Privacy

Privacy Policy

Last updated 31 Aug 2026

The short version: boxofrules.com uses analytics to understand how the site is doing. Those tools only run after you accept the cookie notice. Box Of Rules is one person (James H. Gordy), who is the data controller for this policy. We never sell your data, and we collect no personal information beyond what you choose to send.

Your choice

When you first visit, a notice asks whether to allow analytics cookies. Essential cookies (staying signed in, form protection, Cloudflare) need no consent and are the only ones set until you choose. Nothing in the analytics or measurement section below loads until you choose Accept all. If you choose Essential only, Google Analytics stays in cookieless mode (aggregate, anonymous estimates only) and Microsoft Clarity and the Meta pixel do not load at all. You can change your mind by clearing this site's data in your browser, which brings the notice back.

Analytics and measurement

If you accept, we use the following to measure traffic and improve the site. None of them are used to sell anything about you:

These providers process data under their own privacy policies. We store a small flag in your browser to remember your accept or decline choice so the notice does not keep reappearing.

Newsletter

If you sign up to the mailing list, we store the email address you give us, and nothing else, so we can send you news about releases, plugin builds and shows. It is never sold or shared. Emails are delivered through Postmark (ActiveCampaign, LLC), which processes your address on our behalf to make the delivery under its own privacy policy; we don't use open or click tracking pixels on these emails.

Every email includes an unsubscribe link that removes you immediately (one click, no login, no questions) and supports your mail app's built-in one-click unsubscribe button. Unsubscribing stops all future emails at once; your address stays on our suppression side so we don't accidentally re-add it, unless you sign up again yourself. You can also just reply and ask, or use the contact form to have your address removed entirely.

Plugin usage data

Box Of Rules plugin builds that include usage reporting send small, anonymous usage events to boxofrules.com: things like "the plugin was launched", which major controls get used, and a roughly-hourly snapshot of how the plugin is configured (which channels are active and where the dials sit), with the plugin version, the operating system and its version, and which DAW is hosting the plugin and that DAW's version (for example "Logic Pro"). Each event also notes which channel that copy of the plugin was downloaded through (our own site, MuseHub, or the Mac App Store); that is a fact baked into the build itself, not something read from you or your machine. Which built-in (factory or artist) preset was loaded is counted by its name; these are our names, not yours; the names of presets you create yourself are never transmitted. Clicks on the links in the plugin's footer (Instagram, Spotify and so on) pass through the same counted redirects as the website's social links, described below. Events are queued on your machine and sent in a batch roughly once an hour.

From v1.3 of a plugin these events also cover which individual controls you reach for (the control's name and its new value, at most one reading per control per minute, and only when you move it yourself: changes made by automation or by loading a preset are not counted), how long the plugin's window and its own panels stay open, how many copies of the plugin are loaded, the sample rate, buffer size, channel count and latency the DAW reports, and the processor load and dropout count the plugin already displays to you in its SYS panel. None of that is new information about you. It is the same anonymous install telling us which parts of the plugin get used and whether it is running properly on the machine it is on.

This data contains no personal information, no audio, no file names and no way to identify you: the only identifier is a random ID the plugin makes up on first run, which links events from the same install without saying anything about who you are. That ID is shown to you, in the plugin's SYS panel as INSTALL ID, so that it is yours to use: quote it to us through the contact form and we can find everything that install has sent, erase it, or connect it to your account if you ask us to. IP addresses are not stored with events, and raw events are deleted or aggregated within 12 months. The first time you open a plugin build that reports usage (including after updating from an older build), it shows a one-off notice explaining this, with a link to this page and an opt-out button right there in the notice.

Usage reporting can be switched off at any time, either from that notice or later from the plugin's own settings (the "Send anonymous usage data" checkbox in the plugin's SYS panel, next to a PRIVACY link that opens this page). Switching it off sends one final opt-out signal, discards anything still queued but unsent on your machine, and after that nothing is ever sent again. On our side that opt-out signal marks everything your install ever sent, so it is stored as data from an opted-out install; the choice is shared across all Box Of Rules plugins on your machine. If you later tick the box back on, the plugin sends a single opt-in signal and reporting resumes. The plugin keeps working exactly the same with it off.

As well as the database above, totals from these events are counted in Matomo, the analytics software we run ourselves on our own server at stats.boxofrules.com. It is the same first-party system, not a third party: nothing goes to Google, Meta, or any analytics company, and the data never leaves our server. Because a plugin install is not a person, the install ID above is what identifies it there, which is exactly what lets us act on it when you quote it to us. Opting out erases that install from Matomo as well, not only from the database.

Patreon and Ko-fi supporters

Some plugin builds are perks for people who support Box Of Rules on Patreon or Ko-fi. To unlock them here, you can link your Patreon account to this site. When you do, Patreon asks for your permission and then tells us who you are on Patreon (your Patreon ID, name and email address) and whether you have an active membership to our campaign, and at which tier. We use that only to check your supporter status and hand you the right downloads. We don't see your payment details, we don't post anything to your Patreon account, and we never sell or share any of it.

You can unlink at any time from your Patreon account's connected apps (or ask us via the contact form and we'll remove the link from our side).

Ko-fi works differently: when you tip, join a membership tier or buy something on our Ko-fi page, Ko-fi notifies our server of the payment, and we store what it sends (your Ko-fi display name, the email you used there, the amount and tier, and any message you attached) so we can grant your supporter perks and keep honest records of who supported. Messages marked private on Ko-fi are never shown publicly. None of it is sold or shared, and you can ask us to remove your details via the contact form. Anything happening on Patreon or Ko-fi themselves is covered by their own privacy policies.

Embedded video

Videos do not load until you press play. When you do, the player is served by YouTube in privacy-enhanced mode (youtube-nocookie.com), and YouTube's own terms then apply to that playback.

Plugin downloads

The plugin pages read the public releases feed from GitHub to show the latest build and download links. That request is the same one your browser makes when you open the releases page on GitHub. Nothing about you or your session is sent. Downloads come straight from GitHub, under GitHub's privacy terms.

When you click a download button we also count the click ourselves: just "a download button was clicked", with the plugin, platform and page. The same bare tally covers presses of the audio-example play buttons on the plugin pages ("a sample was played", with the plugin and sample name). No IP address, no cookie and no identifier of any kind is stored with either, so we know which builds and sounds people want.

Streaming and social links

Links out to streaming platforms, Instagram, TikTok and Ko-fi take you to those services, which have their own privacy policies. We do not share any data with them. Some of these links pass through boxofrules.com on the way (for example boxofrules.com/spotify), where we count the click. Nothing more is recorded about you, and no IP address is stored.

Contact

If you use the contact form, we store the name, email address and message you send so we can read it and reply. Nothing else: no IP address, and it is never shared or used for marketing. The one exception is spam: if a message matches our blocklist (a known junk sender or phrase), it is kept aside from our inbox together with the IP address it was sent from, purely so repeat attempts from the same address can be stopped. Want a message removed afterwards? Just ask.

Questions about any of this? Use the contact form.

Back to Home