# Privacy at beacon.host

This page explains what beacon.host stores, why, and who else handles it. Questions: support@beacon.host.

## What we store

- **Your email address**, if you sign in. We use it to send sign-in codes and, rarely, important service messages. Sign-in codes are stored hashed and expire after 10 minutes.
- **API keys**, stored only as SHA-256 hashes. We can't show you a key again after it's issued.
- **What you publish.** Files you upload are stored in Cloudflare R2 and served publicly at your site's address. Worker code is deployed to Cloudflare; we also keep a copy of each deploy so you can roll back. Worker secret values are stored only in Cloudflare; we keep their names, not their values.
- **Site details**: the address (slug), title, description, password settings (the password is stored hashed), version history and timestamps.
- **Request logs**: IP address, user agent, URL, referrer, response status, and the client name an agent sends in the `X-Beacon-Client` header. We use these to prevent abuse, enforce rate limits, debug problems, and count usage. We don't log API keys, claim tokens or sign-in codes.

## What we don't do

- No advertising, no ad trackers, and no third-party analytics scripts on beacon.host pages.
- We don't sell or rent your data.
- We don't look through what you publish, except to investigate abuse reports or keep the service running.

## How long we keep it

- **Anonymous sites** are deleted 24 hours after they're created unless someone claims them.
- **Sites and workers in an account** stay until you delete them or your account is closed.
- Deleted files are removed from storage by a regular cleanup job. Database backups can hold copies for a short time after that.
- Request logs are kept while we need them for security and usage statistics.

## Who else handles your data

- **Cloudflare**: file storage (R2), Workers hosting and DNS
- **DigitalOcean**: the servers that run the beacon.host API
- **Resend**: delivers sign-in emails
- **Datadog**: server monitoring

## Your choices

- Delete any site or worker yourself from the dashboard or the API at any time.
- To delete your account and everything in it, or to get a copy of your data, email support@beacon.host from the address you sign in with.

## Changes

If this policy changes in a way that matters, we'll update this page and change the date below.

Last updated 1 October 2026.
