Privacy

Last updated 2026-07-25 · Private beta — current product behavior; this notice may change as testing evolves.

PostBeacon turns your product URL into a launch plan. That means it handles your product’s page text, the profile built from it, and — if you use the workspace — the results you type in. This page says plainly where each piece lives, which vendors see it, and how to get it out or delete it.

The short version

  • Not signed in? The one-channel preview is processed by the server and AI provider, but is not written to the projects database. Its result stays in this browser for up to one hour so you can explicitly continue after signing in.
  • Signed in? Projects are saved to our database (Supabase) in rows only your account can read.
  • Your page text, profile, plan context and anything you paste to the copilot are sent to your primary AI model to generate output. If the primary model is unavailable, PostBeacon may retry with another configured provider. During this beta that can include DeepSeek, which processes data in China and does not clearly exclude training use; avoid confidential material.
  • We never post to any platform for you, set no advertising cookies, and don’t use your content to train models or build cross-user content or outcome-benchmark datasets.
  • You can export everything as JSON and delete a project or your whole account from inside the app.
  • In-app action reminders are automatic. Event emails are off unless you explicitly enable them, and can be switched off from the workspace.

What we handle, where it lives

DataWhereWhyKeptHow to delete
Signed-out one-channel preview (URL and returned product/channel/draft summary)Processed by the server and AI provider; the result is kept in this browser's localStorage only for the sign-in handoffGive one useful result before sign-in and preserve it across a same-browser sign-inUp to 1 hour in this browser; PostBeacon does not write it to the projects database“Clear this preview” or clear browser data
Signed-out preview quota identityA signed random browser cookie; Upstash receives only a keyed digest and per-window countersEnforce one visitor limit and a shared hard spend cap without IP or device fingerprintingCookie up to 30 days; quota counters expire after the configured window (24h by default)Clear site cookies; server counters expire automatically and contain no submitted content
Account identity (email, optional Google sign-in, display name)Supabase (auth)Sign-in and project ownershipLife of your accountDelete account
Saved projects (profile, fact ledger, strategy, generated content, calendar)Supabase, in rows only you can read (row-level security)Your launch plans, saved across devicesUntil you delete the project or accountDelete project (×) or delete account
Workspace data (experiments, outcomes/metrics you type, tasks, audit log, product memory)Supabase, same owner-only rulesThe publish → measure → learn loopWith its projectDeleting the project cascades all of it
Prompts to the AI model (page text, profile, plan context, pasted feedback)Sent to your primary model; on availability/credit/rate-limit failure, another configured provider (including DeepSeek during this beta) may receive the retryGenerating your profile, strategy, content and copilot answersNot stored by us; the provider retains per its API policy (see table below)Provider-side, per its policy
Copilot chat transcriptsYour browser session onlyThe conversation you're havingGone when the panel session ends — never long-term memory by designAutomatic
Usage metering (plan, launches used, daily calls)SupabasePrivate-beta usage limits and abuse preventionLife of your accountDelete account
Server logs & analyticsVercel platform logs (IP, path); Vercel Web Analytics (cookieless, aggregate page and lifecycle events). Internal product-health calculations return only counts derived from existing owner-scoped lifecycle rowsOperations, security, first-value funnel and weekly retention. Analytics receives no submitted URL/content, email, account id, draft, or outcome value; internal reports expose no raw identities or contentVercel platform defaultsAges out automatically

AI models and your data

Generation starts on the primary model you pick. Prompts include your page’s extracted text, the profile, relevant plan context, and text you paste to the copilot. If that provider is unavailable, out of credit, rate-limited, misconfigured, or cannot return usable structured output, PostBeacon may retry the same prompt with another configured provider. A failed provider may already have received the first attempt. During this beta, automatic fallback can include DeepSeek and China processing. We don’t store chat transcripts; each provider retains API data per its own policy:

ModelRegionPublished API policy (as we read it)
OpenAIUSAPI data isn't used to train models by default; retained up to ~30 days for abuse monitoring.
DeepSeekChinaData is processed in China and training use isn't clearly excluded — avoid confidential material with this model.

Where a provider’s policy doesn’t clearly exclude training use, we never make it the default and we label it in the model picker. If your product is still confidential, don’t paste anything you wouldn’t want retained. During this beta, DeepSeek may also be used as the disclosed automatic fallback; avoid confidential material.

What we deliberately don’t do

  • No auto-posting. PostBeacon never holds your social accounts’ credentials and never publishes on your behalf — you copy and post.
  • No training or cross-user content/outcome benchmarking. Your plan text, drafts, qualitative feedback and outcome values are used only to serve you. We count aggregate lifecycle stages (for example: plan created, manual publish confirmed, scheduled result recorded) to validate the product; those reports contain no submitted content, outcome values or account identifiers. Any future learning from anonymized outcome data would be a separate, explicit, revocable opt-in — de-identified and computed only over large cohorts — and off by default.
  • No ad tech. Analytics are cookieless and aggregate (Vercel Web Analytics), with an allowlist that excludes URLs you submit, content, emails, account IDs and outcome values. We don’t sell or share personal information for advertising.

Your controls

  • Clear browser preview or draft — removes the temporary guest preview or local-only draft from this device.
  • Export my data — in the app’s “Data & privacy” menu: downloads your account’s projects, experiments, outcomes, tasks and plan status as one JSON file.
  • Delete a project — the × beside a saved project; its experiments, outcomes and tasks are deleted with it.
  • Delete my account — in “Data & privacy”: removes your projects, workspace data, usage records and the account itself. If a deployment can’t perform a full deletion, the app says so instead of pretending.

Residual copies can persist briefly in encrypted database backups until those backups age out on the vendor’s schedule.

Retention

This deployment automatically deletes signed-in projects untouched for 30 days (and internal webhook receipts of the same age). Browser-only preview and draft retention is listed in the inventory above.

Vendors and transfers

The full list of vendors that touch data, what each sees, and when, is on the data-vendors page. Hosting is on Vercel (US); if you’re outside the US your data is processed there and by the model provider’s region shown above.

Changes

We’ll update this page as the product evolves and bump the date at the top; material changes will be visible in the app. During the private beta, please tell us if this page does not match what the product actually does.

Questions or requests about your data: privacy@postbeacon.app. © 2026 PostBeacon · postbeacon.app