Back to Virtual Drummer

Virtual Drummer

Privacy Policy

Last updated: October 4, 2026

Virtual Drummer, also known as Octy & Friends, is a local-first Chrome extension. You can use it without an account. This policy explains its local data, optional Google sign-in and account sync, and the separate welcome and feedback website.

Privacy at a glance

  • Guest play, settings, and the local analytics outbox stay in your browser.
  • After optional Google sign-in, Drum Hit progress is sent to our account API for synchronization.
  • We do not sell personal information or use it for advertising.
  • We do not read what you type, form values, passwords, page text, cookies, clipboard contents, or browsing history.

Information handled by the extension

To provide its features, Virtual Drummer stores the following data locally in chrome.storage.local:

  • Extension settings, including whether the character is enabled, its size and position, and the selected character.
  • Website origins where you explicitly choose “Disable on current site.”
  • Local progression data, including Drum Hits, milestones, unlocked characters, entitlements, and session metadata. Account sync state includes the last known total, unsent hits, and batch IDs.
  • A pseudonymous installation identifier used only to associate local extension records with the same installation.
  • A bounded local analytics outbox containing feature events such as milestones, character unlocks, character selections, and session starts. This outbox is not transmitted to the account API or elsewhere.

If you sign in, the extension temporarily keeps a Google access token, your Google account identifier, and any available display name and profile photo URL in chrome.storage.session. The name and photo are used in the popup and are not stored by our account API. The token and profile are cleared from extension session storage when you disconnect.

How page interactions are processed

The character reacts to generic interaction categories such as typing, Space, clicking, and scrolling. These events are processed locally to animate the character and update local progression.

The extension does not record individual keys or typed content. It does not read form values, selected text, page text, passwords, cookies, clipboard contents, or your browsing history. Page events are not cancelled or stopped.

Optional Google account synchronization

Selecting Sign in starts Google authentication. The extension requests the OpenID, email, and profile scopes and obtains your stable Google account identifier, optional display name, and optional profile photo URL from Google. It does not use or store your email address. Google handles authentication under its Privacy Policy.

The extension sends the Google access token to our account API over HTTPS to authenticate requests. Our API checks the token with Google and uses the verified account identifier to associate your progress with your account. It receives Drum Hit count changes and batch IDs, not individual key presses, typed content, page URLs, site exclusions, settings, or the local analytics outbox.

Our Cloudflare Worker and PostgreSQL database hosted by Neon store the Google account identifier, total Drum Hits, batch IDs and counts used to prevent duplicate sync, and character access rights. The server also retains feedback submitted through the in-extension form in older versions. It does not store your Google email, name, photo, or access token in the account database. Cloudflare and Neon process account data to provide this service. Cloudflare may also process standard request metadata, such as IP address and request time, to deliver and protect the API.

Disconnecting does not send a server request or delete your account data. The last known total and unsent hits remain visible locally. Hits earned after disconnect are uploaded if you sign in again; a total copied from one account is not uploaded to another account.

How information is used

Extension information is used to:

  • remember your preferences and character position;
  • show the character on supported websites;
  • respect websites where you disabled the extension;
  • track Drum Hit progress and character unlocks;
  • maintain local feature and session state; and
  • sync Drum Hits across signed-in installations and confirm account character access.

Transmission, sharing, and selling

We do not sell extension data or use it for advertising. Optional account requests go to our Cloudflare-hosted API, which uses Google to verify authentication and Neon to store account progress. The extension does not send page interaction details or local analytics events to that API. The welcome website and voluntary feedback forms are described separately below.

Welcome and privacy website

The extension opens its welcome website after first installation. This website is hosted by Vercel. Like other hosting providers, Vercel may process standard request information needed to deliver and protect the site, such as your IP address, browser and device information, requested page, and request time. The welcome, uninstall, and low-rating feedback pages also use Vercel Web Analytics to measure page views and approximate unique visitors. Vercel identifies visitors using a daily rotating hash and does not use analytics cookies. A welcome-page visit is an estimate of an installation, and an uninstall-page visit is an estimate of an extension removal, because either page can also be opened manually and the same person can be counted again on another day. A low-rating feedback-page visit is a page-view measurement, not confirmation that a form was submitted. The extension does not send settings, progression, interaction events, installation identifiers, or account tokens to this website.

Vercel describes its processing in its Privacy Notice and Web Analytics privacy documentation.

Feedback

Users who choose a low rating in the extension popup may open our low-rating feedback page. Answering is voluntary. The page embeds a Google Forms survey asking what did not work and what would improve the experience, with an optional email address if you would like us to contact you. Google Forms handles and stores submitted answers, which are available to us in the form owner account. The page's Vercel Analytics records page visits only; it does not tell us whether the form was submitted. The page URL does not include your rating or locally stored extension data.

Chrome may also open a separate feedback page after you remove the extension. Answering that uninstall survey is voluntary. It asks for your main reason for removal and any optional suggestions. The form is configured not to collect your email address or require a Google account. Your answers are stored by Google and are available to us in the form owner account. We do not include extension settings, progression, installation identifiers, or other locally stored extension data in the feedback page URL or form.

Google's Privacy Policy explains its handling of form responses and related request data.

Chrome permissions

  • Storage: saves settings and progression locally.
  • Identity: starts optional Google sign-in for account synchronization.
  • Alarms: schedules retries for pending progress batches while signed in.
  • Scripting: makes the extension available on already open supported tabs after installation or an update.
  • Access to HTTP and HTTPS pages: displays and animates the character on supported websites. Browser-internal pages and local files are not supported.

Retention and deletion

Local data remains until the extension changes it, you clear it through browser controls, or you remove the extension. Disconnecting clears the extension's session token and profile but keeps local progress and does not delete server records. Removing the extension clears its local data but does not delete synchronized account data. Account records and batch receipts have no automatic expiry. To request access to or deletion of your server account data, email octyandfriends@gmail.com. Feedback submitted through Google Forms is stored separately by Google; contact us at the same address about responses available to us.

Security and limited use

Local extension storage is not exposed to ordinary website scripts. Account requests use HTTPS, and the server verifies Google tokens before reading or changing account data. We use information received from Chrome APIs only to provide the extension's features, consistent with the Chrome Web Store User Data Policy's Limited Use requirements.

Changes to this policy

If the extension’s data practices change, this policy and the Chrome Web Store disclosures will be updated before the new practices take effect. The date at the top of this page identifies the latest revision.