BEAM PRIVACY POLICY

Privacy Policy

This policy explains how personal data is handled when you use the BEAM TV mobile app, BEAM TV Full, BEAM TV Lite, the BEAM cloud service, or beamtv.app. Together, we call them “BEAM.”

Effective August 25, 2026

1. Who is responsible for your data

PRIMECODE SOLUTIONS SRL (“PRIMECODE,” “we,” “us”) operates BEAM and is the controller for the processing described in this policy. PRIMECODE is a Romanian limited liability company, CUI 50939602, Trade Registry No. J2024044285005, with its registered office at Str. Gramont 38, Et. 6, Ap. 17, Sector 4, 040182 Bucharest, Romania.

Privacy requests: privacy@beamtv.app.
Product support: support@beamtv.app.

2. Scope and product names

BEAM TV is the iOS and Android mobile app. BEAM TV Full is the TV edition with a built-in player and, when authorized, independent provider browsing. BEAM TV Lite is the smaller TV receiver that uses separately installed VLC for Android. “BEAM” also includes the supporting cloud services and this website.

BEAM is a player, catalog, and remote-control companion. It does not provide channels, movies, provider accounts, subscriptions, or viewing rights. Your media provider, device platform, app store, and sign-in provider process data independently under their own notices. VideoLAN does not receive your BEAM viewing information merely because BEAM includes or works with VLC software.

3. Information we process

Account and sign-in information

BEAM may create a limited guest identity so account-related features can initialize without forcing registration. If you create or use a durable BEAM account, we process an account identifier, sign-in method, email address, email-verification status, and any name or profile information your chosen sign-in provider makes available. We do not receive the password for your Apple or Google account. For email/password sign-in, the authentication provider handles the password and related security data.

Your media-provider information

To connect the service you choose, the mobile app processes the provider address, username, password, and provider responses needed to display your catalog and start playback. When you choose “remember me,” credentials are saved in protected storage on your device. BEAM does not create or sell provider accounts.

The app normally connects directly to HTTPS providers. If you deliberately configure an HTTP-only provider, catalog requests may pass through BEAM’s authenticated compatibility gateway. The gateway processes the request only to complete that operation and does not relay video or audio. The connection from the gateway to an HTTP provider is not encrypted by HTTPS; the app warns you about this material risk. Your provider receives the requests and other network information needed to serve them under its own practices.

Optional encrypted provider backup

Provider backup is off until a signed-in user accepts a specific disclosure. If enabled, BEAM stores the provider address, username, and password in an encrypted, server-only record. A Free account may keep one provider backup; Premium may keep more than one.

This backup is encrypted in transit and at rest, with a separate data key protected by Google Cloud Key Management Service. It is not end-to-end encrypted: an authorized BEAM server function can decrypt it when you explicitly restore or activate the provider, or when a Premium user explicitly grants a paired BEAM TV Full installation access. Mobile and TV clients cannot directly read the server record.

Library, preferences, and playback information

Favorites, watch history, playback progress, app preferences, and remembered device choices are stored locally. If a signed-in Premium user enables supported cloud synchronization, BEAM also processes an opaque provider identifier, content identifiers and types, favorite names, optional titles, playback position and duration, completion state, timestamps, and deletion markers. Synced library records do not include the provider address, username, password, stream URL, or artwork URL.

TV pairing and remote control

BEAM processes random phone and TV installation identifiers, local controller bindings, optional BEAM account-to-TV memberships, device display names, pairing presence, route identifiers, connection state, and sanitized playback state. The reusable QR contains the TV installation identifier, its local TLS certificate fingerprint, and a random pairing bootstrap key. It contains no BEAM account, provider credential, network address, or expiry. Pairing is accepted only while the TV pairing screen is visibly open and that local window closes after one phone succeeds. Treat a saved QR image as sensitive and share it only with people you trust to pair while the TV screen is open.

Remote commands contain the requested action and the minimum data needed to perform it. A Play command may briefly contain the media URL, which can itself contain provider credentials, together with an optional title and resume position. It is protected by service authentication, app/device integrity checks, access rules, and transport encryption, but it is not separately end-to-end encrypted at the application layer. Commands expire within 30 seconds and are removed after handling or cleanup. Sanitized cloud status does not include the media URL, provider credentials, or title.

A nearby phone verifies the TV certificate and exchanges the bootstrap for a separate controller credential stored in protected local storage. This local pairing does not require a BEAM account or Internet and remains after account sign-out or deletion until the TV is forgotten or local app data is erased. If the phone is signed in, BEAM may separately create an optional cloud membership for synchronized TV presence and Premium cross-network commands. For bounded signed-in recovery when local discovery does not resolve, short-lived pairing presence may include the TV's private IPv4 address, relay port, temporary six-digit PIN, and TLS certificate fingerprint. Live presence expires within 30 seconds; an idempotent successful-claim result may retain that fallback for up to 10 minutes. Camera access is used only while you open a QR scanner; BEAM does not retain camera recordings or QR images. Local-network access is used for discovery and authenticated local control.

BEAM TV Full and BEAM TV Lite

A TV installation stores a random installation identifier, protected authentication and pairing material, setup choices, and short-lived playback data. Device backup for this protected TV state is disabled. A TV can be linked to more than one authorized BEAM account.

With an explicit Premium grant, BEAM TV Full can receive and store a selected provider credential in Android-Keystore-protected local storage. A grant lasts for the duration selected by the provider owner—24 hours, three days, seven days, or until revoked. BEAM TV Lite cannot receive these provider grants. Both TV editions are ad-free.

Purchases and subscriptions

Apple App Store or Google Play processes payment and store-account details. RevenueCat processes product, purchase, subscription, entitlement, expiration, and customer-association information so BEAM can activate and restore Premium. We do not receive your full payment-card or bank-account details. Amazon Appstore may process download and store-account information for BEAM TV Full; BEAM Premium is not sold in the TV app.

Advertising and consent choices

The Free mobile app may request ads from Google Mobile Ads. Based on your region and choices, Google and its advertising partners may process advertising identifiers, IP address, approximate location inferred from network data, device information, consent signals, ad interactions, diagnostics, and anti-fraud signals. Premium suppresses ad requests. Where required, BEAM displays a consent form and keeps an Advertising privacy choices entry available in Settings.

A Free user may explicitly choose to watch a rewarded ad to unlock mobile playback on that installation for 24 hours. BEAM records the expiration time only after Google reports that the reward was earned. If the ad is unavailable, does not finish, or Google does not report the reward, mobile playback remains locked and no 24-hour grant is stored. Erase data on this phone removes any stored grant.

Diagnostics, security, and support

Optional crash reporting is disabled until you enable it. When enabled, diagnostics may include app and device information, platform version, fixed error categories, and sanitized stack traces. BEAM is designed to exclude provider credentials, provider addresses, stream URLs, catalog identifiers, titles, pairing secrets, and viewing history from reports it submits. Firebase Analytics collection is disabled. If you contact support, we process your message, contact details, attachments, and the information needed to respond.

Website information

beamtv.app does not intentionally run advertising or behavioral analytics. Its hosting and security providers may process ordinary request information such as IP address, browser type, requested page, timestamp, and security signals to deliver and protect the site.

When a phone camera opens the pairing handoff page, the pairing payload stays in the URL fragment, which is not sent in the web request. The page removes that fragment from the visible browser history immediately and may retain the validated encoded payload only in that tab's session storage long enough to open BEAM or return from app installation. The page has no analytics or network API that transmits this payload, and the browser removes session storage when that tab session ends.

4. Why we process information

We use the information above to:

  • create and secure accounts and installations;
  • connect to the provider selected by you and present its catalog;
  • pair phones and TVs and enforce the memberships you create;
  • perform playback, local control, and short-lived remote commands;
  • provide optional backup, synchronization, and BEAM TV Full grants;
  • process, restore, and enforce Premium entitlements;
  • show ads in the Free mobile app according to applicable choices;
  • prevent fraud, abuse, unauthorized access, and service attacks;
  • maintain reliability, diagnose consented crashes, and support users;
  • comply with law and establish, exercise, or defend legal claims.

5. Legal bases under European data-protection law

  • Contract and steps requested by you: account operation, provider connection, pairing, playback, cloud sync, provider backup, TV grants, Premium, and support you request.
  • Consent: personalized advertising where required, optional diagnostics, and permissions or disclosures that the law requires to be consent-based. You may withdraw consent at any time without affecting earlier lawful processing.
  • Legitimate interests: service security, anti-fraud controls, abuse prevention, limited operational logs, reliability, non-personalized advertising where permitted, and improving support, balanced against your rights.
  • Legal obligations and legal claims: billing, tax, accounting, valid government requests, disputes, and the protection of users, PRIMECODE, or others.

6. When information is disclosed

We disclose information only as needed for the purposes above:

  • Google/Firebase and Google Cloud provide authentication, databases, server functions, hosting, app integrity, protected key management, optional crash reporting, and mobile advertising.
  • RevenueCat, Apple, and Google Play administer Premium purchases, subscription state, restoration, and store compliance. Amazon distributes the Full TV edition where offered.
  • Your media provider receives requests from the device or compatibility gateway when you connect its service. A BEAM TV Full installation receives a provider credential only after the signed-in provider owner creates an explicit grant.
  • Professional advisers, authorities, or a successor organization may receive information when reasonably necessary for legal compliance, a claim, security, or a corporate transaction, subject to appropriate safeguards.

We do not sell personal data. The Free mobile app’s disclosure of advertising-related information to Google may be treated as “sharing,” “targeted advertising,” or a similar term in some jurisdictions. Where applicable, you can opt out through BEAM’s Advertising privacy choices or platform controls. TV companion data is not provided to data brokers or used for third-party advertising.

Provider notices include Google Privacy, RevenueCat Privacy, Apple Privacy, and Amazon Privacy.

7. International processing

PRIMECODE is established in the European Economic Area. BEAM uses service providers and regional infrastructure that may process information in the EEA, the United States, Asia, or other countries. Where PRIMECODE is responsible for a transfer outside the EEA, it relies on a valid adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, and supplementary measures where required. Independent controllers describe their own transfer arrangements in their notices. Contact us to request information about safeguards relevant to your data.

8. Retention and deletion

  • Local data remains until you delete it, clear app data, or uninstall the app. Protected TV state is not included in Android backup.
  • The installation-stable TV QR persists until TV identity reset or app-data clearing. Its local authorization window exists only while the visible pairing screen is open and closes after one phone. Optional cloud presence is short-lived; a successful cloud claim result is available for up to 10 minutes to make retries safe. Commands expire within 30 seconds; acknowledgements are scheduled for deletion after 10 minutes.
  • Account, TV-membership, library, and provider-backup records remain while the account or feature is active, until you remove them, or until account deletion, subject to security and legal retention. Deletion-safety markers may remain briefly to prevent a stale device from silently restoring deleted data.
  • Provider grants expire at the duration you select or when revoked. Grant events and sanitized TV notifications are normally removed within 30 days. Unpaired TV registrations may be deleted after 90 days without a successful heartbeat.
  • Guest cloud identities that are abandoned may be removed after 30 days. Security rate-limit records and operational logs are retained only according to their protective purpose and the service configuration.
  • After Premium ends, applicable multi-provider access and TV grants have a seven-day grace period. After grace, Free limits apply. BEAM does not automatically choose or expose one provider when multiple backups remain; you must reduce them to the Free limit or renew Premium before affected credential operations.
  • Apple, Google, Amazon, RevenueCat, your provider, and other independent services retain their own records under their policies and legal duties.

In the mobile app, Erase data on this phone clears local BEAM data. Account deletion is available in Settings and at beamtv.app/delete-account. It removes the BEAM account and associated BEAM cloud data and requests deletion of the linked RevenueCat customer profile. It does not cancel an app-store subscription, delete your independent provider account, erase another user’s membership, delete local TV pairings, or change your provider password. Cancel a subscription through Apple or Google, and change the provider password if a device may have been compromised.

9. Security

BEAM uses measures appropriate to the nature of the data, including transport encryption, scoped authentication and authorization, app/device integrity checks, database access rules, rate limits, protected device storage, certificate-pinned local control, managed encryption keys, short-lived command records, and restricted operational access. No method of storage or transmission is completely secure. You should use a strong unique password, protect your devices, use HTTPS providers where available, link only TVs you trust, and promptly revoke unfamiliar access.

10. Your rights and choices

Depending on where you live, you may have rights to access, know, correct, delete, restrict, or receive a portable copy of personal data; object to certain processing; withdraw consent; and opt out of sale, sharing, or targeted advertising. You may also have the right not to receive discriminatory treatment for exercising a privacy right. BEAM does not make decisions based solely on automated processing that produce legal or similarly significant effects.

Email privacy@beamtv.app. Describe the right you want to exercise and the BEAM account email, if relevant. We may verify your identity and authority before acting. An authorized agent may submit a request where local law permits. We will respond within the period required by applicable law and explain any lawful refusal or extension.

EEA users may complain to Romania’s National Supervisory Authority for Personal Data Processing at dataprotection.ro or to the competent supervisory authority where they live or work. You may contact us first, but you are not required to do so.

Device permissions can be changed in iOS, Android, or Fire OS. Advertising consent can be revisited through Advertising privacy choices when applicable. Optional crash reporting can be disabled in BEAM Settings. Withdrawing a permission may prevent the related feature from working.

11. Children

BEAM is not directed to children under 16 and is not designed to collect personal data from them knowingly. If you believe a child has provided personal data without legally valid authorization, contact privacy@beamtv.app so we can investigate and take appropriate action.

12. Changes to this policy

We may update this policy when BEAM, our providers, or applicable law changes. We will publish the revised policy with a new effective date and provide an additional notice in the app when a material change requires it. Earlier versions may be requested at privacy@beamtv.app.

See also the BEAM Terms and Conditions and Open-source notices and source.