Privacy Policy
Last updated: February 17, 2026
This Privacy Policy explains how Beep.Buzz ("we", "us", or "our") collects, uses, and protects your personal information when you use our service. By using Beep.Buzz you agree to the practices described in this policy.
We collect the following information:
- Account data: email address and username when you create an account
- Learning data: training progress, practice sessions, game scores, achievements, and learned letters
- Chat messages: morse code signals and translated text sent during user-to-user and AI chat sessions
- Contact messages: subject and message content submitted via the contact form
- Usage data: match history, leaderboard rankings, and skill ratings
- Functional cookie: a single cookie named
sidebar_statethat stores your sidebar open/closed preference (see Section 7)
We use the information we collect to:
- Provide, maintain, and improve the Beep.Buzz service
- Track your learning progress and achievements
- Enable matchmaking for user-to-user morse code chat
- Display leaderboards and skill ratings
- Send technical notices and support messages
- Review reports of policy violations and maintain platform safety
- Respond to contact form enquiries and data rights requests
For users in the European Economic Area, we process your personal data on the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)): processing your account data, learning data, and chat messages is necessary to deliver the service you signed up for
- Legitimate interests (Art. 6(1)(f)): displaying leaderboards, computing skill ratings, and maintaining platform safety
We use the following third-party processors to operate the service. Each processor is bound by data processing agreements and applies appropriate security measures.
- Supabase (database and authentication) — United States. Privacy policy
- OpenRouter (AI inference gateway for the AI Chat feature) — United States. Privacy policy
- Google (Gemini 2.0 Flash AI model, accessed via OpenRouter) — United States. Privacy policy
We do not sell your personal information to any third party.
Your data is processed and stored in the United States by our third-party processors. These transfers are covered by standard contractual clauses and the processors' own data protection commitments. By using Beep.Buzz you consent to this transfer.
- Account and learning data: retained until you delete your account
- Match messages: retained for 90 days after the match ends, then deleted
- Contact messages: retained for 12 months, then deleted
- User reports: retained for as long as necessary to investigate and resolve the report
Beep.Buzz uses a single functional cookie:
sidebar_state— stores whether the sidebar is open or closed. Expires after 7 days. This cookie is strictly necessary for the interface to remember your preference and is not used for tracking or advertising.
We do not use any advertising, analytics, or tracking cookies. For full details see our Cookie Policy.
If you are located in the European Economic Area or another jurisdiction with applicable privacy laws, you have the following rights regarding your personal data:
- Access: request a copy of the data we hold about you
- Rectification: request correction of inaccurate data
- Erasure: request deletion of your personal data
- Portability: request your data in a structured, machine-readable format
- Restriction: request that we limit how we process your data
- Objection: object to processing based on legitimate interests
- Lodge a complaint: you have the right to lodge a complaint with your local data protection supervisory authority
To exercise any of these rights, please submit a request via our contact form. We will respond within 30 days.
You can permanently delete your account and all associated data at any time from the account deletion page. Deletion is irreversible. Your data will be removed within 30 days of your request. Match messages may be anonymised rather than deleted where required for service integrity.
Beep.Buzz is intended for users aged 16 and over. We do not knowingly collect personal information from anyone under 16. If you believe a person under 16 has provided us with their data, please contact us and we will delete it promptly.
We use industry-standard security measures including encrypted connections (HTTPS), row-level security on our database, and authenticated API access. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
We may update this privacy policy from time to time. We will notify you of material changes by posting a prominent notice on the site or by email before changes take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.
For questions about this privacy policy or to submit a data rights request, please use our contact form.