1Who we are
Piano Class is the app for iPhone and Android and the website at pianoclass.app, operated by [Tên đơn vị vận hành] ("we"). Contact address: [address, if published]. Email: hotro@pianoclass.app.
2Who this policy covers
- Teachers: adults who sign in with a Google or Apple account, create classes and manage their own students.
- Students: usually children. A student account is created by a parent or a teacher; the child only types a PIN to play. Each student belongs to exactly one teacher, and that teacher is the first person a parent talks to about the child's data.
- Visitors of the website: the public pages set no cookies and run no analytics.
3What we store
The table lists exactly what the system keeps, and nothing more.
| About whom | Data | Where from |
|---|---|---|
| Teacher | Name and email from Google or Apple, the identifier the sign-in provider issues (never a password), the chosen note-name style, the current plan and the order history (plan, term, amount, transfer memo, the bank reference we type in when reconciling). | Sign-in, settings, buying a plan |
| Class | Class name, description, colour, class logo (if uploaded), join code. | Created by the teacher |
| Student | Username, display name, a short note (for example "Grade 3"), an avatar if the teacher set one, waiting or approved status. The PIN is stored only as a one-way hash; we cannot read it. | Created by a parent or the teacher |
| Attempts | The assigned exercise, every answer, right or wrong, the time taken per note, the score, when it started and ended, the number of attempts. | The student playing |
| The teacher's content | Questions, tests, uploaded illustrations. | Written by the teacher |
| Session | A session token (random, stored hashed) so the device does not sign in again every time the app opens. | The app |
| Safety log | For every sign-in or join request: the IP address, the time, success or failure. Used to lock after 5 wrong PINs. The server log records only the path, the status code and the duration, never what was sent. | The server |
4What we do not collect
- No advertising, no advertising identifiers.
- No third-party analytics or crash-reporting kit.
- No location, contacts, microphone or photo library (a picture is sent only when a teacher picks one as a class logo or as a question illustration).
- No tracking across other apps or sites.
- No email, phone number or date of birth of a student.
5What we use the data for
- Running the class: signing in, showing exercises to students, showing results to the teacher.
- Counting the seats of a plan and handling payment.
- Keeping the service safe: limiting PIN attempts, rate limiting, spotting abuse.
- Answering when you contact support.
We do not profile behaviour, do not sell data and do not use it for marketing.
6Who the data is shared with
- Google and Apple, only when a teacher signs in. They confirm the teacher's identity and send us a name, an email and an identifier. Their side is governed by their own policies.
- The hosting provider: [provider name] in [country]. Data lives on a server we administer ourselves.
- The backup storage: [storage provider name]. Backups are encrypted before they leave the server.
[Keep this paragraph if the server is outside Vietnam:] The server is outside Vietnam, which means personal data is transferred abroad for storage and processing. We follow the procedures of Decree 13/2023/NĐ-CP for this transfer.
Beyond those three, nobody else receives the data unless the law requires it.
7Children
- A student account is created by a parent or a teacher, after a class code from the teacher. A child cannot sign up alone.
- We do not ask a child for a real name, an email, a phone number or a date of birth. The display name is chosen by the parent and may be a nickname.
- The teacher of the class sees the child's results. Nobody else does.
- A parent can ask the teacher to correct or delete the child's account, delete it in the app, or write to us. If you believe an account was created without a parent's consent, tell us and it is removed.
8How long we keep it
| Data | Retention |
|---|---|
| Accounts, classes, attempts, content | Until the account is deleted. Deletion removes the rows at once; there is no "trash". |
| Backups | 14 days. A deleted record can survive in a backup for up to 14 days and is never restored on its own. |
| Sessions | Expire after 60 days without use; signing out revokes them at once. |
| Safety log (IP, PIN attempts) | 30 days. |
| Server log | 14 days. |
| Paid orders | For the period accounting law requires, even after the account is deleted. |
9Your rights
Under Decree 13/2023/NĐ-CP on personal data protection you have the right to know, access, correct, delete, withdraw consent and receive a copy of your data. For a child's data, a parent exercises these rights on the child's behalf.
- Access and correction: a student's display name, note and avatar are edited by the teacher; a teacher edits their own name and settings in the app.
- Deletion: in the app, open Settings and choose Delete account. See how to delete an account.
- A copy of your data and other requests: email us from the email you sign in with (teachers) or through the teacher of the class (students). We answer within 30 days.
10Security
- Every connection is encrypted (HTTPS).
- PINs are hashed with scrypt; session tokens are hashed before they are stored.
- Each teacher's data is isolated at the database level: one teacher cannot read another's data even on purpose.
- A 15-minute lock after 5 wrong PINs; rate limits per address.
- Nightly encrypted backups, kept off the server.
No system is perfectly safe. If an incident affects your data, we notify the teachers concerned by email within 72 hours of confirming it.
11Changes to this policy
When the policy changes we update the date at the top and, for a significant change, notify teachers in the app before it takes effect.
12Contact
Any question about data goes to hotro@pianoclass.app. [If there is a data protection officer, put their name and contact here.]