TMTorn Metal

Privacy

We can’t sell what we don’t collect.

So we don’t collect it. This page covers two separate things — what happens when you browse tornmetal.com, and what happens when you use one of our apps. They work differently, so they are written up separately.

Part one

This website

Page counts, link clicks, and a newsletter you have to ask for. No cookies.

Part two

Our apps

Your content stays on your device. One app is a deliberate exception.

Part three

Asking us things

What you can ask for, how long we keep things, and where to write.

Part one · this website

What tornmetal.com records.

We run our own analytics, on our own server, because we wanted to know which apps people are curious about without handing visitors to somebody else’s advertising business. Here is the whole of it.

WhatWhy
The page you opened To count which pages get read. Stored without the .html ending, so /about.html and /about count as one page.
The site you came from Your browser’s referrer, if it sends one — so we can tell a link from a search from someone typing the address in.
A campaign tag The ?ref= value on the address, when a link we published carries one. It tells us which button or post sent you, not who you are.
Your operating system family Windows, macOS/iOS, Linux, or whatever your browser reports. The family only — not the version, not the device model.
Your browser window size Width and height in pixels, so we know whether the layout is being read on a phone or a desktop.
Links and buttons you click A short label, like App Store: PhotoDome or Nav Subscribe. The label, and the time — nothing about you.
The time it happened A timestamp, so the numbers can be read as a day or a week.
A daily visitor number So that one person reading four pages counts as one visitor rather than four. How that number is made is worth explaining properly — see below.

The daily visitor number, honestly

To count visitors rather than page loads, something has to tell two readers apart. The usual answer is a cookie or a stored identifier. We don’t set either.

Instead, when your browser reaches our server, the server takes your IP address, adds a fixed secret and today’s date, and runs the three through a one-way hash. What gets written down is the result of that sum. Your IP address is never stored — it exists in memory for the instant it takes to compute the hash, and is then gone.

Because the date is part of the sum, the number changes at midnight. It cannot be used to follow you from one day to the next, and it cannot be reversed into your IP address. What it can do is tell us that four page loads this afternoon were one person.

We would rather describe this than call it “anonymous” and leave it there. A number derived from your IP address is pseudonymous, not anonymous, and under the GDPR it counts as personal data even though we cannot turn it back into an address. So we treat it as personal data, and it is covered by everything in part three.

What we don’t do

  • ×No cookies. Our code sets none, and stores nothing in your browser.
  • ×No Google Analytics, no Meta pixel, no advertising or attribution SDK of any kind.
  • ×No profile that follows you between visits, and nothing joining your browsing to an app or an email address.
  • ×No selling or sharing of any of it, to anyone, for any purpose. There is no arrangement under which this data leaves our server.

The analytics live in a single database file on our own hosting, reachable only by us through a password‑protected dashboard.

Part one, continued

The two outside services.

Being straight about this is the point of the page. Two services other than us are involved in running the site, both of them tied to the newsletter form, and both can see your IP address because that is how the web works — your browser has to ask them for something.

Brevo — the newsletter

The subscribe form on the home page and the About page is Brevo’s. Pages that show that form load a script from Brevo in order to display it. If you submit the form, the email address and the optional first name you typed are transferred to Brevo and processed under Brevo’s privacy policy. We use it for one thing: sending the newsletter you asked for. Every newsletter carries a one‑click unsubscribe, and unsubscribing removes you from the list.

Google reCAPTCHA — the spam filter

The same form is protected by reCAPTCHA, so that bots can’t sign strangers up to our newsletter. Pages showing the form load reCAPTCHA from Google, which means Google receives your IP address and sets its own cookies on those pages, whether or not you ever use the form. Google’s privacy policy and terms govern what it does with that.

Typefaces — no longer Google’s

This site used to request its typefaces from Google’s font servers, which disclosed your IP address to Google on every page just to deliver the font files. It no longer does. The fonts are served from our own server, so visiting a page here tells Google nothing.

That leaves reCAPTCHA as the only thing on this site that reaches Google at all, and it appears solely on the two pages carrying the newsletter form.

Where each one applies

This pageNothing outside our own server.
App privacy policyNothing outside our own server.
Home & AboutBrevo and reCAPTCHA, because the newsletter form lives there. Nothing else.
App sub‑sitesOur own analytics. Individual app sites may load their own fonts; none of them carry advertising or third‑party analytics.

Our own analytics script runs on every page, including this one. It is the first‑party collection described above — it talks only to tornmetal.com.

Part two · our apps

What our apps keep.

The short version is below. The full text is the app privacy policy, which is the document the App Store listings point at.

It stays on your device

Photos, captures, selections, settings — they live on your device and in your own iCloud account. We have no server holding your content, and no account system that would let us look at it if we wanted to.

Crash reports

If you have opted in to sharing diagnostics at the iOS level, Apple passes us crash reports. We see where the code broke — a stack trace, a device model, an OS version. We never see the contents of your data.

What the App Store says, we do

Each app’s privacy label on the App Store is the authoritative summary for that app. Where an app reports “Data Not Collected,” the only information we receive about it is the aggregate sales and usage reporting Apple gives every developer, which does not identify anyone.

Venture To Space is the exception

One app collects usage data, and it is deliberate rather than an oversight. Venture To Space is a browser for NASA’s imagery archive, and it is our trial run at learning enough to improve an app without violating anyone — which screens and images get opened, what gets saved to favourites, how long a session runs, and how the app performs.

The rules we set ourselves for it: collection is our own code, not a third‑party SDK. It is stored where only we can read it. Nothing in it is designed to trace back to a person, and its App Store label spells out exactly what is gathered.

If that is not a trade you want to make, the App Store label will always tell you the current answer before you install.

Part three · asking us things

How long, and what you can ask for.

How long we keep it

Website analytics: kept for 36 months, then deleted. Three years is enough to compare a season against the same season two years ago, which is the longest comparison we actually make. Anything older stops being useful before it stops being data, so it goes.

This is not a promise we leave to good intentions: the tracking endpoint sweeps out anything past 36 months once a day, on its own, without anyone remembering to run it.

Newsletter: your email stays on the list until you unsubscribe, at which point Brevo removes you from it.

Emails to us: if you write for support, we keep the conversation so that we can pick it up again if you write back.

What you can ask for

Wherever we hold personal data about you, you can ask us to show you what we have, correct it, delete it, or stop using it — and you can object to our analytics specifically. We do this for anyone who asks, wherever you live, rather than checking which law covers you first.

One honest limit: the website analytics are deliberately built so that we cannot pick your rows out of them. There is no identifier we could match you to, which is the point of the design, but it does mean a request to delete “your” analytics is one we have no way to carry out precisely. For the newsletter and for support email, where we can identify you, we can do all of it.

Write to us

Privacy questions and requests go to privacy@tornmetal.com. A person reads it. We aim to answer within 30 days.

Who you are dealing with

Torn Metal LLC, an independent app studio in the United States. Our website is hosted in the United States; Brevo processes newsletter email in the European Union. If you are writing from outside the US, your data will be handled in these places.

Children

Our apps and this site are not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has sent us something, write to us and we will delete it.

CHANGES

When this page changes

If our practices change, this page changes with them, and the date below moves. We don’t make quiet edits — a change that affects what we collect will be described here rather than folded silently into the wording.

Last updated 30 August 2026.

Torn Metal LLC © 2026 · All rights reserved.