← DiscoBeat

Privacy Policy

Last updated: 23 September 2026.

The short version. DiscoBeat works without an account and without sending anything to us. The camera and microphone are analysed on your phone and never recorded or sent. The app talks to your lights directly over your own Wi-Fi. If you choose to, you can send us crash reports (which needs an account) and anonymous measurements that help make the app better (which do not). There is no analytics, no advertising and no tracking, and we do not sell or share anything.

Who is responsible

DiscoBeat is published by Taylor Addison, an individual based in Georgia, USA, who is the controller of the data described here. Questions about this policy go to privacy@discobeat.app.

What stays on your phone

What reaches us, and only if you choose

An account (optional). You never need one to use DiscoBeat. If you sign up in Settings → Account, we store your email address, a password hash (never the password), and the date the account was created. On the web app at my.discobeat.app, signing in sets one strictly necessary cookie that holds your session; no script can read it. The website at discobeat.app sets no cookies.

Diagnostics (optional, needs an account). If you are signed in and switch on Send diagnostics in Settings, the app uploads the crash, hang and performance reports your phone's operating system prepares (Apple's MetricKit on iPhone). They describe how the app behaved — where it crashed, how long it hung — and contain nothing you said, played or filmed. They are linked to your account so that we can delete them with it.

Anonymous measurements (optional, no account). Two separate switches in Settings → Sharing, both off until you turn them on:

Neither carries an account, a device identifier, a light's name or network address, or anything else that points to you, your phone or your home, and samples are not stored with the IP address they arrived from. Because nothing ties a sample to you, we cannot find yours to show or delete it; turning the switch off stops new ones.

Email you send us at support@ or privacy@ is kept to answer you.

Purchases. Pro is bought through the App Store or Google Play, who handle payment under their own policies. We never see your payment details. The purchase is checked on your phone; nothing about it is sent to our server.

That is everything. There are no analytics, advertising, attribution or crash-reporting SDKs in the app, no third-party script on this site or the web app, and we do not track you across other companies' apps or websites.

Who else handles it

None of them may use your data for their own purposes. We do not sell, rent or share personal data with anyone else, and we do not use it for advertising.

Where it lives

Our server is in Georgia, USA, where the publisher is. Cloudflare's network is global, so a request may pass through the Cloudflare location nearest you on its way. If you use DiscoBeat from another country, what you choose to send is transferred there.

How long it is kept

Our server deletes expired data every night. A deleted row still exists in the backups taken before it was deleted until those backups expire: backups are taken nightly and kept for 14 days on the server and 30 days off-site, so anything deleted is gone from every copy within a further 30 days.

Deleting your account

Inside the app: Settings → Account → Delete account. The account, its email address and its diagnostics are erased from the live database at once, and from backups within a further 30 days. You can also email privacy@discobeat.app from the address on the account. Deleting the app removes everything that was only on your phone.

Your rights

You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted, at any time, at the address above, and we will answer within 30 days. If you are in the EU or UK you can also object to how we use your data and complain to your data protection authority. Where we rely on your consent (diagnostics and the anonymous measurements), you can withdraw it by turning the switch off.

Children

DiscoBeat is not directed at children under 13 (16 in some EU countries), and accounts are not for them. We do not knowingly collect their data; tell us if you believe we have, and we will delete it.

Security, honestly

Everything travels over TLS. Passwords are hashed, never stored. The database refuses by default and lets each account reach only its own rows, and the anonymous samples cannot be read back by anyone through the API — not even by whoever sent them. On the web, your session is an HttpOnly cookie no script can read. No system is perfectly secure, and if a breach affects you we will tell you.

Changes

When this policy changes, the date at the top changes with it. Material changes are announced inside the app before they take effect, and nothing already collected is used in a new way without asking.