Legal

Privacy Policy

Last updated: 2026-07-24. Effective on next app release.

Offbeat ("we", "us", "our") operates the Offbeat Music Player mobile application for iOS and iPadOS (the "App", Apple App Store ID 6760564264) and the website at https://offbeatplayer.com (the "Website"). This Privacy Policy explains what data we collect, how we use it, who we share it with, what rights you have, and how to contact us.

Offbeat is built around local playback and creative music tools. Your imported music, videos, recordings, lyrics, exports, and related library assets are intended to stay on your device unless you choose to share or export them. Offbeat does not supply lyrics or sheet music; any lyrics or text you add are user-provided.

1. Data controller

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") the data controller is:

Offbeat
[email protected]

For general support: [email protected].

2. What data we collect

CategorySpecific dataSourcePurposeLegal basis (GDPR)Shared with
Accountemail address, OAuth provider id, display name / avatar metadata, last sign-inyou (sign-up / sign-in)account creation, sign-in, password resetcontract (Art. 6(1)(b))Supabase Auth; Apple / Google if you use those sign-in options
Subscriptiontier, status, product id, current period end, App Store transaction id, store environmentStoreKit on your device, verified with Apple and synced to our backendmanage paid entitlementcontract (Art. 6(1)(b))Apple; Supabase
Product analyticsapp opens, sessions, screen views, playback actions (e.g. play / skip), feature usage, import events, paywall / subscription events, notification-preference events, search query length (not the typed text), app version, platform, plan tier, limited performance samples (e.g. memory)device, when Enable Analytics is onimprove the productlegitimate interest (Art. 6(1)(f)) — controllable in SettingsSupabase; PostHog (EU host eu.i.posthog.com)
Analytics identifiersstable anonymous device_id (Keychain); session id; if you are signed in, user_id may be attached to analytics / crash rows on our serversdevice / auth sessionattribute events to an install or accountsame as analytics / crashSupabase (PostHog does not receive your account email or Supabase user id — we never call PostHog identify)
Crash / diagnosticwhen a crash report is submitted: message, stack trace, breadcrumbs, app version, build number, device class, device_id / session id (and user_id if signed in)device, when Crash Reporting is ondiagnose failureslegitimate interest (Art. 6(1)(f)) — controllable in SettingsSupabase
Optional demographicsage range, primary use caseyou (Settings → Help & Support → Privacy & Security → Help improve Offbeat)product analyticsconsent (Art. 6(1)(a))Supabase (profiles)
Notification preferenceslocal preference flags; optional sync of marketing / account-activity flags when signed inyouschedule local notifications; improve messagingconsent / contractlocal device; Supabase when signed in
Ads (Free tier)ad requests and related technical data via Google AdMob; Google UMP consent where required; under-13 tagging when the age gate says you are 12 or youngerdevice / Google SDKsshow banner (and related) ads; comply with consent / child rulesconsent / legitimate interest depending on region (UMP)Google and its ad partners
Ad attributionanonymous app-launch attribution via TikTok Business SDK (no account email / phone identify)devicemeasure ad campaignslegitimate interest (Art. 6(1)(f))TikTok
Apple Music (optional)library / recently played metadata needed to display and play linked tracksyou (MusicKit permission)in-app Apple Music featuresconsent (Art. 6(1)(a))Apple Music / MusicKit; not uploaded to Offbeat servers
Lyrics search (optional)title, artist, album metadata for a searchyou (in-app consent for LRCLib search)fetch user-selected lyrics matchesconsent (Art. 6(1)(a))lrclib.net
Local-onlyOAuth / session tokens (Keychain); music library, playlists, waveforms, recordings, favorites, bookmarks, age-gate answer, most settingsdeviceoperate the App offlinecontract / necessitynone (optional peer-to-peer Nearby share stays device-to-device)

We do not knowingly collect personal data from children under 13 for accounts. See Children below.

3. What we do NOT do

  • No App Tracking Transparency / IDFA request. We do not call Apple's App Tracking Transparency APIs or use the IDFA for cross-app advertising tracking. Our privacy manifest declares that the App does not track under Apple's definition.
  • No sale of personal data. We do not sell, rent, or lease personal data (CCPA / CPRA). To make a related privacy request, email [email protected].
  • No uploading your library for analytics. We do not upload your music files, recordings, lyrics files, or exports as part of analytics or crash reporting.
  • Search analytics are length-only. We do not send the text of your search queries in analytics events.
  • PostHog stays anonymous to your account. PostHog events are not linked to your email or Supabase user id.

4. How we use data

We use collected data to operate Offbeat, authenticate you, manage subscriptions, improve features, understand engagement, monitor reliability, evaluate notification effectiveness, show ads on the Free tier (subject to consent rules), prevent abuse, and respond to support or legal obligations.

5. Your controls

In the App under Settings → Help & Support → Privacy & Security you can:

  • Turn Enable Analytics on or off (stops product analytics to Supabase and PostHog going forward when off).
  • Turn Crash Reporting on or off (controls whether crash / diagnostic reports may be submitted).
  • Optionally set age range and primary use case under Help improve Offbeat.
  • Export Data (signed-in): requests a JSON export of account-bound data emailed to your registered email (profile, subscriptions, consent, notification preferences, audit log — not a full dump of every raw analytics event row).
  • Delete All Data (signed-in): deletes your account and associated account data via our delete flow, with scrubbing of linked analytics identifiers where implemented.
  • Revise age confirmation under Children.

You can also email [email protected] for access, correction, deletion, or other privacy requests. We respond within 30 days.

6. Sharing and service providers

ProviderRole
AppleApp Store billing, Sign in with Apple, MusicKit / Apple Music, push infrastructure
SupabaseAuthentication, profiles, subscription records, analytics / crash storage, edge functions (EU region)
PostHogAnonymous product analytics (eu.i.posthog.com); session replay off
Google (AdMob / UMP)Free-tier ads and consent messaging
TikTok BusinessAnonymous ad attribution (e.g. app launch)
lrclib.netOptional lyrics search metadata you submit

Purchase processing, billing, renewals, and refunds are handled by Apple through the App Store. When you export or share content, the destination you choose governs what happens to that file.

A detailed sub-processor list is available on request via [email protected]. We aim to notify email subscribers at least 30 days before adding a new sub-processor for personal data.

7. Retention

DataRetention
Product analytics events90 days
Analytics sessions30 days
Crash / diagnostic reports90 days
Account profileuntil you delete the account
Subscription recordsuntil you delete the account + up to 7 years where tax / accounting rules require
Audit log13 months
Local library / mediauntil you delete it on device

After that, data may be deleted, anonymized, or aggregated.

8. Your rights (GDPR / UK GDPR / CCPA / CPRA)

You can:

  • Access your data via Settings → Help & Support → Privacy & Security → Export Data, or by emailing [email protected].
  • Correct inaccurate profile data via Settings → Account → Profile, or by emailing us.
  • Delete your account and data via Settings → Help & Support → Privacy & Security → Delete All Data, or by emailing us.
  • Restrict or object to processing where we rely on legitimate interest.
  • Portability. Export is delivered as JSON you can reuse.
  • Withdraw consent (e.g. analytics, demographics, lyrics search) without affecting prior lawful processing.
  • Lodge a complaint with your supervisory authority (in Germany, the relevant *Landesdatenschutzbehörde*).

9. Children

The App is rated 4+ in the App Store. Free features (local import, playback, library tools) are available without an account. Account creation, Google / Apple / email sign-up, and paid subscriptions are limited to users 13 or older. Before account flows, the App asks whether you are 13 or older; the answer is stored locally (UserDefaults) and is not sent to our servers by default. Users under 13 do not get account creation, and AdMob requests are tagged for under age of consent when the age gate indicates a minor.

10. International transfers

Supabase is hosted in an EU region. PostHog analytics use eu.i.posthog.com. Where a provider processes data outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) where required.

11. Security

We use TLS in transit and industry-standard protections for account credentials (passwords are hashed by Supabase Auth). You should protect your device with a passcode or biometric lock.

12. Changes to this Policy

We will post updates here, on the Website, and bump the in-app policy version. For material changes (new categories of personal data or new sharing arrangements) we will request re-consent in the App where required.

13. Contact

[email protected]
[email protected]
Or Settings → Help & Support → Contact Support inside the App.

>

Website copy: https://offbeatplayer.com/privacy