Legal

Privacy Policy

This Privacy Policy explains how data collected via the Beatair mobile app is used.

Last Updated 31.07.2026

1. Information We Collect

To provide our service, we may process the following data:

  • Location Data: Beatair may use your live location so you can join voting in the venue where you are physically present. This is used for check-in validation and is not kept for continuous tracking.
  • Music Platform Data: The app may integrate with Spotify and YouTube API Services for music discovery, playlist display, venue playback, and voting. Depending on the feature, this may include search queries, playlist identifiers, public content metadata, anonymized listening insights, or access tokens.
  • Device Information: Technical data such as device identifier and IP address may be processed for security and performance.
  • User Content: Messages sent through chat features may be stored to support matching and communication. Supported clients may optionally send supported chat content in encrypted form.

2. YouTube API Services Notice

Beatair uses YouTube API Services. When YouTube-powered features are used, Beatair may send search terms, playlist IDs, track IDs, or other identifiers needed to retrieve public metadata such as titles, channel names, thumbnails, durations, and playlist contents.

Google OAuth user data: When a venue owner chooses Connect YouTube, Beatair requests the owner’s basic Google profile (name and email), YouTube channel ID and title, YouTube playlists and playlist items, and authorization to create playlists and add videos. Beatair uses this data only to identify the linked channel; display, select, and play its playlists; and create playlists or add videos when the owner requests a conversion. OAuth access and refresh tokens, granted scopes, and linked-channel identifiers are stored in access-controlled server storage and transmitted over TLS while the connection is active. Beatair does not sell Google user data, use it for advertising, or share or transfer it except to Google APIs and infrastructure providers required to deliver these features, or when legally required. Disconnecting YouTube in the dashboard deletes the stored Google OAuth tokens and linked-channel metadata. Users may also revoke access from Google Account permissions or request account deletion under Section 6.

Beatair’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google data handling is described in the Google Privacy Policy , and YouTube-specific use is governed by the YouTube Terms of Service.

3. Data Protection and Security

Beatair uses the following technical and organizational data protection mechanisms to protect sensitive data, including Google user data and OAuth credentials, against unauthorized access, alteration, loss, or disclosure.

  • Encryption in transit: Connections between supported Beatair apps or browsers, Beatair servers, and Google APIs use HTTPS/TLS.
  • Protected server-side storage: Google OAuth client credentials, access tokens, refresh tokens, and linked-account metadata remain in access-controlled server-side storage and are not returned to public clients. Application secrets are kept in restricted server configuration rather than source code or browser storage.
  • Least-privilege access controls: Authentication, authorization, and role checks limit sensitive-data access to the service components and authorized personnel that need it to operate or support the requested feature. Administrative server access is restricted and credentials can be revoked or rotated.
  • Log and response protection: OAuth access tokens, refresh tokens, client secrets, and full authorization responses are excluded from normal public API responses and are not intentionally written to routine application logs.
  • Ephemeral location processing: A user’s live coordinates are processed only for the active nearby-venue or check-in request. They are not added to the user profile and Beatair does not maintain a continuous user location history. Venue coordinates saved by a venue owner belong to the venue profile and are handled separately.
  • Optional encrypted chat: Where a supported client enables encrypted chat, supported text or image content is encrypted before upload and the server stores the resulting ciphertext or encrypted file. This protection is optional; ordinary chat content may be stored without client-side encryption and remains protected by authenticated access controls.
  • Data minimization and deletion: Beatair requests only the Google scopes needed for the visible feature. Disconnecting YouTube deletes stored Google OAuth tokens and linked-channel metadata; users can also revoke access in their Google Account.
  • Security maintenance and response: Beatair applies security updates, reviews suspected unauthorized access, and revokes or rotates affected credentials when necessary. If a breach creates a legal notification obligation, affected users and authorities are notified as required by applicable law.

4. How We Use Information

  • Connect you to the correct venue playlist.
  • Protect voting integrity and prevent abuse.
  • Enable interaction through features like Beetle and Chat.
  • Provide venue owners with anonymous aggregate insight on music preferences.

5. Sharing with Third Parties

Personal data is not sold to third parties for marketing without consent, except where legally required. Public profile details such as username and avatar may be visible to other Beatair users in the same venue.

6. Retention and Account Deletion

Google OAuth tokens are retained only while the account connection remains active and are deleted when YouTube is disconnected. Live user coordinates used for nearby-venue or check-in requests are not retained as a user location history. Other data is retained only as long as needed for the purposes described in this policy, security, or legal obligations. Users may delete their account and related data via in-app settings; following a deletion request, account data is removed permanently from our systems within 30 days, unless a longer period is legally required.

7. Contact Information

For privacy, compliance, or support questions, contact us at destekbeatair@gmail.com or visit https://beatairapp.com/support.