Privacy Policy
Last updated: 16 August 2026
Who we are
Beaam is operated by Teqnyk Ltd. We are a monitoring tool for solo founders and small teams. Questions: support@beaam.app
What we collect
- Account data: Email address, billing tier, and alert contact preferences (email address, phone number for SMS).
- Credentials: API keys and tokens for services you connect (AWS, Sentry, Stripe, etc.). These are encrypted at rest using AES-256-GCM with a key held as a Cloudflare Worker secret that is never exposed to browser code. They are never logged or transmitted in plaintext.
- Telemetry and poll data: Metrics collected from your connected services (e.g., Lambda error rates, Stripe transaction counts). Used solely to power monitoring and alerts.
- Usage data: Which integrations you connect, when services are first watched (activation timestamp), when alerts are sent. Used to operate and improve the Service.
How we use it
- To monitor your services and send alerts when something goes wrong.
- To send a daily “all quiet” heartbeat proving the service is alive.
- To manage your subscription and process payments via Polar (our billing provider).
- To improve the product — we look at aggregate usage patterns, not your data content.
Who we share it with
- Supabase — database and authentication (servers in the United States, us-east-1).
- Cloudflare — application hosting.
- Tinybird — time-series metric storage (OTel telemetry data).
- Twilio — SMS alert delivery. Your phone number is transmitted to Twilio only when an SMS alert is sent.
- Resend — email alert delivery.
- Polar — subscription billing. Your payment data is handled entirely by Polar and is not stored by Beaam.
- Anthropic — AI incident explanations, and only if your organization turns them on (off by default). When enabled, at incident time we send Anthropic a short evidence summary — the affected service names, the timings, and any control-plane change we detected — to write a one-sentence explanation. No raw metrics, credentials, or personal data are sent, and Anthropic does not train on it. With the setting off, no data is ever sent to an AI provider.
We do not sell your data to third parties. We do not use your data for advertising.
Data retention
While your account is active, we retain the account, configuration, incident, alert, and delivery records needed to operate the Service and show your history. Raw metric samples expire after 30 days — this covers both the metrics Beaam collects from your connected integrations and any OTLP telemetry you send us. Control-plane change events we read from your providers (deploys, scaling, config changes), used to explain incidents, expire on the same 30-day boundary. Encrypted integration credentials are deleted immediately when you disconnect that integration.
We also keep an hourly health summaryfor each service you watch, and we keep it for as long as your account is open. It records only how many checks ran in that hour and the worst state seen — for example “30 checks, all quiet”. It contains none of the underlying measurements, no request or response contents, and nothing we read from your providers. It exists so your history does not stop a month ago: the detail behind any hour is gone after 30 days, but the shape of that hour remains.
When you delete your account, Beaam deletes your active authentication and control-plane records immediately, including the hourly health summaries described above. Raw metric samples expire from Tinybird within 30 days. Limited backup, billing, email, and SMS records may remain with our processors for their documented retention periods or where legally required. See our retention inventory for the current detail.
Retention inventory
Supabase holds active account and operational data — including the hourly health summaries, which are kept for the life of the account; Tinybird holds raw metrics for 30 days; Cloudflare holds diagnostic logs under our provider plan; Resend, Twilio, Expo, and Polar retain delivery or financial records under their own legal and operational schedules. Beaam does not use an R2 cold-data tier today. Contact support@beaam.app for the current processor-specific detail or a privacy request.
Your rights
You have the right to access, correct, or delete your personal data. To exercise these rights, email support@beaam.app. If you are in the UK or EU, you have additional rights under UK GDPR / GDPR and the right to lodge a complaint with the ICO (UK) or your local supervisory authority.
Cookies
We use session cookies for authentication (via Supabase Auth). No tracking cookies or advertising pixels are used.
Security
Credentials are encrypted with AES-256-GCM before storage. All traffic is encrypted in transit (TLS). Row-level security policies ensure each user can only access their own data in the database. The monitoring watchdog runs on a separate infrastructure account to maintain independence.
Changes
We may update this policy. Material changes will be communicated by email. The “Last updated” date above reflects the most recent revision.