This Privacy Policy explains what data BeatBounty ("we") collects when you use beatbounty.app and app.beatbounty.app (the "Service"), how we use it and what choices you have.
Account data. Email address and a password hash (if you register with email), display names of your profiles, and records of your activity in the Service (campaigns, submissions, wallet transactions).
TikTok data (with your consent). If you sign in with TikTok or link a TikTok account, we receive data through the official TikTok API strictly within the permissions you approve on TikTok's consent screen:
We store the OAuth tokens needed to access this data in encrypted form (AES-256-GCM). We never receive or store your TikTok password. We do not collect data about TikTok users who have not connected their account to BeatBounty.
Technical data. Standard server logs (IP address, user agent, timestamps) kept for security and debugging.
We do not sell your personal data and do not use it for third-party advertising.
Account data is kept while your account exists. Financial ledger records are kept as long as necessary for audit and legal purposes. TikTok OAuth tokens are deleted when you unlink the account; cached public statistics of unlinked accounts are removed from active use.
The web application uses browser local storage to keep you signed in (authentication tokens). We do not use advertising or cross-site tracking cookies.
Privacy-friendly traffic analytics. On our public website (beatbounty.app) we use Cloudflare Web Analytics. It is cookieless, does not track individuals across sites and does not collect personal data — it only aggregates visit counts, referrers and page performance.
Behavioural analytics. On the public website we also use Yandex Metrica to understand how visitors use the site — aggregate visits and sources, click and scroll maps, and anonymized session recordings (Webvisor). Yandex Metrica sets cookies; IP addresses are anonymized. We show a notice about this on your first visit. You can opt out at any time by blocking mc.yandex.ru in your browser or using a browser extension that disables Yandex Metrica; the landing page contains no input fields, so recordings capture navigation only. Data is processed under Yandex Metrica's terms of service.
Data is transmitted over HTTPS. OAuth tokens are encrypted at rest. Access to production infrastructure is restricted by key-based authentication and a firewall. No method of transmission or storage is 100% secure, but we work to protect your data appropriately.
The Service is not directed to children under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
Our servers are located in Europe. By using the Service you understand that your data is processed on these servers regardless of your location.
We may update this Policy as the Service evolves. Material changes will be announced in the Service or by email. The "Last updated" date above reflects the current version.
Privacy questions and requests: [email protected]