Privacy policy
Effective 2026-10-10. Beckon (beckoncli.com) is run by Jay Stewart, the controller of the personal data described here.
What we store
- Account: your email address, and the GitHub account link if you sign in with GitHub.
- Your machines and devices: host labels, device names, public keys, when each was last seen, and each device's push subscription (which lets us send it notifications).
- Session metadata we can read: the program's name, its state (idle, working, blocked, done, error), the kind of prompt, progress, the record path, timestamps and exit code.
- Content we cannot read: message text, titles, commands and working directories are stored only as ciphertext sealed to your paired devices.
- Your settings: notification preferences (time zone, quiet hours, per-state and per-app switches).
- Operational records: a log of notification decisions (without message text) and an audit log of response attempts (which device, which prompt, and the outcome).
- Billing: your plan, and the customer and subscription identifiers Stripe gives us. Card details go to Stripe and never reach us.
- Server logs: our web server records each request's IP address, time, path (without query strings), status and browser user agent. Rate limits store a one-way hash of your IP address (or its /64 network for IPv6) for the length of the limit window.
Why
We use this data only to provide the service you signed up for (to perform our contract with you): signing you in, relaying status and notifications to your devices, billing, and support. Server logs and rate limits protect the service from abuse, which is our legitimate interest. We do not sell your data, use it for advertising, or run analytics or third-party trackers on this site.
How long
- State-change history: 24 hours on the Free plan, 30 days on Pro.
- Short-lived rows (expired login codes, pairing requests, notification decision logs): removed within about a week.
- Server logs: overwritten as they rotate, usually within days.
- Backups: encrypted database backups are kept for up to 90 days, then deleted automatically.
- Everything else until you delete it or delete your account.
Deleting your data
Settings → Delete account cancels any subscription and deletes all of the data above from the live service, immediately. Copies in backups expire within 90 days and are only used to recover from a failure. Stripe keeps the billing records it is required by law to keep.
Where it is, and who else handles it
- Hetzner hosts the service and its database in Helsinki, Finland (EU).
- Cloudflare provides DNS, forwards mail sent to our addresses, and stores our encrypted backups (in North America).
- Stripe processes payments.
- Resend delivers sign-in emails.
- GitHub, if you choose to sign in with it.
- Browser push services (Google, Apple, Mozilla, Microsoft) relay notifications. They see that a push happened, when, and its size, not its content.
Some of these companies are in the United States. Where data leaves the UK or the EU, they protect it under the EU-US Data Privacy Framework and its UK extension, or under standard contractual clauses with the UK addendum.
Your rights
You can see, correct, export or delete your data, object to how we use it, or ask us to restrict it. Most of this is in Settings; for anything else write to privacy@beckoncli.com and we will answer within a month. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or, in the EU, to your national data protection authority.
Cookies
One session cookie to keep you signed in. No tracking cookies.
Children
Beckon is not for anyone under 16, and we do not knowingly collect their data.
Changes
If we change this policy in a way that matters, we will email account holders before it takes effect.
Contact
privacy@beckoncli.com