Privacy policy.
TypeBeatOS ("we", "us") builds an upload pipeline for type-beat producers. This policy explains what we collect, how we use it, who else gets to see it, and what controls you have.
Who runs this
TypeBeatOS is operated from Australia. Questions, requests, or complaints can be sent to [email protected].
What we collect
We collect the minimum producer data needed to render and ship upload packages to YouTube on your behalf:
- Account: email, password hash, producer display name.
- Producer profile: store URLs (BeatStars, Airbit), contact email, YouTube channel URL, Instagram URL, license + footer text.
- Beats you upload: filename, BPM, key, genre, mood, target artist, and the audio file itself stored on our object storage.
- Upload packages: generated SEO title, description, tags, pinned comment, thumbnail image, rendered video.
- YouTube channel data, only after you connect via Google OAuth: channel ID + title, an OAuth access + refresh token scoped to uploads and read-only YouTube access, and per-video stats (views, likes, comments) for the packages we shipped.
- Waitlist: just the email you submitted and the date.
- Operational logs: request IDs, IP addresses, and error traces — kept for 30 days for debugging and abuse prevention.
What we do not collect
- We do not run analytics scripts (Google Analytics, Mixpanel, etc) on producer surfaces.
- We do not read or scan your YouTube channel beyond the channel ID + title at connect, and the public stats of videos we ship for you.
- We do not sell or rent producer data to third parties.
How we use it
- To generate the SEO pack, render the video, and ship to YouTube.
- To show you analytics for the videos we shipped (views, likes, comments, performance by artist keyword).
- To send you transactional email (signup confirmation, upload failures, weekly digest). We do not send marketing email without an explicit opt-in.
- To debug failures, rate-limit abuse, and keep the service running.
Google and YouTube data
TypeBeatOS uses YouTube API Services. By connecting your channel you also agree to the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.
TypeBeatOS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We request only the scopes the upload pipeline needs:
youtube.uploadto publish videos to your channel, andyoutube.readonlyto read your channel ID + title and the public stats of the videos we ship for you. - We use this data solely to provide and improve those user-facing features. We do not use Google user data for advertising, and we do not sell it.
- We do not transfer Google user data to third parties except as needed to provide or improve the service, to comply with applicable law, or in connection with a merger or acquisition.
- We do not send Google or YouTube user data to Gemini, Anthropic, or any other AI provider, and we do not use it to develop, improve, or train general-purpose or third-party AI/ML models.
- We do not allow humans to read your Google user data unless we have your consent for a specific support issue, it is necessary for security purposes (such as investigating abuse), or we are required to by applicable law.
- You can revoke our access at any time by disconnecting YouTube from your producer profile, or from your Google Account permissions.
Who else sees it
- Google / YouTube. Connecting your channel sends your producer-uploaded video to YouTube under your channel. YouTube becomes the controller of that video.
- AI provider. Beat metadata (artist, genre, mood, key, BPM) is sent to Google's Gemini API — or Anthropic's Claude API as a fallback — to generate the SEO pack. We do not send your audio file, YouTube credentials, channel identity, YouTube statistics, or any other Google user data.
- Infrastructure providers. Compute on Azure Container Apps, database at Neon, object storage on Azure Files, transactional email via Resend. Each handles data as a processor on our behalf.
Where data lives
The application and your uploaded files run in Microsoft Azure's Australia East region (Azure Container Apps + Azure Files), and the database is hosted by Neon. Some data is processed overseas by the sub-processors listed above (for example Google, Anthropic, and Resend in the United States).
How we protect your data
- Data is encrypted in transit using HTTPS/TLS. Our managed database and storage providers encrypt stored data at rest.
- Access to production systems and Google OAuth credentials is limited to authorised operators and service components that need it to run TypeBeatOS.
- OAuth tokens and application secrets are kept on the server, are never exposed to the browser, and are not written to application logs.
- We use session protections, OAuth state validation, rate limiting, and operational monitoring to reduce unauthorised access and abuse.
How long we keep it
- Account + producer profile: until you delete the account.
- Beats + generated packages + videos: until you delete them or close the account.
- YouTube tokens, channel ID, and channel title: until you disconnect from your producer profile or delete your account.
- Operational logs: 30 days, then rolled off by our logging platform.
- Waitlist signups: until the waitlist is closed or you ask us to remove your email.
Your controls
- Export every package and uploaded asset from the producer dashboard.
- Disconnect YouTube any time from your producer profile. We revoke the Google authorization, delete the stored access and refresh tokens and connected channel identity, and stop requesting video statistics.
- Delete your account from Settings. This removes your producer profile, beats, packages, generated assets, YouTube tokens, and waitlist signup. Videos already published to YouTube stay on your channel — YouTube controls them now.
- Request a copy of your data, ask us to correct it, or restrict our processing of it by emailing [email protected].
Children
TypeBeatOS is intended for producers aged 16 and over. We do not knowingly collect data from anyone under that age. If you believe a minor signed up, email us and we will delete the account.
Changes to this policy
We will notify producers by email at least 14 days before any material change takes effect. The "Last updated" date at the top of this page always reflects the current version.
Contact
Questions, data requests, or complaints: [email protected].