Privacy Policy
Your privacy is our priority. Learn how Beacon Blocker protects your data.
Last Updated: July 30, 2026
Our Commitment to Privacy
Beacon Blocker is designed to make the web useful without building a complete server-side browsing history. Page details used for a decision are not persisted, activity collection is opt-in, and every stored data class has a defined purpose and deletion path.
Information We Collect
Beacon Blocker collects minimal information necessary to provide our service:
Account and Settings Data: Supabase Authentication processes your email address and authentication credentials. We store your encrypted personal context and prompts, blocking preferences (categories and allow/block lists), weekly-report email choice, and the account identifiers needed to keep settings in sync.
Rule Compilation: When you confirm onboarding or save a rule change that requires a new ruleset, Beacon sends Google Gemini the confirmed context needed to generate candidate rules. This can include your goals and motivation, role or education context you provided, selected use cases and surface choices, schedule and time zone, enabled blocking categories, and any custom rule prompt. Beacon validates and post-processes the result before storing the compiled artifact. This compilation request is separate from optional per-page AI. Beacon does not write the compilation request content or Gemini response to its application database, logs, or analytics. It keeps a per-account count of compilation provider calls for up to seven days solely to enforce the daily allowance, plus non-user-linked daily reliability, token-use, and estimated-cost totals.
Optional Per-Page AI: This feature is off unless you explicitly enable it. When local rules cannot decide, Beacon may send Google Gemini the page URL; title, brief description, and meta keywords; recent search context; your Beacon blocking policy and confirmed context; and current clock and timer state. This request is encrypted in transit. Visible page-body excerpts stay inside the extension and are used only for local deterministic rule matching; they are not included in backend or model requests. These page details are not written to our application database, logs, or analytics tables. Protected financial and payment destinations can still follow explicit local rules, but are never sent for remote AI analysis.
Optional Activity Collection: Activity collection is off unless you explicitly enable it. If enabled, we temporarily store the domain, decision, reason category, and event time so we can build your personal weekly summary. A daily retention job deletes raw activity once it is more than 7 days old. We do not store the full URL, page title, page content, or a server-side browsing history. Turning activity collection off deletes this raw activity and your stored weekly summaries immediately.
Accountability and Feedback: If you use the accountability feature, the Contact name and email are stored encrypted. We also store the unlock requests needed to operate that feature. Bug and feature reports are stored only when you submit them, are deleted after 180 days, and can be submitted while signed out. Beacon does not accept screenshot uploads in this feedback flow.
Payments and Promotions: Stripe handles card and bank information. Beacon does not receive or store your full payment details. We store the Stripe customer and subscription identifiers, subscription status, referral state, and promo redemption state needed to provide and audit account access.
AI Allowances: We store two independent account-linked counts per UTC day for up to 7 days: one for rule-compilation provider calls and one for opted-in per-page AI provider calls. Keeping them separate means browsing decisions cannot consume the user's rule-compilation allowance, or vice versa. Neither counter contains page, URL, title, or search information.
Operational Metrics: We keep daily aggregate counts for request volume, errors, latency, cache use, AI token use, and estimated cost. These rows contain no user ID, email, IP address, URL, domain, or page title. Beacon does not use third-party advertising or behavioral analytics.
Stored Locally: Your detailed block history, local decision cache, and device display preferences remain in your browser and can be cleared there. Local browsing-time and YouTube watch-time analytics are a separate feature and are off by default. If you enable them, the extension stores active time by site, watch time, and a resume marker only on your device; those analytics expire within 90 days. Turning local analytics off immediately stops new analytics records. Existing local analytics remain until they expire or you use the separate erase control. They are not sent to Beacon's server or an AI model.
We Do Not Collect: We do not collect form entries or passwords you type on other websites, and we do not sell personal information or use it for advertising.
How We Process Data
Rule Compilation: After you confirm setup or request a qualifying rule update, the backend builds a bounded prompt from the confirmed context described above and sends it to Google Gemini. Beacon validates and post-processes the candidate rules before encrypting and storing the compiled artifact. Compilation prompts and responses are not stored in application logs or analytics.
Optional Per-Page AI Decisions: Beacon first uses local rules and user-initiated context, including active searches and embedded content, to make requested content accessible without opening unnecessary recommendation surfaces. Visible page-body excerpts are available only to this local rule evaluation. If you explicitly enable optional AI analysis, the backend processes the bounded payload described above without page-body text, returns the result, and does not persist the page or search details. This process is separate from rule compilation.
Personal Context and Rules: Your onboarding context, prompts, and blocking rules are stored to keep your experience consistent across devices. Sensitive context and prompt fields are encrypted at rest, and application tables are accessed through the authenticated backend rather than directly by the browser.
Activity and Weekly Summaries: If you explicitly opt in to activity collection, Beacon uses short-lived domain-level events to calculate your own weekly summary. Collection consent is separate from permission to send a weekly email. We check email consent again immediately before sending.
Operational Reliability: Capacity and cost measurements are added directly to day-and-endpoint totals. We do not create pseudonymous per-user analytics records or store one-way hashes of users, emails, or IP addresses for product analytics.
Accountability Contacts: Contact details are encrypted before storage. A Contact receives only the messages required to review an unlock request.
Email Communications: Transactional messages are sent only when needed to operate requested account, security, billing, or accountability features. Weekly focus reports are the optional recurring email and are sent only while the weekly-report preference is enabled. You can turn them off in the dashboard or use the unsubscribe link in any weekly report.
Service Providers: Beacon uses Supabase for authentication and database hosting, Google Gemini for AI analysis, Stripe for payments, Render for backend hosting, and Resend for email delivery. Each provider receives only the information needed for its role and handles that information under its own terms and privacy commitments.
Data Security
We implement industry-standard security measures:
Encryption in Transit: Connections between the extension, dashboard, backend, and service providers use HTTPS/TLS.
Encryption at Rest: Personal context, prompts, Contact details, compiled rules, and vault ciphertext are encrypted before database storage. Vault entries receive an additional server-secret encryption layer.
Access Control: Supabase Row Level Security is enabled, browser roles have no direct access to private application tables, and privileged database functions are restricted to the backend service role.
Payment Security: Stripe processes payments. Beacon never receives or stores full card or bank account details.
Minimization and Retention: Page data is not persisted, the daily retention job deletes optional raw activity older than 7 days, and database retention runs as a transactional, access-restricted job.
No online service can promise absolute security. We limit collection, encrypt sensitive stored fields, restrict privileged access, and test recovery and deletion paths to reduce risk.
Your Rights
You can control and remove your Beacon data:
Access and Correction: View and update your personal context, rules, and communication choices in the dashboard.
Activity Choice: Activity collection is off by default. You can enable it independently of email delivery, and turning it off erases the associated server-side activity and weekly summaries immediately.
Per-Page AI Choice: Remote AI analysis of ambiguous pages is off by default. You can enable or disable it from the dashboard after reviewing the payload disclosure.
Deletion: Delete your account from Settings to remove your account-linked application data from the active Beacon database. Beacon first cancels any active Stripe subscription so deletion cannot leave you paying for an account you can no longer access. Stripe and infrastructure-provider records may remain for the periods required by their legal, security, and backup obligations.
Local Data: Clear your local block history and cache in the extension. Local analytics have separate enable, disable, and two-step erase controls: disabling stops new records, while erasing removes existing browsing-time, watch-time, event, and resume records. Removing the extension deletes its local storage.
Email Preferences: Unsubscribe from weekly focus reports using the email link or turn weekly reports off in the dashboard. Necessary transactional messages are not marketing subscriptions.
Privacy Requests: Contact support@beaconblocker.com to request access, correction, or deletion help.
Data Retention
Page Analysis: Visible page-body excerpts are not transmitted to Beacon's backend or model. Full URLs, page titles, search text, and page descriptions used for a remote decision are not persisted in Beacon's application database, logs, or analytics.
Expiring Context: Short-lived context facts carry an explicit expiry time. The retention job deletes them after that time and invalidates any older compiled artifact that could have incorporated them.
Optional Raw Activity: A daily retention job deletes domain-level blocking activity and engagement events once they are more than 7 days old. Turning collection off deletes them immediately.
Weekly Summaries: The retention job deletes personal weekly summaries once they are more than 13 weeks old. Turning activity collection off deletes them immediately.
AI Allowance Counters: The separate per-account daily rule-compilation and optional per-page AI request counts contain no page, URL, title, or search information and are deleted once they are more than 7 days old.
Operational Metrics: Daily aggregate reliability, traffic, and AI-cost totals contain no user identifiers. The retention job deletes them once they are more than 90 days old.
Product Feedback: Submitted bug reports and feature ideas are deleted once they are more than 180 days old.
Billing Operations: Active subscription, referral, and promotion state is retained while required to provide account access. The retention job deletes completed or failed Stripe webhook and adjustment records once they are more than 365 days old. These records support safe retries, incident diagnosis, and a bounded audit trail. Pending and processing records are not removed by the retention job.
Local Data: Detailed block history and cached decisions remain on your device until you clear them or remove the extension. Opted-in local browsing-time, YouTube watch-time, event, and resume analytics expire within 90 days and can be erased sooner. Disabling local analytics stops new records but does not silently erase existing history.
Account Deletion: Account deletion removes account-linked application data from Beacon's active database. Non-user-linked daily operational totals cannot be associated with an account and expire under the 90-day limit above.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: support@beaconblocker.com
Response Time: We aim to respond to all privacy-related inquiries within 48 hours.
Updates to This Policy:
We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last Updated" date.
Chrome Web Store Compliance
This extension complies with the Chrome Web Store Developer Program Policies, including the User Data Privacy policy. We certify that user data is handled in accordance with Google's guidelines and is not sold to third parties, used for purposes unrelated to the extension's core functionality, or transferred for creditworthiness or lending purposes.