Terms of Service & Privacy Policy
Effective date: March 23, 2026 · Last updated: August 1, 2026
This document covers the Terms of Service and Privacy Policy for Beat Watcher, a heart rate monitoring app for Apple Watch, developed by Ganotis Holdings, Inc.
Privacy Policy
App Data
Beat Watcher reads heart rate data from Apple Health on your device. Your continuous heart rate readings and Apple Health history remain on your devices and are not uploaded to Beat Watcher servers.
If you choose to use Alert Sharing or Alert Live Activity, Beat Watcher transmits individual high or low alert events to the Beat Watcher alerts service so they can be delivered to trusted contacts you approve or displayed as a Live Activity on your devices. An alert event may include the alert type, event timestamps, beats per minute, the configured threshold, and a random installation identifier. Alert Sharing may also include the display name you provide. Alert Live Activity uses ActivityKit push tokens. Beat Watcher does not transmit continuous heart rate readings through either feature.
Beat Watcher may use a random installation identifier to measure app version, purchase access, aggregate onboarding and purchase-flow interactions, and whether the app has zero, one, or multiple incoming or outgoing trusted contacts or pending invitations. This measurement does not include names, invite details, heart rate, or other Health data. Per-install records expire after 90 days of inactivity, and aggregate metrics that no longer identify an installation may be retained for up to 90 days. Deleting all Alert Sharing data also deletes the current measurement for that installation.
Alert Sharing and Alert Live Activity
The Beat Watcher alerts service uses Cloudflare to process invitations, trusted-contact relationships, Alert Live Activity registrations, alert events, delivery status, and privacy-minimal service metrics. Apple Push Notification service processes notifications and Live Activity updates. Health-related alert events, relationship-event snapshots, delivery attempts, and submissions are available for a seven-day retention window. An hourly cleanup removes records after that window, normally within the following hour. ActivityKit push tokens are retained only while Alert Live Activity is enabled and are removed when you turn the feature off or delete all service data. Daily aggregate service metrics that do not contain heart rate values or names may be retained for up to 90 days to measure reliability and feature use.
If an alert has no eligible trusted contact, the service does not retain its beats-per-minute value, threshold, raw event identifier, or health event row. It may retain one-way hashes of the event and random installation identifiers plus a keyed fingerprint of the event details for up to seven days. This record makes retries consistent, rejects a conflicting duplicate, counts toward abuse limits, and is removed if you delete your Alert Sharing data.
To confirm whether a person can create invitations, share alerts, or enable Alert Live Activity, the service verifies signed purchase evidence with Apple. For eligible legacy users, it may verify App Store receipt evidence. The service retains the entitlement type, product identifier, and a one-way identifier for the verified evidence associated with the random installation identifier. It does not retain the signed transaction or App Store receipt itself. These entitlement records are removed when you delete all service data.
Beat Watcher uses random installation identifiers to authenticate devices with the service. It does not store raw IP addresses for abuse prevention. Short-lived, keyed network fingerprints may be retained for up to 48 hours to enforce rate limits.
You can disconnect a trusted contact at any time. You can also delete your Alert Sharing data from the app, which removes your Alert Sharing identity, relationships, invitations, device registrations, retained alert events, and delivery records from the service. After deletion, one-way hashes of the random installation identifier and authentication proof are honored for seven days only to reject stale credentials and make deletion retries safe. The next hourly cleanup physically removes an expired revocation record, normally within one additional hour. Raw installation identifiers and authentication proofs are not retained in this revocation record. Aggregate metrics that no longer identify an installation may remain until their retention period ends.
You can turn off Alert Live Activity at any time. Turning it off removes its ActivityKit push tokens and pending delivery state from the service without changing Alert Sharing. Deleting all service data also removes any remaining Alert Live Activity registration and event records.
Website Analytics
The Beat Watcher website (beatwatcher.app) uses Google Analytics to collect anonymized usage statistics such as page views, referral sources, and general geographic region. This data is used to understand how visitors find and use the website. Google Analytics may use cookies. No health or personal data from the app is connected to website analytics.
The website may also use Meta Pixel PageView tracking for advertising measurement and retargeting on Meta services, including Facebook and Instagram. Meta Pixel may process page URLs, referral information, browser or device information, and similar website visit data. This website tracking is used to understand whether website visitors later respond to Beat Watcher advertising. It is not connected to heart rate data from the Beat Watcher app.
Crash Reporting (Sentry)
Beat Watcher uses Sentry for crash and error reporting. When the app crashes or encounters an unexpected error, Sentry receives a diagnostic payload that includes the stack trace, device model, operating system version, app version, and a short trail of in-app actions that preceded the error (“breadcrumbs”). This helps us diagnose and fix bugs.
Sentry diagnostic events do not include personal identifiers such as your name, email address, Apple ID, or device advertising identifier. IP addresses are not intentionally collected (the SDK is configured with sendDefaultPii = false). Sentry sets a per-install device identifier internally for grouping crashes from the same device; this identifier is not linked to your identity.
Heart rate data is never sent to Sentry. The Sentry integration explicitly scrubs any breadcrumb key or message containing heart rate, BPM, or HealthKit-related terms before transmission, as a defense-in-depth safeguard.
Data Sharing
We do not sell or rent user data. Alert Sharing and Alert Live Activity data is processed by Cloudflare and Apple only to provide and protect those features. Website analytics data is processed by Google, website advertising and retargeting data may be processed by Meta, and diagnostic crash data is processed by Sentry, each in accordance with their own privacy policies.
App Store refund requests. If you request a refund through Apple for a Beat Watcher purchase or subscription, we may send Apple limited information to help evaluate that request: whether the purchase was delivered, whether a free trial or a description of the app’s functionality was available beforehand, and our recommendation on the refund. We do not send heart rate data or any record of how you used the app. For auto-renewing subscriptions, Apple calculates elapsed-time consumption itself. This information is used only to help Apple review refund requests, never for advertising or tracking, and it is sent only when you request a refund. By purchasing or subscribing and agreeing to this Privacy Policy, you consent to this sharing.
Terms of Service
Subscriptions
Beat Watcher may offer an auto-renewing annual subscription. Subscription details, including pricing, are displayed in the app and on the App Store at the time of purchase. Pricing may vary by region.
- Payment is charged to your Apple ID account at confirmation of purchase.
- Subscriptions automatically renew unless canceled at least 24 hours before the end of the current period.
- You can manage or cancel your subscription in your device’s Settings > Apple ID > Subscriptions.
- Refunds are handled by Apple in accordance with their refund policy.
Legacy Users
Users who purchased Beat Watcher before the transition to a subscription model retain full access to all features without a subscription.
Alert Sharing and Alert Live Activity Services
Alert Sharing lets eligible users share high and low heart rate alert events with trusted contacts who accept an invitation. Trusted contacts can receive alerts and manage their own alert preferences without purchasing a subscription. Delivery depends on both people enabling the relevant alert type, compatible devices, notification permissions, network connectivity, and third-party services.
Alert Live Activity lets eligible users choose to display their own high and low alert episodes on the iPhone Lock Screen, Dynamic Island, and the Apple Watch Smart Stack on compatible devices. The feature is optional, is off by default, and can be turned off at any time.
Alert Sharing and Alert Live Activity are intended for awareness. They are not emergency response, fall detection, medical alert, or monitoring services. Notifications and Live Activities can be delayed, suppressed, duplicated, or missed. Do not rely on either feature to contact emergency services or to make medical decisions.
Medical Disclaimer
Beat Watcher is not a medical device. It is not intended to diagnose, treat, cure, or prevent any disease or health condition. Heart rate data is provided by Apple Watch sensors and may not be accurate in all situations. Do not rely on Beat Watcher for medical decisions. Always consult a qualified healthcare professional regarding any health concerns.
Limitation of Liability
Beat Watcher is provided “as is” without warranty of any kind. To the maximum extent permitted by applicable law, Ganotis Holdings, Inc. shall not be liable for any damages arising from the use or inability to use the app, including but not limited to health outcomes, missed alerts, or inaccurate readings.
Changes to These Terms
We may update these terms from time to time. Changes will be reflected on this page with an updated effective date. Continued use of Beat Watcher after changes constitutes acceptance of the updated terms.
Governing Law
These terms are governed by the laws of the State of New York, United States, without regard to conflict of law principles.
Contact
If you have questions about these terms or your privacy, contact us at [email protected].
Ganotis Holdings, Inc.
New York, United States