How we collect, use, and protect your information
Welcome to BeatOps ("we," "our," or "us"). BeatOps is a beat upload automation platform that helps music producers distribute their beats across multiple platforms including YouTube, BeatStars, and SoundCloud.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. Please read this policy carefully. By using BeatOps, you agree to the collection and use of information in accordance with this policy.
When you create an account, we may collect:
When you use our service, we process:
When you connect your YouTube account, we access:
We automatically collect certain information when you use our service:
Important: BeatOps uses YouTube API Services. By using our YouTube integration features, you agree to be bound by the YouTube Terms of Service.
Through the YouTube API, BeatOps accesses:
We use YouTube API access solely to:
Regarding YouTube data:
You can revoke BeatOps' access to your YouTube account at any time:
Upon revocation, we delete your stored OAuth tokens and YouTube channel information. Previously uploaded videos remain on your YouTube channel (we do not delete content from YouTube).
BeatOps does not share, transfer, or disclose Google user data to any third parties, except in the following limited circumstances:
We do not:
BeatOps' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In addition to this Privacy Policy, your use of YouTube features is also governed by the Google Privacy Policy.
You can connect YouTube in two ways. By default BeatOps connects using its own Google application, and you do not have to provide anything. Alternatively you can create your own Google Cloud project and have BeatOps use those credentials instead ("Bring Your Own Key", BYOK).
Google's sign-in exchange requires the application's client secret. A secret inside a downloaded app is not a secret, so that exchange runs on our server, which holds ours. This is the one part of connecting YouTube that does not happen entirely on your machine.
~/.beatops/credentials/youtube_client_config.json (encrypted)When using BYOK, you are responsible for:
When using BYOK, BeatOps tracks your YouTube API quota usage locally to help you monitor consumption. This data is stored in your local database and is never transmitted to our servers.
You can remove your BYOK credentials at any time via Settings > YouTube API Credentials > Remove. This deletes the encrypted credential file from your computer. Your YouTube connection is removed with it; reconnecting afterwards uses the default BeatOps application.
You can connect SoundCloud in two ways. By default BeatOps connects using its own registered SoundCloud application, and you do not have to provide anything. Alternatively you can register your own application at soundcloud.com/you/apps and have BeatOps use that instead, which requires a SoundCloud Artist Pro subscription.
SoundCloud treats every application as confidential, meaning an application secret is required to obtain a token. A secret inside a downloaded app is not a secret, so the sign-in exchange runs on our server, which holds ours. This is the one part of connecting SoundCloud that does not happen entirely on your machine.
~/.beatops/credentials/soundcloud_client_config.json (encrypted)When using SoundCloud with BeatOps, you are responsible for:
You can disconnect SoundCloud at any time via Settings > Connected Accounts > Disconnect, which deletes your OAuth tokens from your computer. If you configured your own application, you can remove those credentials via Settings > API Keys > SoundCloud API Credentials > Remove.
We use the information we collect to:
We use the following third-party services:
For video uploads and playlist management. See Section 3 for details.
For image search functionality. When you search for images, we send search queries to SerpAPI. SerpAPI's privacy policy is available at serpapi.com/privacy-policy.
For subscription payments, we use Stripe as our payment processor. Stripe is PCI DSS Level 1 compliant, the highest level of certification available in the payments industry.
All payment card information is handled directly by Stripe and never touches our servers. For more information about how Stripe handles your payment data, see Stripe's Privacy Policy.
We do not send marketing emails without your consent. You will never be subscribed to promotional emails without explicitly opting in.
Our website is hosted on Cloudflare Pages for security and performance.
Everything the app asks our own server for runs on Fly.io, in their Amsterdam (EU) region: licence checks, publish counts (section 5.10), update checks (section 5.9), the SoundCloud sign-in exchange (section 3.8) and the feedback form. Fly.io hosts this on our behalf as a processor and does not use the data for its own purposes. Their privacy policy is available at fly.io/legal/privacy-policy.
To identify and fix software errors, BeatOps sends anonymous error reports to Sentry when errors occur in the desktop application.
Anonymous error reports including stack traces, application state, and action breadcrumbs. File paths, usernames, email addresses, beat names, API credentials, and IP addresses are automatically removed before transmission.
Error reporting is enabled by default. You can disable it at any time in Settings. To disable error reporting, go to Settings and turn off the Error Reporting toggle. Changes take effect on the next application restart.
Error reports are retained for 90 days and then automatically deleted.
For more information, see Sentry's Privacy Policy.
To understand how visitors use our website, we use Umami Cloud, a privacy-focused analytics service.
Umami does not use cookies, does not track users across websites, and does not collect personal information. Because Umami does not use cookies or collect personal data, no consent banner is required under GDPR for website analytics.
Anonymous pageview counts, referrer URLs, browser type, and country (derived from IP address, which is not stored). We also collect anonymous, aggregated interaction events (such as how far visitors scroll through a page and which links and buttons they click) to understand which content is useful. These events contain no personal information and are not linked to any individual.
Website analytics applies only to beatops.io. The BeatOps desktop application does not track website-style analytics.
BeatOps can optionally send anonymous usage statistics to help us understand how the app is used and which features to prioritize.
Usage analytics is disabled by default. It is only enabled if you explicitly opt in during setup or in Settings.
Analytics data is stored in a Supabase database. Each record contains only the fields listed above. Data is retained for up to 1 year and then automatically deleted. You can disable analytics at any time in Settings, which stops all future data collection immediately.
When the app starts it sends a small, anonymous update-check ping so we can see which versions and operating systems are in active use and prioritize support and fixes accordingly.
That is all. The ping contains no machine ID and no identifier of any kind, so it cannot be linked to you or your device, and it is never combined with any other data. Because it is fully anonymous and cannot single out an individual or device, it is not personal data and does not require consent. The app sends at most one ping per 24 hours, and only aggregate counts (grouped by version and operating system) are ever read.
The free plan includes a fixed number of publishes per platform, counted once for good rather than per week. To make that limit real, the app checks with our server just before each publish and the server keeps the count. We do this to enforce the limits of the plan you are on, and to prevent those limits being circumvented, for example by reinstalling the app to reset a local counter.
Your passwords are never sent to us, and neither are your OAuth tokens: the app looks up the account ID on your own machine and sends only that, so your BeatStars login stays local. The one exception is connecting SoundCloud with the BeatOps application, where the sign-in exchange runs on our server because SoundCloud requires an application secret for it. Those tokens are passed straight back to your machine, not stored and not logged, and they are never used for the publish counts described here. See section 3.8. The installation token is created the first time the app reaches our server and is stored, encrypted, on your machine. It is random: not derived from your name, email, account or hardware, and reinstalling the app simply creates a new one.
Publishes on a paid plan are recorded in the same pseudonymized way, and are never used to block you: paid limits are applied inside the app. We record them so we can tell whether the product is actually being used, which is what tells us where to improve it. For a paid account we also keep a link between the hashed subscription and the hashed platform account, so we can understand how people move from the free plan to a paid one. We use this only as aggregate insight, not to single you out.
We rely on performance of our contract with you (Article 6(1)(b) GDPR) to apply the plan you chose, and on our legitimate interest in preventing abuse (Article 6(1)(f) and Recital 47) to stop those limits being circumvented. This is not advertising or profiling, and we do not track you across sites or apps. The only thing stored on your device for this is the installation token described above; it is strictly necessary to provide the free publishes and to protect your own count against abuse, so it does not require consent.
Because the free allowance is a lifetime one, these counts are kept indefinitely: erasing them by default would simply hand out a new allowance and there would be no limit left to enforce. The data is stored on servers in the EU (Amsterdam). You can still exercise your rights over this data, including erasure, by writing to privacy@beatops.io; we assess and handle those requests individually.
For uploading your beats to your own SoundCloud account. Unless you registered your own SoundCloud application, the sign-in exchange runs on our server, which holds the application secret SoundCloud requires. We do not store or log the resulting tokens. See section 3.8 for what this does and does not involve. SoundCloud's privacy policy is available at soundcloud.com/pages/privacy.
We implement appropriate security measures to protect your information:
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
You have the right to:
You can request deletion of your data in the following ways:
We will process deletion requests within 30 days and confirm completion via email.
BeatOps is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@beatops.io