The short version: we ask for an email address so your work can follow you between your devices, there is no advertising tracker anywhere, the app has no analytics in it at all, and deleting your account really does delete it.
Super Simple Drum: this site, and the iPhone and iPad app of the same name. One person runs it, and that person reads the mail.
An email address, and only when you choose to sign in. Nothing else about you is required, and both the app and the site work signed out.
If you sign in with Google or Apple on this site instead, that provider hands us the email address on the account, along with the name and picture it carries.
We never ask for your real name, your age, your location, your contacts, your photos or your microphone, and the app requests none of those permissions.
The songs you star. The bars and fills you save or import. Which exercises you have finished and your best tempo on each. How many minutes you practised on a given day, and at what tempo. A few room settings: the click, the count-in, which chart you read, which view of the kit you like.
That is the whole of it. It exists so your work survives a new phone, and so a streak can be counted.
The mailed code and the token your phone keeps are stored as hashes, never as themselves, so reading our database does not hand anybody a login.
A code dies after fifteen minutes. A device keeps a long-lived token so you are not signing in every week; with it we store the label the device reports for itself, such as "iPhone", and when it was last seen, which is what lets you look at your own devices and revoke one.
The app keeps your library, your settings and your sign-in token on the device itself, the token in the keychain. Signed out, none of it leaves the phone.
The unlock purchase is checked with Apple on the device. No receipt and no purchase identifier is sent to us.
We never see a card, on either platform.
In the app, a purchase is Apple’s, made on Apple’s terms, and what we learn is whether this Apple ID owns the unlock.
On this site, checkout is Stripe’s. We keep what Stripe tells us about whether a purchase succeeded, and a Stripe customer id so a second purchase is easier.
This site uses Google Analytics 4: which pages get opened, roughly where from, what kind of device. It sets cookies. It is how a page that nobody can find gets noticed.
The app carries no analytics SDK at all. No Firebase, no crash reporter, no advertising identifier, nothing that phones a third party while you play.
Nothing is sold, and nothing is handed to an advertising network. There is no advertising on either platform.
When a song has a record, it plays from YouTube, so Google’s player loads with the page on this site, and inside a hidden player in the app. Google may set its own cookies and collect its own data there, under its own policy, exactly as it would on any page carrying a YouTube video.
The backing band, which is the song without the drums, is our own audio served from our own storage.
Amazon Web Services: the hosting, the database, and the audio files. Amazon SES: the one email that carries your sign-in code. Google: Analytics on this site, and the YouTube player. Stripe: purchases made on this site. Apple: purchases made in the app.
That is the list. Each of them gets only what its job needs, and none of them gets it to build a profile of you.
We send a sign-in code when you ask for one, and a receipt with a way back in when you buy something. There is no newsletter, no campaign and no reminder, so there is nothing to unsubscribe from.
Sign-in codes: fifteen minutes. A device token until it expires or you revoke it.
Everything else until you delete your account, at which point it goes with the account: the favourites, the bars you made, the progress, the practice log, the settings and the devices. That is a cascade in the database, not a promise in a document.
Our host keeps ordinary web request logs for a short period as part of running a server. We do not mine them and we do not join them to an account.
This is not aimed at children under thirteen and we do not knowingly keep anything belonging to one. If a child has signed in, write to us from the address they used and it will be removed.
In the app: the account room, then DELETE ACCOUNT at the foot of it. It asks once, then removes the account and everything on it, from every device.
Or write to us from the address you signed in with and we will do it for you. Either way it cannot be undone.
The date at the top moves, and the sentence that stopped being true is rewritten rather than softened. We do not keep a copy of the old wording, so if a change matters to you, the time to read it is when the date moves.
Getting help with the app itself is the support page.