beates — Privacy Policy
Version 1.0 — Effective September 9, 2026 Status: LIVE — published for launch. Not yet reviewed by a lawyer; see note below.
A note on where things stand. Like the accompanying Terms of Service, beates is launching before formal company registration — see that document's opening note for why. Every data-handling claim below was checked against the current app code (contact syncing, storage providers, notification delivery) as of this version's date rather than assumed, but code changes over time, so re-verify whenever a new feature that touches personal data ships. This has not yet been reviewed by a lawyer — get that review when practical, especially before expanding into regions with strict data protection regimes (EU/UK) at real scale.
1. Who we are
The individual currently operating beates (reachable at privacy@beates.app), operating beates as an individual from Pakistan ("beates," "we," "us"), operates the beates mobile application (the "Service"). This Privacy Policy explains what personal data we collect, why, and what choices you have. It applies to everyone who uses beates, wherever you're located — beates is a global product, not limited to any one country. If beates is later incorporated as a company, that entity will take over as the party described here, and users will be notified per Section 11.
If you're in the European Economic Area, UK, or another jurisdiction with a data protection authority, beates acts as the "data controller" for the personal data described below unless stated otherwise.
2. Data we collect
a) Data you provide directly
- Phone number — used to create and verify your account.
- Profile information — name, username, profile photo, and any bio/details you choose to add.
- Content — photos, videos, voice messages, captions, comments, and text you send or post through Chat, Status, Status+, and Collab Studio.
- Communications with us — if you contact support or report content.
b) Data collected to make the Service work
- Contacts (with your permission) — when you allow contacts access, beates sends the phone numbers from your device's address book to our server to check which of them already have a beates account. The numbers are matched and not stored. Only the result of the match — which existing beates users are in your contacts, plus the name you saved them under — is kept on our servers, so we can show them to you as suggested chats. Numbers of contacts who aren't on beates are discarded as soon as the check is done.
- Camera and microphone — accessed only when you actively take a photo, record a video, or record a voice message. beates does not access the camera or microphone in the background.
- Photo library — accessed only when you choose to pick or save media from your device gallery.
- Push notification token — a device identifier issued by Apple/Google (via Expo's push service) so we can deliver notifications to your device. This is not a marketing identifier and isn't shared with advertisers.
c) Data generated by using the Service
- Activity and engagement data — likes, saves, comments, follows, reposts, and which posts you've viewed. This is used to personalize your Status+ feed when you choose to turn on the optional ranking feature (the "Power" toggle described in-app under Settings → How Your Feed Works), and to operate core features like showing your like/comment counts.
- Interests you select — the topics you choose in Settings → What You Like to Watch, used the same way.
- Device and technical information — app version, operating system, and standard request metadata (such as IP address at the time of a request) generated automatically when your device communicates with our servers or our service providers.
d) What we don't currently collect
We do not currently use advertising SDKs, third-party analytics/tracking libraries, or precise location data. If that changes — for example, when the creator monetization features described in our Terms of Service are eventually built — we will update this Policy before any such collection begins, and highlight the change in-app.
3. How we use your data
We use the data above to:
- Create and secure your account, and verify your phone number.
- Operate core features — deliver messages, show your Status/Status+ posts to the right audience, run Collab Studio's joint-approval flow, and show you content from people you follow or have matched with via contacts.
- Personalize your Status+ feed when you opt in via the Power toggle, using the signals listed in 2(c).
- Send notifications you've enabled (new messages, likes, comments, follows, Collab Studio activity) and play in-app alert sounds.
- Maintain safety — review reports, enforce our Terms of Service, and respond to legal requests.
- Improve and debug the Service (for example, error logs that may incidentally include technical device data).
We do not sell your personal data, and we do not share your content or activity data with advertisers.
4. Who we share data with
We share data only as needed to operate the Service:
- Supabase (our backend database, authentication, and real-time messaging provider) — stores account data, messages, and content metadata on our behalf, acting as our data processor.
- Cloudinary (our media hosting and content-delivery provider) — stores and serves the photos, videos, and audio you upload.
- Expo, Apple, and Google — deliver push notifications to your device; Apple/Google also distribute the app itself through their app stores.
- Other users — content you post is visible to the audience you choose (contacts for Status, followers/Discover for Status+, the other participant for Chat and Collab Studio), by design.
- Legal and safety — we may disclose data if required by law, legal process, or a good-faith belief it's necessary to protect the rights, property, or safety of beates, our users, or the public.
- Business transfers — if beates is involved in a merger, acquisition, or asset sale, data may be transferred as part of that transaction, subject to this Policy or a successor policy you're notified of.
(Worth confirming the exact hosting region(s) with counsel once beates has meaningful EEA/UK usage — not a launch blocker at current scale.)
5. Data retention
- Status posts automatically expire and are removed 24 hours after posting, by design.
- Status+ posts, Chat messages, and Collab Studio posts are retained while your account is active, or until you delete the specific content, clear a chat, or delete your account — subject to the copies-already-shared exception described in our Terms of Service.
- Contact-match data (Section 2(b): the names you saved and the match links) is kept until you revoke contacts permission, remove synced contacts in Settings → Privacy, or delete your account.
- Account deletion — delete your account yourself in Settings → Account → Security → Delete account, or email us to request it (Section 12). We delete or anonymize your personal data within 30 days of a verified deletion request, except where we're required to retain it for legal, safety, or dispute-resolution purposes.
6. Your rights and choices
Depending on where you live, you may have rights to:
- Access the personal data we hold about you.
- Correct inaccurate data (most profile fields are editable directly in-app).
- Delete your data or account.
- Object to or restrict certain processing, including opting out of the personalized Power/interests ranking at any time (Settings → How Your Feed Works).
- Withdraw consent for contacts, camera, microphone, or notification access at any time via your device's OS settings — features that depend on that permission will stop working until you re-grant it.
- Data portability, where applicable.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at privacy@beates.app. We'll respond within the time required by applicable law.
7. Children's privacy
beates is not directed to children under the minimum age stated in our Terms of Service (13, or higher where local law requires), and we don't knowingly collect personal data from children below that age. If we learn we've collected data from a child under the applicable minimum age, we'll delete it. Parents/guardians who believe their child has provided us data can contact us at the address in Section 12 to request deletion.
8. Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS/TLS) between the app and our service providers, and database access controls that restrict which data a given account can read or write. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
9. International data transfers
Because beates is a global product and our service providers (Supabase, Cloudinary) operate infrastructure across multiple countries, your data may be processed in a country other than the one you live in, including countries that may have different data protection laws than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers. (Worth confirming the exact hosting region(s) with counsel once beates has meaningful EEA/UK usage — not a launch blocker at current scale.)
10. Local storage on your device
Some preferences (such as your chat mute setting, chosen wallpaper, and draft posts) are stored locally on your device rather than on our servers, so they stay private to that device and aren't shared with us or other users beyond what's needed to sync the feature itself.
11. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we'll provide notice through the Service before the change takes effect. The "Last updated" date above reflects the most recent revision.
12. Contact us
Questions about this Privacy Policy or your data: privacy@beates.app (a dedicated privacy@ address is recommended once beates has its own domain — this is the working contact until then).
Version 1.0. See the notice at the top of this document about legal review status.