What we collect, and why.
Privacy is the product here, so this page is written to be read — plain language, app by app, no clauses designed to be skipped.
The short version
Three commitments, and one honest exception.
We make money by selling apps. Not advertising, not profiling, not brokering. There is no version of beep where your data is the product.
Our apps carry no third-party analytics, ad networks or attribution SDKs, and this website sets no cookies and runs no tracking scripts.
Platform, Nestlings and Cadence keep your data on your devices and sync through your own iCloud. Eclipse has accounts and a server — it's the exception, and we say so plainly below.
Who we are
beep is a small independent app studio based in Australia. We build Platform, Nestlings, Eclipse and Cadence, and we run this website at beepml.com. You can reach a real person athello@beepml.com.
We aim to handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). Where you're covered by other privacy law — the GDPR in the EU and UK, for instance — the rights described under Your rights are ones we extend to everyone rather than only where we're compelled to.
App by app
Our apps differ in how much leaves your device, so a single studio-wide claim would be misleading. Here is each one on its own terms.
| App | Account? | Data we hold |
|---|---|---|
| Platform | No | None |
| Nestlings | No | None |
| Eclipse | Yes | Email address, and the forecast data you enter |
| Cadence | No | None |
Platform — Melbourne transit departures. No account, no sign-up.
- No account. Platform never asks who you are, and we hold no profile for you.
- Your pinned stops, favourites and settings sync through your own iCloud account — we can't read them.
- Location, if you allow it, is used on your device to find nearby stops. It is not sent to us.
- Timetable and departure data comes from the PTV API. Those requests contain the stop or route you're looking at, not who you are.
Nestlings — Baby tracking. There is no beep server behind it.
- Feeds, sleep, nappies, expressing, weights and notes stay on your devices and sync through your own iCloud account.
- Sharing with a partner goes over Apple's CloudKit between your accounts. It does not pass through us.
- Insights are generated on-device with Apple's Foundation Models. Nothing is sent to a cloud AI service, and your baby's data is never used to train a model.
- We receive none of it. If you delete the app and your iCloud data, it's gone.
Eclipse — Cashflow forecasting. This one has accounts and a server.
- Eclipse has a sign-in and a backend at api.beepml.com, so we do store data for it: your email address, and the pay cycles, bills and balances you enter.
- It is not connected to your bank. Eclipse never has your banking credentials and never reads your transactions — you tell it what's coming in and going out.
- Data moves over encrypted connections and is stored in our AWS account in Sydney (ap-southeast-2).
- You can edit or delete anything at any time, export a plain record of what Eclipse holds, and ask us to delete your account outright.
Cadence — HYROX race timer for Apple Watch. Entirely on-wrist.
- Runs, stations, splits and session history are kept on your device.
- Heart rate is read from the Watch's sensors during a session and is not transmitted to us.
- If you allow it, workouts are saved to Apple Health, which is yours and not visible to us.
- There is no beep server collecting your training.
Eclipse forecasts across devices and needs somewhere to reconcile that, so it has a sign-in and a backend. We'd rather name the exception than claim "there is no server" across the studio and quietly be wrong about one app.
This website
beepml.com is a static site. It sets no cookies, runs no analytics, and embeds nothing from third parties — no fonts, scripts, pixels or share-buttons phoning home as you read.
It is served from Amazon S3 and CloudFront in our own AWS account. Like any web server, that infrastructure writes access logs: the requested URL, timestamp, response code, referrer, user-agent and the requesting IP address. We use those only to keep the site up and to investigate abuse, and they expire automatically after 90 days.
When you contact us
The contact form opens your own email client — it doesn't post to a server of ours. When you email us, we hold that email, your address and anything you chose to put in it, for as long as it's useful to have the thread.
If you ask for launch updates, we keep your email address for that purpose and nothing else. We don't sell or share the list, and every update we send will tell you how to get off it. Ask us to remove you and we will.
Who else is involved
We keep the list of third parties deliberately short. In full:
- Apple — the App Store distributes our apps, and iCloud and CloudKit sync your data between your own devices. That relationship is between you and Apple, under Apple's privacy policy. Apple may share aggregate App Store analytics with us; it doesn't identify you.
- Amazon Web Services — hosts this website and, for Eclipse only, our backend. Data sits in the Sydney region (ap-southeast-2), except for the CDN edge that serves this site's static files worldwide.
- Public Transport Victoria — Platform queries the PTV timetable API for departures. Those requests describe a stop or route, not a person.
That's the whole list. No advertising networks, no analytics vendors, no data brokers, no "partners".
Children's data
Our apps are made for adults. Nestlings is the one that records information about a child — a parent or carer logging their baby's day — and that information stays on their devices and in their own iCloud account. We never receive it, and we could not produce it if asked.
Your rights
For most of our apps there is nothing for us to give you or delete, because we never had it — the data is on your device and under your control. Where we do hold something (an Eclipse account, a launch update subscription, an email you sent us), you can:
- ask what we hold about you, and get a copy of it;
- correct anything that's wrong;
- have it deleted, including your whole Eclipse account;
- withdraw consent for updates at any time;
- complain to us, and escalate if we don't resolve it.
Email hello@beepml.com and we'll action it — normally within a few days, and within 30 days at the outside. If you're in Australia and we haven't resolved things, you can take a complaint to the Office of the Australian Information Commissioner atoaic.gov.au.
Security
Eclipse accounts are protected with modern authentication, and data moves over encrypted connections and is encrypted at rest. Our infrastructure is defined in code, reviewed before it changes, and scanned for misconfiguration on every change. Access to production is limited to the people who need it.
No system is perfect. If you find a security problem in one of our apps or in this site, please tell us athello@beepml.com before disclosing it publicly, and we'll work it through with you.
Changes to this policy
When our apps change, this page changes with them. We'll update the date at the top, and if a change materially affects what we collect or what we do with it, we'll say so in the app or by email rather than hoping you re-read the page.
Questions
If anything here is unclear, or you want to know something this page doesn't answer, ask us —hello@beepml.com. Plain questions get plain answers.