Privacy Policy
Draft — last updated 2 August 2026
Working draft
This page is an accurate, engineer-written description of what Beacon Governance actually collects and which outside services it uses. It has not been drafted or reviewed by a lawyer, and it is not the finished policy. If you need a signed data processing agreement or a formal privacy commitment before using Beacon, contact us and we will handle it directly rather than pointing you here.
Who this covers
Beacon Governance is operated by Aethelgard Ventures. It is a multi-tenant service: each customer organisation has its own isolated workspace, and the application enforces that separation in the database itself, not only in application code.
What we collect
Identity and account data
Sign-in is handled by Clerk. Your password or social login is held by Clerk — Beacon never receives or stores it. Inside Beacon we store your email address, the identifier Clerk assigns you, your role in your organisation (owner, admin, member or consultant), whether your account is active, and the time of your most recent authenticated request.
Organisation profile
Information your organisation enters about itself: organisation name, primary contact name, contact email, phone number, postal address, website, industry, and the jurisdictions and regulatory frameworks you want to be monitored against. If you upload a logo for your document exports, it is stored inside our database as an image (PNG or JPEG only, capped at 256 KB) rather than in separate file storage.
Content you put into the product
The substance of the service. This includes text you type, documents you upload, and audio or video you submit for transcription, along with everything generated from them: SOP drafts, every saved version of each document, tags, classifications, compliance findings, and attestation records showing who acknowledged which document and when.
Audio and video transcription runs on our own servers using a locally hosted Whisper model. Those files are not sent to a third-party transcription service.
Operational records
Records the system keeps in order to run and to be auditable: a governance log of significant actions, AI usage records (which model was called, for what, and how many tokens), regulatory monitoring results, and server error logs. API keys are stored only as hashes — the full key is shown once, at creation, and cannot be recovered afterwards.
Billing
Payment is handled entirely by Stripe, through Stripe Checkout and the Stripe Billing Portal. Card numbers never reach Beacon's servers. What we store is the Stripe customer and subscription identifier, your plan tier, your subscription status, and the current billing period.
Where it is stored
Application data lives in a single PostgreSQL database hosted on Railway. The web application is served by Vercel. Tenant separation is enforced by PostgreSQL row-level security, so a query issued on behalf of one organisation cannot return another organisation's rows even if application code asks it to.
Third-party services that process your data
The list below is drawn from the service's own code and dependencies, not from a template. These are the outside parties that can see some part of your data in the course of Beacon operating normally.
| Service | What it does | What it can see |
|---|---|---|
| Clerk | Sign-in, sessions, user management | Your email address, name and authentication activity |
| Google (Gemini) | Default AI model for generating and auditing documents | The process descriptions and documents you submit, and the text generated from them |
| Anthropic (Claude) | Alternative AI model, selectable by the operator | The same content as above, when it is the configured provider |
| Stripe | Subscriptions and payments | Your billing contact details and payment method (held by Stripe, not by us) |
| Resend | Transactional email — invitations, API keys, compliance alerts | Recipient email addresses and the contents of those messages |
| Railway | Hosting for the API and the database | All stored data, as the infrastructure provider |
| Vercel | Hosting for the web application | Request metadata such as IP address and browser user agent |
| Cloudflare | DNS, and the bot check shown on the sign-in page | Request metadata at the network edge |
Organisations on the Business tier can configure Beacon to call their own AI provider instead of ours — OpenAI, Anthropic, Azure OpenAI or Google. If you do that, your content goes to the provider you nominated under your own agreement with them, and the credential you supply is stored encrypted and is never returned by the API.
Who inside your organisation can see what
Everyone in your workspace shares its documents, subject to their role. Owners and admins can invite and remove people and see organisation-level settings and billing. A consultant account can be granted access to a client organisation by that organisation, and that access ends when the assignment is revoked. Aethelgard Ventures staff operating the platform have an administrative console that can see organisation-level records — names, plans, usage counts and support diagnostics.
Not yet settled
We would rather list these as open than answer them with something that sounds right and is not yet true:
- How long data is retained after an account is closed, and how deletion is requested and confirmed.
- Whether a formal data processing agreement is offered, and on what terms.
- How data subject access, correction and deletion requests are handled in practice.
- Whether any data is stored or processed outside the United States by the providers above.
- Breach notification timelines.
Ask us about any of these before you rely on them. See also our Terms & Conditions.