Privacy policy
Your data, protected by design
Effective date: April 13, 2026 · Last updated: October 8, 2026
Data controller: Beme Group Limited, Hong Kong
1. Introduction and scope
This Privacy Policy describes how BeMe collects, uses, discloses, and protects personal data from Creators (content creators who monetize on BeMe), Fans (end users who purchase content from Creators via Telegram, BeMe receives limited Fan transactional data indirectly via payment processor for fraud detection and legal compliance only), and Visitors (anyone accessing the BeMe creator dashboard or related web services).
Data controller: Beme Group Limited (Hong Kong).
Creators can connect their Google Drive to BeMe. Data BeMe receives from Google APIs is handled only as described in Section 13 (Google user data). Where Section 13 is stricter than any other part of this policy, Section 13 applies.
Creators, and agencies managing Creators, can also connect a Dropbox account to BeMe. Data BeMe receives from the Dropbox API is handled only as described in Section 14 (Dropbox user data). Where Section 14 is stricter than any other part of this policy, Section 14 applies.
This policy complies with:
- GDPR (General Data Protection Regulation), for EU/EEA residents
- CCPA (California Consumer Privacy Act), for California residents
- FOSTA-SESTA, for U.S. legal compliance on age verification records
- Google API Services User Data Policy, including the Limited Use requirements, for data received from Google APIs (see Section 13)
- Dropbox Developer Terms and Conditions, for data received from the Dropbox API (see Section 14)
- Other local laws as applicable in user jurisdictions
2. Data we collect
2.1 Creator data (identity and verification)
- Legal name, date of birth, address
- Government-issued photo ID (processed via Sumsub KYC)
- Email address and phone number
- Bank account information for payouts
- Nationality and residency status
- Username, profile description, profile photo
- Content titles, descriptions, pricing, and metadata (not content itself). Where this information comes from a Creator's connected Google Drive or Dropbox, it is handled only as described in Section 13 (Google) or Section 14 (Dropbox).
- Earnings, transaction history, payout records
- Login activity, IP addresses, device information
- Support tickets and correspondence
2.2 Fan data (received indirectly)
BeMe does not directly collect Fan personal data. The following is received indirectly via payment processor solely for transaction processing, fraud prevention, and legal compliance:
- Transaction data: billing name, billing address, last 4 digits of card, transaction amount, timestamp
- Purchase records: content ID purchased, Creator account, price paid
BeMe Agent message processing: Fan messages sent to Creators on Telegram are processed in real-time by the BeMe Agent to generate responses on the Creator's behalf. BeMe processes message content solely to produce BeMe Agent responses and does not store fan conversation history for commercial purposes. This processing occurs under the Creator's instruction.
Credit card numbers, expiration, and CVV are processed by payment processors only, NOT stored by BeMe.
2.3 Visitor data (creator dashboard)
- IP address, browser type, pages visited
- Click-through data, time on site, referral source
- Cookies and tracking identifiers (see Section 6)
- Device information (OS, screen resolution)
3. How we use data
3.1 Creator data use
- Platform operations: Account verification, content management, earnings tracking
- Payment processing: Payout calculations, tax reporting, fund disbursement
- Legal compliance: Age verification records (required by FOSTA-SESTA), law enforcement requests
- Fraud prevention: Detecting chargebacks, payment fraud, account abuse
- Communication: Support, policy updates, payment notifications
- Analytics: Aggregated data on creator earnings and transactions. Google user data and Dropbox user data are not used for analytics.
Creator data is NOT sold to third parties or shared with unaffiliated marketers.
Google user data and Dropbox user data are used only to provide and improve the user-facing features described in Sections 13 and 14. They are not used for any of the other purposes in this Section 3.
3.2 Fan data use
- Payment reconciliation: Matching transaction receipts to Creator payouts
- Age verification: Confirming Fan is 18+ (credit card issuer data)
- Legal compliance: Record-keeping per FOSTA-SESTA, NCMEC reporting if needed
- Fraud prevention: Detecting payment fraud and account abuse
Fan data is NOT sold to third parties or used for marketing without explicit consent.
3.3 Data not collected or stored
- Fan credit card numbers, CVV, or full card data
- Creator content (the originals stay in the Creator's Google Drive or Dropbox; see Section 5.1 for the delivery copy)
- Biometric data (except government ID photo, used for age verification only)
- Data from minors (all users must be 18+)
- Cross-site tracking (except analytics platforms listed in Section 6)
4. Data sharing
4.1 Data shared with third parties
Payment processing:
Fan payment method, billing address, and transaction amount, shared on the basis of contractual necessity.
Identity and age verification (Sumsub):
Government ID photo, legal name, date of birth, address (Creator only), required for FOSTA-SESTA compliance.
Analytics (Google Analytics):
Anonymized, aggregated usage data, no personal identifiers. Google user data and Dropbox user data are never sent to analytics providers. Opt-out via browser privacy settings.
Service providers (Supabase, Amazon Web Services, Bunny, AI provider):
Supabase (database and file storage) hosts BeMe's database, hashed passwords, transaction records, and account info. Amazon Web Services is the service that delivers files. Bunny stores and streams copies of content. An AI provider writes content descriptions.
Law enforcement and legal requests:
BeMe discloses data to law enforcement if required by subpoena, court order, or legal process. BeMe will notify users of legal requests unless legally prohibited.
Google user data is shared only in the limited cases listed in Section 13.3. Dropbox user data is shared only in the limited cases listed in Section 14.3.
4.2 Data not shared
- Creator or Fan data with marketing/advertising companies
- Personal data with unaffiliated third parties (except as required above)
- Data for purposes outside this Privacy Policy without explicit consent
- Google user data for any purpose not listed in Section 13, including with consent
- Dropbox user data for any purpose not listed in Section 14
5. Data retention and deletion
5.1 How long we keep your data
- Active accounts: Creator data retained while account is active
- Deleted accounts: Deleted within 30 days of account deletion, except legally required records
- Google user data: See Section 13.7. Deleted when the Creator disconnects Google Drive (except copies of files a Fan has bought) or deletes their account.
- Dropbox user data: See Section 14.7. Deleted when the Creator disconnects Dropbox (except copies of files a Fan has bought) or deletes their account.
- Creator content: BeMe stores a copy of imported files with its delivery provider so Fans can stream and download what they buy, and deletes it within 30 days when storage is disconnected (except copies of files a Fan has bought, which BeMe keeps so that Fan can keep accessing them) or when the account is deleted (see Sections 13 and 14).
- Website analytics and cookies: Retained for 24 months; anonymized after 12 months
5.2 User right to deletion
Email legal@bemeapp.ai with subject "Data Deletion Request."
- Request received and logged
- Account flagged for deletion within 24 hours
- Data deleted within 30 days
- Confirmation email sent
7. Data security
7.1 Security measures
- Access controls: Role-based access (RBAC); only authorized staff access personal data
- Audit logging: All data access logged and monitored for unauthorized activity
- Encryption: Data is encrypted in transit (HTTPS/TLS) and at rest. Google and Dropbox access and refresh tokens are stored encrypted.
- Incident response: Data breach protocol per Section 7.2
7.2 Data breach notification
- Assessment: BeMe investigates scope and impact within 24 hours
- Notification: Affected users notified within 72 hours per GDPR requirements
- Authorities: Competent authorities notified per GDPR if breach poses risk to rights/freedoms
- Remediation: BeMe provides credit monitoring and identity theft protection if appropriate
8. International transfers
8.1 EU-to-third-country transfers
Creator/Fan data from EU/EEA residents transferred to U.S. (the service providers listed in Section 4.1, payment processors) is subject to Standard Contractual Clauses (SCCs) per GDPR Article 46. Users have the right to object to international transfers.
8.2 California (CCPA) compliance
- Right to access personal data (submit request to legal@bemeapp.ai)
- Right to deletion (submit deletion request per Section 5.2)
- Right to opt-out of "sale" of personal data (BeMe does not sell data)
- Right to non-discrimination for exercising CCPA rights
9. Children and minors
BeMe is not intended for users under 18. If BeMe becomes aware that a minor has provided personal data, the account is immediately suspended and data is deleted within 30 days (except legally required records).
10. Your rights
10.1 GDPR rights (EU/EEA users)
- Access: Request a copy of personal data BeMe holds (Article 15)
- Correction: Request correction of inaccurate data (Article 16)
- Deletion: "Right to be forgotten" (Article 17)
- Restriction: Request restriction of data processing (Article 18)
- Portability: Request data in machine-readable format (Article 20)
- Objection: Object to processing, including for marketing (Article 21)
- Automated decision-making: Object to profiling or automated decisions (Article 22)
- Lodge complaint: File a complaint with your local data protection authority (DPA)
Email legal@bemeapp.ai with subject "GDPR Data Request, [Right type]". BeMe responds within 30 days.
10.2 CCPA rights (California users)
- Access: Request personal data disclosed (CCPA § 1798.100)
- Deletion: Request deletion of collected personal data (CCPA § 1798.105)
- Opt-out: Opt out of "sale" of personal data (CCPA § 1798.120)
- Non-discrimination: Not be discriminated against for exercising rights (CCPA § 1798.125)
Email legal@bemeapp.ai. BeMe responds within 45 days per CCPA requirements.
11. Contact and complaints
Data Protection Officer, Beme Group Limited
Unit 02, 16/F, W668, Nos. 668 Castle Peak Road, Cheung Sha Wan, Kowloon, Hong Kong (Company No. 80224676)
Email: legal@bemeapp.ai
12. Policy changes
BeMe may update this Privacy Policy at any time. Changes take effect immediately for new users and 30 days after notice for existing users (via email and website banner). Continued use of the Platform constitutes acceptance. Users may terminate accounts if they disagree with changes.
Exception for Google user data: BeMe will not use Google user data in a new way, or for a purpose not described in Section 13, until it has notified affected Creators and obtained their consent to the updated policy. Continued use alone is not treated as consent for this purpose. The same applies to Dropbox user data and Section 14.
13. Google user data
This section explains how BeMe accesses, uses, stores, shares, and deletes data it receives from Google APIs ("Google user data") when a Creator connects their Google Drive account to BeMe.
13.1 What we access
When a Creator chooses to connect Google Drive, BeMe asks for permission through Google's sign-in and consent screen. With that permission, BeMe accesses:
- Basic Google account information (name, email address) to identify the connected account
- The files and folders in the Google Drive locations the Creator connects to BeMe, including file names, file IDs, file types, sizes, dates, thumbnails, and file content when it is needed to provide the features in Section 13.2
BeMe only requests the permissions needed to provide these features.
13.2 How we use Google user data
BeMe uses Google user data only to provide and improve the following user-facing features, which the Creator controls from the BeMe creator dashboard:
- Content library: Showing the Creator's connected Drive files in the dashboard so the Creator can select, organize, title, and price content.
- Content descriptions: Generating titles, descriptions, and tags for the Creator's own content so the BeMe Agent can describe that content accurately to the Creator's Fans. These are shown to the Creator in the dashboard and can be edited.
- Content delivery: Delivering a specific file the Creator has made available to a Fan who has purchased it, through a temporary, expiring secure link.
BeMe does not use Google user data for any other purpose.
13.3 How we share Google user data
BeMe does not sell Google user data. BeMe transfers Google user data only:
- To deliver a purchased file to the Fan who bought it, at the Creator's direction, as part of the content delivery feature
- To service providers that process it on BeMe's behalf solely to provide the features in Section 13.2 (Supabase for database and file storage, Amazon Web Services for delivering files, Bunny for storing and streaming copies of content, and the AI model provider that generates content descriptions). These providers are contractually prohibited from using the data for their own purposes, including training their models
- For security purposes, such as investigating abuse
- To comply with applicable laws and regulations
- As part of a merger, acquisition, or sale of assets, only after obtaining the Creator's explicit prior consent
13.4 What we never do with Google user data
BeMe never:
- Transfers or sells Google user data to advertising platforms, data brokers, or information resellers
- Uses Google user data to serve ads, including retargeting, personalized, or interest-based advertising
- Uses Google user data to determine credit-worthiness or for lending purposes
- Uses Google user data to create, train, or improve generalized artificial intelligence or machine learning models. Google user data is used only to generate outputs for the specific Creator it belongs to
- Uses Google user data for analytics, marketing, or product research, or shares it with analytics tools such as Google Analytics
13.5 Human access
BeMe staff do not read Google user data unless:
- The Creator has given explicit permission for specific files or data (for example, when requesting support)
- It is necessary for security purposes, such as investigating a bug or abuse
- It is necessary to comply with applicable law
- The data has been aggregated and anonymized and is used for internal operations in line with applicable law
13.6 Storage and security
Google OAuth access and refresh tokens are encrypted at rest. Google user data is encrypted in transit and at rest, and access is limited to authorized systems and staff under role-based access controls. BeMe stores file metadata and generated descriptions needed to run the features in Section 13.2. BeMe stores a copy of imported files with its delivery provider (Bunny) so Fans can stream and download what they buy. When the Creator disconnects Google Drive, BeMe deletes these copies within 30 days, except copies of files a Fan has bought, which BeMe keeps so that Fan can keep accessing them. When the Creator deletes their account, BeMe deletes all copies within 30 days.
13.7 Retention, revoking access, and deletion
BeMe keeps Google user data only while the Creator's Google Drive is connected and only as long as needed for the features in Section 13.2, except copies of files a Fan has bought (see Section 13.6).
A Creator can disconnect Google Drive at any time from the BeMe creator dashboard, or revoke BeMe's access at https://myaccount.google.com/permissions. When we learn that access was revoked, or when the account is deleted, BeMe deletes the stored OAuth tokens and deletes the Google user data it holds within 30 days, except, when access was revoked, copies of files a Fan has bought (see Section 13.6), and except where retention is required by law. Creators can also request deletion by emailing legal@bemeapp.ai with the subject "Data Deletion Request."
13.8 Limited Use disclosure
BeMe's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. The use of information received from Google Workspace APIs will also adhere to the Google Workspace User Data and Developer Policy (https://developers.google.com/workspace/workspace-api-user-data-developer-policy).
14. Dropbox user data
This section explains how BeMe accesses, uses, stores, shares, and deletes data it receives from the Dropbox API ("Dropbox user data") when a Creator, or an agency managing Creators, connects a Dropbox account to BeMe.
BeMe Group Limited, not Dropbox, is responsible for the privacy, security, and integrity of Dropbox user data that BeMe collects or accesses. BeMe is not affiliated with, sponsored by, or endorsed by Dropbox.
14.1 What we access
A Dropbox account is connected through Dropbox's own sign-in and authorization page. BeMe never sees, collects, or stores Dropbox login credentials; it receives only the access token that Dropbox issues after the account holder approves the connection. With that permission, BeMe accesses:
- Basic Dropbox account information (name, email address, account ID) to identify the connected account
- The files and folders in the Dropbox locations the account holder connects to BeMe, including file names, paths, file IDs, file types, sizes, dates, thumbnails, and file content when it is needed to provide the features in Section 14.2
BeMe does not access Dropbox folders that the account holder has not connected.
14.2 How we use Dropbox user data
BeMe uses Dropbox user data only as instructed by the account holder through the BeMe creator dashboard and its settings, and only as necessary to provide the following features:
- Content library: Showing connected Dropbox files in the dashboard so the Creator can select, organize, title, and price content.
- Creator assignment (agencies): Linking each connected Dropbox folder to the correct Creator profile when an agency manages several Creators.
- Content descriptions: Generating titles, descriptions, and tags for the Creator's own content so the BeMe Agent can describe that content accurately to the Creator's Fans. These are shown to the Creator in the dashboard and can be edited.
- Content delivery: Delivering a specific file the Creator has made available to a Fan who has purchased it, through a temporary, expiring secure link.
BeMe does not use Dropbox user data for any other purpose.
14.3 How we share Dropbox user data
BeMe does not sell Dropbox user data. BeMe discloses Dropbox user data only:
- To deliver a purchased file to the Fan who bought it, at the Creator's direction, as part of the content delivery feature
- To service providers that process it on BeMe's behalf solely to provide the features in Section 14.2 (Supabase for database and file storage, Amazon Web Services for delivering files, Bunny for storing and streaming copies of content, and the AI model provider that generates content descriptions). These providers are contractually prohibited from using the data for their own purposes, including training their models
- For security purposes, such as investigating abuse
- To comply with applicable laws and regulations
- As part of a merger, acquisition, or sale of assets, only after obtaining the account holder's explicit prior consent
14.4 What we never do with Dropbox user data
BeMe never:
- Sells Dropbox user data or transfers it to advertising platforms, data brokers, or information resellers
- Uses Dropbox user data to serve ads, including retargeting, personalized, or interest-based advertising
- Uses Dropbox user data to create, train, or improve generalized artificial intelligence or machine learning models. Dropbox user data is used only to generate outputs for the specific Creator it belongs to
- Uses Dropbox user data for analytics, marketing, or product research, or shares it with analytics tools such as Google Analytics
14.5 Human access
BeMe staff do not view Dropbox user data unless:
- The account holder has given explicit permission for specific files or data (for example, when requesting support)
- It is necessary for security purposes, such as investigating a bug or abuse
- It is necessary to comply with applicable law
14.6 Storage and security
Dropbox access and refresh tokens are encrypted at rest. All data transmitted to or from Dropbox uses HTTPS/TLS, and Dropbox user data is encrypted at rest. Access is limited to authorized systems and staff under role-based access controls. Each access token is used only for the BeMe account that authorized it. BeMe stores file metadata and generated descriptions needed to run the features in Section 14.2. BeMe stores a copy of imported files with its delivery provider (Bunny) so Fans can stream and download what they buy. When the account holder disconnects Dropbox, BeMe deletes these copies within 30 days, except copies of files a Fan has bought, which BeMe keeps so that Fan can keep accessing them. When the BeMe account is deleted, BeMe deletes all copies within 30 days. BeMe will report any known or suspected security breach involving Dropbox user data to Dropbox and to affected users as described in Section 7.2.
14.7 Retention, revoking access, and deletion
BeMe keeps Dropbox user data only while the Dropbox account is connected and only as long as needed for the features in Section 14.2, except copies of files a Fan has bought (see Section 14.6).
An account holder can disconnect Dropbox at any time from the BeMe creator dashboard, or revoke BeMe's access from the Connected apps page in their Dropbox account settings (https://www.dropbox.com/account/connected_apps). When we learn that access was revoked, or when the BeMe account is deleted, BeMe deletes the stored access tokens and deletes the Dropbox user data it holds within 30 days, except, when access was revoked, copies of files a Fan has bought (see Section 14.6), and except where retention is required by law. Account holders can also request deletion by emailing legal@bemeapp.ai with the subject "Data Deletion Request."
This Privacy Policy is supplemented by the Terms of Service and Content Policy.