PE Point Pro — Privacy Policy
Effective date: June 10, 2026
Publisher: Charles Ross (sole proprietor, dba PE Point Pro)
Contact: cross@pe-point-pro.com
Patent Pending. The PE Point Pro system and its underlying methods are the subject of a pending United States patent application. All rights reserved.
1. Summary for school technology departments
PE Point Pro is a single-teacher classroom management tool for physical education. The app runs on a teacher's personal or district-issued iPad or iPhone. It is designed to be used by the teacher, not by students.
- FERPA: The teacher and the school remain the controllers of all student records. PE Point Pro acts only as a "school official" tool under the FERPA school-official exception (34 CFR § 99.31(a)(1)) when used with school-provided rosters.
- COPPA: The app is intended for use by adult educators. We do not knowingly collect personal information directly from children under 13. When a teacher enters student information on behalf of the school, that collection is authorized by the school under COPPA's school-authorization framework (FTC COPPA FAQ Section M).
- Storage: All student data lives on the teacher's device using the operating system's app storage (AsyncStorage / Secure Store). PE Point Pro does not operate a backend database that holds student records.
- Selling data: We never sell, rent, or share student data with advertisers. There are no advertising SDKs in the app.
2. Who this policy applies to
This policy covers the PE Point Pro mobile application, the marketing website at pe-point-pro.com, and any related communications with Charles Ross. Throughout this document, "we," "us," and "our" refer to Charles Ross, the sole publisher of PE Point Pro.
"Teacher" means the adult educator who installs and uses the app. "Student" means a child or young adult whose information the teacher enters into the app on behalf of the school.
3. Information we collect
3.1 Information the teacher enters about students
The teacher may enter the following per student, on the teacher's device:
- First and last name
- Class period or section assignment
- Daily Rubric Points and Community Points
- Mile-run times and fitness-test results
- Attendance status (absent, tardy, excused)
- Bathroom and locker-room sign-out timestamps
- Free-text notes the teacher writes about the student
- Tournament, challenge, and skill-tracking results
- Optional roster identifiers from the teacher's LMS (Schoology, Canvas, or Google Classroom enrollment IDs) used solely to match grade pushes
Students do not log in to the app and do not interact with it directly. Photos, videos, audio recordings, biometric data, and precise location are not collected.
3.2 Information about the teacher
- The teacher's email address, only when they sign in with Google
- OAuth access and refresh tokens issued by Google, Schoology, or Canvas, stored encrypted on the device using Expo Secure Store
- Teacher-configured preferences (bell schedule, point reasons, color choices)
3.3 Information collected automatically
The PE Point Pro app does not include analytics, advertising, or third-party tracking SDKs. The marketing website does not set advertising cookies. Apple TestFlight and the App Store may collect standard install and crash diagnostics under their own privacy policies; we receive only aggregated, non-identifying summaries from Apple.
4. Where and how data is stored
Student records, point logs, mile times, notes, and tournament data are stored only on the teacher's device using AsyncStorage, the iOS application's sandboxed local storage. These records are not transmitted to any server operated by us.
Sensitive credentials (OAuth tokens, LMS API keys) are stored using Expo Secure Store, which uses the iOS Keychain. The Keychain is encrypted at rest by iOS and protected by the device passcode or biometric lock.
We operate a thin proxy server that forwards requests from the app to Canvas, Google Classroom, Google Calendar, and Google Sheets. The proxy exists to perform OAuth handshakes and to mitigate SSRF risk. The proxy does not store request bodies, student records, grades, or tokens; logs are limited to short-lived operational metadata (HTTP status codes and timestamps) and are automatically rotated within 7 days.
5. Learning management system integrations
When a teacher chooses to connect a learning management system, the app uses the teacher's own credentials to access only the courses the teacher already teaches. The teacher initiates every action.
- Schoology (OAuth 1.0a): Reads section rosters that the teacher selects. Writes grades and comments only to assignments the teacher selects. The teacher's Schoology consumer key and secret are stored encrypted on the device.
- Canvas LMS (OAuth 2.0): Reads course rosters; writes grades to selected assignments. API calls are proxied through our server only to enforce the teacher's chosen Canvas domain and prevent server-side request forgery.
- Google Classroom (OAuth 2.0): Reads course rosters; writes grades to selected coursework.
Grade sync is initiated manually by the teacher. The app does not upload student records to us as part of grade sync; data flows from the teacher's device, through our proxy where required, directly to the school-provisioned LMS.
6. Google Sign-In, Calendar, and Sheets
When a teacher signs in with Google, we receive their email address and an OAuth token. The teacher chooses which Google features to use, and the app accesses only what each feature needs:
- Google Calendar (read only). If the teacher enables calendar sync, we read upcoming events from the teacher's calendar to display them on the dashboard. We never create, change, or delete calendar events.
- Google Sheets (read and write). If the teacher uses the District Fitness Sheet feature, the app writes fitness-test scores into one specific Google Sheet the teacher selects. It reads that sheet's existing student names and test-column headings so it can place each score in the matching cell. It only fills cells that already exist — it never adds rows, columns, or tabs — and it does not touch any other spreadsheet in the teacher's account.
- Google Drive (per-file access only). The app uses Google's narrow per-file Drive permission so it can open only the specific sheet the teacher selects. It cannot list, read, or access any other files in the teacher's Google Drive.
The teacher initiates every Google action, and access can be revoked at any time from the teacher's Google Account permissions page. Google Classroom access is described separately in Section 5. We do not access any Google services beyond those described in this policy.
PE Point Pro's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
7. FERPA compliance
The Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g; 34 CFR Part 99) protects the privacy of student education records. PE Point Pro is designed to operate within FERPA's framework as follows:
- School official designation. When a teacher uses PE Point Pro to manage class records on behalf of a school, PE Point Pro functions as a tool used by a school official with a legitimate educational interest, consistent with the FERPA school-official exception at 34 CFR § 99.31(a)(1).
- Direct control by the school. The teacher and the school remain in direct control of all education records entered into the app. Records are stored on the teacher's device, not on our servers.
- No re-disclosure. We do not redisclose personally identifiable information from education records to any third party except when (a) the teacher initiates a grade push back to the school's own LMS, (b) the teacher initiates a sync of fitness scores to a Google Sheet the teacher selects, or (c) we are legally compelled to do so. We do not use student records for any purpose other than providing the service.
- Data minimization. The app collects only the data fields the teacher needs to manage class: names, points, attendance, fitness data, and notes.
- Data Privacy Agreements. We are willing to sign reasonable Student Data Privacy Agreements (including the National DPA standard contract) at the school or district's request. Email cross@pe-point-pro.com.
8. COPPA and children under 13
The Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501–6506; 16 CFR Part 312) imposes additional requirements when an operator collects personal information online from children under 13. PE Point Pro is structured to meet these requirements as follows:
- No direct collection from children. Students do not download, log into, or interact with the PE Point Pro app. The app is intended for adult educators only. Information about a student is entered by the teacher on the teacher's device.
- School-authorized collection. Where a teacher enters limited personal information about students under 13 (such as name and class section) for the school's educational purpose, that collection is authorized by the school acting in loco parentis, consistent with the Federal Trade Commission's COPPA FAQ guidance for ed-tech (Section M, "COPPA and Schools"). The school's authorization substitutes for individual parental consent for the limited educational purposes for which the school has engaged the operator.
- Use limited to the school's purpose. We use student information only to provide the classroom management service the teacher requested. We do not use student information for advertising, profiling, building user profiles for non-educational purposes, or any commercial purpose unrelated to providing the service.
- No behavioral advertising. The app contains no advertising SDKs and does not engage in targeted advertising to children or adults.
- Heightened handling for under-13 data. All student records — including those of children under 13 — are kept on the teacher's device, encrypted at rest by iOS, and never transmitted to our servers as part of normal app use. Free-text notes, attendance flags, and bathroom logs are treated as sensitive and are subject to the same on-device-only storage rule.
- Parental review and deletion. Because we do not hold student records, a parent or guardian seeking to review or delete their child's data should contact the child's teacher or school. The teacher can delete a student's record from the app at any time using the Students screen, which removes all associated points, notes, attendance entries, and tournament history from the device. School administrators or parents may also contact us at cross@pe-point-pro.com and we will assist the school in fulfilling the request.
9. Data sharing and third parties
We do not sell student or teacher data. We share information only as follows:
- With the school's own LMS when the teacher initiates grade sync (Schoology, Canvas, or Google Classroom).
- With Google, when the teacher initiates a Google action: reading calendar events to show on the dashboard, or writing fitness scores into a Google Sheet the teacher selects. This data is sent directly to Google's APIs on the teacher's behalf and is governed by Google's own terms.
- With infrastructure providers that operate the proxy server (currently Replit Deployments). These providers process traffic on our behalf and are bound by their own security and confidentiality terms; they do not have access to stored student records because no records are stored on the proxy.
- When required by law, such as a valid subpoena or court order.
10. Data retention and deletion
Because student data lives on the teacher's device, deletion is immediate and complete when:
- The teacher removes a student from the Students screen.
- The teacher uses Settings → Reset All Data to wipe everything.
- The teacher uninstalls the app from the device.
Encrypted OAuth tokens are removed when the teacher signs out of the corresponding LMS or revokes access in their LMS account. Operational proxy logs (status codes and timestamps only) rotate automatically within 7 days.
11. Security
We use industry-standard safeguards appropriate to the sensitivity of the data:
- iOS sandboxed app storage encrypted at rest by the operating system
- Secrets stored in the iOS Keychain via Expo Secure Store
- TLS 1.2 or higher for all network traffic, including LMS proxying
- OAuth flows with PKCE where supported by the provider
- No collection of payment information; the app is distributed free through Apple TestFlight and the App Store
No system can be guaranteed perfectly secure. If a security incident affects student data we maintain or transmit, we will notify affected schools without unreasonable delay and assist in any required notifications under applicable state student-data-privacy laws.
12. Parent, student, and school rights
Parents, eligible students, and school officials have the right to:
- Inspect and review student records held in the app (via the teacher).
- Request correction of inaccurate records (via the teacher).
- Request deletion of records (via the teacher or by contacting us).
- Receive a copy of any Student Data Privacy Agreement we have signed with their school.
Because we operate as a tool for the school under FERPA, requests from parents are most efficiently handled through the child's teacher or school administrator, who has direct control of the records.
13. Changes to this policy
If we make material changes to this policy, we will update the "Effective date" at the top of this page and post a notice on the marketing website. For changes that affect how student data is handled, we will notify schools that have signed a Data Privacy Agreement with us by email before the change takes effect.
14. How to contact us
For privacy questions, Data Privacy Agreement requests, parent or school inquiries, or to report a concern:
Charles Ross
PE Point Pro
Email: cross@pe-point-pro.com
We respond to school and parent privacy inquiries within 5 business days.
PE Point Pro and the underlying methods described on this site are the subject of a pending United States patent application. "PE Point Pro" is an unregistered trademark of Charles Ross.
PE Point Pro
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.