Privacy Policy
The short version
There is no Beacon server. Beacon runs on your computer, talks to Google directly from there, and keeps its cache on your disk. Your mail, calendar entries, tasks and notes are never sent to us, because there is nowhere to send them. We collect no analytics, no crash reports and no usage metrics. If you have never emailed us, we hold nothing about you at all.
Who we are
Beacon is made and sold by Brad Wyse, a sole proprietor in Canada (“we”, “us”). We are the data controller for the limited personal information described below. Contact: hello@mybeaconapp.io.
What Beacon accesses, and why
When you connect a Google account, Beacon asks Google for permission to use these services. Nothing is accessed until you grant it, and you can withdraw permission at any time.
| Access | What Beacon does with it |
|---|---|
| Gmail (read and modify) | Shows your mail, sends it, and applies the changes you make — read, star, label, archive, trash. Beacon deliberately does not request permanent-deletion access, so it cannot destroy a message beyond recovery. |
| Google Calendar | Shows your calendars, and creates or edits the events you create or edit. |
| Contacts (read only) | Completes addresses as you type a recipient. |
| Google Drive — app folder only | Stores the encrypted sync bundle that carries your tasks, notes and settings between your own devices. This permission cannot see any other file in your Drive. |
| Basic profile and email address | Labels the account in the interface, so you can tell two mailboxes apart. |
Limited Use
Beacon’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means your Google data is used only to provide the features you can see in the app, on your own device. It is never sold, never used for advertising, never used to train any model, and never read by a human.
Where your information lives
- On your computer. A local database holds a cache of mail metadata, calendars, tasks and notes so the app starts instantly and keeps working offline. It stays on your disk.
- In your operating system’s keystore. Google access tokens are encrypted by Windows itself. They are never written to the cache and never logged.
- In your own Google Drive, if you turn on sync. Sync is bring-your-own-storage: an end-to-end encrypted bundle in your Drive’s private app folder, readable only by devices you have joined with your passphrase. We cannot read it; we do not have the key and never receive one.
What leaves your computer
Three things, and nothing else:
- Requests to Google, made directly from your machine, to do what you asked — fetch mail, send a message, save an event.
- An update check to GitHub, where Beacon’s releases are published. Beacon asks whether a newer version exists and downloads it if so. Like any web request this reveals your IP address and the version you are running to GitHub, whose privacy policy then applies. No account information and no content is sent.
- Email you choose to send us, if you write for support.
Your licence key is checked entirely on your own device using a signature. Beacon does not contact us to validate it, so we cannot tell whether, when or how often you use the app.
What we receive
If you email us, we receive your address and whatever you write, and we keep it while we deal with your question. If you buy a licence, our payment provider — who is the merchant of record, and the seller for tax purposes — handles the payment and passes us your email address and the fact that you purchased. We never see your card details.
That is the complete list. No analytics service, no crash reporter, no product metrics and no advertising or tracking of any kind is present in Beacon.
Removing your data
- Disconnect an account in Beacon and its cached data is deleted from the device.
- Revoke Beacon’s access to your Google account at any time at myaccount.google.com/permissions. This works whether or not Beacon is installed.
- Delete the sync bundle from your Drive — it is in the hidden app-data folder, and removing Beacon’s access removes it too.
- Uninstall Beacon to remove the app; you choose whether to keep the local data folder.
- Ask us at hello@mybeaconapp.io to delete the support emails and purchase record we hold.
Your rights
Under Canadian privacy law (PIPEDA), and under the GDPR if you are in the UK or EU, you may ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Because we hold so little — support emails and a purchase record — these requests are usually answered in full within a few days. Write to hello@mybeaconapp.io. If you are in the EU or UK and are unhappy with our answer you may complain to your national data protection authority; in Canada, to the Office of the Privacy Commissioner.
Others who process information
- Google — your mail, calendar and Drive provider. Beacon talks to them on your behalf.
- GitHub — hosts the application updates Beacon downloads.
- Our payment provider — processes purchases and handles tax. Their privacy policy covers the payment itself.
We use no other processor, and we share information with nobody else.
Security
Tokens are encrypted at rest by the operating system. The sync bundle is encrypted on your device before it is uploaded, with a key derived from a passphrase we never see. Message bodies are rendered in a locked-down frame with remote images blocked by default, so tracking pixels do not fire unless you ask for the pictures.
If you find a security problem, please write to hello@mybeaconapp.io with the subject line “Security”. We aim to acknowledge within three working days.
Children
Beacon is not directed at children and we do not knowingly collect information from anyone under 16.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how your information is handled, say so in the app’s release notes.