Privacy Policy
Offbeat ("we", "us", "our") operates the Offbeat Music Player mobile application for iOS and iPadOS (the "App", Apple App Store ID 6760564264) and the website at https://offbeatplayer.com (the "Website"). This Privacy Policy explains what data we collect, how we use it, who we share it with, what rights you have, and how to contact us.
Offbeat is built around local playback and creative music tools. Your imported music, videos, recordings, lyrics, exports, and related library assets are intended to stay on your device unless you choose to share or export them. Offbeat does not supply lyrics or sheet music; any lyrics or text you add are user-provided.
1. Data controller
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") the data controller is:
Offbeat
[email protected]
For general support: [email protected].
2. What data we collect
| Category | Specific data | Source | Purpose | Legal basis (GDPR) | Shared with |
|---|---|---|---|---|---|
| Account | email address, OAuth provider id, display name / avatar metadata, last sign-in | you (sign-up / sign-in) | account creation, sign-in, password reset | contract (Art. 6(1)(b)) | Supabase Auth; Apple / Google if you use those sign-in options |
| Subscription | tier, status, product id, current period end, App Store transaction id, store environment | StoreKit on your device, verified with Apple and synced to our backend | manage paid entitlement | contract (Art. 6(1)(b)) | Apple; Supabase |
| Product analytics | app opens, sessions, screen views, playback actions (e.g. play / skip), feature usage, import events, paywall / subscription events, notification-preference events, search query length (not the typed text), app version, platform, plan tier, limited performance samples (e.g. memory) | device, when Enable Analytics is on | improve the product | legitimate interest (Art. 6(1)(f)) — controllable in Settings | Supabase; PostHog (EU host eu.i.posthog.com) |
| Analytics identifiers | stable anonymous device_id (Keychain); session id; if you are signed in, user_id may be attached to analytics / crash rows on our servers | device / auth session | attribute events to an install or account | same as analytics / crash | Supabase (PostHog does not receive your account email or Supabase user id — we never call PostHog identify) |
| Crash / diagnostic | when a crash report is submitted: message, stack trace, breadcrumbs, app version, build number, device class, device_id / session id (and user_id if signed in) | device, when Crash Reporting is on | diagnose failures | legitimate interest (Art. 6(1)(f)) — controllable in Settings | Supabase |
| Optional demographics | age range, primary use case | you (Settings → Help & Support → Privacy & Security → Help improve Offbeat) | product analytics | consent (Art. 6(1)(a)) | Supabase (profiles) |
| Notification preferences | local preference flags; optional sync of marketing / account-activity flags when signed in | you | schedule local notifications; improve messaging | consent / contract | local device; Supabase when signed in |
| Ads (Free tier) | ad requests and related technical data via Google AdMob; Google UMP consent where required; under-13 tagging when the age gate says you are 12 or younger | device / Google SDKs | show banner (and related) ads; comply with consent / child rules | consent / legitimate interest depending on region (UMP) | Google and its ad partners |
| Ad attribution | anonymous app-launch attribution via TikTok Business SDK (no account email / phone identify) | device | measure ad campaigns | legitimate interest (Art. 6(1)(f)) | TikTok |
| Apple Music (optional) | library / recently played metadata needed to display and play linked tracks | you (MusicKit permission) | in-app Apple Music features | consent (Art. 6(1)(a)) | Apple Music / MusicKit; not uploaded to Offbeat servers |
| Lyrics search (optional) | title, artist, album metadata for a search | you (in-app consent for LRCLib search) | fetch user-selected lyrics matches | consent (Art. 6(1)(a)) | lrclib.net |
| Local-only | OAuth / session tokens (Keychain); music library, playlists, waveforms, recordings, favorites, bookmarks, age-gate answer, most settings | device | operate the App offline | contract / necessity | none (optional peer-to-peer Nearby share stays device-to-device) |
We do not knowingly collect personal data from children under 13 for accounts. See Children below.
3. What we do NOT do
- No App Tracking Transparency / IDFA request. We do not call Apple's App Tracking Transparency APIs or use the IDFA for cross-app advertising tracking. Our privacy manifest declares that the App does not track under Apple's definition.
- No sale of personal data. We do not sell, rent, or lease personal data (CCPA / CPRA). To make a related privacy request, email [email protected].
- No uploading your library for analytics. We do not upload your music files, recordings, lyrics files, or exports as part of analytics or crash reporting.
- Search analytics are length-only. We do not send the text of your search queries in analytics events.
- PostHog stays anonymous to your account. PostHog events are not linked to your email or Supabase user id.
4. How we use data
We use collected data to operate Offbeat, authenticate you, manage subscriptions, improve features, understand engagement, monitor reliability, evaluate notification effectiveness, show ads on the Free tier (subject to consent rules), prevent abuse, and respond to support or legal obligations.
5. Your controls
In the App under Settings → Help & Support → Privacy & Security you can:
- Turn Enable Analytics on or off (stops product analytics to Supabase and PostHog going forward when off).
- Turn Crash Reporting on or off (controls whether crash / diagnostic reports may be submitted).
- Optionally set age range and primary use case under Help improve Offbeat.
- Export Data (signed-in): requests a JSON export of account-bound data emailed to your registered email (profile, subscriptions, consent, notification preferences, audit log — not a full dump of every raw analytics event row).
- Delete All Data (signed-in): deletes your account and associated account data via our delete flow, with scrubbing of linked analytics identifiers where implemented.
- Revise age confirmation under Children.
You can also email [email protected] for access, correction, deletion, or other privacy requests. We respond within 30 days.
6. Sharing and service providers
| Provider | Role |
|---|---|
| Apple | App Store billing, Sign in with Apple, MusicKit / Apple Music, push infrastructure |
| Supabase | Authentication, profiles, subscription records, analytics / crash storage, edge functions (EU region) |
| PostHog | Anonymous product analytics (eu.i.posthog.com); session replay off |
| Google (AdMob / UMP) | Free-tier ads and consent messaging |
| TikTok Business | Anonymous ad attribution (e.g. app launch) |
| lrclib.net | Optional lyrics search metadata you submit |
Purchase processing, billing, renewals, and refunds are handled by Apple through the App Store. When you export or share content, the destination you choose governs what happens to that file.
A detailed sub-processor list is available on request via [email protected]. We aim to notify email subscribers at least 30 days before adding a new sub-processor for personal data.
7. Retention
| Data | Retention |
|---|---|
| Product analytics events | 90 days |
| Analytics sessions | 30 days |
| Crash / diagnostic reports | 90 days |
| Account profile | until you delete the account |
| Subscription records | until you delete the account + up to 7 years where tax / accounting rules require |
| Audit log | 13 months |
| Local library / media | until you delete it on device |
After that, data may be deleted, anonymized, or aggregated.
8. Your rights (GDPR / UK GDPR / CCPA / CPRA)
You can:
- Access your data via Settings → Help & Support → Privacy & Security → Export Data, or by emailing [email protected].
- Correct inaccurate profile data via Settings → Account → Profile, or by emailing us.
- Delete your account and data via Settings → Help & Support → Privacy & Security → Delete All Data, or by emailing us.
- Restrict or object to processing where we rely on legitimate interest.
- Portability. Export is delivered as JSON you can reuse.
- Withdraw consent (e.g. analytics, demographics, lyrics search) without affecting prior lawful processing.
- Lodge a complaint with your supervisory authority (in Germany, the relevant *Landesdatenschutzbehörde*).
9. Children
The App is rated 4+ in the App Store. Free features (local import, playback, library tools) are available without an account. Account creation, Google / Apple / email sign-up, and paid subscriptions are limited to users 13 or older. Before account flows, the App asks whether you are 13 or older; the answer is stored locally (UserDefaults) and is not sent to our servers by default. Users under 13 do not get account creation, and AdMob requests are tagged for under age of consent when the age gate indicates a minor.
10. International transfers
Supabase is hosted in an EU region. PostHog analytics use eu.i.posthog.com. Where a provider processes data outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) where required.
11. Security
We use TLS in transit and industry-standard protections for account credentials (passwords are hashed by Supabase Auth). You should protect your device with a passcode or biometric lock.
12. Changes to this Policy
We will post updates here, on the Website, and bump the in-app policy version. For material changes (new categories of personal data or new sharing arrangements) we will request re-consent in the App where required.
13. Contact
[email protected]
[email protected]
Or Settings → Help & Support → Contact Support inside the App.
>
Website copy:
https://offbeatplayer.com/privacy