LAST UPDATED 27 SEPTEMBER 2026

Privacy

The short version: we ask for an email address so your work can follow you between your devices, there is no advertising tracker anywhere, the app has no analytics in it at all, and deleting your account really does delete it.

WHO THIS IS

Super Simple Drum: this site, and the iPhone and iPad app of the same name. One person runs it, and that person reads the mail.

WHAT WE ASK FOR

An email address, and only when you choose to sign in. Nothing else about you is required, and both the app and the site work signed out.

If you sign in with Google or Apple on this site instead, that provider hands us the email address on the account, along with the name and picture it carries.

We never ask for your real name, your age, your location, your contacts, your photos or your microphone, and the app requests none of those permissions.

WHAT WE KEEP BECAUSE YOU MADE IT

The songs you star. The bars and fills you save or import. Which exercises you have finished and your best tempo on each. How many minutes you practised on a given day, and at what tempo. A few room settings: the click, the count-in, which chart you read, which view of the kit you like.

That is the whole of it. It exists so your work survives a new phone, and so a streak can be counted.

SIGN-IN CODES AND DEVICES

The mailed code and the token your phone keeps are stored as hashes, never as themselves, so reading our database does not hand anybody a login.

A code dies after fifteen minutes. A device keeps a long-lived token so you are not signing in every week; with it we store the label the device reports for itself, such as "iPhone", and when it was last seen, which is what lets you look at your own devices and revoke one.

WHAT STAYS ON YOUR DEVICE

The app keeps your library, your settings and your sign-in token on the device itself, the token in the keychain. Signed out, none of it leaves the phone.

The unlock purchase is checked with Apple on the device. No receipt and no purchase identifier is sent to us.

PAYMENTS

We never see a card, on either platform.

In the app, a purchase is Apple’s, made on Apple’s terms, and what we learn is whether this Apple ID owns the unlock.

On this site, checkout is Stripe’s. We keep what Stripe tells us about whether a purchase succeeded, and a Stripe customer id so a second purchase is easier.

ANALYTICS, AND WHERE THERE IS NONE

This site uses Google Analytics 4: which pages get opened, roughly where from, what kind of device. It sets cookies. It is how a page that nobody can find gets noticed.

The app carries no analytics SDK at all. No Firebase, no crash reporter, no advertising identifier, nothing that phones a third party while you play.

Nothing is sold, and nothing is handed to an advertising network. There is no advertising on either platform.

A SONG’S RECORD

When a song has a record, it plays from YouTube, so Google’s player loads with the page on this site, and inside a hidden player in the app. Google may set its own cookies and collect its own data there, under its own policy, exactly as it would on any page carrying a YouTube video.

The backing band, which is the song without the drums, is our own audio served from our own storage.

WHO ELSE TOUCHES IT

Amazon Web Services: the hosting, the database, and the audio files. Amazon SES: the one email that carries your sign-in code. Google: Analytics on this site, and the YouTube player. Stripe: purchases made on this site. Apple: purchases made in the app.

That is the list. Each of them gets only what its job needs, and none of them gets it to build a profile of you.

TRANSACTIONAL MAIL ONLY

We send a sign-in code when you ask for one, and a receipt with a way back in when you buy something. There is no newsletter, no campaign and no reminder, so there is nothing to unsubscribe from.

HOW LONG WE KEEP IT

Sign-in codes: fifteen minutes. A device token until it expires or you revoke it.

Everything else until you delete your account, at which point it goes with the account: the favourites, the bars you made, the progress, the practice log, the settings and the devices. That is a cascade in the database, not a promise in a document.

Our host keeps ordinary web request logs for a short period as part of running a server. We do not mine them and we do not join them to an account.

CHILDREN

This is not aimed at children under thirteen and we do not knowingly keep anything belonging to one. If a child has signed in, write to us from the address they used and it will be removed.

HOW TO DELETE ALL OF IT

In the app: the account room, then DELETE ACCOUNT at the foot of it. It asks once, then removes the account and everything on it, from every device.

Or write to us from the address you signed in with and we will do it for you. Either way it cannot be undone.

IF THIS PAGE CHANGES

The date at the top moves, and the sentence that stopped being true is rewritten rather than softened. We do not keep a copy of the old wording, so if a change matters to you, the time to read it is when the date moves.

ANY QUESTION ABOUT THIS
hello@supersimpledrum.com

Getting help with the app itself is the support page.