BeatWatch
‹ Back

BeatWatch Privacy Policy

Last updated and effective: September 22, 2026

BeatWatch Corporation, operating the BeatWatch website, iOS application, and Apple Watch application (“Company” “we” or “us” or “our”), respects the privacy of its users (“user” or “you”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the BeatWatch website and applications (together, the “Site”). Please read this Privacy Policy carefully. IF YOU DO NOT AGREE WITH THE TERMS OF THIS PRIVACY POLICY, PLEASE DO NOT ACCESS THE SITE.

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this Policy. If we make a material change to how we collect, use, or share personal data, we will notify affected customers by reasonable electronic means, such as email or a prominent notice on the Site, and we will give you a reasonable opportunity to withdraw any consent you previously gave before we apply the materially different practice to personal data collected under the prior version of this Policy. Changes apply to personal data collected after their effective date, and your continued use of the Service after that date means the updated Policy governs that data. We review this Privacy Policy at least once every 12 months.

Definitions

The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

“Account” means a unique account created for you to access our Site or parts of our Site.

“Affiliate” means an entity that controls, is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.

“Business,” for the purpose of the California Consumer Privacy Act (“CCPA”), refers to the Company as the legal entity that collects Consumers' personal information and has the meaning set forth in CCPA § 1798.140(d).

“Consumer,” for the purpose of the CCPA, means a natural person who is a California resident and has the meaning set forth in CCPA § 1798.140(i).

“Cookies” are small files that are placed on your computer, mobile device or any other device by a website, containing the details of your browsing history on that website among its many uses.

“Device” means any device that can access the Site such as a computer, a cellphone or a digital tablet.

“Do Not Track” (“DNT”) is a concept that has been promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.

“Personal Information” is any information that relates to an identified or identifiable individual. For the purposes of the CCPA, Personal Information means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you and has the meaning set forth in CCPA § 1798.140(v).

“Sale,” for the purpose of the CCPA means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer’s Personal Information by the Company to a third party for monetary or other valuable consideration and has the meaning set forth in CCPA § 1798.140(ad).

“Site” refers to the BeatWatch website, iOS application, and Apple Watch application.

“Service Provider” means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies and individuals employed by the Company to facilitate the Site, to provide the Site on behalf of the Company, to perform services related to the Site or to assist the Company in analyzing how the Site is used.

“Third-party Social Media Service” refers to any website or any social network website through which a User can log in or create an account to use the Site.

“Usage Data” refers to data collected automatically from use of the Site or the Site infrastructure, including Internet Protocol address, user agent, request path, and server log information.

“Website” refers to the BeatWatch website, accessible at https://beatwatch.app/.

“You” and “you” means the individual accessing or using the Site, or the company, or other legal entity on behalf of which such individual is accessing or using the Site, as applicable.

COLLECTION OF YOUR INFORMATION

We may collect information about you in a variety of ways. The information we may collect via the Site depends on the content and materials you use, and includes:

Personal Information

The personal information we collect depends on how you use the Site. Account and identity information includes your email address, display name, account creation time, optional profile photo, and account credentials processed by Supabase Authentication. We do not collect a telephone number. Crew and communication information includes crew membership, crew names, invite codes, join times, message text, sender information, delivery and read timestamps, uploaded photos, event map images, notification preferences, check-in status, SOS records, reminder labels and notes, support communications, and moderation reports. Sweepstakes information includes your email address, verification timestamp, hashed verification token, full legal name, date of birth, full postal address, nearest airport, acceptance of the applicable official rules, entries, referrals, and draw results. Purchase and subscription information includes what you bought, the amount paid, subscription status, and subscription dates. Device information includes a push notification token that identifies one device and one installation. When you use the sweepstakes entry form, your browser generates a random identifier once and stores it in local browser storage. The entry form sends a SHA-256 hash of that identifier with the entry. We use the hash only to detect whether the same browser is used to claim more than one referral. The identifier is not derived from device characteristics and is not used for cross-site or cross-app tracking. Clearing local browser storage causes the browser to generate a new identifier.

If you use location features, we collect precise latitude and longitude while the app is open. Your current position is visible only to members of the applicable crew while the app is open. We store one current position per person per crew and overwrite it as the position changes. We do not maintain location history or collect background location. If you use health features, BeatWatch reads heart rate, steps, and sleep information from Apple HealthKit. We store heart rate only and do not store step counts or sleep values. The Apple Watch app may continue collecting heart rate while a heart-rate session is active in the background until you turn that session off. The phone app reads health information only while it is open. Apple Health may ask you to authorize BeatWatch to save workouts because watchOS requires that authorization for an active heart-rate session. BeatWatch does not save a completed workout.

Derivative Data

Information our servers and service providers automatically collect when you access the Site, including Internet Protocol address, user agent, request path, and server log information generated through Supabase and Cloudflare.

Financial Data

We do not collect or store full payment card numbers, security codes, or bank account credentials. Stripe processes card payments made through the Website, and Apple processes in-app purchases. We receive purchase, amount-paid, subscription status, and subscription date information needed to provide paid features and maintain transaction records.

We may also collect the following information:

Information collected from other Sources

We collect personal information directly from you when you sign up, create or join a crew, send messages, upload content, or use Site features. Those features include check-ins, SOS, reminders, sweepstakes, purchases, and other interactions with the Site. We receive health information from Apple HealthKit when you authorize those features. Your device generates a push token for notification delivery. Supabase and Cloudflare process server and request data as platform operators.

Third-Party Data

We may receive transaction status and related purchase information from Apple and Stripe when they process payments. We receive heart rate, steps, and sleep information from Apple HealthKit when you authorize those features, although we store only heart rate. We do not receive personal information from advertising networks, analytics providers, or data brokers.

Email Data

We use your email address to send transactional, account, support, sweepstakes, and other service communications. We do not use a third-party email provider.

USE OF YOUR INFORMATION

Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the Site to:

• Respond to a subpoena.

• Maintain records for sweepstakes administration, transactions, tax, fraud prevention, and legal compliance.

• Create and manage your account.

• Email you regarding your account, and send push notifications about direct messages, group chat, crew changes, check-ins, and SOS alerts.

• Display your display name, profile photo, messages, check-ins, notes, event maps, and other crew content to the people with whom you share that content.

• Process a schedule image you choose through Anthropic to extract set times, and send a question you type in the in-app information feature to 2CB.com for a response.

• Increase the efficiency and operation of the Site.

• Monitor and review server and security logs to maintain, secure, and improve the Site.

• Notify you of updates to the Site

• Administer sweepstakes and promotions.

• Perform other business activities as needed.

• Operate crew, messaging, Friend Compass, check-in, SOS, reminder, health, sweepstakes, referral, purchase, and subscription features.

• Request feedback and contact you about your use of the Site.

• Resolve disputes and troubleshoot problems.

• Respond to product and customer service requests.

• Detect, investigate, and respond to abuse, safety concerns, fraud, and rule violations.

• Solicit support for the Site.

DISCLOSURE OF YOUR INFORMATION

We may share information we have collected about you in certain situations. Your information may be disclosed as follows:

By Law or to Protect Rights

If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation. This includes exchanging information with other entities for fraud protection and credit risk reduction.

Third-Party Service Providers

We share information with service providers that perform services for us or on our behalf. Supabase, hosted on AWS, provides database hosting, authentication, file storage, and server functions and receives the information stored through the Site. Expo receives your push token, notification title and body, and related data payload to deliver notifications. Message notifications may include up to 120 characters of message text. SOS notifications may include the raiser’s profile identifier and crew identifier. Apple receives the same push notification payload through Apple Push Notification service, processes in-app purchases, and distributes the app through the App Store. Stripe processes card payments made through the Website. Cloudflare hosts the Website and sweepstakes entry form and receives visitor IP address, user agent, request path, and information submitted through hosted forms. Anthropic receives a user-selected image and a fixed prompt when you use schedule-image processing. BeatWatch does not send Anthropic your profile identifier, user identifier, or authentication token. 2CB.com receives the text of a question you type in the information feature, an empty history array, and a locale string, without your profile identifier, user identifier, session identifier, or token.

Profile photos and event map images are served from public URLs, so anyone with the exact URL can retrieve the image without signing in. Avatar renders are private.

Advertising Partners

We do not use advertising partners, ad networks, or advertising SDKs. We do not read an advertising identifier or request Apple’s App Tracking Transparency permission.

Affiliates

We may share your information with our affiliates, in which case we require those affiliates to honor this Privacy Policy. Affiliates include entities that control, are controlled by, or are under common control with us.

Sale or Bankruptcy

If we reorganize or sell all or a portion of our assets, undergo a merger, or are acquired by another entity, we may transfer your information to the acquirer or successor entity. If we go out of business or enter bankruptcy, your information would be an asset transferred or acquired by a third party. You acknowledge that such transfers may occur and that the transferee may decline honor commitments we made in this Privacy Policy.

We are not responsible for the actions of third parties with whom you share personal or sensitive data, and we have no authority to manage or control third-party solicitations. If you no longer wish to receive correspondence, emails or other communications from third parties, you are responsible for contacting the third party directly.

TRACKING TECHNOLOGIES

Cookies and Web Beacons

The app and public Website do not use cookies or pixels for tracking or advertising. The sweepstakes entry form uses local browser storage for the random browser identifier described above and sends only its SHA-256 hash with the entry. Supabase and Cloudflare process IP addresses and server logs as platform operators. Expo and Apple use device push tokens to deliver notifications.

Analytics and Advertising

We do not use a third-party analytics provider, advertising network, attribution provider, or advertising identifier. We do not request Apple’s App Tracking Transparency permission.

If these practices change, we will update this Privacy Policy before using personal information for those purposes.

DATA RETENTION

We retain information according to the following schedule. Messages are retained for up to 12 months and are deleted sooner when the associated account is deleted. Photos, avatars, and event maps are retained until deletion and may remain for up to 30 days after deletion. We do not retain location history. We keep one current position per person per crew and delete it when the person leaves the crew or deletes the account. Heart-rate data and check-in records are retained for up to 90 days and are deleted sooner with account deletion. Reminder logs and notes are retained for up to 12 months and are deleted sooner with account deletion. SOS records are retained for up to 24 months and are deleted sooner with account deletion. Moderation reports you file are deleted with your account, while moderation reports about you may remain for up to 24 months. Support records are retained for up to 24 months. Sweepstakes entrant and entry records, referral records, and draw results are retained for four years from the drawing. Purchase and subscription records are retained for seven years. Server logs are retained for 90 days, and database backups are retained on a seven-day rolling basis. Anthropic retains schedule-image inputs and outputs for up to 30 days under its standard commercial API terms. When personal data is no longer needed for the purposes described in this Privacy Policy, we delete it or de-identify it unless a longer period is required by law.

THIRD-PARTY WEBSITES

The Site may contain links to third-party websites and applications of interest, including external services, that are not affiliated with us. Once you have used these links to leave the Site, any information you provide to these third parties is not covered by this Privacy Policy, and we cannot guarantee the safety and privacy of your information. Before visiting and providing any information to any third-party websites, you should inform yourself of the privacy policies and practices (if any) of the third party responsible for that website, and should take those steps necessary, in your discretion, to protect the privacy of your information. We are not responsible for the content or privacy and security practices and policies of any third parties, including other sites, services or applications that may be linked to or from the Site.

SECURITY OF YOUR INFORMATION

We use administrative, technical, and physical security measures to help protect your personal information. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse. Any information disclosed online is vulnerable to interception and misuse by unauthorized parties. We cannot guarantee complete security if you provide personal information.

POLICY FOR CHILDREN

The Site is intended for adults and is not offered to users under 18. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has created an account or provided personal information through the Site, please contact us using the information below, and we will delete the account and associated data, subject to records we are legally permitted or required to retain.

CONTROLS FOR BROWSER PRIVACY SIGNALS

We do not sell personal information for money, share personal information for cross-context behavioral advertising, or use personal information for targeted advertising. We do not use advertising cookies, advertising pixels, an advertising identifier, or other cross-site or cross-app tracking technologies. The app does not receive browser privacy signals. Because we do not engage in sale, sharing, or targeted advertising, a universal opt-out preference signal does not change our current processing practices. You can also submit privacy requests through our Privacy Choices page at https://beatwatch.app/privacy-choices/.

OPTIONS REGARDING YOUR INFORMATION

Account Information

You can delete your account from within the app. You can request a machine-readable export of your data from within the app. You can correct your display name and profile photo through the profile screens. You may also contact us using the information below for access, correction, or other privacy requests.

When you delete your account, we delete the authentication record and associated account data, including crew membership, current location, check-ins, SOS alerts, activity events, messages, read receipts, reminder buttons and logs, push tokens, heart pairings, heart rate samples, notification preferences, reports you filed, and uploaded files. Certain records survive account deletion for the retention periods described above. Sweepstakes entrant records are retained for four years from the drawing and include email address, verification data, full legal name, date of birth, full postal address, nearest airport, acceptance of the applicable official rules, entries, referrals, hashed browser identifier, and draw results. Other retained records include purchase and subscription records, moderation reports about you, crews that remain in use by other members, and quoted activity preserved without attribution.

Emails and Communications

If you no longer wish to receive optional push notifications from us, you may opt out by:

• Turning off direct message, group chat, crew change, or check-in notifications in the app or through your device settings

• Contacting us using the contact information provided below

SOS notifications cannot be disabled through the app because they are part of the safety feature. If you no longer wish to receive correspondence, emails, or other communications from third parties, you are responsible for contacting the third party directly.

CALIFORNIA PRIVACY RIGHTS

California Consumer Privacy Act (“CCPA”)

California residents have certain rights with respect to the processing and use of their personal information, including the following rights:

The right to notice. You must be properly notified which categories of Personal Information are being collected and the purposes for which the Personal Information is being used.

The right to know and access. You have the right to request that the Company disclose the personal information it has collected about you, the categories of sources, the business purposes for collecting it, the categories of third parties to which it was disclosed, and the specific pieces of personal information collected.

The right to opt out of the sale or sharing of Personal Information. You have the right to direct the Company not to sell your Personal Information and not to share it for cross-context behavioral advertising. You can submit such a request through the “Do Not Sell or Share My Personal Information” control on our Privacy Choices page at https://beatwatch.app/privacy-choices/ or through the other privacy request methods described in this Privacy Policy.

The right to correct. You have the right to request that the Company correct inaccurate Personal Information it maintains about you, taking into account the nature of the Personal Information and the purposes of processing it. We may ask for information needed to verify your identity and the requested correction.

The right to limit the use of sensitive Personal Information. To the extent the Company uses or discloses your sensitive Personal Information beyond the purposes the CCPA permits without a right to limit, you have the right to direct the Company to limit its use and disclosure of that information to those permitted purposes. You can exercise this right through the "Limit the Use of My Sensitive Personal Information" link, where provided, or the privacy request methods described in this Privacy Policy.

The right to know about your Personal Information. You have the right to request and obtain from the Company information regarding the disclosure of the following:

• The categories of Personal Information collected;

• The sources from which the Personal Information was collected;

• The business or commercial purpose for collecting or selling the Personal Information;

• Categories of third parties with whom we share Personal Information; and

• The specific pieces of Personal Information we collected about you

The right to delete Personal Information. You have the right to request the deletion of your Personal Information, subject to the CCPA's limits and exceptions.

The right not to be discriminated against. You have the right not to be discriminated against for exercising any of your Consumer's rights, including by:

• Denying goods or services to you;

• Charging different prices or rates for goods or services, including the use of discounts or other benefits or imposing penalties;

• Providing a different level or quality of goods or services to you;

• Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.

INFORMATION COLLECTED

Category Examples Collected
Identifiers A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers Yes
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories Yes
Protected classification characteristics under California or federal law Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information), medical records and other data covered by HIPAA Yes
Commercial information Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies Yes
Biometric Information Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data No
Internet or other similar network activity Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement Yes
Geolocation data Physical location or movements Yes
Sensory data Audio, electronic, visual, thermal, olfactory, or similar information Yes
Professional or employment-related information Current or past job history or performance evaluations. No
Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)) Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. No
Inferences drawn from other personal information Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes No
Sensitive personal information Account log-in credentials, precise geolocation, government identification numbers, financial account credentials, racial or ethnic origin, religious beliefs, contents of mail or messages, genetic data, biometric identification, health, or sex life or sexual orientation. We collect account log-in credentials, precise geolocation, health information, message contents, and other content that may reveal health or substance-use information. Yes

Categories Sold, Shared, or Disclosed

In the preceding 12 months, we have not sold Personal Information or shared Personal Information for cross-context behavioral advertising. We have disclosed Identifiers, California Customer Records information, protected classification information consisting of age, commercial information, Internet or other electronic network activity, geolocation data, sensory data, and sensitive personal information. We have also disclosed user-generated content and sweepstakes information for the business purposes described in this Privacy Policy. Depending on the feature used, recipients include Supabase and AWS, Expo, Apple, Stripe, Cloudflare, Anthropic, 2CB.com, other users with whom you share content, and persons who obtain the exact public URL for a profile photo or event map. We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.

Personal information does not include:

We collect personal information directly from you when you sign up, create or join a crew, send messages, upload content, use location, health, check-in, SOS, reminder or information features, enter a sweepstakes, make a purchase, or otherwise interact with the Site. We receive health data from Apple HealthKit when you authorize those features, payment and subscription information from Apple and Stripe, and server and request data through Supabase and Cloudflare.

Exercising your CCPA Rights

To exercise the privacy rights described in this Policy, you may submit a request by email at privacy@beatwatch.app or through our Privacy Choices page at https://beatwatch.app/privacy-choices/. You may also use the in-app export and account-deletion controls described above. If an authorized agent submits a request on your behalf, we may ask for proof of the agent’s authority and verification of your identity before acting on the request. To verify a request, we may match the email address on the request to the email address on your account and send a confirmation message to that address before we act.

The Company will disclose and deliver the required information free of charge within 45 days of receiving your verified request. The time period to provide the required information may be extended once by an additional 45 days when reasonably necessary and with prior notice.

Do Not Sell or Share My Personal Information

We do not sell personal data for money, share personal data for cross-context behavioral advertising, or use personal data for targeted advertising. California residents can submit sale or sharing opt-out requests through the “Do Not Sell or Share My Personal Information” control on our Privacy Choices page at https://beatwatch.app/privacy-choices/.

We maintain the Privacy Choices page so you can exercise applicable privacy rights in one place, including rights that do not depend on whether we currently sell or share personal information.

If our practices change, we will update this Privacy Policy and provide any additional legally required opt-out mechanism before using personal data for sale, sharing, or targeted advertising.

Website Tracking Controls

We do not use advertising or similar third-party tracking in the app or on the public Website.

We do not read an advertising identifier or request Apple’s App Tracking Transparency permission.

Browser Privacy Signals and Online Activity Disclosures

We do not use third-party analytics, targeted advertising, advertising identifiers, or cross-site or cross-app tracking. We do not respond to browser Do Not Track signals because the Site does not use those tracking technologies. Universal opt-out preference signals do not change our current processing because we do not sell or share personal information for cross-context behavioral advertising. You can also submit privacy requests through our Privacy Choices page at https://beatwatch.app/privacy-choices/.

California Business and Professions Code § 22581

The Site is not offered to users under the age of 18. Content you submit through the Site, such as your display name, messages, photos, event maps, check-ins, notes, and other crew content, may be visible to the people with whom you share that content. Profile photos and event maps are served from public URLs, so anyone with the exact URL can retrieve the image without signing in. If you believe a minor has posted content through the Site, please contact us using the information below and we will remove it, subject to any record we are legally permitted or required to retain. California Business and Professions Code § 22581 provides registered users under 18 a right to request removal of publicly posted content, and we will honor any such request.

ADDITIONAL STATE PRIVACY DISCLOSURES

YOUR U.S. PRIVACY RIGHTS

We extend the following rights to all United States consumers, whether or not the law of your state requires it. You have the right to confirm whether we process your personal data and to access that data; the right to correct inaccurate personal data, taking into account the nature of the data and the purposes of the processing; the right to delete personal data; the right to obtain a copy of the personal data you previously provided to us in a portable and readily usable format; and the right to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.

For your protection, we will not send certain data in response to an access request, including Social Security numbers, driver's license or other government identification numbers, financial account numbers, health insurance or medical identification numbers, account passwords, security questions and answers, and biometric data. If we have collected information of that kind, we will tell you so with enough specificity to identify it, without disclosing the data itself.

SENSITIVE PERSONAL DATA

Supabase Authentication processes your account log-in credentials, which are sensitive personal information under California law, and we use them to authenticate you and maintain your account. We also collect precise geolocation while the app is open, heart rate when you use the health feature, and the contents of messages you send through the Site. BeatWatch reads steps and sleep information from Apple HealthKit but does not store those values. Check-in status, reminder labels or notes, and questions you type into the information feature may reveal health, medication, substance-use, or other sensitive information depending on what you enter. We use sensitive personal information only to deliver the features you request, secure and operate the Site, and comply with law. We do not use sensitive personal information to infer characteristics for advertising, and we do not sell it or share it for cross-context behavioral advertising. Our processors, including Supabase and AWS, may process precise location and heart rate on our behalf to operate the Site. We do not disclose precise location or heart rate to independent third parties for their own purposes. Questions transmitted to 2CB.com do not include your profile identifier, user identifier, session identifier, or token. The question remains associated with your signed-in request inside BeatWatch before the onward request to 2CB.com is stripped of those identifiers. Your use of optional sensitive-data features begins with an affirmative action, such as granting permission, turning on a session, or submitting information. Where applicable law requires separate consent, we request it before the relevant processing. You can withdraw consent from future collection by disabling the relevant feature or permission or by contacting us. We do not use or disclose sensitive personal information for any purpose other than those permitted under 11 CCR § 7027(m). Washington consumers, and consumers whose health data is collected in Washington, may review our separate Consumer Health Data Privacy Policy at https://beatwatch.app/wa-health/.

PAYMENT CARD DATA

We do not collect or store payment card numbers, security codes, or bank account credentials. Stripe processes card payments made through the Website, and Apple processes in-app purchases. We receive information about items purchased, amounts paid, subscription status, and subscription dates needed to provide paid features and maintain transaction records.

CALOPPA WEBSITE DISCLOSURES

We do not sell personal information for money, share personal information for cross-context behavioral advertising, or use personal information for targeted advertising. We do not use advertising cookies, advertising pixels, an advertising identifier, or cross-site or cross-app tracking technologies. We do not respond to browser Do Not Track signals because the Site does not use those tracking technologies. Universal opt-out preference signals do not change our current processing for the same reason.

No third-party analytics provider collects information about your activity on the Site. Supabase and Cloudflare process Internet Protocol addresses and server logs as platform operators.

These website-level California disclosures stand alongside the broader California privacy disclosures in this Policy.

DELAWARE PRIVACY DISCLOSURES

No third-party analytics provider collects information about your activity on the Site. We do not use advertising networks, targeted advertising, or cross-site or cross-app tracking technologies.

FLORIDA PRIVACY DISCLOSURES

For Florida residents, this Privacy Policy describes the categories of personal data we process, the purposes for processing, the categories of personal data shared with third parties, and the categories of third parties that receive personal data.

Florida residents can use the privacy request methods listed in this Privacy Policy to submit rights requests, and can use the appeal path in this Privacy Policy when a request is denied.

CONNECTICUT PRIVACY DISCLOSURES

For Connecticut residents, BeatWatch processes sensitive data only when reasonably necessary for the feature you request. Where Connecticut law requires consent, we request it before processing the sensitive data and allow you to withdraw it as described above. We use the Anthropic API to extract set times from an image you choose for schedule processing. We transmit the selected image and a fixed prompt without your profile identifier, user identifier, or authentication token. Under Anthropic’s commercial API terms, Anthropic does not use customer content to train its models and deletes inputs and outputs within 30 days by default. We also transmit the text of a question you type into the in-app information feature to 2CB.com. That request includes an empty history array and locale string but excludes your profile identifier, user identifier, session identifier, and token. BeatWatch does not store the question in its application database. The request passes through BeatWatch’s platform layer while associated with your signed-in account. BeatWatch removes those identifiers before the onward request to 2CB.com. We do not use artificial intelligence to make decisions that produce legal or similarly significant effects concerning you. We do not use personal data to train large language models or other artificial intelligence systems. We have not sold personal data to any third party.

NEVADA PRIVACY DISCLOSURES

For Nevada consumers, consumer health data may include heart rate and information you submit that relates to health, medication, or substance use. We collect that information from you and Apple HealthKit to operate health, safety, communication, reminder, and information features you request. Supabase and AWS process consumer health data on our behalf for hosting and storage. When a question you submit to 2CB.com contains consumer health data, 2CB.com receives the question text as described above. If a push notification contains consumer health data, Expo and Apple receive that notification content to deliver the notification. We do not sell consumer health data. We do not use advertising networks, targeted advertising, or cross-site or cross-app tracking technologies to collect consumer health data.

Nevada consumers may use the privacy request methods described in this Privacy Policy to ask whether we collect, share, or sell their consumer health data. They may request access to recipient information, cessation of future collection or sharing, deletion, or review and correction of consumer health data. You can submit a request or appeal by email at privacy@beatwatch.app or through our Privacy Choices page at https://beatwatch.app/privacy-choices/, and you may use the in-app export and deletion controls described above. We notify affected consumers of material changes by updating the Last updated date and by reasonable electronic notice where appropriate. Before we collect, use, or share additional categories of consumer health data, use consumer health data for a new purpose, or share it with an additional third party or affiliate, we disclose the change and obtain affirmative, voluntary consent where Nevada law requires it. No third party collects consumer health data over time and across unrelated websites or online services through the Site. This Privacy Policy is effective September 22, 2026.

OKLAHOMA PRIVACY DISCLOSURES

Beginning January 1, 2027, Oklahoma residents may have the right to confirm whether we process their personal data, access that data, correct inaccuracies, delete personal data provided by or obtained about them, obtain a portable copy of personal data they previously provided to us where technically feasible, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. We generally respond to qualifying requests within 45 days and may extend that period once by an additional 45 days when permitted by law.

If we deny an Oklahoma privacy request, we will explain the reason for the denial and describe how to appeal. We generally decide Oklahoma appeals within 45 days. If we deny an Oklahoma appeal, we will provide information about the Oklahoma Attorney General's online complaint mechanism.

When we process sensitive data about Oklahoma residents, we do so only with the consent required by Oklahoma law.

SALE, SHARING, AND TARGETED ADVERTISING OPT-OUTS

We do not sell or share personal data for cross-context behavioral advertising and do not use personal data for targeted advertising. You can submit applicable sale, sharing, and targeted advertising opt-out requests through our Privacy Choices page at https://beatwatch.app/privacy-choices/. If those practices change, we will update this Privacy Policy and provide any additional legally required opt-out mechanism before using personal data for those purposes.

STATE PRIVACY APPEALS

If we deny your privacy request, you can appeal that decision by email at privacy@beatwatch.app or through our Privacy Choices page at https://beatwatch.app/privacy-choices/. Include your original request details and the reason you are appealing. We will respond to an appeal in writing within 45 days, and if we deny your appeal, we will tell you how to submit a complaint to your state’s Attorney General.

HOW TO CONTACT US

If you have a privacy concern, complaint, or a question for us, please contact us at:

privacy@beatwatch.app.

BeatWatch Corporation

151 Calle San Francisco, Suite 200, PMB 5338

San Juan, PR 00901

Unless otherwise stated, BeatWatch stores its primary database, file storage, and backups through Supabase on AWS in the us-east-1 region of the United States. Supabase server functions may run through its global edge network, and Cloudflare hosts the Website and sweepstakes entry form through its distributed edge network. Other processing may occur where Anthropic, 2CB.com, Expo, Apple, Stripe, or other parties processing information are located.