Live Beats WebRadio ("the app"), package name com.lbwebradio.radio, is an internet radio player built with a privacy-first approach. This policy explains what stays on your device, what technical data is shared with third parties, and who is responsible for the app. For the terms governing your use of the app itself — including licensing, third-party stream content, and liability — see our End-User License Agreement.

Data Controller

Live Beats WebRadio is developed and maintained by Christian Flach, who acts as the data controller for this app. Contact: livebeatswrp@gmail.com.

Summary

  • No account needed. We don't collect your name, email, or any other personal identifier.
  • No ads, no behavioral or listening analytics. The app includes optional crash and diagnostic reporting (Firebase Crashlytics), on by default and toggleable off in Settings — see below.
  • No cookies. The app's network clients don't use a cookie jar.
  • Your favorites, settings, and preferences live in Android DataStore, on your device. We never see them.
  • A few things do go to outside services — finding stations, looking up server locations, pulling up album art, and optional crash diagnostics — and they're listed below.
  • The optional PRO upgrade is purchased and processed entirely through Google Play Billing — we never see or handle your payment details.
  • The app may occasionally show an in-app prompt asking you to rate it. This is managed by the app itself based on your usage — it is not Google Play's built-in review system. If you tap "Rate now," you're taken to the Google Play Store to leave a rating or review.
  • Tapping the support email icon in Settings pre-fills a small amount of basic device/app info into the email draft, to help us help you faster — nothing is sent unless you choose to send that email yourself.
  • We do not sell or share your personal information with third parties for money or for their own advertising purposes.

Information Stored On Your Device

The following stays on your device and is never transmitted to us:

  • Your favorite stations, including any "Super Favorites" and genre tags
  • App settings (theme, language, album art preference, data tracking preference, sleep timer, whether crash log sharing is enabled, etc.)
  • Listening session history (previous/next station navigation)
  • Estimated data usage statistics — bytes consumed per session and month, tracked locally to power the "Data Guard" and usage reporting features
  • Saved songs, if you use that feature
  • Cached server location data (country and flag) for your favorite stations
  • A small amount of local state used to time the in-app rating prompt, such as how many favorites you've added and when you were last asked
  • A short local record of which stations you've recently voted for, used only to apply a cooldown so you can't vote for the same station repeatedly — this record is never sent anywhere

Backing up or moving your favorites to the desktop app uses .lbrx files. That file gets created and read locally, wherever you choose to save it — your device, or somewhere like Google Drive if you pick that as the destination. We never see a copy.

Information Sent to Third Parties

To work, the app talks to a handful of outside services. As with any internet request, your IP address is automatically visible to each receiving server, and every request identifies the app name, version, and that it's running on Android via a standard User-Agent string. Under some data protection laws (including the GDPR), an IP address is itself considered personal data, so this exposure is treated as personal data processing below, not merely "technical" data — see the Legal Basis section for how we justify it.

Service Purpose What is sent
Radio-Browser
(radio-browser.info)
Station directory, search, and the Discover/Browse tab Your search terms and filters (country, language, tag, codec, bitrate) are sent to Radio-Browser's servers whenever you search or browse, as this is how the directory feature works — this happens by default, not only when you explicitly submit a search. Playing a station sends an automatic "play count" signal, the same way any app using their directory does. Tapping the thumbs-up icon sends a one-time vote — this only happens on that explicit tap, never automatically.
Internet radio stream servers Playing the stream you picked A connection to that station's stream URL — no different than opening the same stream in a browser.
ipwho.is Identifying the server location (country and flag) of the radio station Only the streaming server's IP address, sent to ipwho.is/{ip}?fields=success,country_code,flag.emoji — a request scoped to just that data. No account, device, or personal identifiers are included. Your own IP is visible to this service during the request, as with any internet request.
Apple iTunes Search API Looking up album artwork for the currently playing track The artist and track name read from the station's broadcast metadata (ICY metadata), when available. This reveals what you're currently listening to, to Apple. No account or device identifier is included.
Last.fm API Fallback album artwork lookup if iTunes has no match The artist and track name — again revealing current listening activity, this time to Last.fm — sent using an app-level API key (not specific to you or your device).
Image & CDN hosts
(various)
Displaying station favicons and album artwork The app downloads images from URLs supplied by Radio-Browser, iTunes, or Last.fm — for example Apple's is1-ssl.mzstatic.com or Last.fm's lastfm.freetls.fastly.net, or a station's own web server. These can be many different third-party hosts depending on the station or track, not one fixed service.
Firebase Crashlytics
(Google)
Diagnosing app crashes, freezes (ANRs), and unexpected background terminations, so we can fix them — and tracking overall app stability Crash stack traces, device model, OS version, app version, and basic device state at the time of the crash (such as available memory and free storage), plus three diagnostic values we set ourselves to help identify silent terminations: last_exit_reason (e.g. crash, ANR, low-memory kill, or normal user exit), last_exit_description (a short OS-provided explanation), and last_exit_timestamp (when the previous session ended). No account, name, email, precise location, or listening history is included, and no advertising identifier is sent. Crashlytics does assign an installation-scoped identifier to group reports from the same device install over time, but this is not a hardware ID and is not linked to any account. Separately from crash reports, Crashlytics also sends a minimal session signal on ordinary app launches that don't crash — no stack trace or diagnostic content, just enough for Google to calculate stability metrics like crash-free sessions. This is on by default but can be turned off at any time via the "Help improve the app by sending crash logs" toggle in Settings — once disabled, no further diagnostic data, including this session signal, is sent. See Google's own Privacy Policy and Firebase's data processing terms for how this data is handled.
Google Play Billing Processing the optional one-time purchase that unlocks PRO features Handled entirely by Google Play on your device — payment details, billing address, and transaction data go directly to Google, not to us. We only receive a purchase confirmation (whether PRO is active), with no payment or card information ever passed to or stored by the app. See Google's own Privacy Policy and Play Terms of Service for how Google Play Billing handles this data.
In-App Rating Prompt Occasionally asking you, inside the app, whether you'd like to rate Live Beats WebRadio The prompt itself is our own in-app dialog, not Google's built-in review flow, and no data about the prompt (whether it was shown, dismissed, or acted on) is sent to us or anyone else — it's decided and tracked entirely by local, on-device logic. If you choose "Rate now," the app opens the Google Play Store listing for Live Beats WebRadio in your browser or the Play Store app; anything you do from that point (submitting a star rating or review) is between you and Google. See Google's own Privacy Policy and Play Terms of Service for how Google Play handles that.

You can turn most of these off. The "Show Album Art", "Show Server Location", and "Help improve the app by sending crash logs" settings actually do what they say: switch them off and the app stops contacting iTunes, Last.fm, ipwho.is, or Firebase Crashlytics entirely. The in-app rating prompt doesn't currently have its own on/off setting; if you dismiss it enough times, the app stops showing it automatically.

Contacting Support

Tapping the email icon under Settings → About opens your own email app with a support email pre-addressed to us, pre-filled with a small amount of diagnostic information: app version, radio database version, Android version, device manufacturer and model, and whether you're a Pro or Free user. This is meant to help us assist you faster without you having to look up these details yourself.

This information is only ever sent if you choose to send that email — nothing is transmitted automatically. You can review, edit, or delete any of the pre-filled text in your email app before sending, the same as with any other email. No account, name, or personal identifier is added by the app beyond whatever is already part of your own email account and message.

Legal Basis for Processing (GDPR)

For users in the European Economic Area, we rely on legitimate interest (GDPR Article 6(1)(f)) to provide the core app functionality you've requested, limited to what's necessary to deliver streaming, station directory, and metadata services. This includes the technical data described above, such as IP addresses visible to third-party services during these requests, which we recognize as personal data under the GDPR even though no account or identity information is attached to it. Crash and diagnostic reporting via Firebase Crashlytics — including the minimal session signal used for stability metrics — is also based on legitimate interest, namely identifying and fixing app stability issues, and is limited to technical diagnostic data; it can be disabled at any time in Settings. The diagnostic info pre-filled into support emails is provided at your own initiative and under your control before sending, so no separate legal basis analysis applies beyond your own action in sending it. Where the app processes a PRO purchase, this is instead based on the necessity to perform a contract (GDPR Article 6(1)(b)) — fulfilling the purchase you initiated via Google Play Billing. The in-app rating prompt is also based on legitimate interest, limited to minimal on-device usage signals (such as your favorites count and when you were last asked) used only to decide when to show the prompt; nothing about it is sent off your device.

International Data Transfers

Some of the third-party services listed above — including Firebase Crashlytics and Google Play Billing (Google), and the iTunes Search API (Apple) — are operated by companies based in, or that process data in, the United States, outside the European Economic Area (EEA) and United Kingdom. Where this happens, the transfer relies on the safeguards those providers make available under the GDPR: Google and Apple participate in or otherwise rely on mechanisms such as the EU-U.S. Data Privacy Framework and/or the European Commission's Standard Contractual Clauses (SCCs), which are legal tools intended to ensure your data continues to receive a level of protection equivalent to what the GDPR requires, even once it leaves the EEA. We don't operate our own servers outside the EEA and don't independently transfer your data anywhere — any cross-border transfer happens as part of using these providers' services as described in the table above. You can find more detail on each provider's own safeguards in Google's Privacy Policy and Apple's Privacy Policy.

Notifications

Android's notification system shows playback controls while a station plays in the background. That's all handled by the OS — no outside service involved.

Permissions

Permission Why it's needed
Internet Streaming, searching stations, fetching metadata/artwork
Access Network State Checking connectivity type (e.g. Wi-Fi vs. mobile data) to support the "Wi-Fi Only" setting and Data Guard usage tracking. No data is sent anywhere for this — it's a local system check only.
Notifications Playback control notification (Android 13+)
Wake Lock Keeps audio playing when the screen turns off
Foreground Service / Media Playback Android requires this for background audio apps
Billing (com.android.vending.BILLING) Allows the app to offer the optional PRO purchase through Google Play Billing. Purchase and payment data is handled by Google, not by us — see the third-party table above.
Check License (com.android.vending.CHECK_LICENSE) Standard Google Play licensing check used alongside Billing to verify entitlement to purchased features. No personal data is sent by this permission itself.

Security Note

Some radio stations still broadcast over plain http:// instead of https://. That's a limitation of those individual stations, not something we can fix on our end — it's common across radio apps generally. In practice it means your network provider could potentially see which station you're streaming, same as with any unencrypted connection.

If you'd rather avoid unencrypted connections entirely, the HTTPS Only setting blocks playback of any station using an unencrypted http:// link, requiring https:// instead. If you're listening to an http:// stream when you turn this on, playback stops immediately and the app shows "Insecure (HTTP) stream blocked by your settings." Turning it on means some stations may become unavailable, since not every station offers an encrypted stream.

Data Retention & Deletion

We don't run servers that store your favorites, settings, or listening history — there's nothing on our end to retain in the first place. That data lives in Android DataStore on your device and stays there until you delete it yourself, either inside the app or by clearing the app's data/storage in Android settings. Uninstalling the app removes it too.

Because we never receive this data, we have no way to retain or delete it on your behalf — your device is the only copy. The one exception is anything you choose to export yourself (like an .lbrx backup file); once it's saved somewhere, deleting it is up to you, the same as any file. Purchase records for the PRO upgrade are retained by Google as part of your Google Play account, separately from anything stored by this app; see Google's Privacy Policy and Play Terms of Service to manage or delete that record. The local, on-device state used to time the in-app rating prompt (such as your favorites count and last-shown date) is deleted the same way as any other app data — clearing storage or uninstalling. If you go on to leave a rating or review through the Play Store after tapping "Rate now," that rating is retained by Google as part of your Google Play account, not by us. Crash and diagnostic data sent to Firebase Crashlytics — including the minimal session signal described above — is retained by Google per their standard Crashlytics data retention period; see Firebase's data processing terms for details. Any support email you send, including the pre-filled diagnostic info, is retained in your own email account and ours, like any other email correspondence.

How to Delete Your Data

Live Beats WebRadio does not use accounts, so there is no central account or server-side profile to delete. All app data — favorites, listening history, saved songs, settings, cached server-location info, and the local state behind the in-app rating prompt — is stored locally on your device in Android DataStore and was never sent to us in the first place.

To delete this data yourself:

  • In-app: use the "Clear History" and "Delete Favorite" options found in the Favorites and History screens to remove specific items.
  • Full reset: go to Android Settings → Apps → Live Beats WebRadio → Storage & cache → Clear storage. This immediately and permanently erases all app data on your device, including any saved state for the in-app rating prompt.
  • Uninstalling the app also removes all locally stored data.

The only data that ever leaves your device — search terms sent to Radio-Browser, artist/track lookups sent to iTunes/Last.fm for album art, diagnostic data (including the minimal session signal) sent to Firebase Crashlytics, or diagnostic info included in a support email you choose to send — is not linked to any account, so there's no request needed to delete it: it isn't retained or tied back to you by those services in a way we can act on. (Crashlytics does use an installation-scoped identifier to group reports from the same device install over time, as noted above, but this isn't an account or hardware identifier.) If you disable "Show Album Art", "Show Server Location", or "Help improve the app by sending crash logs" in Settings, the app stops sending these lookups going forward. Purchase history for the PRO upgrade is managed through your Google account at Google Play → Payments & subscriptions, not through this app. Any rating or review you've left through the Play Store after using the in-app "Rate now" option can be edited or removed the same way — through your Google Play account — since it was never stored by this app.

Your Rights Under GDPR

If you're in the European Economic Area, the GDPR gives you the following rights over your personal data. Because Live Beats WebRadio doesn't use accounts and doesn't hold a server-side copy of your favorites, settings, or listening history, most of these rights are already satisfied by design — there's simply nothing centrally stored for us to act on. Here's how each one applies in practice:

  • Right of access — You already have full access to everything the app stores, since it all lives in Android DataStore on your own device. We hold no separate copy to request access to.
  • Right to rectification — Anything the app stores (station names, genres, saved song titles, etc.) can be edited directly in-app at any time.
  • Right to erasure ("right to be forgotten") — See How to Delete Your Data above for exactly how to remove any or all app data.
  • Right to restrict processing — You can disable "Show Album Art", "Show Server Location", or "Help improve the app by sending crash logs" in Settings at any time to stop that specific processing going forward.
  • Right to data portability — Your favorites can be exported at any time as a .lbrx file, in a format you control and can move elsewhere.
  • Right to object — You can object to any processing based on legitimate interest (see the Legal Basis section above) by disabling the relevant setting, or by uninstalling the app, which removes all local data immediately.
  • Rights related to automated decision-making and profiling — The app doesn't perform automated decision-making or profiling about you, so this right doesn't apply to anything we do.
  • Right to lodge a complaint — If you believe your data has been mishandled, you have the right to complain to your local data protection supervisory authority, regardless of anything above. You can find your national authority via the European Data Protection Board's member list.

For any of the above, or if something isn't covered here, you can also reach out directly — see Contact below.

Your Privacy Rights Under CCPA/CPRA (California)

If you're a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you rights over your personal information similar to those described above under the GDPR: the right to know what personal information is collected, the right to delete it, the right to correct inaccurate information, and the right to non-discrimination for exercising any of these rights. We do not sell or share your personal information, as those terms are defined under the CCPA/CPRA — we don't exchange it for money, and we don't disclose it to third parties for cross-context behavioral advertising. The limited technical data described in the Information Sent to Third Parties table above is shared only as needed to provide the app's core functionality (station search, artwork lookup, crash diagnostics), which falls outside the CCPA/CPRA's definition of a "sale" or "share." Because we don't use accounts, most of what you could request access to or deletion of already lives on your device under your control — see How to Delete Your Data above. To exercise any CCPA/CPRA right, or if you have questions about how this applies to you, contact us — see Contact below.

Do Not Track Signals

Some browsers offer a "Do Not Track" (DNT) signal, and some U.S. states have laws addressing how site operators should respond to it. Live Beats WebRadio doesn't run in a browser and doesn't perform behavioral tracking or cross-site/cross-app tracking of any kind, so there's no tracking for a DNT signal to opt you out of — the app simply doesn't respond to DNT signals because it has no tracking behavior to disable in the first place.

Children's Privacy

The app isn't directed at children and doesn't knowingly collect personal information from anyone. The age at which someone can use online services without parental involvement varies by country — for example, 13 in the United States, and up to 16 in some European Union member states (with others setting it as low as 13). We don't gate any content by age beyond whatever individual radio stations broadcast.

Changes to This Policy

If anything here changes, we'll update the "Last updated" date above. Using the app after a change goes live means you accept the updated version.

Contact

Questions about this policy or the app's data practices can be sent to:
Live Beats WebRadio
Developer: Christian Flach
Email: livebeatswrp@gmail.com