Privacy Policy

Last updated: August 12, 2026

What We Collect

Crowdsource data sharing is opt-in and off by default. On first launch the app asks you to choose, with the option switched off; you can change it any time in Settings → Privacy. Nothing is sent to our server until you turn it on. When you do, the BetaMuncher Android app sends the following:

  • A randomly generated device UUID (not tied to your identity)
  • Package names and display names of apps that actually have a beta program, and which of the three states each one is in — Open, Enrolled, or Full

Your installed-app list is not sent. An app is included only if BetaMuncher found a beta program for it. Apps with no beta program, apps whose status could not be determined, and apps you have hidden in the app all stay on your device.

What We Do Not Collect

  • Your Google account password
  • Google Play session cookies — stored on your device only (encrypted) and never sent to our server
  • Device identifiers used for advertising (advertising ID)
  • Location data
  • Payment card or billing details — voluntary tips on the Play build go through Google Play Billing; we never see card numbers

Optional Diagnostics & Analytics

The Google Play (play) build of the Android app can send anonymous crash reports (Sentry) and usage events (PostHog). Both are opt-in and off by default: nothing is collected until you complete the first-launch privacy prompt and switch them on, and you can turn them off again in Settings → Privacy. Events may include screen names and feature usage (e.g. sync completed, beta enrolled). They do not include your Google email, passwords, or Play session cookies.

The F-Droid (fdroid) build does not include the Sentry or PostHog SDKs at all, so it cannot send crash reports or usage events under any setting. Every app feature ships in both builds; the flavors differ only in which third-party SDKs they link.

How We Use Your Data

The anonymous beta status reports are aggregated to power the public beta directory. This helps other users discover which apps have open beta programs on Google Play.

IP Addresses

Your IP address is used solely for rate limiting to prevent API abuse — capping how often one device may sync and how many devices may sync from one address. It is stored on your device's record, which means it is technically linkable to that device's reports inside our database, but it is never published in the public directory and is not shared with third parties.

Data Retention

A daily cleanup job deletes beta reports once they are 30 days old. The IP address recorded against a device is erased after 30 days without a sync, and the device record itself — including its UUID and every report still attached to it — is deleted after 90 days without a sync. Nothing is kept beyond that on our side.

What the 7-day window controls is display, not storage: the public directory only lists betas reported in the last 7 days (and confirmed by at least two distinct devices). Older reports stop appearing on the site but remain in our database. Each device keeps one row per app package, so a later report for the same app overwrites the previous status, timestamp, and stored IP for that device rather than adding a new record.

You can delete your data at any time, from inside the app. Open Settings → Privacy and turn off crowdsource sharing; you will be asked whether to also remove what you have already shared. Choosing to delete removes your device record and every beta report tied to it from our database, and the app then generates a new anonymous device identifier, so re-enabling sharing later does not reconnect you to the deleted data. Turning the setting off always stops future sharing, whether or not you delete the past data.

Deleting from the app is immediate and does not wait for those windows.

Opting Out

You can disable crowdsource data sharing at any time in the app's Settings. When disabled, no data is sent to our server. Beta scanning continues to work locally on your device.

Website Analytics

The betamuncher.com website uses PostHog and Google Tag Manager for analytics after you accept cookies via the consent banner. Crowdsource uploads store an anonymous device UUID and client IP on our server for rate limiting — IP is not shown on the public directory.

Third Parties

We do not use third-party advertising SDKs. Sentry (crash reporting) and PostHog (product analytics) are used only as described above and can be disabled in app Settings. On the Play build, Google Play Billing processes voluntary one-time tips (nothing is unlocked by tipping). We do not sell or share your personal data with data brokers.

Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. Continued use of the app after changes constitutes acceptance.

Contact

Questions about this policy? Open an issue on GitHub.