Privacy Policy
Version: 2.1
Effective Date: June 8, 2026
Last Updated: June 8, 2026
BeatValet ("we," "us," or "our") is operated by BeatValet, a sole proprietorship based in Ontario, Canada. This Privacy Policy describes how we collect, use, store, and protect information when you use the BeatValet desktop application and related services (collectively, the "Service"), and when we conduct business outreach to music producers.
By using BeatValet, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
If you are a music producer who received outreach from us and want to be removed from our records, see Section 3.5 below.
1. Information We Collect
1.1 Account Information
When you create a BeatValet account, we collect:
- Email address
- Password (stored as a salted hash; we never store plaintext passwords)
- Self-reported attribution source (optional, e.g., your answer to "How did you hear about us?")
- Self-reported YouTube channel URL or handle (optional, used to personalize your experience and link your account to your channel)
1.2 User Configuration Data
To operate the Service, we store your preferences and settings, including:
- Output folder paths and file naming preferences
- Media generation settings (e.g., image generation prompts, template choices)
- Platform behavior preferences (visibility defaults, description templates, license settings)
This data is stored in our database hosted on Supabase.
1.3 Project Metadata
When you process a beat through BeatValet, we collect and store:
- Project file name and beat title
- Musical metadata (BPM, key, genre tags)
- Processing status and stage progress
- Upload URLs (BeatStars, YouTube) once published
- Error logs for troubleshooting
We do not upload or store your audio files, FL Studio project files (.FLP), or rendered stems on our servers. Audio processing occurs locally on your device.
1.4 Payment Information
When you subscribe to a paid plan, payment is processed by Stripe, Inc. We receive limited information from Stripe necessary to administer your subscription:
- Stripe customer ID
- Subscription tier and billing status
- Payment success and failure events
- Billing email (which may differ from your account email)
We do not receive or store your full credit card number, CVV, or bank account details. Payment information is collected and stored by Stripe directly under Stripe's privacy policy.
1.5 YouTube Data — Accounts You Connect to BeatValet
When you connect your YouTube account, BeatValet accesses the following through the YouTube API using the youtube.force-ssl scope:
- Channel information — to display your channel name and verify your account connection.
- Video uploads — to upload videos to your YouTube channel on your behalf, including setting the video's title, description, tags, thumbnail, visibility, and scheduled release date at the time of upload.
- Playlist management — to add uploaded videos to your existing YouTube playlists.
- Video metadata updates — to modify titles, descriptions, tags, thumbnails, visibility, and scheduled release dates on videos previously uploaded through BeatValet.
- YouTube Channel ID — stored on our servers and associated with your BeatValet account to support multi-channel features available on certain subscription tiers and to enforce per-tier connection limits.
How YouTube data is handled:
- YouTube OAuth tokens (access and refresh tokens) are stored only on your local device using your operating system's secure credential storage (Windows DPAPI, macOS Keychain, or Linux Secret Service). They are never transmitted to or stored on our servers.
- We do not access, collect, or store your YouTube watch history, subscriptions, comments, analytics, or any YouTube data beyond what is described above.
- We do not use YouTube data accessed through your connected account for advertising, outreach, marketing attribution, market research, or any purpose unrelated to the functionality you initiate within BeatValet.
- We do not transfer your YouTube data to any third party, except as required to deliver the Service you have requested (for example, uploading a video to YouTube on your behalf).
- Our handling of YouTube user data complies with the Limited Use requirements of the Google API Services User Data Policy (see Section 10).
1.6 Communications Data
When you contact us for support or respond to our communications, we retain:
- The content of your messages
- Email metadata (timestamps, sender)
- Any attachments you choose to send
We use this only to respond to you and improve our support and product.
1.7 Automatically Collected Information
We may collect limited technical information to maintain and improve the Service:
- Application version and operating system
- Error reports and crash logs (no personal content included)
- Aggregate, non-identifying product usage telemetry (e.g., feature usage counts)
We do not use third-party behavioral analytics or cross-site tracking services. We do not place advertising cookies.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service — process your beats, organize files, generate media assets, and upload to platforms you have connected.
- Administer your subscription — process payments, send billing notifications, and manage your account tier.
- Maintain your preferences — remember your configuration settings across sessions.
- Troubleshoot and improve — diagnose errors and improve reliability.
- Communicate with you — respond to support requests, notify you of important changes to the Service, and send product updates and tips (you may opt out of marketing emails at any time).
- Operate the producer research and outreach activities described in Section 3 below.
We do not use your information for behavioral advertising, sell your data to third parties, or use your content to train artificial intelligence models.
3. Producer Research and Outreach Practices
This section describes how we collect and use publicly available information about music producers for product research and direct business outreach. It applies whether or not you are a BeatValet user.
3.1 What We Do
BeatValet operates an internal database of music producers active in the type-beat market segment. This database is used for two purposes:
- Product research and analytics, including understanding niche trends, market segmentation, and ecosystem evolution.
- Direct business outreach to producers who have publicly published a business contact email on their YouTube channel, inviting them to evaluate BeatValet.
3.2 What We Collect
For each producer in the database, we may collect and store the following from publicly accessible sources:
- YouTube channel ID, channel name, and channel URL
- Business contact email address published in YouTube video descriptions
- Country information (where publicly displayed by the channel)
- Channel statistics: subscriber count, total view count, video count
- Recent video upload metadata: titles, upload dates, video IDs
- Derived information: niche and genre categorization, upload frequency, growth trends
We collect this information through the official YouTube Data API v3. We do not bypass technical access controls or use the API in ways that violate YouTube's Terms of Service.
3.3 Lawful Basis and Consent
We process this information on the basis of legitimate business interest in identifying and contacting potential customers in our target market. The contact email addresses we use are publicly published by producers in their video descriptions to receive business inquiries.
We do not collect data from producers who do not publish a business contact email or who indicate that they are not open to business contact.
3.4 Outreach Practices
When we contact producers from this database, our communications:
- Identify BeatValet clearly as the sender, with a real business address
- Include a clear opt-out mechanism in every message
- Are sent via Instantly.ai, an email delivery service provider that handles unsubscribe and bounce processing on our behalf
- Are designed to comply with Canada's Anti-Spam Legislation (CASL), the U.S. CAN-SPAM Act, and equivalent legislation in other applicable jurisdictions
3.5 How to Opt Out or Be Removed
If you are a music producer and you want to be removed from our database, take any of the following steps:
- Reply to any email from us with "remove me" or "unsubscribe." This adds you to our permanent suppression list within 24 hours.
- Click the unsubscribe link in any email from us.
- Email privacy@beatvalet.com with your YouTube channel URL or the contact email we used. We will confirm removal within 7 days and permanently exclude your channel from future re-collection.
Removal is permanent. We maintain a suppression list keyed on YouTube channel ID and email address. Once added, your information is purged from our active database; only the suppression list entry is retained to ensure you are never re-added.
3.6 Retention and Refresh
Active producer profile records used for outreach are refreshed at least every 30 days through the YouTube API. If an active profile record cannot be refreshed within that window (because the channel has become inaccessible or deleted, or we have stopped active outreach research on it), the active profile record is removed from our outreach database within 30 days. We may retain historical statistical snapshots and derived, non-contact analytics for longitudinal research, trend analysis, and product planning, provided those retained records are not used to contact the producer unless the active profile is refreshed again. Suppression list entries (Section 3.5) are retained indefinitely to honor opt-out requests.
3.7 What We Do Not Do
To be explicit, we do not:
- Sell, license, or transfer producer data to any third party other than the service providers listed in Section 4, who act on our behalf and only for the purposes described
- Combine producer data with data from other major platforms in ways that would enable cross-platform profiling
- Use this data for any purpose unrelated to product research and our own direct business outreach
- Use this data to train artificial intelligence models
- Contact producers who have opted out, regardless of how many times we encounter their channel in subsequent research
4. Third-Party Services
BeatValet uses the following third-party service providers to deliver its functionality. We do not share information with any third parties beyond those listed below, and these providers act on our behalf only for the purposes described. If we add new third-party services, we will update this policy before any data is shared.
4.1 Supabase
- Purpose: User authentication, database storage for account settings, project metadata, and the producer research database.
- Data shared: Email address, user preferences, project metadata, producer research data (not audio files).
- Privacy Policy: https://supabase.com/privacy
4.2 Stripe
- Purpose: Payment processing and subscription management.
- Data shared: Email address, billing details (collected directly by Stripe).
- Privacy Policy: https://stripe.com/privacy
4.3 Google APIs (YouTube Data API v3)
- Purpose: Upload videos and manage video metadata on your YouTube channel; read public producer channel metadata for research purposes (see Section 3).
- Data shared: Video files (generated locally and uploaded directly to YouTube), video metadata (title, description, tags, thumbnail).
- Privacy Policy: https://policies.google.com/privacy
BeatValet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See Section 10 for our full Limited Use affirmation.
4.4 Google Gemini / Imagen API
- Purpose: Generate thumbnail images for your beats based on text prompts.
- Data shared: Text prompts that may include your beat title, genre, and style descriptors. No audio files are shared.
- Privacy Policy: https://policies.google.com/privacy
4.5 SendGrid
- Purpose: Transactional email delivery (account confirmations, password resets, billing notifications).
- Data shared: Email address, message content.
- Privacy Policy: https://www.twilio.com/legal/privacy
4.6 AWeber
- Purpose: Marketing email communications to existing customers and subscribers who have opted in.
- Data shared: Email address, opt-in preferences.
- Privacy Policy: https://www.aweber.com/privacy.htm
4.7 Instantly.ai
- Purpose: Outreach email delivery for the producer research program described in Section 3. Manages unsubscribe lists, bounce processing, and reply tracking on our behalf.
- Data shared: Producer business contact emails (collected from public YouTube video descriptions), email message content, unsubscribe and reply status.
- Privacy Policy: https://www.instantly.ai/privacy-policy
You may unsubscribe from marketing or outreach emails at any time using the unsubscribe link included in every email. Unsubscribing from these does not affect transactional communications related to your account (e.g., password resets, billing notifications, critical service notifications).
5. Data Storage and Security
5.1 Where Your Data Is Stored
- Server-side data (account settings, project metadata, subscription data, producer research database) is stored on Supabase infrastructure. Supabase hosts data on Amazon Web Services (AWS) with servers located in regions that may include the United States and Canada.
- Payment data is stored by Stripe in their own infrastructure under their own privacy policy.
- Local data (audio files, rendered exports, YouTube OAuth tokens) remains on your device and is never transmitted to our servers.
5.2 Security Measures
We use commercially reasonable measures to protect your data, including:
- Encrypted connections (TLS/HTTPS) for all communications between the desktop application and our servers.
- Salted password hashing for account credentials.
- Operating system secure credential storage for sensitive tokens (YouTube OAuth, BeatStars sessions).
- AES-256-GCM encrypted local data container for sensitive cached information, with platform-native key wrapping (DPAPI on Windows, Keychain on macOS).
- Row-level security policies on our database to ensure users can only access their own data.
- Restricted access to the producer research database; only authorized personnel can query it.
No method of electronic storage or transmission is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Data Retention
- Account data is retained for as long as your account is active.
- Project metadata is retained for as long as your account is active to provide upload history and status tracking.
- Payment data retention is governed by Stripe and applicable financial record-keeping laws (typically 7 years for tax purposes).
- Active producer outreach profile data is refreshed at least every 30 days, otherwise removed from the outreach database within that window. Historical statistical snapshots and derived, non-contact analytics may be retained for longitudinal research, trend analysis, and product planning, subject to the limits described in Section 3.6.
- Suppression list entries (for producers who have opted out) are retained indefinitely to honor opt-out requests.
- Communications data is retained for 24 months after our last interaction with you, then deleted unless required for legal or accounting purposes.
- Local data (audio files, exports, tokens) is under your control and is not managed by us.
When you delete your account, we will delete your account data and project metadata from our servers within 30 days. Some data may persist in encrypted backups for up to 90 days before being purged. Subscription history may be retained for accounting purposes as required by law.
7. Your Rights and Choices
7.1 Access and Portability
You may request a copy of the personal data we hold about you by contacting us at privacy@beatvalet.com. We respond to verified requests within 30 days.
7.2 Correction
You may update your account information and preferences through the BeatValet application at any time. For other corrections, contact privacy@beatvalet.com.
7.3 Deletion
You may request deletion of your account and associated data by contacting us at privacy@beatvalet.com. We will process deletion requests within 30 days. Some data may be retained where required by law (e.g., payment records).
7.4 Revoking Third-Party Access
- YouTube: You can revoke BeatValet's access to your YouTube account at any time through your Google Account permissions page. Revoking access will delete the locally stored YouTube tokens from BeatValet.
- BeatStars: You can disconnect your BeatStars session through the BeatValet settings screen at any time.
7.5 Opting Out of Producer Outreach
If you are a music producer and want to be removed from our outreach database, see Section 3.5 for instructions.
7.6 Canadian Privacy Rights
If you are a resident of Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to access, correct, and request deletion of your personal information. To exercise these rights, contact us at privacy@beatvalet.com.
7.7 European Economic Area Privacy Rights
If you are a resident of the European Economic Area, the United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including:
- The right to access, correct, or delete your personal data
- The right to restrict or object to processing
- The right to data portability
- The right to lodge a complaint with a supervisory authority
To exercise these rights, contact us at privacy@beatvalet.com. We process most data on the basis of contractual necessity (for our users) or legitimate interest (for producer outreach), and we will respect objections and erasure requests as required by law.
7.8 California Privacy Rights
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, request deletion, and opt out of any sale of personal information. We do not sell personal information.
8. Children's Privacy
BeatValet is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at privacy@beatvalet.com.
9. International Data Transfers
If you are located outside of Canada, please be aware that your information may be transferred to, stored, and processed in Canada and the United States (where our infrastructure providers operate). By using the Service, you consent to this transfer. We rely on standard contractual clauses or equivalent safeguards with our sub-processors where required.
10. Compliance with Google API Services User Data Policy
BeatValet's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide or improve user-facing features that are prominent in BeatValet.
- We do not transfer Google user data to others except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- We do not use Google user data to serve advertisements, including retargeted, personalized, or interest-based advertising.
- We do not allow humans to read Google user data, unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes (such as investigating abuse), to comply with applicable law, or our use is for internal operations and the data has been aggregated and anonymized.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI/ML models.
Public producer data described in Section 3 is collected through the YouTube Data API for legitimate research and outreach purposes and is treated as a separate category from YouTube user data accessed via OAuth. We do not use producer research data to enrich, attribute, or profile authenticated BeatValet users.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Version," "Effective Date," and "Last Updated" date at the top of this page and notify you through the BeatValet application. For material changes, we will require re-acceptance of the updated policy before continued use of the Service.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: privacy@beatvalet.com
Website: https://www.beatvalet.com
For YouTube data-related questions specifically, you may also contact us at the same address with "YouTube Data" in the subject line for priority handling.
This Privacy Policy was last updated on June 8, 2026 (Version 2.1).