Data Protection & AI Processing Policy
Last updated:
This page explains specifically how Beanoc handles your data when it calls AI models, and the controls we put around it.
What is sent to OpenAI
When you run a tool, our server sends the OpenAI API (chat completions, default model gpt-4o-mini) the text of your brief for that tool, plus your saved brand-voice profile if you have one set. This call is made server-side using a server-held API key — the key is never exposed to your browser.
What is never sent
We do not send your account credentials, billing/payment details, or other users' data to OpenAI. Only the specific brief and brand-voice fields relevant to the tool you are running are included in a request.
No model training
Your briefs, brand-voice profile and generated output are not used to train Beanoc's own models, and we do not sell your content. We do not enable any provider "improve the model" data-sharing option for your content.
Retention and deletion of generations
Generations are stored in your workspace's history so you can find and reuse them, for as long as your account is active. You can delete individual history items from inside the app; deleting your account deletes your stored briefs, outputs and brand-voice profile within a reasonable period, except where we must retain billing records for legal or tax reasons.
Brand-voice storage
Your brand-voice profile is stored in your account's database record and is only applied to your own generations. It is not shared with other accounts and is not used to train models.
Access control
Every table in our database enforces row-level security (RLS) policies, so a request can only read or write rows belonging to the authenticated account making it. Plan and quota limits are enforced server-side on every generation request, not just in the browser.
Breach notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required by law, and notify affected users without undue delay where required.
Data export and deletion process
To request an export or deletion of your personal data, email privacy@beanoc.com from your account's registered email address. We will verify your identity and action the request within the timeframe required by applicable law.
Subprocessor change notice
We will update our subprocessor list and, where the change is material, notify customers by email before adding or replacing a subprocessor involved in processing personal data.