Privacy Policy
Last updated 30 September 2026 · See also the Terms of Service
The short version
- You can practise without an account. The first time you save something, we make an anonymous guest record for your browser. No name, no email.
- If you log in, you do it with your Google account: Google tells us your email address and name, and we store those. We never see or store a password.
- We store your practice: which rhythms you played, at what tempo, how each note was graded, and the timing of your taps. That’s what the app is for. We don’t record audio.
- We use one cookie, to keep you signed in. No advertising and no tracking cookies. To count visits we use a cookieless analytics service that never identifies you (see Analytics below).
- We don’t sell your data or share it with anyone except the company that hosts the service and the analytics service, which only counts visits.
- You can see your history in the app and delete runs yourself. To delete your account or get a copy of your data, email hello@rhythmkata.com.
This policy covers Rhythm Kata: this website (rhythmkata.com) and the practice app at app.rhythmkata.com (together, “the service”). It describes what the service actually does today. Rhythm Kata is in beta, so it changes, and this policy will change with it (see Changes).
- Who runs Rhythm Kata
- What we collect
- What we don’t collect
- How we use it, and why we may
- Cookies and browser storage
- Who else sees it
- Where it’s stored
- How long we keep it
- Security
- Your rights, and how to use them
- Children
- Changes to this policy
- Contact
Who runs Rhythm Kata
Rhythm Kata is a small, independent service (“we”, “us”). We decide what data the service keeps and why, which makes us the “controller” of your personal data under data protection laws such as the EU and UK GDPR. You can reach us at hello@rhythmkata.com.
What we collect
If you only look around
Reading this website, opening the app or trying the notation doesn’t create any record about you in our database. We don’t set a cookie until you save something. Like every web server, our hosting provider sees your IP address and basic request details (see Technical data).
If you practise as a guest
The first time you save something (finish a run, play a rhythm back, or change a setting), we create a guest for your browser: a random ID, when it was created and when it was last used. We set a cookie so your browser is recognised as that guest next time. A guest has no name or email address unless you add a display name.
If you log in
You log in with your Google account. Google asks you to agree to share your basic profile with us, and then tells us:
- Email address, which is what makes your account an account.
- Name, used as your display name unless you already had one. You can change or clear it at any time (up to 40 characters).
- Google’s ID for your account, a number that recognises you the next time you log in even if your email changes. It means nothing outside Rhythm Kata.
- When the account was created and when it was last used.
Creating an account on a browser where you practised as a guest turns that guest into your account, history included. Logging in to an existing account moves the guest’s runs and listens into it, and the guest record is closed: kept, marked as deleted, and never used again.
Your practice
Whether you’re a guest or have an account, we store:
- Each run you finish: which rhythm, the tempo, the settings it was played with (metronome on or off, whether held notes were graded, your latency calibration, input method, whether Adaptive picked it), the scores, how each note was graded and how early or late it was, whether you had listened to the rhythm first, and when you played it.
- The timing of your taps: the moments you pressed and released, measured from the start of the rhythm. We keep these so a run can be played back and graded again if the scoring rules improve. We don’t record which key you pressed, and no sound.
- Each time you play a rhythm back: which rhythm, the tempo, how much of it played, where in the app, and when.
- Your settings: tempo, number of bars, difficulty, time signature, metronome and tap sound, latency calibration, sight-reading mode, and your daily goals. A few settings for features that aren’t available yet are stored at their defaults.
Your progress, daily goals, streaks and weekly daruma are worked out from this data; they aren’t collected separately. If you open a rhythm that isn’t in our library (for example from a link), the rhythm itself is added to the shared library; that entry isn’t linked to you except through your own runs.
Technical data
- Sessions. When you save something or log in, we create a session: a random token in a cookie on your browser. On our side we store only a one-way hash of the token, when it was created, when it was last used and when it expires.
- IP address. To stop abuse, we count some actions per IP address (log-ins started, new guests). These counts are kept only in the server’s memory, for at most an hour, and are not written to our database.
- Error logs. When something goes wrong on the server, we log the error so we can fix it. An error log can include details of the request that failed, such as your user ID or something you entered (for example an email address).
- Hosting logs. Our hosting providers may log requests to the service, including IP address, time, the page requested and your browser’s user agent, to run and protect its network.
What we don’t collect
No microphone or camera access, no location, no contacts, no payment details, no advertising identifiers, and no tracking across other sites. The app’s fonts and code are served from our own domain, so opening it doesn’t send requests to Google or any other third party. Adding the app to your home screen doesn’t give us any extra access to your device.
Tapping is the only input today. If we add a way to play into your microphone, we’ll update this policy before it launches to say exactly what it does with the sound.
How we use it, and why we may
Data protection law asks us to name a “legal basis” for each use. We don’t use your data for advertising or sell it, and we don’t make decisions about you that have legal or similar effects.
| What we do | Why we may |
|---|---|
| Run the app: save your runs, grade them, show your history and progress, remember your settings, keep you signed in. | To provide the service you asked for (contract). |
| Create and secure your account; move a guest’s history into your account when you log in. | Contract. |
| Limit how often actions can be repeated, log errors and fix problems. | Our legitimate interest in keeping the service secure and working. |
| Grade stored runs again when the scoring rules improve (the old scores are kept alongside), and study how runs are graded to make the grading fairer. | Our legitimate interest in improving the service, which is also what you use it for. |
| Close guests that never practised. | Our legitimate interest in not keeping data we don’t need. |
| Contact you about your account or an important change to the service or these documents (we don’t send newsletters or marketing). | Contract, or our legitimate interest in keeping you informed. |
| Comply with the law or respond to valid legal requests. | Legal obligation. |
Where we rely on legitimate interests, you can object (see Your rights).
Cookies and browser storage
The service uses one cookie and a few small entries in your browser’s storage, all of them for the app itself:
| Name | Type | What it’s for | How long |
|---|---|---|---|
rr_session | Cookie (HttpOnly, SameSite=Lax, Secure) | Keeps you signed in as your guest or account. Set only once you save something or log in. | 90 days since you last used the app; ended when you log out. |
rhythm-kata:current:… | Local storage | The rhythm last on the practice page, so reopening the app returns to it. | Until you log out or clear site data. |
read-rhythm:piece-preview | Local storage | Whether the count-in and metronome are on when you preview a rhythm. | Until you clear site data. |
rhythm-kata:guest-limit-dismissed | Session storage | Remembers that you closed the guest-limit notice. | Until you close the tab. |
Why there’s no cookie banner. Consent isn’t required for storage that is strictly necessary to provide a service you asked for. Each item above either keeps you signed in or remembers something you did in the app; none is used for analytics, advertising or tracking, and none is read by anyone but us. If we ever add storage that isn’t strictly necessary, we’ll ask first.
You can clear cookies and site data in your browser at any time. If you’re a guest, clearing the cookie means your browser can no longer open that guest’s history, so create an account first if you want to keep it.
Analytics
To understand how many people use Rhythm Kata and which pages they visit, this website and the app use Plausible Analytics, a privacy-friendly analytics tool that doesn’t use cookies or local storage and doesn’t track you across sites. It records page views, clicks on the links into the app, a few steps in the app (your first run, each run saved with its level and a score range but never your score, listening to a rhythm, logging in, and reaching the guest limit), the referring site and any campaign tags in the link you followed (for example, that you came from one of our videos), your browser and device type, and your country (worked out from your IP address, which is not stored). We only see totals, never individual visitors. We rely on our legitimate interest in understanding and improving the service.
Who else sees it
We don’t sell, rent or trade your personal data, and we don’t share it with advertisers.
- Service providers. A cloud hosting provider runs the app and its database, and a website hosting provider serves this website; each processes data only on our behalf, under a data processing agreement. Google handles logging in: it knows you logged in to Rhythm Kata, under its own privacy policy, and learns nothing about your practice. Plausible Analytics counts visits to this website and the app, as described under Analytics, and sees only what is listed there.
- The law. We may disclose data if the law requires it, or to protect the rights, safety or property of our users, the public or us.
- If Rhythm Kata changes hands. If the service is transferred to someone else, your data may go with it, under this policy. We’ll tell you beforehand, and you can ask us to delete your data instead.
Your display name and practice history are private to you; there are no public profiles or leaderboards.
Where it’s stored
Your data is stored by our cloud hosting provider in the United States. If it is processed outside the UK or the European Economic Area, we rely on safeguards the law recognises, such as an adequacy decision or the European Commission’s standard contractual clauses. You can ask us for details.
How long we keep it
- Accounts, with their practice history and settings: until you ask us to delete the account.
- Guests that never practised (no runs and no listens): closed after 30 days without use, their sessions ended. The record (a random ID and when it was used) is kept, marked as deleted.
- Guests with practice history: kept, so the history is there when that browser comes back. If you practised as a guest and want that data deleted, contact us.
- Runs you delete are hidden from your history and progress straight away, and you can undo it.Reset progress does the same for all of your runs at once. Deleted runs stay in our database, marked as deleted, and aren’t used again; Reset progress doesn’t touch your listens or settings. To have any of it erased for good, ask us.
- Sessions stop working 90 days after you last used them, or when you log out. We keep the record of an ended session (a one-way hash of its token and its times), marked as ended.
- Rate-limit counts (by IP address): in memory only, for at most an hour.
- Error and hosting logs: 7 days.
Logging out ends the session on that browser but doesn’t delete your account or your history. If we keep backups, deleted data drops out of them as they expire.
Security
We take reasonable, proportionate measures for a small service, including:
- No passwords at all: you log in with Google. Session tokens are stored only as hashes, so a copy of the database doesn’t reveal them.
- The session cookie can’t be read by page scripts, and is only sent over encrypted (HTTPS) connections.
- Limits on log-ins and saves, protection against cross-site requests, and a strict content security policy.
- Error details stay on the server; the browser is only shown a general message.
No service can be perfectly secure. Keeping your Google account secure (with two-step verification) keeps your Rhythm Kata account secure too. If we learn of a breach that affects your data, we’ll tell you and the authorities where the law requires it.
Your rights, and how to use them
Depending on where you live, you have the right to access your data, correct it, delete it, get a copy of it in a portable format, restrict or object to how we use it, and complain to a data protection authority. We give everyone these rights, wherever they live.
In the app
- See your runs, listens and progress on your account page and the progress page.
- Change your display name and settings.
- Delete individual runs, or, with an account, all of them with Reset progress on the progress page (see How long we keep it).
By email
For anything else (deleting your account and everything in it, a copy of your data, or deleting a guest’s history), email hello@rhythmkata.com. Please write from the email address on the account, so we know the request is yours. A guest has no email address, so for a guest’s data tell us as much as you can (such as when you practised and which rhythms); we can only act on a guest we can reliably identify. We’ll reply within one month.
If you’re unhappy with how we’ve handled your data, please tell us first. You can also complain to your local data protection authority (in the UK, the ICO; in the EU, the authority in your country).
Children
Rhythm Kata is not meant for children under 13. If you live somewhere that requires a parent’s consent to use online services at your age (in parts of the EU, that’s up to 16), you need your parent’s or guardian’s permission to create an account. If you believe a child has given us personal data without the permission they needed, contact us and we’ll delete it.
Changes to this policy
We’ll update this policy when the service changes, for example if we add analytics, a microphone mode or payments. The date at the top shows when it last changed. If a change matters, such as a new use of your data, we’ll tell you in the app or by email before it takes effect.
Contact
Questions or requests about your data: hello@rhythmkata.com.