Privacy Policy
Information on the processing of your personal data pursuant to the GDPR
1. Controller
The controller responsible for data processing on this website is:
Fabian Kunz · Schmittmannstr. 10 · 50935 Köln, Germany · Email: info@beatfloe.com
2. Scope
This website is the product and sales site for Beatfloe, a desktop application for music producers. Besides the data technically required to deliver the pages to your browser (Section 3), we process personal data when you create a user account (Section 5) and when you purchase and manage a subscription (Section 6).
We use a cookieless audience measurement tool that stores nothing on your device and does not recognise you across days or websites (Section 7). With your consent — and only with your consent — we additionally use the Meta pixel to measure our advertising (Section 7). Beyond that we do not use advertising, profiling, or cross-site tracking, and we do not operate a newsletter. If you write to us through the support form on this website, we process the data you enter there (Section 14). The Beatfloe desktop application additionally processes Google user data if — and only if — you connect your YouTube channel to it (Section 8), and — if and only if you connect it — data from your Dropbox account (Section 9). When you use the Beatfloe desktop application, the app additionally verifies your subscription, reports minimal usage signals, and counts the beats you publish with it (Section 10).
3. Server log files
When you visit this website, our hosting provider automatically collects and temporarily stores information transmitted by your browser in server log files: IP address, date and time of the request, browser type and version, operating system, referrer URL, and the requested page or file. This data is not merged with other data sources. Processing is based on Art. 6(1)(f) GDPR; our legitimate interest lies in the secure, stable, and functional operation of the website. The data is stored only as long as necessary for this purpose and then deleted.
4. Hosting
This website is hosted by Hostinger International Ltd., 61 Lordou Vironos str., 6023 Larnaca, Cyprus. The server is located in Germany. Hostinger processes the server log file data described above exclusively on our behalf as a processor under a data processing agreement pursuant to Art. 28 GDPR. As both the provider and the server are located within the EU, no transfer of personal data to a third country takes place.
5. User accounts and authentication
To use Beatfloe you need a user account. When you register we process your email address, your password (stored only as a salted hash — we never see it in plain text), your first and last name, an internal user ID, and the timestamps of creation and last sign-in. We use this data to create and operate your account, to authenticate you, and to link your subscription entitlement to you. Legal basis is Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures).
Accounts and authentication run on Supabase, provided by Supabase Inc. Supabase acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Insofar as personal data is transferred to a third country in the process, this is done on the basis of the EU Standard Contractual Clauses.
You can delete your account at any time under "Account" on this website. Deletion cancels a running subscription, removes your subscription record, and deletes your user account, including the data listed above. If you only cancel your subscription but keep your account, we retain the subscription record with the status "canceled", because it tells us that a free trial has already been used; legal basis is Art. 6(1)(f) GDPR, our legitimate interest in preventing repeated use of the one-time free trial.
6. Payment processing and subscriptions
Payment processing and the sale of the paid subscription are handled by Paddle as our Merchant of Record. For customers outside the USA and Canada this is Paddle.com Market Ltd, Judd House, 18-29 Mora Street, London, EC1V 8BT, United Kingdom; for customers in the USA, Paddle.com Inc; for customers in Canada, Paddle.com (Canada) Ltd. Legal basis is Art. 6(1)(b) GDPR.
When you start a checkout, we transmit your email address and your internal Beatfloe user ID to Paddle so that the purchase can be assigned to your account. All payment and billing data — payment method, card details, billing address, and tax-relevant information — is collected by Paddle directly from you and processed by Paddle under its own responsibility. We never receive or store your card details. Paddle's privacy policy is available at paddle.com/legal/privacy.
In return, Paddle notifies our server of the status of your subscription. We store the subscription status, the plan, the end of the current billing period, and the Paddle subscription and customer IDs, in order to unlock the application for you and to display your subscription status. Managing your subscription — changing the payment method, viewing invoices, cancelling — takes place in Paddle's customer portal, which we open for you from your account page.
7. Cookies and web analytics
We only use cookies that are strictly necessary for operation. These are the session cookies that keep you signed in after logging in; without them, protected pages such as your account page cannot work. Storing them is permitted under § 25(2) no. 2 TDDDG without consent; the associated processing is based on Art. 6(1)(f) GDPR, our legitimate interest in a functioning login. During checkout, Paddle may additionally set cookies that are necessary to process the payment.
Our own web analytics (below) works entirely without cookies and without any other storage on your device. The only advertising technology on this website is the Meta pixel (below), and it is used exclusively with your prior consent, which we ask for in a consent banner. If you decline, or simply ignore the banner, no advertising cookies are set. You can delete cookies at any time in your browser settings; you will then be signed out.
To understand how this website is used — which pages are visited, how visitors arrive, from which countries they come, and how much of our traffic comes from automated bots — we use PostHog. The provider is PostHog, Inc.; the service runs on PostHog's EU infrastructure with servers in Frankfurt, Germany, and acts as our processor under a data processing agreement pursuant to Art. 28 GDPR. No personal data is transferred to a third country.
We have configured PostHog so that it sets no cookies and writes nothing to your browser's local or session storage. To count the page views of one visit together, a random identifier is kept solely in your browser's memory for the duration of the visit; it disappears as soon as you close the tab and can never link you across visits, days, or websites. When our processor receives an event, it derives your approximate location (country level) from your IP address and uses your browser's user agent string to distinguish automated bot traffic from human visits. The IP address itself is discarded immediately after receipt — it is neither stored nor available to us. We do not create user profiles, and we never connect this data to your user account, even while you are signed in.
Data processed: the pages you open, referrer, your approximate location (country level, derived from your IP address as described above), approximate technical details of your browser and device (such as browser type, operating system, and screen size), and interactions with page elements such as clicks and scroll depth.
Legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in understanding and improving the use of our website and in assessing our server load. Since no information is stored on or read from your device, consent under § 25 TDDDG is not required. You have the right to object to this processing at any time under Art. 21(1) GDPR; an email to the address in Section 1 is sufficient. You can also prevent the processing yourself at any time by enabling the "Do Not Track" setting in your browser — we honour that signal and then collect nothing at all.
Meta pixel (with consent only). To measure the effectiveness of our advertising on Meta platforms (Facebook, Instagram), we use the Meta pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. The pixel is loaded only after you have expressly agreed in our consent banner; before that, no connection to Meta is established and no cookies are set. If you consent, the pixel sets cookies (such as "_fbp") and transmits to Meta information about your visit — the pages you view, your IP address, browser information, and, if you have a Meta account and are logged in, Meta can link this data to your account. Meta uses this data for ad measurement and, under its own responsibility, for its advertising products; details are in Meta's privacy policy at facebook.com/privacy/policy.
For the collection and transmission of this data we and Meta are joint controllers under Art. 26 GDPR; for all further processing, Meta is solely responsible. Data may be transferred to Meta Platforms, Inc. in the USA; this transfer is covered by Meta's certification under the EU-U.S. Data Privacy Framework. Legal basis is your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw your consent at any time with effect for the future via the "Cookie settings" link in the footer of this website — the pixel then stops immediately and its cookies are removed. Your consent decision itself is stored locally in your browser so we do not have to ask you on every visit; this storage is strictly necessary and permitted under § 25(2) TDDDG.
8. Google user data (YouTube integration)
The Beatfloe desktop application uses the YouTube Data API with your explicit consent via Google OAuth. Processing is based on Art. 6(1)(a) GDPR; you may withdraw your consent at any time with effect for the future.
Data accessed: your YouTube channel identity, and the videos the app uploads for you — including their title, description, thumbnail, scheduling and privacy status.
How it is used: solely to provide the app's core feature — uploading your beat videos to your own channel, scheduling them, and updating their descriptions with your store link. All processing happens locally on your computer; your OAuth token is stored only on your device. We do not store Google user data on our servers.
Sharing: we do not share, transfer, or disclose Google user data to anyone. It is not used for advertising and not transferred to third parties.
You can revoke access at any time at myaccount.google.com/permissions or by disconnecting YouTube in the app's settings, which deletes the local token.
Beatfloe's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
9. Dropbox integration
The Beatfloe desktop application connects to your own Dropbox account after you grant access via Dropbox OAuth. Processing is based on Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future, and you can remove the app's access at any time under "Connected apps" in your Dropbox account settings.
Data accessed: basic account information (account_info.read), file and folder names (files.metadata.read), writing files (files.content.write), and sharing settings (sharing.read, sharing.write). The app does not request permission to read the contents of your files, and it has no access to files it did not create itself.
How it is used: to deliver the stem files that belong to your beat. The app packs the stems you selected into a ZIP archive, uploads that archive to your Dropbox, and creates a download link for it, which is then included in your release. Nothing else in your Dropbox is touched.
Where data is stored: processing happens on your computer. Your Dropbox access and refresh tokens are kept on your device only, in a permission-restricted configuration file in the app's local data directory. We do not store your Dropbox files or tokens on our servers.
Sharing: we do not share, transfer, or disclose Dropbox user data to anyone. The download link is created in your own Dropbox account and goes only where you publish it.
10. Desktop application (Beatfloe app)
The Beatfloe desktop application requires a sign-in with your user account (Section 5). At every launch the app verifies against our server that your account has an active subscription or trial; for this it processes your email address, your internal user ID, and your subscription status. Legal basis is Art. 6(1)(b) GDPR (performance of a contract) — the check is what unlocks the application you subscribed to.
While you are signed in and the app is running, it additionally sends a short "heartbeat" to our server approximately every five minutes. A heartbeat consists of your internal user ID, a timestamp, the app version, and your operating-system platform (macOS or Windows) — nothing else. We use this to know how many people actively use the app and to notice outages; legal basis is Art. 6(1)(f) GDPR, our legitimate interest in operating and improving the product. The app does not track what you do inside it: no beats, file names, project contents, clicks, or usage behavior are transmitted, and the app contains no third-party analytics or advertising technology. The one exception is the publication counter described below, which counts beats without describing them.
Only the most recent heartbeat per account is stored — each new heartbeat overwrites the previous one, so no history of your individual activity is kept. For long-term statistics we store only daily aggregate counts of active users, which contain no reference to individual accounts.
When the app has finished publishing a beat for you, it reports that one beat was published and to which destinations it went (YouTube, Beatstars, or both). That report consists of your internal user ID, the date, the destination, and a counter, and nothing else: no beat names, no file names, no titles, no links, no images, and nothing from the audio itself. We use these counts to see how much use producers actually get out of Beatfloe and, in aggregate, how many beats are published through the software. Legal basis is Art. 6(1)(f) GDPR, our legitimate interest in understanding and improving the product. You can object to this processing at any time under Art. 21(1) GDPR; an email to the address in Section 1 is sufficient, and we will switch the counter off for your installation. The software works exactly the same either way.
The entitlement check, the heartbeat, and the publication counter all run on Supabase under the data processing agreement described in Section 5. Your rights under Sections 12 and 13 apply to this processing as well.
11. SSL/TLS encryption
This website uses SSL/TLS encryption for security. You can recognize an encrypted connection by "https://" in your browser's address bar.
12. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise these rights, contact us at info@beatfloe.com.
13. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
14. Support requests
On our support page you can send us a message. We process the email address you enter, the subject category and the operating system you select, the text of your message, and the time of receipt. If you are signed in while sending, we also store your internal Beatfloe user ID so we can assign the request to your account. Nothing else is collected; there is no hidden field and no tracking in the form.
We use this data solely to read your request, answer it, and follow up on the problem you describe. Legal basis is Art. 6(1)(b) GDPR where your request concerns your contract with us, and otherwise Art. 6(1)(f) GDPR, our legitimate interest in answering enquiries about our product.
Your request is stored in our Supabase database (Section 5) and is delivered to our support mailbox by Resend, Inc., San Francisco, California, USA. Resend acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR. The transfer to the USA is based on the EU Standard Contractual Clauses. Resend's privacy policy is available at resend.com/legal/privacy-policy.
We delete support requests twelve months after the enquiry has been dealt with, unless a longer statutory retention period applies. If you delete your account, the requests linked to your account are deleted with it. You can object to the processing at any time under Art. 21(1) GDPR; an email to the address in Section 1 is sufficient.
15. Status
This privacy policy is current as of September 2026.