Privacy
Last updated 2026-07-25 · Private beta — current product behavior; this notice may change as testing evolves.
PostBeacon turns your product URL into a launch plan. That means it handles your product’s page text, the profile built from it, and — if you use the workspace — the results you type in. This page says plainly where each piece lives, which vendors see it, and how to get it out or delete it.
The short version
- Not signed in? The one-channel preview is processed by the server and AI provider, but is not written to the projects database. Its result stays in this browser for up to one hour so you can explicitly continue after signing in.
- Signed in? Projects are saved to our database (Supabase) in rows only your account can read.
- Your page text, profile, plan context and anything you paste to the copilot are sent to your primary AI model to generate output. If the primary model is unavailable, PostBeacon may retry with another configured provider. During this beta that can include DeepSeek, which processes data in China and does not clearly exclude training use; avoid confidential material.
- We never post to any platform for you, set no advertising cookies, and don’t use your content to train models or build cross-user content or outcome-benchmark datasets.
- You can export everything as JSON and delete a project or your whole account from inside the app.
- In-app action reminders are automatic. Event emails are off unless you explicitly enable them, and can be switched off from the workspace.
What we handle, where it lives
| Data | Where | Why | Kept | How to delete |
|---|---|---|---|---|
| Signed-out one-channel preview (URL and returned product/channel/draft summary) | Processed by the server and AI provider; the result is kept in this browser's localStorage only for the sign-in handoff | Give one useful result before sign-in and preserve it across a same-browser sign-in | Up to 1 hour in this browser; PostBeacon does not write it to the projects database | “Clear this preview” or clear browser data |
| Signed-out preview quota identity | A signed random browser cookie; Upstash receives only a keyed digest and per-window counters | Enforce one visitor limit and a shared hard spend cap without IP or device fingerprinting | Cookie up to 30 days; quota counters expire after the configured window (24h by default) | Clear site cookies; server counters expire automatically and contain no submitted content |
| Account identity (email, optional Google sign-in, display name) | Supabase (auth) | Sign-in and project ownership | Life of your account | Delete account |
| Saved projects (profile, fact ledger, strategy, generated content, calendar) | Supabase, in rows only you can read (row-level security) | Your launch plans, saved across devices | Until you delete the project or account | Delete project (×) or delete account |
| Workspace data (experiments, outcomes/metrics you type, tasks, audit log, product memory) | Supabase, same owner-only rules | The publish → measure → learn loop | With its project | Deleting the project cascades all of it |
| Prompts to the AI model (page text, profile, plan context, pasted feedback) | Sent to your primary model; on availability/credit/rate-limit failure, another configured provider (including DeepSeek during this beta) may receive the retry | Generating your profile, strategy, content and copilot answers | Not stored by us; the provider retains per its API policy (see table below) | Provider-side, per its policy |
| Copilot chat transcripts | Your browser session only | The conversation you're having | Gone when the panel session ends — never long-term memory by design | Automatic |
| Usage metering (plan, launches used, daily calls) | Supabase | Private-beta usage limits and abuse prevention | Life of your account | Delete account |
| Server logs & analytics | Vercel platform logs (IP, path); Vercel Web Analytics (cookieless, aggregate page and lifecycle events). Internal product-health calculations return only counts derived from existing owner-scoped lifecycle rows | Operations, security, first-value funnel and weekly retention. Analytics receives no submitted URL/content, email, account id, draft, or outcome value; internal reports expose no raw identities or content | Vercel platform defaults | Ages out automatically |
AI models and your data
Generation starts on the primary model you pick. Prompts include your page’s extracted text, the profile, relevant plan context, and text you paste to the copilot. If that provider is unavailable, out of credit, rate-limited, misconfigured, or cannot return usable structured output, PostBeacon may retry the same prompt with another configured provider. A failed provider may already have received the first attempt. During this beta, automatic fallback can include DeepSeek and China processing. We don’t store chat transcripts; each provider retains API data per its own policy:
| Model | Region | Published API policy (as we read it) |
|---|---|---|
| OpenAI | US | API data isn't used to train models by default; retained up to ~30 days for abuse monitoring. |
| DeepSeek | China | Data is processed in China and training use isn't clearly excluded — avoid confidential material with this model. |
Where a provider’s policy doesn’t clearly exclude training use, we never make it the default and we label it in the model picker. If your product is still confidential, don’t paste anything you wouldn’t want retained. During this beta, DeepSeek may also be used as the disclosed automatic fallback; avoid confidential material.
What we deliberately don’t do
- No auto-posting. PostBeacon never holds your social accounts’ credentials and never publishes on your behalf — you copy and post.
- No training or cross-user content/outcome benchmarking. Your plan text, drafts, qualitative feedback and outcome values are used only to serve you. We count aggregate lifecycle stages (for example: plan created, manual publish confirmed, scheduled result recorded) to validate the product; those reports contain no submitted content, outcome values or account identifiers. Any future learning from anonymized outcome data would be a separate, explicit, revocable opt-in — de-identified and computed only over large cohorts — and off by default.
- No ad tech. Analytics are cookieless and aggregate (Vercel Web Analytics), with an allowlist that excludes URLs you submit, content, emails, account IDs and outcome values. We don’t sell or share personal information for advertising.
Your controls
- Clear browser preview or draft — removes the temporary guest preview or local-only draft from this device.
- Export my data — in the app’s “Data & privacy” menu: downloads your account’s projects, experiments, outcomes, tasks and plan status as one JSON file.
- Delete a project — the × beside a saved project; its experiments, outcomes and tasks are deleted with it.
- Delete my account — in “Data & privacy”: removes your projects, workspace data, usage records and the account itself. If a deployment can’t perform a full deletion, the app says so instead of pretending.
Residual copies can persist briefly in encrypted database backups until those backups age out on the vendor’s schedule.
Retention
This deployment automatically deletes signed-in projects untouched for 30 days (and internal webhook receipts of the same age). Browser-only preview and draft retention is listed in the inventory above.
Vendors and transfers
The full list of vendors that touch data, what each sees, and when, is on the data-vendors page. Hosting is on Vercel (US); if you’re outside the US your data is processed there and by the model provider’s region shown above.
Changes
We’ll update this page as the product evolves and bump the date at the top; material changes will be visible in the app. During the private beta, please tell us if this page does not match what the product actually does.
Questions or requests about your data: privacy@postbeacon.app. © 2026 PostBeacon · postbeacon.app