This policy explains what information Beam collects when you use the website, the app, the CLI, the MCP server, and the API, how we use it, who we share it with, and the choices you have.
1. Who we are
Beam is provided by [COMPANY LEGAL NAME] ("Beam", "we", "us"), [COMPANY ADDRESS]. We are responsible for the personal data described in this policy. You can reach us about privacy at legal@beam.host.
2. Information we collect
Account information
- Email sign-up: your name, email address, and a hash of your password. We never store your password itself.
- GitHub or Google sign-in: the profile details that provider shares with us: your name, email address, and avatar image.
- Sessions and devices: session records for the web app and device-login tokens that keep the CLI signed in, along with basic details such as when they were created and last used.
- API tokens: the tokens you create for agents and tools, their names, and when they were created and used. We store tokens in a form that lets us verify them.
- Teams: the teams you create or join, members, invitations, and roles.
Your content
Files you or your agents upload to personal storage, team storage, and workspaces, and the metadata that describes them: filenames, sizes, folders, tags, and timestamps. We also keep records of the shares you create.
Billing information
If you subscribe to a paid plan, Stripe collects and processes your payment details. We receive and store your subscription status, plan, and a Stripe customer reference. We do not receive or store your full card number.
Technical information
When you use Beam, our hosting provider processes technical data such as IP address, browser or client type, and request logs, which we use to operate and secure the Service. Bot protection on sign-up and some forms (Cloudflare Turnstile) evaluates signals from your browser to tell people from automated abuse.
Messages and reports
If you email us or report content, we keep your message and the details you include.
3. How we use information
We use the information above to:
- create and run your account, and sign you in on the web, CLI, and MCP server;
- store, sync, and share your content the way you ask us to;
- process payments, trials, and subscriptions;
- send transactional email, such as email verification and password reset messages;
- let our team know when someone new signs up, so we can welcome and support new users;
- prevent abuse, enforce our Terms of Service, review reported content, and keep Beam secure;
- fix problems and improve the Service;
- comply with the law.
We do not sell your personal data, and we do not use it for advertising.
4. Legal bases
Where laws such as the GDPR apply, we process your data to perform our contract with you (running your account and the Service), for our legitimate interests (security, abuse prevention, and understanding sign-ups), to comply with legal obligations, and with your consent where we ask for it. You can withdraw consent at any time.
5. Service providers we use
We share personal data only with service providers that help us run Beam, and only as needed for the purposes below:
| Provider | What they do for Beam |
|---|---|
| Cloudflare | Hosting, file storage (R2), database for metadata and accounts (D1), bot protection (Turnstile), and transactional email (Cloudflare Email Service). |
| Stripe | Billing and payment processing for paid plans. |
| GitHub | Sign-in, only if you choose to sign in with GitHub. |
| Sign-in, only if you choose to sign in with Google. | |
| Discord | Internal staff notification when a new account is created, containing the new user's name and email address. |
We may also disclose information if the law requires it, to protect the rights and safety of Beam, our users, or others, or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to your data.
When you share content, the people and agents you share it with can see it. That is sharing you control, not sharing by us.
6. Where your data is stored
Your files are stored in Cloudflare R2 and your account data and file metadata in Cloudflare D1. Our providers operate globally, so your data may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses for these transfers.
7. Retention and deletion
- Your files stay in your storage until you delete them. You can delete files at any time from the app, the CLI, or the API.
- Anonymous quick shares expire five minutes after they are created and are then deleted.
- Your account: to delete it, email legal@beam.host from the address on the account. We will delete your account, your personal storage, and associated data within a reasonable time, except where we must keep some records to meet legal, tax, or accounting obligations, resolve disputes, or prevent abuse.
- Sessions and tokens are kept until they expire or you sign out or revoke them.
Deleted data may remain in backups and logs for a limited period before it is overwritten.
9. Security
We use industry-standard measures to protect your data, including encryption in transit, hashed passwords, and access controls. No system is perfectly secure, so please use a strong password, keep your API tokens secret, and revoke tokens you no longer need.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict some processing, and to withdraw consent. You can update much of your information and delete your files directly in the app. For anything else, email legal@beam.host. We may need to verify your identity first.
If you are unhappy with how we handle your data, please contact us first. You can also complain to your local data protection authority.
11. Children
Beam is not intended for children, and we do not knowingly collect personal data from anyone below the minimum age in our Terms of Service. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as Beam changes. We will update the date at the top of this page and, for material changes, notify you by email or in the app.
13. Contact
Questions or requests about your data? Email legal@beam.host, or write to [COMPANY LEGAL NAME], [COMPANY ADDRESS].