Privacy
What is stored, for how long, and who else can see it. Including the parts that are not flattering.
Effective [TO SUPPLY: OWNER_EFFECTIVE_DATE]. Controller: [TO SUPPLY: OWNER_LEGAL_NAME], [TO SUPPLY: OWNER_POSTAL_ADDRESS]. Questions: [TO SUPPLY: OWNER_SUPPORT_EMAIL].
This website
The site you are reading sets no cookies, writes nothing to local or session storage, and loads nothing from any other origin - no hosted fonts, no CDN scripts, no embedded media, no chat widget, no analytics of any kind, cookieless or otherwise.
That is enforced rather than promised: the site sends a Content Security Policy naming no external origin, and a test in its own source fails if a directive ever gains one. The fonts are served from this domain.
Standard web server logs exist at the hosting layer, as they do for every site on the internet. We run no analytics on top of them.
If you join the Pro waitlist on this site
The pricing page has one form, and it is the only thing on this site that stores anything about you. If you use it we keep your email address, the date and time you consented, the exact wording you agreed to, the IP address the submission came from, and a random removal code that makes your unsubscribe link work. There is no name field, no company field and nothing else recorded.
The wording is stored rather than a yes/no tick, so that changing the form later cannot re-attribute new wording to somebody who agreed to the old one. This list is separate from any waitlist on anybody's Beacon: it is the product's own list, held in its own database, and it is not visible to any account holder.
It has no automatic retention limit yet. The app erases the consent IP on its own waitlist after 24 months; nothing schedules the equivalent here, so until that exists an entry is kept until you remove it or we remove it by hand. That is stated rather than glossed because it is the one place this site is behind the app.
Nothing has been sent to this list, and there is no mail integration on this site at all. You can remove yourself at any time using the link on the pricing page or in any email, and removal deletes the row outright.
What happens when someone reads a Beacon
Nothing is recorded. There is no view counter and no table that could hold one - a beacon_views table existed briefly during development and was dropped outright.
The one exception, stated because it is an exception: if a Beacon page fails to render in someone's browser, the app records a diagnostic - the error and its stack, the route, and the browser's user-agent string - and keeps it for 30 days so the crash can be fixed. It is written on a crash, not on a visit.
The app
If you have an account
- Your identity, held by our sign-in provider - email address and name.
- The work you enter, which is what produces your capacity figure.
- Your settings, including your timezone and the words you have chosen to describe your own work.
- Published capacity snapshots, an activity log of changes you made, and a log of email we attempted to send you.
Signing in sets a session cookie. It is strictly necessary - without it you cannot stay signed in - which is a different statement from "no cookies at all", and the difference is why this paragraph exists rather than a claim that we use none.
The app also sets a small cookie when you dismiss an advisory banner, so it stays dismissed, and keeps view preferences such as your sort order in your browser's local storage. Those never leave your device.
What your public Beacon exposes
You are inviting people to read this page, so it is worth being exact about what is on it: your name, your published percentage and status, your next opening, your profile image, how recently you updated it, and anything you typed yourself - bio, testimonials, booking banner, and your own wording on the waitlist form.
It does not carry your clients, your project names, your rates, your drafts, or anything you have not published. Nor does it carry your waitlist: an answer somebody gives to your extra waitlist question is yours alone and never appears on any public surface.
Your profile image is served from our sign-in provider's image host, so loading a Beacon does fetch one image from a third party.
If someone joins your waitlist
Their email address, optionally their name and their answer to your extra question, and a consent record: when they consented, through which form, and the IP address it came from.
This is single opt-in - consent is recorded when the form is submitted and there is no confirmation click to complete. They get one email telling them they are on the list, carrying a one-click removal link that asks nothing of them.
Nothing is sent to your waitlist automatically. There is no "a spot opened up" trigger, no scheduler and no capacity hook; they hear from you when you decide to tell them.
- No tracking pixels. Open tracking is off. A remote image that reports back when a message is opened is not something this product does to your clients.
- Click tracking is currently on, and that is worth knowing. Our mail provider rewrites links so they pass through its redirector before reaching where they are going, which means it sees that a link was followed. Turning it off is a change we intend to make and have not yet made. It is on this page because omitting it would make the section above misleading.
- Transactional email - a confirmation, a security notice - is a different class from marketing email and is not something you unsubscribe from without closing your account.
- Marketing email always carries one-click unsubscribe and a postal address. If the postal address is not configured, the app refuses to send rather than sending without one.
How long things are kept
| What | Kept for |
|---|---|
| Published capacity snapshots | 90 days, except ones you saved deliberately |
| Activity log of changes | 1 year |
| Waitlist entries that unsubscribed | 30 days |
| Waitlist entries that never consented | 30 days |
| Crash diagnostics | 30 days |
| Email delivery log | 90 days |
| Soft bounce records | 90 days |
| The IP recorded alongside a waitlist consent | 24 months, then erased - the consent record itself is kept |
| Suppression list (hard bounces, spam complaints) | Kept indefinitely, deliberately - it is the record of someone asking not to be contacted |
Deleting your account
Deletion is done through the sign-in provider's own control, which is the single path - there is deliberately not a second delete button elsewhere. Removing your identity triggers erasure of your data across the app.
It is not instantaneous, and the old version of this page was wrong to say it was. Erasure normally completes within seconds. If the notification is lost in transit, a nightly reconciliation catches it, so the worst case is about 24 hours. Until it completes, your public Beacon is still live.
One record survives, deliberately: the log row for the deletion confirmation email itself, because it is written after your account is already gone. The address on it is masked to its first character - the domain remains.
Who else processes your data
Derived from what the app actually connects to, not from a template.
| Who | What for |
|---|---|
| Cloudflare | Hosting, the application server, and the database |
| Clerk | Sign-in, your identity, and profile image hosting |
| Resend | Sending email |
There is no payment processor, because there is nothing to pay for yet. When there is, it becomes a fourth row here before it becomes a checkout.
Where each of them stores data: [TO SUPPLY: OWNER_DATA_REGION].
What we commit to
[TO SUPPLY: OWNER_DATA_COMMITMENT]
Attribution, and what it is not
Links from this site to the app carry a source parameter saying which page you came from. That is the entire mechanism: a word in a URL you were following anyway. There is no cookie, no identifier, no script, and nothing recorded on this side.
Stated precisely: the app does not currently read that parameter, so today it does nothing at all.
Your rights
You can ask for a copy of your data, ask for it to be corrected, or delete your account as described above. Write to [TO SUPPLY: OWNER_SUPPORT_EMAIL].