BeatMe

Legal

Privacy Policy

This policy explains what personal data BeatMe collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It is written to be read, not skimmed past — so it uses plain language wherever the law allows.

Effective
28 July 2026
Last updated
28 July 2026
Applies to
BeatMe app (iOS & Android) and beatme.dev

1. Who we are

BeatMe is a social daily-games app operated by FractalX (“BeatMe”, “we”, “us”, “our”), a company established in the United Arab Emirates.

For the purposes of the EU/UK General Data Protection Regulation (GDPR) and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), FractalX is the data controller for the personal data described in this policy.

You can reach us about anything in this policy — including all privacy requests — at admin@fractalx.io. We have not appointed a Data Protection Officer, as our processing does not meet the thresholds that require one; privacy requests are handled directly by the FractalX team at the address above.

2. Scope of this policy

This policy covers the BeatMe mobile app on iOS and Android, the BeatMe website at beatme.dev (including invite links and the waitlist form), and the backend services that run them.

BeatMe includes third-party games that run inside the app. Those games run in a sandboxed in-app browser view, are served from our own storage, and receive only the gameplay session data needed to run and score a round. They do not receive your name, email, avatar or contact details.

Where we link out to a third party (an app store, an advertiser’s landing page, a sign-in provider), that party’s own privacy policy governs what it does with your data. We are not responsible for third-party sites we do not control.

3. Summary of what we collect

The short version, matching the Data Safety disclosure on our Google Play listing and the Privacy Nutrition Labels on our App Store listing:

CategoryCollected?Linked to you?Shared?
Account info (email, display name, avatar, birth year)YesYesNo
Gameplay activity (scores, plays, rankings)YesYesNo
Messages you send in group chatYesYesNo
App diagnostics (platform, app version, errors)YesYesNo
Advertising identifier (AAID / IDFA)Only with your consentYesYes — to ad partners
Push notification tokenYesYesYes — to Google/Apple to deliver
Install attribution (Play install referrer)YesNoNo
Precise locationNo
Contacts, photos, files, health, financial dataNo
We never sell your personal data for money. Sharing an advertising identifier with ad partners for personalised ads may count as a “sale” or “share” under some US state laws — see section 6 and section 13 for how to opt out.

4. Data we collect, why, and on what legal basis

We only collect what the product actually needs. The table below lists every category, why we process it, and the legal basis we rely on under the GDPR (Article 6). Under the UAE PDPL the equivalent bases are consent, performance of a contract, protection of legitimate interests, and compliance with a legal obligation.

WhatWhy we need itLegal basis
Email address and, for email sign-up, a hashed password. If you use Sign in with Apple or Google, the identifier and email that provider returns (Apple may return a private relay address, which is fine — we never need your real one).To create and secure your account, sign you in, and send account-critical email such as password resets.Performance of a contract
Display name, avatar image URL, birth year, language preference.To show you to your group, run the age gate, and localise the app.Performance of a contract; legal obligation (age assurance)
Groups you create or join, group memberships, invite codes you generate or redeem, join requests.The core social feature — a private league needs to know who is in it.Performance of a contract
Gameplay data: scores, placement points (gems), play attempts, daily play sessions, high scores, standings, season results and season recaps, game ratings you leave.To run the daily game, calculate rankings and seasons, and prevent score tampering. Scoring is server-side, so we must store it.Performance of a contract; legitimate interests (anti-cheat)
Chat messages and reactions you post in a group.To deliver your messages to your group and keep the conversation history.Performance of a contract
Gameplay events: game started / completed / abandoned / errored, plus platform (iOS or Android) and app version.To see which games break, on which OS and build, and to fix them. This is product diagnostics, not behavioural profiling.Legitimate interests (keeping the app working)
Push notification token issued by Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS), and your notification on/off preference.To send the daily-game nudge and group notifications you asked for.Consent
Advertising identifier (Android Advertising ID, iOS IDFA), coarse ad-request signals such as IP-derived country, device type and OS.To show ads that fund the free app, cap how often you see the same ad, and measure whether an ad worked.Consent for personalised ads and for the IDFA/AAID; legitimate interests for non-personalised ads
Rewarded-ad grants: a record that you watched a rewarded ad and received an extra try.To grant the reward and stop the same ad view being claimed twice.Performance of a contract; legitimate interests (fraud prevention)
Google Play install referrer: the campaign or invite link that led to your install. Not tied to a name or email.To understand which invite links and campaigns bring players in.Legitimate interests (measuring our own reach)
Reports you file, reports filed about your content, moderation decisions, suspensions and bans.To keep groups safe and enforce our terms.Legitimate interests (safety); legal obligation
Server logs from our backend and hosting providers, which include IP address, timestamp and request metadata.Security, abuse detection, rate limiting and debugging. Kept short and never used to build a profile of you.Legitimate interests (security)
Waitlist email, if you submit one on beatme.dev.To tell you when BeatMe launches in your market.Consent

Where we rely on legitimate interests, we have balanced those interests against your rights and concluded the processing is limited, expected and low-risk. You can object at any time — see section 13.

Where we rely on consent, you can withdraw it at any time, and withdrawing is as easy as giving it: turn notifications off in your profile, reopen the ad privacy form from your profile, or email us. Withdrawal does not affect processing that already happened lawfully.

5. What we do not collect

  • Precise or background location. BeatMe never requests location permission.
  • Your contacts, calendar, photo library, microphone, camera or files.
  • Payment or financial data. BeatMe is free; there are no in-app purchases, so no card details ever reach us.
  • Special-category data under GDPR Article 9 — health, biometrics, race, religion, political opinions, sexual orientation or trade union membership. Please do not put such data in your display name or chat messages.
  • Your device's phone number, IMEI or hardware serial.
  • Keystroke, screen-recording or session-replay data.

6. Advertising, consent and advertising IDs

BeatMe is free and is funded by ads. We use Google AdMob with mediation from Liftoff Monetize (Vungle). Ads appear as rewarded videos you choose to watch in exchange for an extra try, and as occasional interstitials.

In the EEA, UK and Switzerland we show Google’s certified consent form (the User Messaging Platform, an IAB TCF-compliant consent management platform) before any personalised advertising or advertising-identifier access happens. Your choice is recorded with a timestamp and passed to every ad partner. If you decline, you still get ads — but non-personalised ones, selected from the content of the screen rather than from a profile of you.

On iOS, we additionally ask for App Tracking Transparency permission before the IDFA can be read. Decline and no IDFA is accessed at all.

You can change your ad choices at any time: Profile → Ad privacy reopens the consent form. On Android you can also reset or delete your advertising ID in Settings → Privacy → Ads; on iOS, in Settings → Privacy & Security → Tracking.

Ad partners act as independent controllers for the data they collect through their SDKs. Their policies: Google and Liftoff/Vungle.

Users we know to be under the applicable age of digital consent are never served personalised ads, and no advertising identifier is requested for them, regardless of any consent signal.

7. Push notifications

If you allow notifications, we store a push token for your device so we can send the daily-game nudge, group activity alerts and season results. The token identifies a device installation, not you personally, but we link it to your account so we know where to send.

Turn notifications off any time in Profile → Notifications or in your OS settings. Tokens are deleted immediately when you delete your account, and stale tokens are pruned automatically.

8. Groups, chat and other players

BeatMe is a social product, so some of your data is visible to other people by design. Inside a group you belong to, other members can see your display name, avatar, birth year is not shown, your scores and placement for each daily game, your position in the standings and season table, your chat messages and reactions, and your season recap if you share it.

Groups are private and invite-only. Anyone holding a valid invite code or link can request to join, so treat invite links like the keys to the group. Certain aggregate leaderboards (for example a global top score for a given game) may show your display name outside your group.

Content you post to a group is stored so the group can keep reading it. If you delete your account, your messages and scores are deleted along with it, which will change what other members see of past rounds.

9. Moderation, reports and enforcement

You can report a message or a player from inside the app. A report records who reported what, the reported content, and a reason. Our staff review reports through an internal admin console; every administrative action is written to an audit log.

Outcomes can include removing content, temporarily suspending an account, or a permanent ban. We keep a record of enforcement decisions for as long as needed to make them stick and to defend them if challenged. Access to the admin console is restricted to named staff accounts and protected by passwordless email authentication.

10. Who we share data with

We do not sell your personal data. We share it only with the service providers below, each under a written contract that limits them to processing on our instructions (a GDPR Article 28 data processing agreement, or equivalent), except where the party is noted as an independent controller.

ProviderWhat they handleRole
SupabaseOur database, authentication, file storage and server-side functions. Effectively all account, group, gameplay and chat data lives here.Processor
Google (Firebase Cloud Messaging, Firebase Remote Config)Delivering push notifications; serving feature-flag configuration to the app.Processor
Google (AdMob, User Messaging Platform, Play Install Referrer, Sign in with Google)Serving and measuring ads, collecting ad consent, install attribution, and social sign-in.Independent controller
Liftoff / VungleAd mediation and ad serving when AdMob mediates to them.Independent controller
Apple (Sign in with Apple, Apple Push Notification service)Social sign-in and push delivery on iOS.Independent controller
VercelHosting for beatme.dev and the staff admin console.Processor
Fly.ioHosting for the realtime server behind multiplayer arena games.Processor

We may also disclose personal data where we must or should:

  • To comply with a law, court order or valid request from a competent authority — we review each request and disclose only the minimum required.
  • To establish, exercise or defend legal claims.
  • To protect the rights, safety or property of BeatMe, our players or the public — for example when investigating fraud, cheating or threats.
  • To a buyer or successor, if FractalX is involved in a merger, acquisition or sale of assets. You will be notified before your data becomes subject to a different privacy policy.

11. International data transfers

FractalX is established in the UAE, and our providers operate data centres in the European Union, the United States and elsewhere. This means your personal data may be transferred outside your country of residence, including outside the EEA and the UAE.

For transfers of EEA/UK personal data to countries without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), incorporated into our contracts with each provider, together with the technical measures described in section 16. For transfers out of the UAE we rely on the mechanisms permitted by Articles 22 and 23 of the PDPL — an adequate level of protection, contractual undertakings, or your explicit consent.

Ask us at admin@fractalx.io if you want details of the safeguards applying to a specific transfer.

12. How long we keep data

We keep personal data only as long as we need it for the purpose it was collected for, then delete or irreversibly anonymise it.

DataRetention
Account, profile, groups, scores, standings, chat messages, reactions, game ratingsFor as long as your account exists. Deleted immediately when you delete your account.
Push tokensUntil you disable notifications, the token becomes invalid, or you delete your account — whichever is first.
Gameplay diagnostic eventsUp to 24 months, then deleted or aggregated into statistics that no longer identify you.
Rewarded-ad grant records12 months, for fraud and reward-abuse checks.
Reports, moderation decisions, bans and admin audit logsUp to 24 months after the decision, or longer where an ongoing dispute or legal claim requires it. Ban records may be kept longer to stop a banned user simply re-registering.
Server and security logsTypically 30–90 days, depending on the provider.
Waitlist emailUntil launch in your market or until you ask us to remove it, whichever is first.
Aggregate and anonymised statistics (e.g. how many people played a game)Indefinitely. This data cannot be traced back to you.

13. Your rights

Depending on where you live, you have some or all of the following rights. We honour all of them for every user, everywhere, rather than checking your passport first.

  • Access — get confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected. Your display name, avatar and birth year are editable directly in the app.
  • Erasure — have your personal data deleted. You can do this yourself, instantly, from Profile → Delete account.
  • Restriction — ask us to pause processing while a dispute about accuracy or legitimate interests is resolved.
  • Portability — receive the data you gave us in a structured, commonly used, machine-readable format (we provide JSON), or have it sent to another controller where technically feasible.
  • Objection — object to processing based on legitimate interests, including any profiling, on grounds relating to your situation.
  • Withdraw consent — at any time, for notifications, personalised ads or the waitlist, without affecting past lawful processing.
  • No automated decisions — not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions; see section 19.
  • Complain — lodge a complaint with your data protection authority. See section 21.

UAE residents additionally have the PDPL rights to request the cessation of processing, to object to automated processing, and to be informed of any cross-border transfer of their data.

California residents have the rights to know, delete and correct, the right to opt out of the “sale” or “sharing” of personal information for cross-context behavioural advertising, and the right not to be discriminated against for exercising them. We do not sell personal information for money. To opt out of personalised advertising, use Profile → Ad privacy or email us. We do not knowingly sell or share the personal information of anyone under 16.

14. How to exercise your rights

Fastest route

  • Delete everything: Profile → Delete account. This is immediate and permanent — your account, profile, group memberships, scores, messages and push tokens are erased in one operation. There is no grace period and no recovery. No longer have the app? Request deletion here.
  • Fix your details: Profile → edit name, avatar or birth year.
  • Change ad consent: Profile → Ad privacy.
  • Turn off notifications: Profile → Notifications.
  • Everything else (access, export, restriction, objection): email admin@fractalx.io from the address on your account, with “Privacy request” in the subject.

We respond to every request within 30 days. If a request is unusually complex we may extend by a further two months and will tell you why within the first 30 days. Requests are free; we may charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive, and we will explain if so.

We may ask you to verify your identity before acting — normally by confirming you control the email address on the account. This is to stop someone else deleting or downloading your data.

15. Children and teens

BeatMe is not for children under 13. We do not knowingly create accounts for, or collect personal data from, anyone under 13. We ask for your birth year after sign-in and block accounts below the minimum age.

In the EEA and UK, the age of digital consent ranges from 13 to 16 depending on the country. Where a user is below their country’s threshold, we do not rely on consent for processing that requires it: no advertising identifier is requested, and only non-personalised ads are served.

If you believe a child under 13 has given us personal data, email admin@fractalx.io and we will delete the account and its data promptly. Parents and guardians may exercise any of the rights in section 13 on behalf of their child.

16. How we protect your data

  • All traffic between the app, the website and our backend is encrypted in transit with TLS. Data at rest is encrypted by our hosting providers.
  • Every database table is protected by row-level security, so a signed-in user can only read the rows they are entitled to — group members see their own group, and nothing else.
  • The app ships only a public anonymous key. Privileged operations run server-side through audited functions; the service-role key never leaves our servers.
  • Scoring, ranking and score validation happen server-side, so a tampered client cannot forge results or read other players' data.
  • Staff access to the admin console is limited to an explicit allowlist of named accounts, uses passwordless email authentication, and writes every action to an audit log.
  • We keep dependencies patched and review third-party SDKs before adding them.

No system is perfectly secure. We cannot guarantee absolute security, but we do commit to the measures above and to telling you honestly if something goes wrong.

17. Data breaches

If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Article 33 and the UAE PDPL. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly and without undue delay, describing what happened, what data was involved, what we are doing about it, and what you should do.

18. Our website, cookies and local storage

beatme.dev sets no advertising or analytics cookies and runs no third-party trackers. We do not show a cookie banner because we have nothing to ask you about.

The site uses strictly necessary storage only: a session cookie for staff signing into the admin console, and browser local storage used by the in-browser game player to hold your current session. Strictly necessary storage is exempt from consent requirements under the ePrivacy Directive.

Fonts are self-hosted and served from our own domain, so loading the site does not disclose your IP address to a font CDN. If you submit the waitlist form, we store the email address you typed and where you submitted it from; nothing else.

19. Automated decision-making

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. Rankings, standings and season results are computed automatically from your scores, but these are game outcomes, not decisions about you as a person.

Automated checks flag suspicious scores and possible cheating, but a person reviews the case before any account is suspended or banned, and you can contest the outcome by emailing admin@fractalx.io.

20. Changes to this policy

We update this policy when the product changes — a new feature, a new SDK, a new provider. The “last updated” date at the top always reflects the current version.

For material changes — a new purpose, a new category of data, a new class of recipient — we will give you notice in the app before the change takes effect, and where the law requires it, we will ask for your consent again rather than assume it.

21. Complaints

Please come to us first at admin@fractalx.io — most issues are faster to fix directly. You always have the right to go straight to a regulator instead.

  • UAE: the UAE Data Office (Federal Data Office), established under Federal Decree-Law No. 45 of 2021.
  • EEA: the data protection authority of the country where you live, work, or where you think the infringement happened.
  • UK: the Information Commissioner's Office (ico.org.uk).

22. Contact us

FractalX — operator of BeatMe
United Arab Emirates
Privacy contact: admin@fractalx.io

Put “Privacy request” in the subject line and we will route it correctly. We answer within 30 days.