Privacy Policy

Last updated July 30, 2026

Metronome.Rocks (“we,” “the app”) is a single-purchase metronome. There is no user account system, no sign-up, and no profile — the only interaction that involves a third party is buying the app once. This page explains exactly what happens with your data when you do.

Who runs this

Metronome.Rocks is built and operated by Riverun. If you have questions about this policy or your data, contact privacy@riverun.app.

Payments — Stripe

When you buy Metronome.Rocks, your payment is processed entirely by Stripe. We create a Stripe Checkout Session server-side and redirect you to Stripe's hosted payment page — your card number, billing address, and other payment details are entered directly into Stripe and never pass through or get stored on our servers. We only ever see a Stripe checkout session ID and its payment status (paid / not paid), nothing else. Stripe's own privacy policy governs how they handle your payment information.

The access cookie

After a successful purchase, we set one cookie named mmr_access in your browser. It is an HMAC-signed reference to your Stripe checkout session — not your name, email, card details, or any other personal information. It is:

  • httpOnly — inaccessible to page JavaScript
  • Sent only to metronome.rocks, never to third parties
  • Used for one purpose: unlocking the paid /app route on this device

This is the only cookie we set beyond what Stripe itself may use during checkout on stripe.com.

Local, on-device settings

All of your metronome settings — tempo, time signature, subdivision, accent patterns, presets/setlists, and preferences like haptics or silent-practice mode — are stored locally in your browser via localStorage. This data never leaves your device and is never transmitted to us or anyone else. Clearing your browser storage or uninstalling the app removes it permanently; we have no copy and cannot recover it.

Analytics

We use two lightweight, privacy-respecting analytics tools to understand aggregate usage (e.g. how many people visit the landing page, general performance metrics):

  • Vercel Analytics — anonymous, aggregated page-view and performance data. No cookies, no cross-site tracking, no individual profiles.
  • Riverun Pulse (our own first-party analytics script, served from pulse.riverun.site) — anonymous, aggregated visit and engagement counts for metronome.rocks specifically.

Neither service is used for advertising, neither builds an advertising profile of you, and neither is shared with ad networks. We do not run ads and we do not use ad-tracking SDKs of any kind.

MIDI access (optional, on-device only)

If you choose to enable MIDI Clock output to sync tempo with external gear or a DAW, the app requests Web MIDI access from your browser. This connects directly to a MIDI device you select, on your own device — it does not transmit any data to us or to the internet.

What we don't do

  • No accounts, no sign-up, no passwords
  • No collection of your name, email, or contact details (Stripe may collect an email for your receipt — that relationship is between you and Stripe)
  • No advertising or ad-tracking SDKs
  • No selling or renting of any data to third parties
  • No location tracking
  • No access to your microphone, camera, contacts, or files

Children's privacy

Metronome.Rocks is a general-audience utility app with no user-generated content, chat, or social features, and it does not knowingly collect personal information from anyone, including children.

Data retention

We retain only what Stripe retains for payment/checkout records (per Stripe's own policies) and standard, short-lived aggregate analytics data. Your on-device settings persist until you clear your browser storage or uninstall the app — we hold no copy of them.

Changes to this policy

If this policy changes, we'll update the “last updated” date at the top of this page. Continued use of the app after a change constitutes acceptance of the updated policy.

Contact

Questions, concerns, or data requests: privacy@riverun.app