Back to Beaconry

Privacy Policy

Beaconry Privacy Policy

Effective date: 11 July 2026

Last updated: 11 July 2026

1. Who we are

Beaconry is operated by Petterik Oy, Lekkerikallio 5, 02400 Kirkkonummi, Finland.

For privacy questions or requests, contact Petteri Kolehmainen at [email protected].

In this policy, "Beaconry", "we", "us", and "our" refer to the operator of the Beaconry mobile app, backend service, website, and related services.

2. What Beaconry does

Beaconry is a mobile-first website monitoring service. Users add websites they want to protect, and Beaconry checks those websites from one or more regions depending on the plan. When checks indicate downtime, degraded availability, SSL certificate issues, domain expiry issues when available, or similar service problems, Beaconry may create an incident and send mobile push notifications.

3. Data we collect

We collect the data needed to operate Beaconry.

Account data

  • Email address.
  • Internal user, team, and account IDs.
  • Authentication timestamps and login events.
  • Short-lived magic-link authentication tokens.
  • Apple sign-in subject identifier when you use Sign in with Apple.
  • Google sign-in subject identifier when you use Google Sign-In.
  • Hashed IP address and user-agent metadata for session security and abuse prevention.

Protected-site data

When you add a protected site, we store information such as:

  • Website URL or domain.
  • Display name or label you give the site.
  • Monitoring settings, expected status range, optional expected keyword, and enabled regions.
  • Check results, including timestamps, status codes, response times, error categories, SSL certificate expiry metadata, domain expiry metadata when available, and incident history.
  • Limited technical metadata needed to diagnose downtime.

Beaconry does not store full page contents by default. When an expected keyword check is configured, the checker reads only a bounded response prefix to decide whether the keyword matched and stores the result of that check, not the full page body.

Notification data

If you enable push notifications, we store the device push token or installation identifier needed to send alerts to your device. Beaconry also stores notification delivery status, delivery attempts, token hashes, and delivery errors so it can retry delivery and remove invalid tokens.

Subscription data

If you subscribe through Apple App Store, we may store subscription entitlement data such as:

  • Platform.
  • Product ID.
  • Original transaction ID when provided by the app.
  • Subscription status.
  • Subscription expiry date when available.

We do not receive or store your full payment card details.

Technical and security data

We may process technical data needed to keep the service secure and working, such as:

  • Hashed IP address where the app records it for security-sensitive authentication events.
  • Request timestamps.
  • App version.
  • Device operating system version where provided by the app or system logs.
  • Server logs.
  • Error logs.
  • Security and abuse-prevention logs.

We do not use this data for advertising or cross-site tracking.

Support data

If you contact us, we process the information you include in your message so we can respond and handle your request.

Enterprise pricing requests include your work email, organisation, requested site and member capacity, optional message, and a hashed IP address used to limit automated abuse.

4. Data we do not collect

Beaconry does not collect or access:

  • Contacts.
  • Photos or videos.
  • Camera or microphone data.
  • Precise location.
  • Health or fitness data.
  • SMS or private messages.
  • Advertising identifiers for ad tracking.

Beaconry does not include advertising trackers, third-party analytics trackers, or behavioural advertising SDKs in the first release.

5. How we use data

We use personal data to:

  • Create and manage your account.
  • Authenticate you with magic-link login and Sign in with Apple.
  • Monitor the websites you add.
  • Store check results and incident history.
  • Send downtime, recovery, SSL, domain expiry, and account-related alerts.
  • Manage subscriptions and access to paid features.
  • Provide support.
  • Protect the service against abuse, fraud, and security threats.
  • Comply with legal obligations.

Where GDPR applies, we rely on the following legal bases:

  • Contract: to provide the Beaconry service, authentication, monitoring, alerts, and subscription access.
  • Legitimate interests: to secure the service, prevent abuse, diagnose technical problems, and improve reliability without using advertising trackers.
  • Consent: where required, such as enabling push notifications on your device or receiving optional marketing emails if those are introduced later.
  • Legal obligation: where we must keep records or respond to lawful requests.

7. Protected websites and monitoring checks

When you add a website to Beaconry, our checker servers request that website to verify whether it is reachable. The website you monitor may see requests from Beaconry checker IP addresses and a Beaconry user agent.

You should only monitor websites, APIs, or services that you own, operate, or have permission to monitor.

If you monitor a client website, you are responsible for making sure you are allowed to do so and for explaining the monitoring to your client where needed.

8. Processors and service providers

We use service providers where needed to run Beaconry.

The Beaconry code and deployment configuration use these providers:

  • Hetzner Online GmbH, for primary backend, scheduler, same-host Postgres, and EU checker hosting.
  • DigitalOcean, LLC, for regional checker nodes in the United States and Singapore.
  • Cloudflare, Inc., for DNS, proxying, and related network/security services.
  • Amazon Web Services, Inc., for Amazon SES transactional email delivery.
  • Apple Inc., for app distribution, Sign in with Apple, Apple Push Notification service, and App Store purchase flows.

Only providers used for Beaconry operations are used for production data. If a provider processes personal data on our behalf, we use appropriate contractual safeguards where required.

9. International transfers

Beaconry's primary production infrastructure is intended to run in the EU/EEA. The primary app server, database, scheduler, and EU checker are configured for the Helsinki region.

Beaconry also uses regional checker nodes outside the EU/EEA, including the United States and Singapore. Protected-site URLs and check-result metadata may be processed in those regions to perform monitoring.

Where personal data is transferred outside the EU/EEA, we use appropriate safeguards such as data processing agreements and Standard Contractual Clauses where required.

10. Data retention

We keep data only as long as needed for the purposes described in this policy.

  • Account data: until you delete your account, plus a short period needed for deletion processing.
  • Protected-site configuration: until you delete the protected site or your account.
  • Check results and incident history: while your account or protected site remains active, subject to plan history limits where those limits are implemented.
  • Magic-link tokens: short-lived and expired after login or after 15 minutes.
  • Sessions: normally up to 60 days unless the server is configured with a shorter or longer session period.
  • Server and security logs: kept for the period configured on production systems, usually around 30 days unless longer retention is needed for security investigation or legal compliance.
  • Backups: deleted data may remain in encrypted backups until those backups rotate out, usually within 30-90 days.

11. Security

We use technical and organisational measures designed to protect personal data, including:

  • Encryption in transit using HTTPS/TLS.
  • Access controls.
  • Short-lived login links.
  • Signed checker communication where applicable.
  • Logging limits and data minimisation.
  • Operational monitoring and backups.

No online service can be guaranteed to be perfectly secure, but we aim to keep the data we collect limited and protected.

12. Your rights

Depending on where you live, you may have rights to:

  • Access your personal data.
  • Correct inaccurate data.
  • Delete your data.
  • Restrict or object to processing.
  • Receive a copy of your data in a portable format.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

To make a request, contact [email protected].

If you are in Finland, you may contact the Office of the Data Protection Ombudsman. Users in other EU/EEA countries may contact their local supervisory authority.

13. Account deletion

You can request deletion of your account by contacting [email protected].

Deleting your account deletes or disables your account, protected sites, monitoring configuration, and associated incident data, except where retention is required for security, fraud prevention, legal compliance, or backup rotation.

14. Children

Beaconry is not intended for children and is not directed at users under 16. We do not knowingly collect personal data from children.

15. Changes to this policy

We may update this policy when Beaconry changes. If we make material changes, we will update the "Last updated" date and, where appropriate, notify users in the app or by email.

16. Contact

Petterik Oy

Lekkerikallio 5, 02400 Kirkkonummi, Finland

Contact: Petteri Kolehmainen, [email protected]

Support: [email protected]