隱私權政策與資料刪除說明
DrummerUpSkill(打鼓練習工具)・最後更新:2026-10-06
DrummerUpSkill 是一個鼓手練習用的網頁/App 工具,由開發者個人維護(非商業公司營運)。本頁說明我們會蒐集哪些資料、哪些資料會被公開、怎麼使用,以及如何刪除。
重點摘要
- 沒有登入時,你的模組、群組與練習紀錄只存在你自己的裝置(瀏覽器本機儲存),不會上傳。
- 登入後,你的模組、群組、偏好設定與評分紀錄會同步存到你的雲端帳號底下,只有你本人讀得到。
- 你主動「分享」模組或群組時,內容會變成公開:任何拿到連結的人都看得到,包含你選擇的分享者資訊(公開分享會顯示你的帳號名稱與頭像,可能是真名;匿名分享只顯示你自訂的匿名名稱)。公開的分享文件裡不含你的帳號 ID、Email 或裝置資訊。分享前可修改分享設定,分享後可隨時撤回。
- 目前沒有啟用 Google Analytics。日後啟用時,也只有在你同意後才會使用;拒絕不影響任何功能,並可隨時在齒輪選單的「隱私與數據分析」撤回(這個選項在啟用後才會出現)。
- 你可以在 App 內直接刪除帳號,雲端帳號底下的資料與你建立的公開分享會一併刪除;唯一例外是後台人工維護的訂閱等級紀錄,需寄信申請刪除(見「如何刪除帳號與資料」)。
我們會蒐集哪些資料
- 登入帳號資訊:你可以用 Google、GitHub、Microsoft 或電子郵件/密碼登入。使用第三方登入時,我們只會取得該服務提供的基本識別資訊——顯示名稱、電子郵件、大頭貼網址——用來建立並辨識你的帳號,不會取得你在該平台上的貼文、好友清單或其他資料。電子郵件/密碼登入由 Firebase Authentication 處理,我們看不到你的密碼。
- 你在 App 裡建立的內容(登入後同步到雲端):練習模組(鼓譜)、群組(名稱、圖示、說明)與模組所屬群組、音軌排列、音色與音量等偏好設定、延遲補償設定、評分練習紀錄(成績、打擊時間誤差等)。
- 訂閱/付費等級:是否為付費方案使用者(目前為人工後台設定,沒有串接金流)。
資料怎麼使用、會不會分享給別人
上述資料只用來提供本服務本身的功能(跨裝置同步你的模組/紀錄、依訂閱等級開放對應功能)。我們不會把你的個人資料出售或分享給第三方行銷用途。資料存放於 Google Firebase(Authentication、Firestore 資料庫、Hosting),屬於提供雲端代管服務的基礎設施供應商。除此之外,只有在你同意數據分析時,才會有分析資料交給 Google Analytics(見下方「數據分析與 Cookie」);除此之外不會把資料交給其他單位。
分享連結(公開資料)
只有在你主動按下分享時,才會建立公開文件;任何持有連結的人都能開啟,不需要登入。公開內容如下:
| 分享類型 | 公開的內容 |
|---|---|
單一模組分享(連結含 ?p=) | 模組內容、分享名稱、分享者(帳號名稱與頭像網址,或匿名名稱)、分享留言(選填)、建立時間、有效期限設定 |
群組分享(連結含 ?g=) | 群組名稱(分享名稱)、群組圖示與說明、群組內的模組(最多 20 個)、分享者(帳號名稱與頭像網址,或匿名名稱)、分享留言(選填)、建立時間、有效期限設定 |
- 分享名稱:預設帶入模組或群組自己的名稱,每次分享前都可以改,只影響分享出去的那份。
- 分享者:每次分享時選擇。「公開分享」會顯示你的帳號名稱(例如 Google 名稱,通常是真名)與頭像,頭像由你的登入服務的網址載入;「匿名分享」只顯示你自訂的匿名名稱(預設帶入偏好設定中的匿名分享名稱),不顯示帳號名稱與頭像。公開的分享文件不含你的帳號 ID;我們另外在你自己的私人資料裡記錄你擁有哪些分享(只有你本人讀得到),用來讓你管理與撤回,所以匿名分享對打開連結的人是真的匿名。
- 你的電子郵件、成績單與評分紀錄不會出現在分享內容裡。
- 連結一旦被別人取得或轉傳,我們無法控制對方是否已複製內容;撤回只會讓連結失效。
- 建立分享時可以選擇有效期限;到期後連結將無法開啟。
- 你可以在 App 的分享管理中隨時撤回分享(刪除公開文件),刪除帳號時也會一併刪除你建立的所有分享。
如何刪除帳號與資料
App 內自行刪除:登入後在帳號設定選擇「刪除帳號」,會刪除你雲端帳號底下的所有資料(模組、群組、評分紀錄、偏好設定、頭貼)、你建立的所有公開分享,以及登入帳號本身;訂閱等級紀錄不在其中,見下一段。裝置本機儲存的資料可從瀏覽器清除網站資料自行移除。
其餘資料:訂閱等級紀錄由後台人工維護,無法由 App 自行刪除;如需一併清除,或你無法登入 App,請用登入時使用的電子郵件寄信到:
信件標題請註明「DrummerUpSkill 資料刪除申請」。我們會在收到申請後盡快(通常不超過 30 天)處理並回信告知。
數據分析與 Cookie
目前狀態:尚未啟用。本網站目前不會載入 Google Analytics,也不會出現數據分析的同意視窗與齒輪選單的「隱私與數據分析」。以下是日後啟用時的做法;啟用前我們會先更新本頁。
只有在你同意後,我們才會使用 Google Analytics 4(透過 Firebase Analytics 提供),了解 DrummerUp 怎麼被使用,以改善功能、找出錯誤。服務提供者是 Google;Google 依《Google Ads 資料處理條款》擔任我們的受託處理者。
- 同意後會蒐集的資料:
- 隨機產生的瀏覽器識別碼:
_ga、_ga_<ID>cookie(預設最長 2 年),以及存在瀏覽器 IndexedDB 的 Firebase Installation ID。 - 頁面瀏覽和功能使用事件,例如開啟練習、評分、分享等功能的次數。網址中的分享碼與成績單 ID 會先移除。
- 裝置與瀏覽器類型、作業系統、螢幕大小、語言。
- 由 IP 位址推算的大致位置(國家、地區,可能到城市)。Google 表示 Google Analytics 不會記錄或儲存 IP 位址。
- 參考來源網址。
- 隨機產生的瀏覽器識別碼:
- 我們不會送給 Google Analytics 的資料:Email、姓名、帳號 ID、鼓譜或群組名稱、分享名稱、成績單內容。
- 我們的設定:關閉 Google signals 與廣告個人化、不連結任何廣告帳戶、不與 Google 共用資料供其自身產品使用。我們不做廣告,也不出售你的資料。
- 資料保留期間:分析資料在 Google Analytics 中的使用者層級與事件層級資料保留 14 個月,之後只剩無法辨識個人的彙總統計。
- 法律依據:你的同意。
- 你的選擇:第一次使用時,「接受」與「拒絕」一樣容易選擇;不選擇的話不會啟用分析。你可以隨時在齒輪選單的「隱私與數據分析」撤回同意,撤回後我們會停止收集並刪除瀏覽器裡的
_gacookie;撤回不影響撤回前處理的合法性。拒絕或撤回都不會影響你使用任何功能。 - 必要的本機儲存:我們使用瀏覽器 localStorage(名稱以
drummer-upskill.開頭)保存你的鼓譜、設定、成績單與你的選擇,Firebase 也會保存你的登入狀態。這些是提供你要求的服務所必要的,不需要同意,也不會用來追蹤你。 - 跨境傳輸:Google 可能在美國及其他國家處理分析資料。從歐洲經濟區、英國、瑞士的傳輸,依 Google 資料處理條款中的標準契約條款,以及 Google LLC 的 Data Privacy Framework 認證處理。
更多資訊:Google 如何使用使用其服務的網站資料。
錯誤回報
你在 App 齒輪選單用「錯誤回報」送出時,我們會收到你填寫的標題、詳細說明、聯絡 Email(選填)、截圖(選填),以及自動附上的環境資訊:App 版本、目前頁面路徑(不含網址參數)、練習或評分模式、目前模組名稱、輸入裝置名稱、介面與瀏覽器語言、介面主題、螢幕大小與瀏覽器資訊(User-Agent);有登入時另附你的帳號 ID。送出前視窗上會列出這些項目。
為了防止濫用,我們會用你 IP 位址的雜湊值(不保存原始 IP)限制送出次數。截圖在你的瀏覽器裡會先重新繪製再送出,照片裡的拍攝位置等 EXIF 資訊會被移除;請避免在截圖或說明裡放入不想提供的個人資料。
回報存放在我們的 Firebase 專案(Firestore 與 Cloud Storage,只有開發者讀得到),並透過 Gmail 寄到 support@drummerup.com,只用來處理這次回報與回覆你。回報保留到處理完畢,最長 12 個月後刪除;你也可以寫信到 privacy@drummerup.com 要求提早刪除。
安全驗證(防止濫用)
為了防止自動化程式濫用雲端服務,網頁版使用 Firebase App Check 搭配 Google reCAPTCHA Enterprise,確認對資料庫與雲端服務的請求來自本網站。你開啟網站時會在背景載入 Google 的 reCAPTCHA 程式(不會要你勾選「我不是機器人」),並把 IP 位址與瀏覽器特徵等資訊傳給 Google 做風險判斷,用途僅限於安全驗證,不用於廣告。這是保護服務所必要的,不受上述「數據分析」同意與否影響。reCAPTCHA 適用 Google 的隱私權政策與服務條款。Android App 目前沒有使用 App Check。
聯絡方式
如對本政策有任何問題,歡迎寄信至 privacy@drummerup.com。
Privacy Policy and Data Deletion
DrummerUpSkill (drum practice tool) · Last updated: 2026-10-06
DrummerUpSkill is a web/app tool for drummers, maintained by an individual developer (not a company). This page explains what data we collect, what becomes public, how it is used, and how to delete it.
Summary
- When you are not signed in, your patterns, groups and practice records stay on your own device (browser local storage) and are not uploaded.
- When signed in, your patterns, groups, preferences and score reports are synced to your cloud account and readable only by you.
- When you choose to share a pattern or group, that content becomes public: anyone with the link can see it, including the sharer information you choose (public sharing shows your account name and avatar, which may be your real name; anonymous sharing shows only a name you pick) . The public share document does not contain your account ID, email or device information. You can edit the share settings before sharing and revoke a share at any time.
- Google Analytics is not currently enabled. If we enable it in the future, it will only be used with your consent; declining affects no feature, and you can withdraw at any time via "Privacy & Analytics" in the gear menu (that option appears only once analytics is enabled).
- You can delete your account inside the app; the data under your cloud account and the public shares you created are deleted with it. The only exception is the subscription-tier record maintained manually by the developer, which you can ask us to delete by email (see "How to delete your account and data").
What we collect
- Sign-in information: you can sign in with Google, GitHub, Microsoft, or email/password. With a third-party provider we only receive basic identity information (display name, email, avatar URL) to create and recognize your account; we do not access posts, friend lists, or other data on that platform. Email/password sign-in is handled by Firebase Authentication and we cannot see your password.
- Content you create in the app (synced to the cloud when signed in): practice patterns, groups (name, icon, description) and which group each pattern belongs to, track layout, sound and volume preferences, latency-compensation settings, and score reports (scores, hit timing errors, etc.).
- Subscription tier: whether you are on a paid plan (currently set manually by the developer; there is no payment integration).
How data is used and shared
This data is used only to provide the service itself (syncing across devices and enabling features by tier). We do not sell your personal data or share it for third-party marketing. Data is stored on Google Firebase (Authentication, Firestore, Hosting), the infrastructure provider. Apart from that, analytics data goes to Google Analytics only if you consent (see "Analytics and cookies" below); no data is handed to any other party.
Share links (public data)
A public document is created only when you press share. Anyone with the link can open it without signing in. The public content is:
| Share type | Publicly visible content |
|---|---|
Single pattern (link contains ?p=) | Pattern content, share name, sharer (account name and avatar URL, or an anonymous name), message (optional), creation time, expiry setting |
Group (link contains ?g=) | Group name (share name), icon and description, the patterns in the group (up to 20), sharer (account name and avatar URL, or an anonymous name), message (optional), creation time, expiry setting |
- Share name: defaults to the pattern's or group's own name; you can change it before each share, and it only affects the shared copy.
- Sharer: chosen on each share. "Share publicly" shows your account name (e.g. your Google name, often your real name) and avatar, loaded from your sign-in provider's URL; "Share anonymously" shows only a name you pick (defaulting to the anonymous share name in Preferences) and no account name or avatar. The public share document does not contain your account ID; we record which shares you own separately in your own private data (readable only by you) so you can manage and revoke them, so anonymous sharing is genuinely anonymous to people who open the link.
- Your email address, score reports and practice records are not included in shares.
- Once someone has the link or forwards it, we cannot control whether they copied the content; revoking only disables the link.
- You can choose how long a share lasts when creating it; after expiry the link stops opening.
- You can revoke a share (delete the public document) at any time from the app's share management, and deleting your account also deletes every share you created.
How to delete your account and data
In the app: when signed in, choose "Delete account" in account settings. This deletes everything under your cloud account (patterns, groups, score reports, preferences, profile photo), all public shares you created, and the sign-in account itself; the subscription-tier record is not included, see below. Data in your device's local storage can be removed by clearing site data in your browser.
Everything else: the subscription-tier record is maintained manually by the developer and cannot be deleted from the app. To have it removed, or if you cannot sign in, email the address below from the email you signed in with:
Please use the subject "DrummerUpSkill data deletion request". We will process it as soon as possible (normally within 30 days) and reply when done.
Analytics and cookies
Current status: not enabled. The site does not currently load Google Analytics, and you will not see the analytics consent banner or the "Privacy & Analytics" option in the gear menu. The following describes how analytics will work once enabled; we will update this page before enabling it.
Only if you agree, we use Google Analytics 4 (provided through Firebase Analytics) to understand how DrummerUp is used, so we can improve features and find bugs. The provider is Google, which acts as our processor under the Google Ads Data Processing Terms.
- What is collected if you agree:
- Random browser identifiers: the
_gaand_ga_<ID>cookies (up to 2 years by default) and a Firebase Installation ID stored in your browser's IndexedDB. - Page views and feature-usage events, such as how often practice, scoring or sharing is used. Share codes and report IDs are stripped from URLs first.
- Device and browser type, operating system, screen size and language.
- Approximate location derived from your IP address (country, region, possibly city). Google states that Google Analytics does not log or store IP addresses.
- The referring URL.
- Random browser identifiers: the
- What we never send to Google Analytics: your email, name, account ID, pattern or group names, share names, or report contents.
- Our settings: Google signals and ad personalization are off, no advertising accounts are linked, and data is not shared with Google for its own products. We don't run ads and never sell your data.
- Retention: user- and event-level analytics data is kept in Google Analytics for 14 months; after that only aggregated statistics that don't identify you remain.
- Legal basis: your consent.
- Your choices: on your first visit "Decline" is as easy as "Accept"; if you don't choose, analytics stays off. You can withdraw consent at any time via "Privacy & Analytics" in the gear menu; we then stop collection and delete the
_gacookies from your browser. Withdrawal does not affect processing before it. Declining or withdrawing never limits any feature. - Strictly necessary storage: we use your browser's localStorage (keys starting with
drummer-upskill.) to keep your patterns, settings, reports and your choice, and Firebase keeps you signed in. This is needed to provide the service you ask for, does not require consent, and is not used to track you. - International transfers: Google may process analytics data in the United States and other countries. Transfers from the EEA, UK and Switzerland rely on the Standard Contractual Clauses in Google's data processing terms and Google LLC's Data Privacy Framework certification.
More information: how Google uses information from sites that use its services.
Problem reports
When you send a report with "Report a problem" in the app's gear menu, we receive the title, details, contact email (optional) and screenshot (optional) you provide, plus automatically attached environment information: app version, current page path (without URL parameters), practice or scoring mode, current pattern name, input device name, interface and browser language, interface theme, screen size and browser information (User-Agent); if you are signed in, also your account ID. The dialog lists these items before you send.
To prevent abuse, we use a hash of your IP address (the raw IP is not stored) to limit how often reports can be sent. Screenshots are redrawn in your browser before sending, which removes EXIF data such as photo location; please avoid including personal information you don't want to share in screenshots or details.
Reports are stored in our Firebase project (Firestore and Cloud Storage, readable only by the developer) and emailed via Gmail to support@drummerup.com, used only to handle the report and reply to you. Reports are kept until handled and deleted after at most 12 months; you can ask for earlier deletion at privacy@drummerup.com.
Security verification (abuse prevention)
To prevent automated abuse of our cloud services, the website uses Firebase App Check with Google reCAPTCHA Enterprise to confirm that requests to our database and cloud services come from this site. When you open the site, Google's reCAPTCHA code loads in the background (you will not be asked to tick "I'm not a robot") and information such as your IP address and browser characteristics is sent to Google for risk assessment, solely for security verification and not for advertising. This is necessary to protect the service and does not depend on your analytics consent above. Google's Privacy Policy and Terms of Service apply to reCAPTCHA. The Android app does not currently use App Check.
Contact
Questions about this policy: privacy@drummerup.com.