Legal · Privacy
Privacy Policy
Effective 2026-05-20.
Summary
We collect the minimum data needed to run the Beacons hosted control plane. We do not sell user data, ever. End-user mesh traffic is end-to-end encrypted and never decrypted by our services.
What we collect
- Account info — email, name, organization, IdP claims (only where you sign in via federation)
- Fleet metadata — fleet IDs, peer DIDs, governance manifests, audit chain heads
- Operational telemetry — coordinator request rate, region distribution, error rates
- Billing data — peer counts, bandwidth, SIM usage; never traffic content
What we do not collect
- Mesh traffic payloads — encrypted end-to-end, opaque to us
- Private keys — never leave the peer host
- Cellular content — only metering data; the cellular operator carries the bits
Retention
Account data: kept while the account is active and 90 days after closure. Audit chain anchors: permanent (anchored on Sigil). Operational telemetry: 13 months rolling.
Your rights
GDPR access, rectification, erasure, and portability requests: privacy@beacons.sh. We respond within 30 days.
Contact
For any privacy question, privacy@beacons.sh.