Data vendors

Last updated 2026-07-25 · Private beta — current product behavior; this notice may change as testing evolves.

These are the vendors currently configured for this private beta. A vendor only receives the data described below when the related feature is actually used.

Current vendors

VendorRoleData it can seeRegionWhen
VercelHosting, serverless functions, cookieless aggregate product analyticsAll request traffic (platform logs: IP, user agent, path); aggregated page views and allowlisted lifecycle event names with low-cardinality stage/provider/checkpoint labels — never submitted URLs, content, email, account ids, or outcome valuesUSAlways
SupabaseAccounts (auth) and databaseEmail / OAuth identity, saved projects, workspace experiments & outcomes, usage entitlementsOperator-chosen project regionOnly when accounts are configured and you sign in
OpenAIAI model (GPT)Your product page text, profile, plan context, and anything you paste to the copilotUSOnly if configured, and when selected as primary or used as a clear-policy fallback
DeepSeekAI modelYour product page text, profile, plan context, and anything you paste to the copilotChinaWhen selected as primary, or as the explicitly enabled beta fallback after another provider fails
GoogleOptional OAuth sign-inOAuth handshake onlyUSOnly if you choose “Continue with Google”
UpstashAnonymous preview abuse limitsA keyed digest of a random visitor token and aggregate request counts — never the submitted URL, page text, IP, user agent, or draftOperator-chosen database regionOnly when the signed-out one-channel preview is enabled

You choose a primary AI provider. If the primary model is unavailable, PostBeacon may retry with another configured provider. During this beta that can include DeepSeek, which processes data in China and does not clearly exclude training use; avoid confidential material. A failed provider may already have received the first attempt.

Questions or requests about your data: privacy@postbeacon.app. © 2026 PostBeacon · postbeacon.app