TheMetalNet

Privacy Policy

Privacy Policy

Last updated 29 July 2026

01

Overview

This Privacy Policy explains what TheMetalNet collects, why, how long we keep it, and the choices you have. It is written to match what the product actually does, not a generic template. The service is built around exploration: you can browse without an account, and signing in adds features that need a persistent identity on our side.

The data controller is Solaris Endeavors Ltd, a company registered in Israel (“Solaris”, “we”, “us”). You can reach us at contact@solaris-e.com or through the support page. We do not sell personal information, and we do not use it to serve advertising.

02

When you browse without an account

Most of the experience works as a guest, at any age. We still record coarse usage signals so we can understand which parts of the app are used and fix problems.

  • A random identifier is created in your browser's local storage the first time an analytics event is sent. It is not tied to your name or email unless you sign in.
  • Page visits record the path you viewed inside the app, not the full address of an external site you came from. If you arrived from another website, we store only that site's hostname on the first visit of a session.
  • We infer a broad device class (desktop, mobile, or tablet) from your browser information. We do not build a fingerprint of your hardware.
  • Our hosting and security providers process standard technical and log data — IP address, browser and device type, and timestamps — to run and secure the Service. We do not store your IP address in our own analytics tables, and we filter out automated traffic such as crawlers and bots before events are saved.

Where configured, a cookieless, privacy oriented analytics script (Plausible) loads alongside a first party events pipeline that records the same event names on our own servers. Neither is used for advertising or cross site tracking, and no non essential cookie is set for either.

03

When you create an account

Signing in lets you save bands, build personal galaxies, and sync across devices. You can sign up with an email and password, or without a password using a one time magic link sent to your email. The following information can be associated with your account:

  • Email address and, when applicable, a verification timestamp
  • Display name, username, and short bio you choose
  • Profile image you upload
  • Preferences stored as structured settings (for example view mode)
  • Your saved likes and galaxy collections, including any you choose to share publicly
  • Product events linked to your account instead of only the anonymous browser id

Passwords are never stored in plain text. We keep a one way hash produced with scrypt. Magic link and email change flows use single use tokens, valid for 15 minutes; only a hash of each token is stored. Requests are rate limited per address and per IP to slow abuse.

Sessions are represented by an HTTP only cookie signed on the server. It lasts about one week and can be invalidated immediately when you change your password or sign out everywhere. The cookie does not contain your email or password.

04

Contributions and payments

Voluntary contributions are processed by Polar, which acts as the merchant of record. You choose a preset tier or a custom amount between $1 and $1,000. We do not store full card numbers. We keep a record of the amount, currency, status, and the Polar checkout and order identifiers needed for accounting and support. If you are signed in, the contribution is linked to your user id. If you pay while signed out, we may store the email you provide at checkout.

Contributions support platform development, hosting, and maintenance. They are optional, give you no goods, services, or perks in return, and are non refundable except where the law requires. Polar collects your payment and billing details and processes them under its own privacy policy.

05

Support requests

When you contact support, we store the name and email you submit, the category and subject you choose, and your message. If you are signed in, the ticket is also linked to your account. The form may attach lightweight diagnostics such as your browser user agent string and the page you were on. These diagnostics are for troubleshooting only.

We send transactional email for verification, passwordless sign in, support replies, and similar operational messages. Sends are logged internally with recipient, purpose, and delivery status. We aim to respond to formal legal or privacy requests within 30 days.

06

Administration and security

Operator accounts use an additional signed session cookie and, where enabled, WebAuthn passkeys as a second step. Passkey public keys and metadata are stored; private keys remain on your device and are never sent to us.

Sensitive admin actions, including failed sign in attempts, are written to an audit log for security investigation. This logging applies to the admin surface, not to ordinary browsing analytics.

07

How we share information

We do not sell or rent your personal information. We share it only with:

  • Service providers who host, deliver, and secure the Service — including our hosting provider, Polar for payments, and our email provider — under arrangements that require them to protect your data and use it only to provide the service to us.
  • Authorities or others where the law requires it, to meet legal process, enforce our terms, or protect users, the public, or Solaris.
  • A successor, in the event of a merger, acquisition, financing, or sale of assets, under this Policy.
08

International data transfers

Solaris is based in Israel, which the European Commission recognizes as providing an adequate level of data protection for transfers from the EU and, separately, the UK. Our service providers may process data in other countries. Where personal data leaves the EEA or UK, we rely on that adequacy decision or on safeguards such as the EU or UK Standard Contractual Clauses.

09

Retention and deletion

  • Account data is kept while your account is active.
  • Analytics events are retained for product measurement and recommendation quality.
  • Support tickets are kept so we can reference past conversations.
  • Contribution records are kept for up to 7 years, as tax and accounting law requires.
  • Admin audit log entries are kept for security investigation and are not linked to ordinary user analytics.

You can request deletion or export of your account data through support. Some aggregated or de identified analytics may remain after deletion because it cannot be tied back to you.

10

Your rights

EU / UK. If you are in the EEA or UK, you can access your data and get a copy, correct it, erase it, restrict or object to certain uses, get it in a portable format, and withdraw consent at any time. You can also complain to your local supervisory authority, or the ICO in the UK. We may need to verify your identity before we act on a request.

California. If you are a California resident, you can know what we collect, access it, delete it, correct it, and not be treated differently for exercising these rights. We do not sell or share personal information, and we do not knowingly sell or share the personal information of anyone under 16. You may use an authorized agent to submit a request, and we will verify it.

Israel. If you are in Israel, you have rights under the Protection of Privacy Law, 5741-1981, including to review the personal information we hold about you and to ask us to correct or delete information that is wrong, incomplete, or out of date.

Outside of these regions you may still have rights to access, correct, or delete personal information under applicable law. We honor valid requests consistent with the law that applies to you. Other ways to limit what we hold:

  • Browse without signing in to minimize account linked data.
  • Clear site data in your browser to remove the anonymous analytics id.
  • Block cookies to prevent session based sign in (the app will treat you as a guest).
  • Contact support to correct profile information or ask for account deletion.
11

Children

TheMetalNet is a general audience service for music lovers of all ages, not one aimed at children. Browsing is open to everyone and collects no data that identifies a child beyond the limited technical data described above. Some catalog content is mature by nature, so viewer discretion is advised.

Creating an account and contributing are intended for users 16 or older, or the minimum age required in your country if higher. We do not currently run a technical age check at sign up, so we rely on this policy and on you providing accurate information. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us using the details above and we will review and delete it promptly.

12

Changes to this policy

This document describes the product as built today and will change as it evolves. We will revise the “Last updated” date whenever it changes, and describe material changes in the app or by email where appropriate. For material changes to how we use your personal data, we will seek fresh consent where the law requires it.

Questions about data handling can be sent through the support page or to contact@solaris-e.com.