Privacy Policy
Last updated August 22, 2026
What we collect. IP address (temporary, for rate limiting — never persisted to the database), the code you paste or upload (for the life of the published site), and basic metadata about each deploy (detected type, size, timestamps). An account is optional for basic use — creating one, subscribing, using the public API, or enabling lead capture additionally involves account credentials or OAuth identity, billing state, basic per-site visit analytics, API keys, custom domain names, and (only if you opt in as a site owner) visitor-submitted leads.
What we don't do. We don’t use third-party advertising trackers or sell data. An anonymous device identifier and basic per-site visit analytics (referrer, country) exist for abuse-prevention and product-usage purposes only, not advertising or cross-site tracking.
Payments. Payment details (card number, etc.) go directly to Stripe via Checkout or the Billing Portal and never touch Beamship’s own servers or database. Beamship’s database only stores the amount, the tier, and Stripe’s own reference IDs.
Subprocessors. Cloudflare (hosting, storage, DNS, analytics), E2B (isolated code execution for the React/Vite build path), Neon (database), Stripe (payment processing), Resend (transactional email — password reset), and Google or GitHub (only if you choose their OAuth login).
Content you publish is public. Anything you paste and deploy is served publicly at its subdomain or connected custom-domain URL to anyone who has or guesses the link, for as long as the site remains published. Don’t paste secrets, credentials, or private data into Beamship.
Lead capture. If you’re a site owner and enable lead capture on your own site, Beamship stores the email addresses your own visitors submit, visible only to you. Beamship processes this data on your behalf as the site owner — you’re responsible for how you use it and for your own visitors’ privacy expectations, consistent with applicable law in your and your visitors’ jurisdictions.
Data retention. Site content and metadata are deleted automatically when a site expires (see our Terms of Use). Deleted or expired site files stop being publicly served immediately, and are quarantined for 14 days (recoverable in that window) before being permanently purged from internal storage. Rate-limiting IP records expire within about an hour by design. Account data is retained for as long as the account exists — there is currently no self-serve account-deletion flow; contact us below to request deletion.
Contact. support@beamship.app