Version: 2026-09-17
Effective date: 2026-09-17
Applies to: Drumza web (drumza.app / staging) and the iOS app com.drumza.app (builds that use Sign in with Apple or Google)
Product draft — not counsel-certified. Not a claim of GDPR certification. A fuller privacy/GDPR program remains on the firm backlog.
This version updates
2026-09-16: signed-in users can Delete Account in-app on iOS and web (removes account and cloud-synced notepads). Contactsupport@drumza.appremains for help and edge cases.
Contact: support@drumza.app
Drumza is a drum notation product. On web and iOS, when you are signed in, your notepads can sync across devices and platforms through our cloud service under your account (staging and production environments as configured for that build).
Web and iOS (com.drumza.app): Sign in with Apple and Sign in with Google.
| Category | Examples | Why |
|---|---|---|
| Account / auth | Email (if the provider shares it); Apple/Google identifiers; auth session tokens | Sign-in, account security |
| Profile | User id, role, created time | Account record |
| Terms acceptance | User id, terms version id, accepted-at timestamp | Record that you accepted Terms before using the service; re-prompt when version bumps |
| Your content | Notepad titles/descriptions, measures, patterns, dynamics, sharing email lists | Provide editor + sync/share across devices |
| Technical | Standard host logs (IP, timestamps, request metadata); essential/session cookies for auth | Operate, secure, debug |
| Category | Examples | Why |
|---|---|---|
| Account / auth | Email (if the provider shares it); Apple/Google user identifiers; session tokens on device | Sign-in, stay signed in |
| Avatar | Optional provider profile image URL, or a locally generated icon | Profile button UI |
| Your content (synced) | Notepad titles, measures, patterns, dynamics stored in our cloud service under your user id | Cross-device sync iOS ↔ web |
| On-device copies | Local cache / on-device copies of your charts | Offline use and performance |
We do not sell your personal data.
Payments: No paid features, in-app purchases, or card processing at this version.
Analytics / crash: No product analytics or telemetry SDK is enabled in the web app today. iOS does not add a separate product-analytics or crash-reporting SDK for this release. Our hosting and cloud providers may still collect standard operational logs.
We use third-party providers to help run the Service. At a high level, these include:
We do not describe vendor wiring or implementation details here. Provider lists may change as we operate the Service.
We use essential / session cookies and similar storage needed to keep you signed in and run the web app. We do not use advertising cookies. You can block cookies in your browser; some sign-in features may then stop working.
If you add someone’s email to a notepad’s share list on web, that person may read the shared notepad. You control those lists.
We may also disclose information if required by law, to protect safety or enforce our Terms, or in connection with a merger, acquisition, or asset transfer (in which case we will take reasonable steps so the recipient honors this Policy).
We keep account data, synced notepad data, and web Terms acceptance records while your account is active (or as needed to show prior acceptance). On-device copies remain until you delete them or uninstall (device OS rules apply).
If you are signed in, you can Delete Account in the iOS app (profile avatar menu) and on the web app. That permanently deletes your account and cloud-synced notepads (and related account records such as Terms acceptance). Sign-out alone does not delete your account. Local-only pads that were never synced may remain on a device until you remove them. For help or edge cases, contact support@drumza.app — we handle requests in good faith.
We rely on industry-standard protections from our providers (including encrypted transport and access controls). No method of transmission or storage is 100% secure.
Drumza’s App Store age rating is 4+. The Service may be used by children with a parent or guardian’s guidance. Parents and guardians should review this Policy. We do not sell children’s personal information. If you believe we have collected a child’s information inappropriately, contact us and we will delete it in good faith. This section is not a claim of COPPA certification or any other children’s-privacy certification.
Data may be processed in regions where our providers operate.
Depending on where you live, you may have rights to access, correct, or delete personal data. While signed in, you can Delete Account in-app on iOS and web to remove your account and cloud-synced data. You can also Sign out anytime (sign-out does not delete your account). Contact support@drumza.app for help. This policy does not claim full GDPR certification. We do not sell personal information (including under CCPA “sale” as we understand it); California residents may contact us for requests.
We may update this Policy with a new version id. Material changes that affect the web Terms accept gate will be paired with a Terms version bump when required.
support@drumza.app (inbox wiring may follow; this is the public contact address).