Privacy Policy — Metal Notes
Last updated: August 27, 2026
This first-pass product policy explains the information Metal Notes handles and why. Questions can be sent to support@metalnotes.net.
Accounts and authentication
Individual accounts use Firebase Authentication. We handle your account email, Firebase user identifier, and authentication status so you can sign in and use account features. We do not receive your password from Firebase.
Welcome emails
After an eligible account is created, Metal Notes uses Resend to process a transactional welcome email. We keep limited mail-submission metadata in mailState, including a send timestamp recording whether and when the welcome email was submitted and the provider message identifier, so duplicate sends can be avoided and email support can be provided.
Practice and progress
Metal Notes stores settings, practice and progression data, XP, streaks, and related app state in local storage on your device. When you sign in, eligible progress and settings can also sync to cloud storage so your account can recover and continue that progress.
Microphone use
The practice app uses your microphone for real-time pitch analysis and feedback. The current app flow does not upload or store practice audio recordings. Your browser or device controls microphone permission.
Error reports and diagnostics
When configured, Sentry may receive filtered technical error details such as the app build, screen, instrument, scale, browser type, and a non-email user identifier. Metal Notes is designed to exclude microphone audio, practice recordings, passwords, authentication tokens, tester codes, and sensitive form values. Session replay is disabled. Support diagnostics are copied only when you choose to copy them.
Access and payment records
We handle tester-code redemptions, administrator-granted entitlement records, and related audit information to manage access. If payments later activate, payment identifiers and status records may be handled to confirm access; the app does not grant paid access from browser-only claims.
Account deletion
You can permanently delete a signed-in account from Settings in the practice app or through the authenticated external account deletion page. Deletion removes the server account and app-owned server data or scrubs identifying fields where a minimal operational record must remain. We retain a minimal UID deletion tombstone to prevent a deleted account from recreating data with an older still-valid sign-in token; it does not restore access if the same email later creates a new account with a different UID. In-app deletion also clears Metal Notes local data in that browser after the server confirms deletion. The external account deletion page cannot erase practice-app local data on devices or browsers where you used Metal Notes; you may need to clear the app data in that browser or device yourself. Deletion cannot be performed by email alone.
Children and future classroom use
Individual Metal Notes accounts are not intended for children under 13. A parent or guardian should not create an individual account for a child under 13 through the current flow. Any future school or classroom system will be separate from today’s individual-account experience and will require additional review before launch.
Contact
For privacy or account questions, contact support@metalnotes.net.