Privacy Policy
1. Who we are
Beatle is operated by Humble Superintelligence. For the purposes of the UK GDPR and EU GDPR, we are the data controller for the personal data described here. Contact: privacy@beatle.fm.
2. What we collect
- Nothing, by default. You can open Beatle and use every tool without giving us an identifier. In that mode your profile and sessions are written only to your own browser's local storage.
- Email address — only if you choose to sign in. It is used to send you a one-time sign-in link and to associate your saved work with you. There is no password.
- Artist profile — the name, genres, DAW, career stage and goal you choose to enter. This exists so the tools stop giving you generic advice.
- Session transcripts — the prompts you send and the responses you receive inside each tool, stored so a session survives a reload.
- Shared responses — where you explicitly press Share, the response, the prompt that produced it and a view count are stored against a random token so the link resolves for other people.
- Technical data — standard server logs kept by our hosting and infrastructure providers, including IP address and user agent, retained for security and abuse prevention.
We do not collect payment card details directly; any future paid plans will be processed by a PCI-compliant payment provider.
3. Where your data goes
- Anthropic — the text you send to a tool, plus the tool's instructions and your artist profile, is transmitted to Anthropic's API to generate a response. It is processed under Anthropic's commercial terms. Do not paste anything into Beatle that you would not send to a third-party processor.
- Supabase — where the deployment is configured for it, authentication, your profile and your sessions are stored in a Supabase Postgres database, protected by row level security so rows are readable only by the account that owns them.
- Hosting provider — the site and its serverless functions are served by a hosting provider such as Vercel or Netlify, which processes request metadata.
We do not sell personal data, we do not share it with advertising networks, we run no affiliate programme, and we do not use your conversations to train any model.
4. Legal bases
Where GDPR applies, we rely on: contract, to provide the Service you asked for; legitimate interests, to keep the Service secure, prevent abuse and understand aggregate usage; and consent, where you volunteer optional profile information or choose to publish a shared response. You may withdraw consent at any time.
5. Storage in your browser
Beatle uses your browser's local storage rather than tracking cookies. It holds your profile, your sessions and your interface preferences. If you sign in, Supabase additionally stores an authentication token so you stay signed in. We set no advertising or analytics cookies. Clearing site data removes all of it.
6. Your personal API key
If you supply your own Anthropic API key in the settings panel, it is held in memory for that browser tab only. It is never written to local storage, never placed in a cookie, and never transmitted to us — requests using it go directly from your browser to Anthropic. Closing the tab discards it.
7. Retention
Locally stored data persists until you clear it, which you can do at any time from the settings panel. Cloud-stored profiles and sessions persist until you delete them or request account deletion. Shared responses persist until deleted on request. Server logs are retained by our providers for a limited period consistent with their standard practice.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. California residents have the right to know, delete, correct and opt out of any sale or sharing of personal information — we do not sell or share it as those terms are defined. To exercise any right, write to privacy@beatle.fm. We will respond within the period required by applicable law. You also have the right to complain to your local supervisory authority.
9. Security
Traffic is encrypted in transit with TLS. The Anthropic API key used to serve visitors is held only in the server environment and is never exposed to the browser. Database access is constrained by row level security. No system is perfectly secure, and we cannot guarantee absolute security.
10. International transfers
Our providers operate globally, so your data may be processed in the United States and other countries. Where required, transfers out of the UK or EEA rely on appropriate safeguards such as the European Commission's standard contractual clauses.
11. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes
If this policy changes materially we will update the date above and, where practicable, give notice in the Service.
13. Contact
privacy@beatle.fm. See also the Terms & Conditions.