GenresCountriesHow it worksSupportContribute

TheMetalNet

Q&A
Terms of ServicePrivacy Policy
TheMetalNet© 2026An independent project. Not affiliated with or endorsed by any band, label, or streaming platform.
Terms of Service

Privacy Policy

Last updated 3 September 2026

01

Overview

This Privacy Policy explains what TheMetalNet (the “Service”) collects, why, who we share it with, how long we keep it, and the choices you have. You can browse without an account; signing in adds features that require a persistent identity.

The data controller is Solaris Endeavors Ltd, a company registered in Israel (“Solaris”, “we”, “us”). You can reach us at [email protected] or through the support page. We aim to respond to formal privacy or legal requests within 30 days.

We do not sell or rent personal information, we do not “share” it as the CPRA defines that term, we do not use it to serve advertising, and we do not track you across other websites.

02

Summary

  • Browsing is open to everyone, at any age. No account, no name, no email.
  • Accounts are 16+. Creating an account, rating, suggesting corrections, and contributing are intended for users 16 or older.
  • We host no music. Audio and video stream from YouTube and Bandcamp, and only once you press play. Album cover thumbnails are cached and served by us so your browser never has to contact the archives they came from; band photographs load from Wikimedia.
  • We measure how the Service is used, on our own servers.Page views, how long a page held you, where you clicked, and what broke — all of it written to our own database. We removed every third party analytics provider we used to embed. See Analytics and monitoring.
  • Session recording is opt in, and self hosted.If you agree, your visit is recorded — including the galaxy itself — so we can see where the interface confuses people. The recording is stored on a server we run, never a vendor's. It stays off until you say yes, and you can withdraw at any time.
  • No ad tracking, no data sales. Nothing we collect is used for advertising or sold to anyone.
  • You can delete your account yourself, at any time, from your settings. See Your rights and choices.
03

Scope and consent

This Policy covers the TheMetalNet website and our communications with you. Third party services we use or link out to — YouTube and Bandcamp, our payment provider, Wikipedia, streaming services, artist and label sites, and others — have their own privacy policies, and this Policy does not govern them.

Where consent is the basis for something — non essential cookies and analytics — we ask for it separately and up front, and you can withdraw it at any time without losing access to the rest of the Service.

04

When you browse without an account

Most of the experience works as a guest, at any age. We still record coarse usage signals so we can understand which parts of the app are used and fix problems.

  • Two random identifiers are created in your browser's local storage the first time anything is measured: one for the browser, which lasts until you clear site data, and one for the visit, which is replaced after thirty minutes of inactivity. Neither is tied to your name or email unless you sign in, and neither is derived from anything about your device.
  • Product events record what happened (for example that a band page opened, or that a preview played) and the path you viewed inside the app. Event names and a small, schema checked set of properties are stored; oversized properties are rejected.
  • Moving around the galaxy is recorded the same way: which part of the map you opened, how long you stayed, and whether the map failed you — a tap that hit nothing, a search that found nothing, a device the scene ran badly on. It is the only way we can see the map at all, because it is drawn rather than built out of a page. What youtype into the search box is never sent: we record how many characters it was and whether you opened one of the results, and the words themselves stay in your browser.
  • We record each page you open, how long it held your attention while the tab was in front, how far down it you scrolled, and which page you left from. Time spent in a background tab is not counted as attention.
  • We record where you click: the position within the window as a proportion of its size, and — where the thing you clicked is a control rather than text — its short name, such as “Save band”. That is what a heatmap is made of. Text long enough to be something you wrote is never stored, and clicks inside the sign in and support forms record a position and nothing else.
  • We record errors that happen in your browser — the message, where in our code it came from, and the page you were on — so a fault that only happens on one browser or one device is visible to us at all.
  • If you arrived from another website, we store only that site's hostname, on the first visit of a session, plus any campaign parameters that were in the link — including the click identifier an advertising network adds, which is how a paid click is told apart from an ordinary search result. The full referring address is discarded before anything is written down, because a full URL can carry personal information. We also keep a note of what brought you here the first time, so that a site or a campaign can be credited for a reader who comes back; it is the same handful of facts, kept once rather than per visit, and it is deleted on the same schedule as everything else here.
  • We record a broad device class (desktop, mobile, or tablet) inferred from your browser information, and a country inferred by our network edge. We do not build a fingerprint of your hardware, and we do not store your IP address in our own analytics tables.
  • Our hosting, network, and security providers process standard technical and log data — IP address, browser and device type, request paths, and timestamps — to deliver and secure the Service. We also use your IP address transiently to rate limit abusive traffic.
  • Automated traffic such as crawlers and bots is identified and dropped before any event is saved.
  • We keep it until we no longer need it, or until you ask us to erase it. See Retention and deletion.

None of the above is session recording, and none of it needs your agreement first: it is our own measurement of our own site, it is never shared, and it is never combined with anything from anywhere else. Recording your session is a separate thing, described in Analytics and monitoring, and it happens only if you say yes.

05

When you create an account

Signing in lets you save bands, build personal galaxies, rate releases, suggest catalog corrections, and sync across devices. You sign up with an email address and a password. If you forget it, we email a one time link that lets you set a new one. The following information can be associated with your account:

  • Email address and, when ownership has been proven, a verification timestamp
  • Display name, username, and short bio you choose
  • Profile image you upload, stored on our servers and served publicly from your profile
  • Preferences stored as structured settings (for example view mode)
  • Your saved likes and galaxy collections, including any you choose to share by link
  • Ratings you give to bands and albums, one per account per subject
  • Catalog corrections you suggest, including your note and the reviewer's outcome
  • Product events linked to your account instead of only the anonymous browser id

Passwords are never stored in plain text. We keep a one way hash produced with scrypt. Password reset and email change flows use single use tokens, valid for 15 to 30 minutes; only a hash of each token is stored. Requests are rate limited per address and per IP to slow abuse.

Sessions are represented by an HTTP only, SameSite=Lax cookie signed on the server, marked Secure over HTTPS. It lasts about one week, refreshes as you keep using the Service, and can be invalidated immediately when you change your password or sign out everywhere. The cookie does not contain your email or password.

06

Ratings and catalog corrections

Signed in users can rate bands and albums from 1 to 10, and can propose corrections to catalog fields with a short note explaining the change and its source. Both are tied to your account, deliberately: a rating is one vote per account, and a reviewer weighing a claim about a band needs to know who stands behind it.

Ratings are published only in aggregate — an average and a count — never as your individual score attached to your name. Correction proposals are visible to our reviewers, together with your account, the value you proposed, and your note. Accepted corrections change the catalog; the resulting catalog value is public, and it is not labelled with your name.

07

Contributions and payments

Voluntary contributions are processed by PayPal. You choose a preset tier or a custom amount between $1 and $1,000. Payment happens on PayPal’s own surface and we never receive or store your card number, bank details, or PayPal password. We keep a record of the amount, currency, tier, status, PayPal’s processing fee, and the PayPal order and payment identifiers needed for accounting, receipts, and support. If you are signed in, the contribution is linked to your user id. If you pay while signed out, we store the email address you provide before checkout so we can send a receipt and answer questions about the payment.

Contributions support platform development, hosting, and maintenance. They are optional, give you no goods, services, or perks in return, and are non refundable except where the law requires. PayPal collects your payment and billing details and processes them under its own privacy policy; PayPal also emails you a receipt for each payment, and may share the name and email address on your PayPal account with us so we can identify and support the payment.

08

Support and email

When you contact support, we store the name and email you submit, the category and subject you choose, and your message. If you are signed in, the ticket is also linked to your account. The form attaches lightweight diagnostics — your browser user agent string, the page you were on, and the build identifier — used only for troubleshooting.

We send transactional email for verification, passwordless sign in, email changes, support acknowledgements and replies, and similar operational messages, through a third party email provider. Each send is logged internally with the recipient address, purpose, subject, delivery status, and any error, so we can prove whether a message you were expecting actually left our system.

We do not currently run a marketing mailing list. If we introduce one, it will be opt in, will be about our own features, and every message will carry a one click unsubscribe.

Some pages link to an external feedback form hosted by Google Forms. Following that link takes you to Google, and anything you submit there is handled by Google under its own privacy policy, not by us.

09

Analytics and monitoring

We measure how the Service is used so we can improve it. None of it is used for advertising, and none of it is sold.

We used to embed four third party analytics providers. All four are gone. Contentsquare (formerly Hotjar), Google Analytics, PostHog and Plausible have been removed from this site, along with the cookies and browser storage they set. What replaced them is our own measurement, written to our own database, and one self hosted session recorder.

  • Our own measurement. Page views, attention, scrolling, clicks, errors and product events, written straight to our database, as described in When you browse. No third party is involved at any point, and nothing leaves our servers. This is the source of nearly everything we know about how the site is used.
  • OpenReplay for session recording, only if you agree. It is open source software that we run on our own server: the recording is uploaded to us, and no analytics vendor receives it or has access to it.
    A recording reconstructs your visit inside our interface — what was on the page, what you clicked, what you scrolled, how the page responded, and, because our galaxy is drawn rather than laid out as a page, images of the map itself. That last part is the reason we changed tools: no other recorder could see the main thing this site is.
    It is not a recording of your screen, your other tabs, your camera or your microphone, and it cannot see anything outside this site. What you type is not captured: every input field is excluded by default, email addresses, numbers and dates are masked in the page text, and the sign in and support forms are marked so that they and everything inside them are obscured entirely. Network activity is recorded as addresses and status codes with the query string stripped, never as the contents of a request or a response. It sets nothing until you agree, and withdrawing stops it.
  • Sentry for error and performance monitoring. When something breaks, it receives the error and its stack trace, the page it happened on, and technical context about the browser and request. A small sample of requests is traced for performance. We do not use it for analytics, and we do not enable its session replay.

Album art is served from our own domain: we fetch it from the Cover Art Archive once, cache it, and serve it to you ourselves, so your browser never contacts them and they never see your IP address. Our fonts are served from our own domain too, so no font provider sees your visit. Band photographs load directly from Wikimedia, which therefore sees your IP address and browser information as part of serving them, under its own policy.

Players. Audio and video play in embedded players from YouTube (operated by Google) and Bandcamp. Neither loads while you are simply reading: nothing is requested from either until you press play, and until then they see nothing of your visit at all. When you do press play, that provider receives your IP address and browser information and may store data in your browser in order to play the content, under its own policy. We use YouTube's privacy-enhanced domain, youtube-nocookie.com, which limits how embedded views are used to personalize YouTube and advertising. This does not prevent all data collection or browser storage. We receive nothing back about what you played, and no player is connected to any account of yours unless you signed into that provider yourself.

10

Cookies and local storage

We use cookies and browser storage for two things: keeping you signed in, and measuring how the Service is used. We set no advertising cookies and no cross site tracking cookies.

  • Essential — session cookie. Set when you sign in. HTTP only, SameSite=Lax, Secure over HTTPS, about one week. Without it you cannot stay signed in.
  • Essential — admin session cookie. The same, for operator accounts only. Ordinary visitors never receive it.
  • Essential — consent cookie. Records the answer you gave to the question below, so we do not have to ask again. Named tmn_consent, it holds one word — granted or denied — and the date you chose, SameSite=Lax, Secure over HTTPS, six months. Remembering that you declined is what honours the refusal, so this one needs no consent of its own. If you are signed in we keep the same answer on your account, so it applies on your other devices too.
  • Essential — arrival cookie. Named tmn_acq, written on the first page you open and deleted again within seconds. It holds the site you arrived from, the page you landed on, and any campaign name in the link you followed — the same three facts described under Analytics, handed from the page request to the measurement request that follows it, because a visit that leaves before our JavaScript runs would otherwise be recorded as having come from nowhere. It contains no identifier of any kind, nothing derived from your address or your device, and nothing that can be joined to anything else. SameSite=Lax, Secure over HTTPS, thirty minutes at the outside.
  • Essential — local storage. A copy of that consent answer for browsers that block cookies, a random analytics identifier, your saved view preferences, and flags recording which one time hints you have already seen. These stay in your browser.
  • Session recording — OpenReplay. Browser storage holding an identifier for the recording, set only after you agree and read only by our own server. No third party analytics cookie is set by this site, by anyone, any more.
  • Players — YouTube and Bandcamp.When you press play, the provider's embedded player may store what it needs in your browser in order to play the content. This is not set by us and not until you ask for a track: reading the catalog never loads either player. We use YouTube's privacy-enhanced domain, which does not set Google's advertising identifier.
  • Marketing. None, in any category, from any provider.

Essential cookies do not require consent. The non essential storage — the session recorder's — is set only after you agree, and we ask everyone, not only visitors in regions whose law requires it. Until you answer, recording stays off; declining keeps it off permanently. You can change or withdraw your choice at any time using Cookie settings in the footer of any page, which states the choice currently in force and lets you switch it; withdrawing reloads the page so collection actually stops rather than merely being marked as unwanted. We ask again after six months, or sooner if the tools we use change materially.

You can also block or clear cookies in your browser: the Service will treat you as a guest, and the catalog stays fully browsable either way. Nothing behind the consent question is needed to read anything on the site.

11

Why we use your information, and our legal bases

If you are in the EEA or UK, the GDPR requires us to name a legal basis for each purpose. Ours are:

  • Running, delivering, and securing the Service— technical and log data, essential cookies. Legitimate interests, and performance of the terms you accept by using features you ask for.
  • Providing your account and its features— email, profile, saves, galaxies, ratings, suggestions. Performance of a contract with you.
  • Session recording— OpenReplay, on our own server. Your consent, asked of everyone rather than only where the law requires it, and withdrawable at any time.
  • Aggregate measurement and improving the Service— our own page views, attention, clicks, errors and product events, and error monitoring. Legitimate interests in understanding and fixing a product we give away: it is first party, it is never shared or sold, and it is never combined with data from anywhere else. You can object at any time, ask us to erase it, and switch it off for your browser entirely with Cookie settings in the footer.
  • Answering support requests and sending operational email— ticket and message content, email log. Performance of a contract, and legitimate interests in answering you.
  • Processing voluntary contributions— payment confirmation data. Performance of a transaction, and legal obligations for tax and accounting.
  • Preventing abuse and keeping users safe— technical data, rate limits, audit logs. Legitimate interests, and legal obligation.

Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time using the contact details above.

12

Administration and security

Operator accounts use an additional signed session cookie and, where enabled, WebAuthn passkeys as a second step. Passkey public keys and metadata are stored; private keys remain on your device and are never sent to us.

Sensitive admin actions, including failed sign in attempts, are written to an audit log for security investigation. This logging applies to the admin surface, not to ordinary browsing analytics.

We use reasonable technical and organisational measures to protect your information: encryption in transit, encryption at rest for third party access tokens, one way password hashing, single use short lived sign in tokens, rate limiting, and a strict content security policy. No method of storage or transmission is completely secure, so we also keep what we collect to the minimum the Service needs.

13

Data we show that is not about you

Most of what the Service displays is factual music information, not personal data about our users. Our sources:

  • Open music metadata databases. We host copies of public, openly licensed music-metadata datasets, released into the public domain under CC0 1.0. Such a dataset can include limited personal data about the volunteer editors who compiled it, such as usernames and edit history, which we use only to operate the Service and to handle related requests.
  • Wikipedia / Wikimedia. Descriptive text under CC BY-SA, credited to the article it came from. Photographs only where the file is hosted on Wikimedia Commons under a licence permitting reuse, credited to the photographer and the named licence beneath the image.
  • YouTube and Bandcamp. Audio and video, played in their own embedded players and subject to their privacy policies.
  • Artists, labels, and rights holders. Names, images, and biographical facts, shown for factual identification.

If you are a musician listed here

The catalog includes a page for each person recorded as a member of a band, built from public music-metadata sources rather than from anything you gave us. Where those sources record it, such a page can show your name, the country and city associated with you, the years you were active, the bands you played in, and a biography drawn from Wikipedia. We did not collect this from you directly, so this paragraph is the notice the GDPR requires us to give you about it.

  • Where it comes from: publicly available music-metadata databases and Wikipedia. We add no private information of our own and we do not attempt to find any.
  • Why we publish it: our legitimate interest in operating a free reference work about metal music, and the public interest in accurate information about published creative work. We do not use it for advertising, we do not sell it, and we do not profile anyone.
  • What you can do:ask us to correct anything inaccurate, or to remove your entry altogether. A removal is permanent — we keep a record of the request itself so that later refreshes of our data cannot quietly put the entry back.

Write to [email protected] or use the support page. You do not need to give a reason, and you can also complain to your data protection authority — see Your rights and choices.

14

How we share information

We do not sell or rent your personal information. We share it only with:

  • Service providers who host, deliver, secure, measure, and support the Service — our hosting and network providers, PayPal for payments, our transactional email provider, and the analytics and error monitoring providers named in Analytics and monitoring— under arrangements that require them to protect your data and use it only to provide their service to us.
  • YouTube and Bandcamp, when you press play — the provider serving that track receives your IP address and browser information in order to play it, under its own privacy policy.
  • Authorities or others where the law requires it, to meet legal process, enforce our terms, or protect users, the public, or Solaris.
  • A successor, in the event of a merger, acquisition, financing, or sale of assets, under this Policy.

Anything you choose to publish is shared by you, not by us: a public share link exposes the collection you shared to anyone holding the link, and your profile page shows the display name, username, bio, and image you set.

15

International data transfers

Solaris is based in Israel, which the European Commission recognizes as providing an adequate level of data protection for transfers from the EU and, separately, the UK. Our service providers may process data in other countries, including the United States. Where personal data leaves the EEA or UK, we rely on that adequacy decision or on safeguards such as the EU or UK Standard Contractual Clauses.

16

Retention and deletion

We keep data for as long as it serves the purpose we collected it for. We would rather say that plainly than publish a timetable we do not keep, so this section names a period only where one is real: fixed by law, or by how the server stores something. Whatever the period, you can ask us to erase your data, or delete your account yourself, at any time.

  • Account data is kept while your account exists, and is deleted when you delete the account.
  • Sign in tokens expire after 15 minutes and are single use.
  • Analytics (visits, page views, clicks, errors, console messages and product events) is kept for as long as the site runs. There is no automatic deletion: these are counts of how the site is used, and a history that keeps being erased cannot answer whether anything we changed helped. On account deletion the link to your account is removed immediately, leaving rows that point at no one, and you can ask us to erase yours at any time.
  • Session recordingsare held by the recording server we run, and are deleted on that server's own retention setting.
  • Server and security logsare rotated by the server on a short cycle — web server logs within about two weeks — and system logs are kept until their storage is reclaimed.
  • Support tickets and the email log are kept so we can reference past conversations and prove delivery. We do not delete them on a timer; you can ask us to erase a conversation and we will unless we are required to keep it.
  • Contribution recordsare kept for at least 7 years, as tax and accounting law requires. They carry the payer's email independently of any account.
  • Admin audit log entries are kept for security investigation and are not linked to ordinary user analytics.

What deleting your account does.Deleting removes your user record, and the database removes everything that hangs off it: your profile and uploaded image, your passkeys, your saves, your ratings, your suggestions, and every saved galaxy — including any share links other people are holding, which stop working. Two things deliberately survive, and you should know about both. First, a record of the deletion is written to our support queue before the account is removed, holding your name, email, when the account was opened, how many bands it had saved, and the reason you gave; it exists so we can answer questions about a deletion afterwards, and it is kept under the support retention above. Second, contribution records are kept for the statutory period described above. You can ask us to delete the support record too, and we will unless we are required to keep it.

17

Your rights and choices

Some things you can do yourself, immediately, without asking us:

  • Delete your account and its data from your settings.
  • Change your email, display name, username, bio, and profile image.
  • Sign out everywhere, invalidating every existing session.
  • Browse signed out, so nothing is linked to an account.
  • Clear site data in your browser to remove the anonymous analytics identifier.
  • Change or withdraw your analytics cookie choice.

EU / UK. If you are in the EEA or UK, you can access your data and get a copy, correct it, erase it, restrict or object to certain uses, get it in a portable format, and withdraw consent at any time without affecting processing already carried out. You can also complain to your local supervisory authority, or the ICO in the UK. We may need to verify your identity before we act on a request, to protect your data.

California. If you are a California resident, you can know what we collect, access it, delete it, correct it, and not be treated differently for exercising these rights. The categories we collect, our sources, our purposes, and who we disclose to are set out in the sections above, and retention is in Retention and deletion. We do not sell or share personal information, and we do not knowingly sell or share the personal information of anyone under 16, so there is nothing to opt out of. You may use an authorized agent to submit a request, and we will verify it.

Israel. If you are in Israel, you have rights under the Protection of Privacy Law, 5741-1981, as amended, including to review the personal information we hold about you and to ask us to correct or delete information that is wrong, incomplete, or out of date.

Outside these regions you may still have rights to access, correct, or delete personal information under applicable law. We honor valid requests consistent with the law that applies to you. To exercise any right that is not self serve above, contact us through the support page or at [email protected].

18

Children

TheMetalNet is a general audience service for music lovers of all ages, not one aimed at children. Browsing is open to everyone, requires no account, and collects no data that identifies a child beyond the limited technical data described above. We do not build advertising profiles, track across sites, or sell anything we collect. Some catalog content is mature by nature, so viewer discretion is advised.

Creating an account, rating, suggesting corrections, and contributing are intended for users 16 or older, or the minimum age required in your country if higher. We do not currently run a technical age check at sign up, so we rely on this policy and on you providing accurate information.

United States (COPPA). We do not knowingly collect personal information from children under 13. We never require anyone to provide personal information in order to browse.

Parents and guardians. If you believe a child has given us personal information, contact us using the details above and we will check and delete it promptly.

19

Changes to this policy

This document describes the product as built today and will change as it evolves. We will revise the “Last updated” date whenever it changes, and describe material changes in the app or by email where appropriate. For material changes to how we use your personal data, we will seek fresh consent where the law requires it. We will not apply material changes retroactively.

Questions about data handling can be sent through the support page or to [email protected].

Sections

  1. 01Overview
  2. 02Summary
  3. 03Scope and consent
  4. 04When you browse without an account
  5. 05When you create an account
  6. 06Ratings and catalog corrections
  7. 07Contributions and payments
  8. 08Support and email
  9. 09Analytics and monitoring
  10. 10Cookies and local storage
  11. 11Why we use your information, and our legal bases
  12. 12Administration and security
  13. 13Data we show that is not about you
  14. 14How we share information
  15. 15International data transfers
  16. 16Retention and deletion
  17. 17Your rights and choices
  18. 18Children
  19. 19Changes to this policy