BeatWatch
‹ Back

BeatWatch Privacy Policy

Effective August 8, 2026 · Last updated August 8, 2026

1. Who we are

BeatWatch ("BeatWatch", "we", "us") is operated by Stephen Lucas, an individual doing business as BeatWatch, 151 Calle San Francisco, Suite 200, San Juan, PR 00901.

Contact: privacy@beatwatch.app

If we transfer the app and this service to a company we form (see §14), that company becomes the operator named above and this policy continues to apply to your information.


2. The short version

BeatWatch helps a group of friends — a "crew" — stay connected at a festival or event. To do that it handles some genuinely sensitive information: where you are, your heart rate, and what you say to your crew.


3. What we collect, why, and who can see it

What Why we have it Who can see it
Email address To create and sign in to your account You and us
Display name So your crew knows who you are Your crew members
Profile photo (optional) Your avatar in crew lists and chats Your crew members
Precise location To show your crew where you are on the Friend Compass Members of the crew you shared it with
Heart rate To show your live pulse and, if you accept a partner, whether your hearts are in sync You, and one crew member whose pairing you accepted
Message content To deliver your messages to your crew Members of that conversation
Photos you upload Event maps and schedule images you add to a crew Members of that crew (see §6 for schedule images)
Other content you write Activity notes, check-ins, BRB posts and custom button labels Members of that crew
User ID The internal identifier that ties your data to your account Us
Device ID (push token) To send you notifications (e.g. a crew member's SOS) Us and our push provider (§7)

Legal bases (EEA/UK users): we process this information to perform our contract with you (providing the app's features), on the basis of your consent where the device asks for it (location, Apple Health, notifications, photo library), and for our legitimate interests in keeping the service secure and working.


4. Health data — how we treat it

BeatWatch reads heart rate from Apple Health (HealthKit), including from a paired Apple Watch. If you use the BeatWatch watch app, it reads your heart rate directly on the watch.

Specific commitments, which mirror Apple's requirements for apps that use HealthKit:

You can revoke BeatWatch's access to Apple Health at any time in iOS Settings → Privacy & Security → Health, or in the Health app under Sharing.


5. Location — how we treat it


6. Messages, photos and other content


7. Service providers we share data with

We use a small number of providers to run the service. None of them is an advertiser, an analytics vendor or a data broker.

Provider What it receives Why
Supabase (hosted on AWS, US East region) Everything in §3 — it is our database, authentication, file storage and server functions It is where the app's data lives
Expo (push service) Your device push token and the contents of notifications we send you — which can include a crew member's display name and crew name (e.g. "Alex needs help") To deliver push notifications
Apple (APNs) The same notification payload, as the operator of iOS push delivery To deliver push notifications to your device
Anthropic Only a schedule image you explicitly choose to upload for extraction (§6) To read the text of a festival schedule out of the picture
2CB Only the text of a question you type into the in-app information feature To answer that question

We may also disclose information if we are legally required to, or where we believe in good faith it is necessary to protect someone's safety.


8. What we do not do

Stated plainly, because these are the questions people actually have:


9. Deleting your account

You can delete your account from inside the app: Settings (the gear on the home screen) → Delete Account. You will be asked to type the word DELETE to confirm, because it cannot be undone.

What is permanently deleted:

Two consequences that affect other people, stated plainly because they are easy to miss:

  1. ⚠️ Your messages are removed from crew threads. Messages you sent are deleted from group chats, direct messages and activity threads. Other members of those conversations will see your messages disappear. We cannot delete your messages from a conversation without changing what the other participants see.
  2. Crews you created are NOT deleted. If you set up an event, it keeps running for everyone still in it — they keep the crew, the chat and the schedule. Your name is simply removed as its creator. We designed it this way deliberately: one person leaving must not destroy an event other people are still using.

Timing. Deletion happens immediately when you confirm. Copies may persist for a short period in routine encrypted backups before being overwritten, and we may retain the minimum records required by law.

You can also just log out if you want to stop using the app without deleting anything.


10. How long we keep things


11. Security

Access to your data is enforced in the database itself, not only in the app. Row-level security rules mean, for example, that heart-rate rows can only ever be read by their owner and an accepted partner, and that crew content can only be read by that crew's active members. Data is encrypted in transit. No system is perfectly secure, and we cannot guarantee absolute security.


12. Your rights

Everyone. You can access, correct, export or delete your information. Account deletion is available in the app (§9); for anything else, contact us at privacy@beatwatch.app.

EEA / UK. You have rights of access, rectification, erasure, restriction, objection and data portability, and the right to complain to your local supervisory authority. Where we rely on consent, you may withdraw it at any time.

California. You have the right to know what personal information we collect and how we use it, to request deletion and correction, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA. We do collect information that is "sensitive personal information" — precise geolocation and health data — and we use it only to provide the features you asked for, which does not trigger a right to limit its use.


13. Children

BeatWatch is an 18+ service. You must be at least 18 years old to use it. It is not directed to children and we do not knowingly collect information from anyone under 18.

We set the floor at 18 rather than at the US legal minimum of 13 for two reasons: most of the festivals and events BeatWatch serves are themselves 18+, and an 18+ product means we do not collect health data or precise location from minors at all.

If you believe someone under 18 has created an account, contact us at privacy@beatwatch.app and we will delete it.


14. International transfers, and changes of ownership

Our infrastructure is hosted in the United States. If you use BeatWatch from outside the US, your information is transferred to and processed in the US.

Change of ownership. BeatWatch is currently operated by an individual and we intend to transfer it to a company being formed in Puerto Rico. If that happens — or in any merger, acquisition or sale of assets — your information will transfer with the service, and the new operator will be bound by this policy until it gives you notice of any change.


15. Changes to this policy

If we make a material change we will update the "Last updated" date and, where the change is significant, tell you in the app. Continuing to use BeatWatch after a change means you accept it.


16. Contact

privacy@beatwatch.app · 151 Calle San Francisco, Suite 200, San Juan, PR 00901