) days. Deletion of a student removes the student's account record, all associated video and audio submissions, and derived data such as aggregate progress statistics.
Legal holds. Records subject to a legal hold, or which Provider is required to retain by law, are retained for the required period and deleted promptly thereafter. Provider will inform the affected School where a legal hold prevents deletion within the timeframes above.
Provider does not pre-screen or actively monitor User Content. The Platform may make available reporting and moderation tools to assist School oversight; however, Provider does not assume responsibility for monitoring or enforcing content standards.
Schools remain solely responsible for supervision, discipline, and enforcement of acceptable use policies.
Requests by students, parents, or guardians to access, correct, or delete Student Data must be directed to the applicable School. Provider responds to such requests only as instructed or authorized by the School and does not independently verify or fulfill individual rights requests.
Practice Pulse is intended solely for use in School-authorized educational contexts. Parents or guardians with questions regarding data practices should contact their School directly. Provider does not have a direct relationship with parents or guardians and provides the Platform solely pursuant to School authorization.
Provider may update this Privacy Policy from time to time. Material changes will be communicated to Schools as required by applicable agreements or law.
Questions regarding this Privacy Policy may be directed to:
Viddi Labs LLC, doing business as Practice Pulse
13740 N Highway 183, Ste L2 #588
Austin, TX 78750
Email: help@joinpracticepulse.com