Privacy Policy
Last updated: 6 September 2026
Who we are
Beaam is operated by Teqnyk Ltd. We are a monitoring tool for solo founders and small teams. Questions: support@beaam.app
What we collect
- Account data: Email address, billing tier, and alert contact preferences (email address, phone number for SMS).
- Credentials: API keys and tokens for services you connect (AWS, Sentry, Stripe, etc.). These are encrypted at rest using AES-256-GCM with a key held as a Cloudflare Worker secret that is never exposed to browser code. They are never logged or transmitted in plaintext.
- Telemetry and poll data: Metrics collected from your connected services (e.g., Lambda error rates, Stripe transaction counts). Used solely to power monitoring and alerts.
- Usage data: Which integrations you connect, when services are first watched (activation timestamp), when alerts are sent. Used to operate and improve the Service.
How we use it
- To monitor your services and send alerts when something goes wrong.
- To send a daily “all quiet” heartbeat proving the service is alive.
- To manage your subscription and process payments via Polar (our billing provider).
- To improve the product — we look at aggregate usage patterns, not your data content.
Who we share it with
- Supabase — database and authentication (servers in the United States, us-east-1).
- Cloudflare — application hosting.
- Tinybird — time-series metric storage (OTel telemetry data).
- Vonage — our messaging carrier, and a subcontractor acting on our instructions. Your phone number is transmitted to Vonage only to deliver an SMS you asked for, never for marketing. See SMS alerts and mobile information below.
- Resend — email alert delivery.
- Loops — lifecycle email: the welcome message, onboarding reminders and product updates. Receives your email address and which setup milestones you have reached, never monitoring data. Alerts do not go through Loops. Every message carries an unsubscribe link, and unsubscribing does not affect the alerts you have asked for.
- Polar — subscription billing. Your payment data is handled entirely by Polar and is not stored by Beaam.
- Anthropic — AI incident explanations, and only if your organization turns them on (off by default). When enabled, at incident time we send Anthropic a short evidence summary — the affected service names, the timings, and any control-plane change we detected — to write a one-sentence explanation. No raw metrics, credentials, or personal data are sent, and Anthropic does not train on it. With the setting off, no data is ever sent to an AI provider.
- Google Analytics — optional, consent-gated analytics for visits to the public beaam.app marketing site and one completed-signup event. It does not receive your email or signed-in product activity.
- Google Ads— optional measurement of whether one of Beaam's own advertisements led to a completed account signup. Its tag is not requested until you explicitly allow advertising measurement.
We do not sell your data to third parties or use monitoring data to target advertising.
SMS alerts and mobile information
SMS alerts are optional and off until you add your own mobile number as a notification channel in Settings → Notifications and enable it. Adding and enabling that channel is your consent to receive Beaam Alerts text messages at that number, and we send a confirmation text when you do. We never buy, rent, or import phone numbers, and we never send marketing or promotional texts. Message frequency varies with incidents on the services you monitor; message and data rates may apply. Reply STOP to any message to opt out, or delete the channel in Settings; reply HELP for help.
We use your mobile number for one purpose: delivering the monitoring alerts and account notifications you asked for. It is passed to Vonage, our messaging carrier and a subcontractor acting on our instructions, only to deliver those messages.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service and message delivery, is permitted. All of the sharing categories described in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Your number is deleted from our records as soon as you delete the channel or your account. The full SMS program terms are in Terms of Service §11.
Data retention
While your account is active, we retain the account, configuration, incident, alert, and delivery records needed to operate the Service and show your history. Raw metric samples expire after 30 days — this covers both the metrics Beaam collects from your connected integrations and any OTLP telemetry you send us. Control-plane change events we read from your providers (deploys, scaling, config changes), used to explain incidents, expire on the same 30-day boundary. Encrypted integration credentials are deleted immediately when you disconnect that integration.
We also keep an hourly health summaryfor each service you watch, and we keep it for as long as your account is open. It records only how many checks ran in that hour and the worst state seen — for example “30 checks, all quiet”. It contains none of the underlying measurements, no request or response contents, and nothing we read from your providers. It exists so your history does not stop a month ago: the detail behind any hour is gone after 30 days, but the shape of that hour remains.
When you delete your account, Beaam deletes your active authentication and control-plane records immediately, including the hourly health summaries described above. Raw metric samples expire from Tinybird within 30 days. Limited backup, billing, email, and SMS records may remain with our processors for their documented retention periods or where legally required. See our retention inventory for the current detail.
Retention inventory
Supabase holds active account and operational data — including the hourly health summaries, which are kept for the life of the account; Tinybird holds raw metrics for 30 days; Cloudflare holds diagnostic logs under our provider plan; Resend, Loops, Vonage, Expo, and Polar retain delivery or financial records under their own legal and operational schedules. Beaam does not use an R2 cold-data tier today. Contact support@beaam.app for the current processor-specific detail or a privacy request.
Your rights
You have the right to access, correct, or delete your personal data. To exercise these rights, email support@beaam.app. If you are in the UK or EU, you have additional rights under UK GDPR / GDPR and the right to lodge a complaint with the ICO (UK) or your local supervisory authority.
Cookies
We use essential session cookies for authentication via Supabase Auth. Plausible measures visits to the public marketing site without cookies or a cross-site identifier.
Google Analytics and Google Ads measurement are optional and off until you choose “Allow measurement”. If allowed, Google Analytics receives public marketing page URLs, referral and campaign information, device/browser information, coarse location, scrolls, outbound clicks and one event when a Beaam account signup is completed. Google Ads may receive the ad click identifier and that same completed- signup event. Beaam does not enable enhanced conversions or advertising personalization, so your email address is not sent, and the tag does not report activity inside your Beaam account. Your choice is stored for 180 days in the beaam_google_measurement_consent cookie across beaam.app and app.beaam.app; beaam_ads_consent is retained as a compatibility copy during the measurement rollout.
Declining leaves the Google tag unloaded. You can change your choice at any time; choosing Decline withdraws permission for future measurement. Google may retain data already received under its own retention terms.
Security
Credentials are encrypted with AES-256-GCM before storage. All traffic is encrypted in transit (TLS). Row-level security policies ensure each user can only access their own data in the database. The monitoring watchdog runs on a separate infrastructure account to maintain independence.
Changes
We may update this policy. Material changes will be communicated by email. The “Last updated” date above reflects the most recent revision.