Privacy Policy

BeatSync Privacy Policy

Effective date: August 12, 2026  |  Last updated: August 12, 2026

This Privacy Policy explains what information BeatSync (“BeatSync,” “we,” “us”) collects, why we collect it, how we store it, who we share it with, and the choices you have. It applies to the BeatSync web application at https://beat-sync.com and to the BeatSync companion app for iPhone and Apple Watch.

1. Information we collect

  • Account information. Your name, email address and age. Age is required to calculate your age-based maximum heart rate (220 minus age), which powers the app's safety alerts.
  • Heart-rate data. Heart-rate readings supplied by a source you explicitly connect: Google Health, or the BeatSync Apple Watch app.
  • Workout data. Workout type, genre selection, session start and end times, HIIT interval configuration, and the tracks matched to your session.
  • Device pairing data. If you pair the Apple Watch app, we store a device token and the device name you supply so the app can post readings to your account.
  • Usage analytics. Page views and feature interactions collected through Google Analytics, used in aggregate to understand how the app is used.

2. Google user data

BeatSync uses Google APIs. This section describes exactly which Google user data we access, why, and what we do with it.

2.1 Signing in with Google

If you choose “Sign in with Google,” we request the basic openid, email and profile scopes. We receive and store your Google account email address, your display name and your profile picture URL. This is used only to create and authenticate your BeatSync account.

2.2 Connecting Google Health

If you choose to connect Google Health, we request the single read-only scope https://www.googleapis.com/auth/googlehealth.health_metrics_and_measurements.readonly. We use it to read your most recent heart-rate data point. We request no write access and no other health data type.

2.3 How that data is used

  • • To display your current heart rate on your dashboard.
  • • To calculate a target song tempo and select Spotify tracks that match it.
  • • To trigger max-heart-rate safety warnings during a session.
  • • To save your own workout history so you can review past sessions.

2.4 How that data is stored

OAuth access and refresh tokens are stored encrypted at rest in our database and are never exposed to the browser or to any third party. Heart-rate readings are stored against your account only. Nothing is written to Google — access is read-only.

2.5 Limited Use disclosure

BeatSync's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, BeatSync:

  • • uses Google user data only to provide and improve the user-facing features described in this policy;
  • • does not sell, rent or trade Google user data;
  • • does not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with your explicit consent;
  • • does not use Google user data for advertising or ad personalisation;
  • • does not use Google user data to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models;
  • • does not allow humans to read Google user data, except with your explicit consent for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.

2.6 Revoking access and deletion

You can disconnect Google Health at any time from the Connect Device panel on your BeatSync dashboard. Disconnecting immediately deletes the stored access and refresh tokens from our database and stops all further reads. You can also revoke BeatSync's access directly at myaccount.google.com/permissions. To have heart-rate readings already stored in your account deleted, delete your account or email us at [email protected].

2.7 Health data is never used for the purposes below

The aggregate business-analytics practices described in our separate Data Collection & Management Policy do not apply to Google user data. Google user data is excluded from investor reporting, due-diligence disclosure and any data set shared outside BeatSync.

3. Apple Health and the BeatSync watch app

The BeatSync iPhone and Apple Watch app reads heart rate from Apple HealthKit with your on-device permission. Readings are transmitted over HTTPS to your BeatSync account using a device token you generate on your dashboard. We do not read any other HealthKit data type, and HealthKit data is never used for advertising or sold to anyone. Revoking permission in the iOS Health app, or deleting the device token from your dashboard, stops the transfer immediately.

4. Spotify

BeatSync queries the Spotify catalogue for tracks whose tempo matches your target BPM. Only a workout type and a numeric target tempo leave our servers — no personal information, no account identifier and no heart-rate data is sent to Spotify.

5. Who we share data with

  • Hosting and database providers that run the BeatSync service on our behalf, under contract.
  • Google Analytics, for aggregate usage statistics. Heart-rate values and Google user data are not sent to Analytics.
  • Spotify, limited to workout type and target tempo as described above.
  • Legal authorities, where we are required by law to do so.

We do not sell personal data. We do not share individually identifiable health or heart-rate data with advertisers, insurers or employers.

6. Retention and security

Account, workout and heart-rate data is retained while your account is active and is deleted when you delete your account. Google OAuth tokens are deleted as soon as you disconnect. We protect data with encrypted password storage (bcrypt), encryption in transit (HTTPS), database encryption at rest, session-based access control and authenticated API endpoints.

7. Your rights

You may request access to, correction of, or deletion of your personal data, and you may withdraw consent at any time by disconnecting a data source or deleting your account. Depending on where you live you may also have the right to data portability and to lodge a complaint with a supervisory authority. Contact us to exercise any of these rights.

8. Children

BeatSync is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.

9. Changes to this policy

We will update this page whenever our data practices change, and we will revise the “last updated” date above. Material changes affecting Google user data will be announced in the app before they take effect.

10. Contact us

BeatSync Data Privacy

Email: [email protected]

Website: https://beat-sync.com