Privacy Policy
This policy explains what Live BPM (“the App”) collects, why, who processes it, and what you can do about it. The App is developed and published by Kostiantyn Pogorielov (“we,” “our,” or “us”), who is the data controller for the purposes of the GDPR. It is available on the App Store and on Google Play.
1. The short version
- Tempo detection runs on your device. Audio from the microphone is not recorded, stored, or uploaded.
- You can use the App without an account. Signing in is optional and only needed to sync your saved sessions across devices.
- The free tier shows ads, and ads mean an advertising identifier is collected and shared with Google for advertising purposes.
- We use analytics and crash reporting to see what breaks and what gets used.
- You can delete your account and its data from inside the App, or by writing to us.
2. The microphone and your audio
The App asks you for exactly one device permission: the microphone. It is active only while a listening tool is running, and it stops when you stop it or leave the tool.
Tempo detection happens entirely on the device. The audio stream is analysed in real time to derive a tempo, a beat position and a signal level; the audio itself is not written to storage, not retained after analysis, and never sent to us.
There is one exception, and it is the Track ID tool. When you ask the App to identify a track, it converts a few seconds of audio into an acoustic signature on the device and sends that signature to Apple’s ShazamKit service, which returns a match if it finds one. A signature is a compact fingerprint of the audio, not the audio itself. Track ID only runs when you use it.
A third-party library used for track recognition declares permissions relating to the phone and to files. The App removes them from its own manifest, so it never requests them from you and does not use them. An older release may still list them on Google Play.
3. What we collect, and who processes it
Some of this is collected by the App itself, and some by third-party SDKs it includes. Both are listed here.
3.1 Collected whenever you use the App
- App interactions — which screens and tools you use, which actions you take, session length. Processed by Google Analytics for Firebase; also collected by the Google Mobile Ads SDK on the free tier.
- Crash logs and diagnostics — stack traces, device model, operating system, app version, and app-performance measurements such as start-up time and network latency. Processed by Firebase Crashlytics and Firebase Performance Monitoring.
- Approximate location, derived from your IP address — used for country-level segmentation of analytics and performance data, and by the ads SDK to estimate general location. We do not collect precise location, and the App has no location permission.
3.2 Collected while ads are shown (free tier only)
- Device and advertising identifiers (the Android advertising ID, or the IDFA on iOS if you allow it), app interactions, diagnostics and IP address, collected by the Google Mobile Ads SDK to serve and measure ads and to prevent fraud.
3.3 Collected only if you sign in (optional)
- Email address, and your name if your Google or Apple account provides one, plus a user identifier we generate for your account. Processed by Supabase, which hosts the account backend on our behalf.
- Content you create in the App — saved sessions, detections, identified tracks and collections — when sync is enabled for your account.
3.4 Collected only if you buy something (optional)
- Purchase history — which plan you bought, its status and its renewal state, tied to the identifier above. Processed by RevenueCat on our behalf. Payment itself is handled by Apple or Google; we never receive your card details.
3.5 Collected only if you opt in to improving back tap (optional)
- Short windows of motion — one second of accelerometer and gyroscope readings around each knock the App detects on the back of your phone, plus a few numbers describing what the App made of that knock. Sent only over Wi-Fi, and only if you tapped Allow on the card that asks.
This one is unlike everything above it: it carries no identifier at all — no account, no device ID, no installation ID — so it cannot be linked back to you, by us or by anyone. Because of that it is not personal data, and the rights in section 10 have nothing to attach to; there is no way to retrieve or delete an individual contribution once it is sent. You can stop contributing at any time in Account → Help improve back tap, which also deletes anything still waiting on your phone.
Full detail, including exactly what is and is not in a contribution: Back tap — what we collect.
4. Why we collect it
- To run the App — accounts, sync, purchases and entitlements. Legal basis: performance of a contract with you.
- To keep it working — crash reporting and performance monitoring. This runs whenever the App runs; it is operational telemetry and is not tied to your ad consent. Legal basis: our legitimate interest in a stable product.
- To understand usage — analytics on which features are used and where people get stuck. Legal basis: consent where consent is required, otherwise our legitimate interest.
- To show ads on the free tier, and to measure them. Legal basis: consent where consent is required.
- To improve back-tap detection, if you opted in (section 3.5). Legal basis: your consent, which you can withdraw at any time. Used for nothing else — not analytics, not advertising, not profiling.
5. Sharing
We do not sell your data.
Advertising is a sharing relationship. When ads are shown, the Google Mobile Ads SDK collects and shares identifiers, IP address, app interactions and diagnostics with Google, which uses them for advertising across its customers. That is a transfer to a third party, and we disclose it as such.
The other services listed above act on our behalf as processors, and use the data only to provide their service to us: Firebase Analytics, Crashlytics and Performance Monitoring (Google), Supabase (accounts and sync hosting), RevenueCat (purchase state), and ShazamKit (track matching). Each of them is bound by a written agreement to process the data only on our instructions and to protect it to at least the standard set out in this policy. Google acts as an independent controller for advertising data under its own terms. We may also disclose data where the law requires it.
6. Where your data goes
We are based in Ukraine, and the services listed above run in the European Union and the United States. Where personal data leaves the EEA or the UK, we rely on the transfer mechanism the receiving service makes available to us: an adequacy decision of the European Commission where one covers that service, and otherwise the European Commission’s standard contractual clauses, together with the UK’s international data transfer addendum for UK data. You can ask us for a copy of the clauses that apply to a given service by writing to the address at the end of this policy.
7. Security
Data moving between the App and our services travels over TLS. Account data at Supabase is held under row-level security, so each record is reachable only by the account it belongs to. Deleting your account removes it and the data attached to it, as described in section 9. No system is perfect, and we do not claim otherwise — if we ever become aware of a breach affecting your data, we will notify you and the relevant authority as the law requires.
8. Ads, consent and your choices
- If you are in the EEA, the UK or another region with equivalent rules, the App shows a consent form before ads and analytics collection is enabled, and analytics and ad storage default to denied until you answer it. If your region requires it, you can reopen that choice at any time from Account → Privacy Settings in the App.
- Outside those regions, ads and analytics on the free tier are part of how the App is funded and are not individually optional — but you can remove ads entirely with a one-time purchase, and paying tiers load no advertising SDK at all.
- On iOS, if the system asks you for tracking permission, declining it means ads stay non-personalised.
- On Android you can reset or delete your advertising ID in the system settings; on iOS you can turn tracking off for the App at any time.
9. Retention and deletion
- On your device: your sessions and settings live in local storage and are removed when you uninstall the App.
- Your account: data held for your account is kept until you delete it. You can do that in the App at Account → Delete account, which removes the account and the data attached to it. You can also request deletion without the App — see Delete your account and data, which lists exactly what is removed.
- Analytics, crash and advertising data are held by the services named above under their own retention schedules; they are not tied to your name or email.
- Deleting your account does not cancel a subscription — manage that in your App Store or Google Play account.
10. Your rights
Depending on where you live, you have the right to access the data we hold about you, to have it corrected or deleted, to object to or restrict processing, to withdraw consent you previously gave, and to receive your data in a portable form. Write to the address at the end of this policy and we will answer. If you are in the EEA or the UK you also have the right to complain to your local data protection authority; in the UK that is the Information Commissioner’s Office (ico.org.uk).
11. Children
The App is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has provided us with personal data, write to us and we will delete it.
12. This website
This policy covers livebpm.app as well as the App.
The site sets no cookies and does not identify you. It stores one value in your browser’s local storage — the last global detections figure our server reported to your browser — so the counter on the page does not appear to run backwards; it stays on your device and is cleared with your browser data. That counter is read from our database when the page loads and about once a minute while you are using the page, and tapping the pad on the page adds to it; those requests carry no identifier, but as with any request your IP address is visible to the database provider named in section 3. When you click a store badge, the site records which badge, in which part of the page, and the page’s language, with no identifier attached. Our Worker sees the country your request arrives from, as any web server does, and writes no cookie. Where we measure page traffic, we use a service that sets no cookies and stores no identifiers.
The store links carry a campaign tag so Apple and Google can tell us how many installs came from this site. They report totals to us, never individuals.
13. Changes to this policy
We update this policy when the App changes. The date at the top is the date of the current version, and material changes will be reflected here.
14. Contact
Kostiantyn Pogorielov
Email: support@livebpm.app
