Effective 24 August 2026
This policy applies to the Beacone website and service at beacone.dev. Beacone does not sell personal data, serve advertising, or use third-party analytics. For any privacy question or request, email support@beacone.dev.
Information Beacone processes
Website and waitlist
Beacone’s servers necessarily receive an IP address and basic request information when you visit. Beacone uses an IP address to enforce the rate limit on the public waitlist endpoint. If you join the waitlist, Beacone stores your email address and signup time so it can contact you about availability.
Account and sign-in
When you sign in with GitHub or Google, Beacone receives identifiers and profile details such as your name, handle, email address, email-verification status, and avatar URL. Beacone stores the details needed to recognize your account and show your connected sign-in methods. Google access tokens are discarded after sign-in.
GitHub connection
Beacone stores your encrypted GitHub authorization credentials; GitHub App installation, account, repository, event, and permission identifiers; repository names and visibility; and the notification rules, repositories, and actors you mute or follow. GitHub may send notification content such as repository names, issue or pull-request titles, comment snippets, actor names, and links. Beacone processes that content to decide whether to notify you and to compose the outgoing message.
Beacone does not clone repositories and does not persist source code, diffs, issue or pull-request titles, or comment bodies. It stores delivery metadata such as the reason, repository name, thread number, delivery time, and provider message identifier.
Telegram and Slack delivery
For Telegram, Beacone stores your chat identifier and connection status. For Slack, it stores workspace and app identifiers, your Slack user and private App Home conversation identifiers, connection status, and encrypted workspace access and refresh tokens. Slack OAuth supplies the information needed to establish that connection. After connection, Beacone’s Slack Events subscription is limited to theapp_uninstalled and tokens_revoked lifecycle events; Beacone does not read your Slack messages or replies.
The notification itself is sent to the destination you select. Telegram or Slack will retain that delivered message under its own terms and your workspace or account settings.
Support
If you contact support, Beacone receives your email address and whatever information you include. Please do not send passwords, OAuth codes, access tokens, webhook secrets, or private repository content.
How Beacone uses information
Beacone uses personal data only to:
- create and secure your account and browser session
- connect the GitHub, Telegram, and Slack services you choose
- filter, deliver, amend, and display a history of your notifications
- apply your rules, mutes, repository choices, and delivery preference
- operate, troubleshoot, back up, and protect the service
- answer support and privacy requests
- contact waitlist members about Beacone’s availability
These uses are necessary to provide the service you request or are in Beacone’s legitimate interests in keeping that service reliable and secure. Where consent is required, you may withdraw it without affecting earlier processing.
Retention
- Account and preferences
- Until you delete your account.
- GitHub connection
- Connection credentials and user-specific repository access are removed when you disconnect GitHub. Account preferences, mutes, and any GitHub sign-in method stay until you remove them or delete your account.
- Telegram destination
- Removed when you disconnect Telegram or delete your account. Beacone requires one connected delivery destination, so you must select another one before disconnecting the current destination.
- Slack personal connection
- Your Slack user and private App Home conversation link are removed when you disconnect Slack or delete your account. Workspace-level installation data is covered below.
- Browser sessions
- Up to 30 days, or until you sign out or delete your account.
- Delivery activity
- Removed by the daily cleanup after 30 days. An amendment after that does not recreate or extend the activity record.
- Message amendment references
- Removed by the daily cleanup after 90 days from the original delivery, even if the message is amended later. These contain identifiers, not message content.
- Webhook delivery identifiers
- GitHub delivery IDs and Slack lifecycle-event IDs, removed by the daily cleanup after 7 days to prevent retries from being processed twice.
- Database backups
- Retained for up to 30 days for disaster recovery before automatic expiry.
Expired operational records are removed by a daily cleanup. Rotating technical logs are kept only as needed to operate and secure the service. Support correspondence is retained while it is needed to resolve the request and maintain an appropriate record. Information may be kept longer if required by law or to establish, exercise, or defend legal claims.
A Slack installation belongs to the workspace, not solely to one Beacone account. Workspace-level installation identifiers and encrypted credentials may therefore remain after an individual deletes their Beacone account. The workspace manages that installation in Slack. When Slack reports that the app was uninstalled or its tokens were revoked, Beacone marks the workspace connection unavailable.
Service providers and data transfers
Beacone stores the data it controls, including backups, in the European Union.
When you connect or use them, GitHub and Google process authentication and account information, and GitHub supplies notification events. Telegram or Slack receives the messages you ask Beacone to deliver. Each provider also processes information under its own privacy policy. Some providers may process data outside your country; their applicable contractual and legal transfer safeguards apply.
Beacone may also disclose information when legally required, to protect the service or its users, or as part of a business transfer with appropriate safeguards. It does not sell or rent personal data.
Deletion and your rights
You can disconnect providers and delete your Beacone account from Account settings. Account deletion removes the account and account-linked data from the active database. A deleted record may remain in a disaster-recovery backup for up to 30 days before it expires.
Deleting your Beacone account does not itself uninstall the GitHub App from a GitHub account or organisation, or the Slack app from a workspace. Manage those installations with the relevant provider.
Waitlist subscriptions are stored separately from accounts. Deleting an account does not remove an email address that you separately submitted to the waitlist. Ask support to remove it.
Depending on where you live, you may have rights to access, correct, receive, restrict, object to the use of, or delete your personal data, and to complain to your local data protection authority. Email support@beacone.dev to make a request. Beacone may need to verify that the request concerns your account.
Security and changes
Beacone uses HTTPS, restricted database access, signed webhook verification, and encryption at rest for provider access and refresh tokens. No service can promise perfect security; please contact support if you believe your account or data is at risk.
This policy may change as Beacone develops. Material changes will be highlighted on the website or communicated through an appropriate account channel, and the effective date above will be updated.