Privacy

What is stored, for how long, and who else can see it. Including the parts that are not flattering.

Effective [TO SUPPLY: OWNER_EFFECTIVE_DATE]. Controller: [TO SUPPLY: OWNER_LEGAL_NAME], [TO SUPPLY: OWNER_POSTAL_ADDRESS]. Questions: [TO SUPPLY: OWNER_SUPPORT_EMAIL].

This website

The site you are reading sets no cookies, writes nothing to local or session storage, and loads nothing from any other origin - no hosted fonts, no CDN scripts, no embedded media, no chat widget, no analytics of any kind, cookieless or otherwise.

That is enforced rather than promised: the site sends a Content Security Policy naming no external origin, and a test in its own source fails if a directive ever gains one. The fonts are served from this domain.

Standard web server logs exist at the hosting layer, as they do for every site on the internet. We run no analytics on top of them.

If you join the Pro waitlist on this site

The pricing page has one form, and it is the only thing on this site that stores anything about you. If you use it we keep your email address, the date and time you consented, the exact wording you agreed to, the IP address the submission came from, and a random removal code that makes your unsubscribe link work. There is no name field, no company field and nothing else recorded.

The wording is stored rather than a yes/no tick, so that changing the form later cannot re-attribute new wording to somebody who agreed to the old one. This list is separate from any waitlist on anybody's Beacon: it is the product's own list, held in its own database, and it is not visible to any account holder.

It has no automatic retention limit yet. The app erases the consent IP on its own waitlist after 24 months; nothing schedules the equivalent here, so until that exists an entry is kept until you remove it or we remove it by hand. That is stated rather than glossed because it is the one place this site is behind the app.

Nothing has been sent to this list, and there is no mail integration on this site at all. You can remove yourself at any time using the link on the pricing page or in any email, and removal deletes the row outright.

What happens when someone reads a Beacon

Nothing is recorded. There is no view counter and no table that could hold one - a beacon_views table existed briefly during development and was dropped outright.

The one exception, stated because it is an exception: if a Beacon page fails to render in someone's browser, the app records a diagnostic - the error and its stack, the route, and the browser's user-agent string - and keeps it for 30 days so the crash can be fixed. It is written on a crash, not on a visit.

The app

If you have an account

  • Your identity, held by our sign-in provider - email address and name.
  • The work you enter, which is what produces your capacity figure.
  • Your settings, including your timezone and the words you have chosen to describe your own work.
  • Published capacity snapshots, an activity log of changes you made, and a log of email we attempted to send you.

Signing in sets a session cookie. It is strictly necessary - without it you cannot stay signed in - which is a different statement from "no cookies at all", and the difference is why this paragraph exists rather than a claim that we use none.

The app also sets a small cookie when you dismiss an advisory banner, so it stays dismissed, and keeps view preferences such as your sort order in your browser's local storage. Those never leave your device.

What your public Beacon exposes

You are inviting people to read this page, so it is worth being exact about what is on it: your name, your published percentage and status, your next opening, your profile image, how recently you updated it, and anything you typed yourself - bio, testimonials, booking banner, and your own wording on the waitlist form.

It does not carry your clients, your project names, your rates, your drafts, or anything you have not published. Nor does it carry your waitlist: an answer somebody gives to your extra waitlist question is yours alone and never appears on any public surface.

Your profile image is served from our sign-in provider's image host, so loading a Beacon does fetch one image from a third party.

If someone joins your waitlist

Their email address, optionally their name and their answer to your extra question, and a consent record: when they consented, through which form, and the IP address it came from.

This is single opt-in - consent is recorded when the form is submitted and there is no confirmation click to complete. They get one email telling them they are on the list, carrying a one-click removal link that asks nothing of them.

Nothing is sent to your waitlist automatically. There is no "a spot opened up" trigger, no scheduler and no capacity hook; they hear from you when you decide to tell them.

Email

  • No tracking pixels. Open tracking is off. A remote image that reports back when a message is opened is not something this product does to your clients.
  • Click tracking is currently on, and that is worth knowing. Our mail provider rewrites links so they pass through its redirector before reaching where they are going, which means it sees that a link was followed. Turning it off is a change we intend to make and have not yet made. It is on this page because omitting it would make the section above misleading.
  • Transactional email - a confirmation, a security notice - is a different class from marketing email and is not something you unsubscribe from without closing your account.
  • Marketing email always carries one-click unsubscribe and a postal address. If the postal address is not configured, the app refuses to send rather than sending without one.

How long things are kept

WhatKept for
Published capacity snapshots90 days, except ones you saved deliberately
Activity log of changes1 year
Waitlist entries that unsubscribed30 days
Waitlist entries that never consented30 days
Crash diagnostics30 days
Email delivery log90 days
Soft bounce records90 days
The IP recorded alongside a waitlist consent24 months, then erased - the consent record itself is kept
Suppression list (hard bounces, spam complaints)Kept indefinitely, deliberately - it is the record of someone asking not to be contacted

Deleting your account

Deletion is done through the sign-in provider's own control, which is the single path - there is deliberately not a second delete button elsewhere. Removing your identity triggers erasure of your data across the app.

It is not instantaneous, and the old version of this page was wrong to say it was. Erasure normally completes within seconds. If the notification is lost in transit, a nightly reconciliation catches it, so the worst case is about 24 hours. Until it completes, your public Beacon is still live.

One record survives, deliberately: the log row for the deletion confirmation email itself, because it is written after your account is already gone. The address on it is masked to its first character - the domain remains.

Who else processes your data

Derived from what the app actually connects to, not from a template.

WhoWhat for
CloudflareHosting, the application server, and the database
ClerkSign-in, your identity, and profile image hosting
ResendSending email

There is no payment processor, because there is nothing to pay for yet. When there is, it becomes a fourth row here before it becomes a checkout.

Where each of them stores data: [TO SUPPLY: OWNER_DATA_REGION].

What we commit to

[TO SUPPLY: OWNER_DATA_COMMITMENT]

Attribution, and what it is not

Links from this site to the app carry a source parameter saying which page you came from. That is the entire mechanism: a word in a URL you were following anyway. There is no cookie, no identifier, no script, and nothing recorded on this side.

Stated precisely: the app does not currently read that parameter, so today it does nothing at all.

Your rights

You can ask for a copy of your data, ask for it to be corrected, or delete your account as described above. Write to [TO SUPPLY: OWNER_SUPPORT_EMAIL].

See also cookies and terms.