← Back to home

Privacy Policy

Last updated: 2026-09-09. The principles described below reflect how Beat Breeze actually handles data.

1. What we collect

To operate the Beat Breeze service we collect:

  • Account information. Name, email, organisation, role, and billing details, provided when you sign up or upgrade.
  • Authentication identifiers. Logto provides authentication, account identity, organisations, invitations, sessions, and MFA. Logto is not the source of Beat Breeze business roles, scopes, tenant authorization, or other business permissions. We do not store passwords directly.
  • Content you create or upload. Brand assets (logos, images), voiceover audio, cover art, playlists, schedules, and prompts you submit to AI features. (Music files uploaded before July 2026 remain stored for accounts that used the discontinued upload feature.)
  • Usage logs. Which features you use, what music played in which zone, playback actions such as skips or blocked tracks, and when content was rendered or exported. Used to operate the service, personalize music for the venue, and bill metered actions correctly.
  • Device and technical data. IP address, browser/device type, and similar metadata, captured automatically by web requests.

2. Android Box Player operation and managed-box support

Required Box Player operation

To pair and operate the dedicated Android TV/box edition, we receive an app-scoped device credential and keep its zone association, request IP address and user-agent, liveness, volume, current track identifier, and playback position. We also receive track and playlist identifiers, start times, seconds played and whether playback completed, plus playback and curation actions such as skips, blocked tracks, and playlist, schedule, or playback-setting changes. We use this required data for authentication, playback, service and licensing records, support, reliability analysis, security, and venue-music personalization.

This operational data is required while the Box Player is paired. It continues when optional support diagnostics are off.

Optional Box Player support diagnostics

The Box Player can additionally send a small optional operational snapshot with its authenticated device heartbeat so BMAsia support can diagnose a venue player without remote-desktop access. This sharing is off on a fresh install and starts off again for each new Player pairing identity. The pairing screen explains the sharing and presents a separate, unchecked choice before pairing. It can also be turned off later in Player settings without stopping music.

The support snapshot is associated with the paired venue zone and includes:

  • Player package, version, and installation source.
  • Android version, SDK level, device manufacturer, and model.
  • Total and available storage, available memory, and Android's low-memory state.
  • Network transport and whether a connection and validated internet access are available.
  • Audio output route, music volume, maximum volume, and mute state.
  • Uptime and a short marker used to distinguish restarts.
  • Offline-cache state, track counts, and total cached-audio bytes.
  • At most one classified error code and generic message, such as network unavailable or audio download failed, and the time it was observed.

This support snapshot does not contain Wi-Fi names or passwords, device credentials or tokens, raw logs or exception text, audio recordings, music contents, or filenames. Normal Player requests still use the paired device token for authentication and report liveness, current playback, and volume; those service functions continue when optional support diagnostics are off.

Guardian on BMAsia-prepared boxes

A BMAsia-prepared box may also have the separate Guardian service. When installed and enrolled, Guardian sends BMAsia a box-specific identifier, request IP address, Android and security-patch version, hardware and firmware identifiers and security status, storage and memory health, network connection type and status, audio route and volume, uptime and restart status, installed Beat Breeze package versions and signing-certificate fingerprints, debugging state, and update or recovery status. Guardian sends periodic background check-ins and can send additional check-ins while its support screen is open. Delivery depends on connectivity and Android background scheduling. These check-ins let BMAsia identify the prepared hardware, monitor availability, verify installed software, deliver signed updates, and recover the Player.

Guardian monitoring is part of BMAsia's managed-box service and is not controlled by the optional Box Player diagnostics setting. The Guardian diagnostic snapshot does not contain Wi-Fi names or passwords, recordings, music files or filenames, app credentials, or raw logs; Guardian requests use an app-scoped credential for authentication. Guardian is separate from the Play-distributed Box Player and is not installed when a customer installs only the Box Player from Google Play.

3. How we use it

We use your data to:

  • Provide the Beat Breeze service (account access, playback, AI features).
  • Personalize venue music using playback and curation actions.
  • Bill you correctly for plans and metered consumption.
  • Send transactional emails (receipts, security alerts, service notices).
  • Improve product reliability and performance.
  • Detect and prevent abuse, fraud, and copyright infringement.

We do not sell your personal data. When you use or enable an AI feature, including automated Music Director suggestions, information needed for that feature may be processed by the AI sub-processors named below and in our maintained Sub-processors list.

4. Third parties

Beat Breeze relies on a small number of sub-processors that handle data on our behalf. Logto processes identity data in the Beat Breeze production Logto Cloud EU tenant. Silverhand Inc., the Logto provider, is a U.S. company.

  • Logto (Silverhand Inc.) — authentication, account identity, organizations, invitations, sessions, and MFA.
  • Cloudflare R2 — audio and image storage.
  • Render — application hosting and PostgreSQL database.
  • Stripe — payment processing and invoicing.
  • Anthropic — user-initiated Music Director chat and related AI assistance.
  • OpenRouter and configured model-hosting providers — AI text and curation, including automatic Music Director suggestion copy derived from aggregated venue playback actions when that feature is enabled. The configured hosts for DeepSeek models are DigitalOcean, Streamlake, and GMICloud.
  • Mureka — AI music composition (invoked explicitly).
  • fal.ai, Google AI Studio — image, video, and voice generation features that you invoke explicitly.
  • Resend — transactional email delivery.

The full, maintained list — with purposes and processing locations — lives at Sub-processors. Business customers can request a signed Data Processing Agreement.

5. Data retention

Account and content data is retained for as long as your account is active. When you delete content or close your account, we remove it from active systems within 30 days, except where retention is required to handle takedown counter-notices, comply with legal obligations, or resolve disputes.

Zone-linked raw playback and activity history is retained for 30 days. Older raw playback rows are converted into per-track monthly totals that do not contain account, zone, or device identifiers, so we can maintain provider and licensing reports; older activity rows are deleted. A zone's blocked-track selections remain while the zone or account is active, unless they are removed earlier.

For an active Android Box Player, we keep only its latest optional Player support snapshot and latest Guardian health snapshot, replacing each when a newer snapshot arrives. Turning optional Player diagnostics off immediately stops new optional collection on the box. When the service receives that choice, or when a Player is unpaired, Guardian is revoked, a box is retired, or its account is archived, the corresponding diagnostics are immediately removed from active support views.

A classified generic Player error stops being available to support no later than seven days after its first server receipt. A Player or Guardian support snapshot stops being available no later than 30 days after its server receipt; each fresh snapshot replaces the previous one and starts a new 30-day period. Expiry of a Player snapshot does not unpair the Player or change its saved diagnostics choice. If the same paired Player reconnects while sharing remains enabled, a new snapshot can be collected. The payload and diagnostic detail from a support action requested by BMAsia stop being available no later than 30 days after completion, or after creation if the action never completes. Scheduled retention sweeps remove expired payloads from storage. A minimal audit record of the action, time, outcome, result code, and staff issuer may be retained for security and accountability.

When an account is archived, its Player and Guardian diagnostics are scrubbed immediately. Credentials for every paired Player associated with the account, including browser, mobile, desktop, and Android Box Players, plus all Guardian credentials and assignments, are retained for a 30-day restore grace period. After that period, all of those credentials are revoked and every Guardian is unassigned. Every affected Player must pair again, and Guardian must be assigned again, before returning to service. This bounded access purge does not erase the account, its zones, or its historical Player rows; those records remain subject to the ordinary account-retention rules above.

6. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict its processing. Use our privacy-requests channelto exercise any of these rights — we respond within 30 days as required by Thailand's PDPA.

7. International transfers

Beat Breeze hosting is primarily in Singapore. Logto processes identity data in the Beat Breeze production Logto Cloud EU tenant; Silverhand Inc. is a U.S. company. Other sub-processors (including Stripe, Cloudflare, Anthropic, OpenRouter, fal.ai, and Google) may process data in the United States, the European Union, or other stated locations. Such transfers are covered by the applicable transfer requirements. We use contractual or other recognized safeguards where they are required for a transfer.

8. Changes

We may update this policy from time to time. Material changes will be communicated via email or in-app notice.

9. Contact

The data controller is BMAsia Limited (Hong Kong).

Privacy inquiries: [email protected]
See also the Cookie Policy and the Terms of Service.