Privacy Policy

Last updated: September 10, 2026

This page describes what the Beacons app and this website actually collect, who else receives it, how long we keep it, and what you can do about it. It was written from the code, and we update it when the code changes.

Who we are

Beacons, operated by Bendes Technology Group, LLC. If anything on this page is unclear, email hi@sendbeacons.com.

What we collect and why

Identity

You sign in with a phone number. Google Firebase sends the one-time code and confirms the number; we never see the code. We do not store your phone number as a number. It is hashed on your device with a fixed salt, then hashed again on our server with a secret that never leaves the server. What we keep is the result, and it is only used to match you with contacts who already know your number. You also choose a name to display. That is the whole profile: no email address, no photo, no birthdate.

Contacts

If you allow access to your contacts, the phone numbers in your address book are hashed on your device the same way. Only the hashes are sent, so we can tell you which contacts are already on Beacons. Names and anything else from your address book stay on your phone. We do not store the hashes from a lookup. If you choose to invite someone who is not on Beacons, we store the hash of that one number so we can connect the two of you when they sign up, and the invitation itself is a text message sent from your phone, by you. We never message your contacts ourselves.

Location while you use the app

With your permission, the app reads your location to show how far away each beacon is and to suggest nearby places when you light a beacon. The distance is worked out on your phone; the feed request itself carries no coordinates. What reaches our server, whether the app is open or not, is the same snapped point described next: about 3 km across, one per device, no history. That point is what decides which beacons are close enough to show you.

Location in the background

If you turn on nearby alerts, the app asks for background location on both iPhone and Android so we can tell you when a connection lights a beacon near you. This is the most sensitive thing we do, and it is shaped to reveal as little as possible:

  • Before it leaves your phone, the point is snapped to a grid about 3 km across. We never receive your exact position.
  • We keep one point per device, overwritten each time. There is no history.
  • A point older than 24 hours is ignored.
  • Turning the setting off clears the stored point. So does deleting your account.

The stored point is only ever compared with the location of a beacon to decide whether to send you a notification. It is never shown to anyone.

Beacons

A beacon is what you make: an activity, a time, a place, how many people can join, and who can see it. The meetup pin is stored at full precision, because a meetup needs a real address, and it is shown to the people you chose as the audience, including before they join. If you would rather not show a specific address, pick a general spot.

Chat

Each beacon has a chat. Messages are visible only to the host and the people who joined, and they are deleted 48 hours after the beacon ends. If someone reports a message, we keep a copy of that message with the report.

Connections and tags

We store your connection requests, your connections, and the settings you attach to them: who you have muted, who you have starred as a close connection, and the audiences you build for your beacons. Stars are private to you. Tags describing what you have done together are computed nightly from beacons you both attended and are the same on both sides.

Notifications

To deliver push notifications we store a device token from Apple or Google along with the platform. Notification text, such as who lit a beacon, a chat message, or a reminder, passes through Apple and Google to reach your phone.

Reports and blocks

If you report someone, we store who reported whom, the reason you wrote, and a snapshot of the message if you reported one. If you block someone, we store the block so that the two of you no longer see each other. The person you blocked is not told. A block is meant to hold: alongside it we keep a hash of the blocked person’s number, so if they delete their account and sign up again with the same number, your block is put back before they can reach you. That hash is kept only for as long as your account exists, and only for this.

Invites and links

You have one personal invite code, which you can share as a link. When someone opens it and signs up, we record that your code brought them in and create a connection request between you. Beacon links work the same way for a single beacon. The public pages behind those links count visits by IP address, in memory only and never stored, to limit abuse.

Analytics and diagnostics

We use PostHog to see which parts of the app get used and where it breaks. Events are tied to your internal account id, never your phone number. They never include your precise location, your contacts, or anything you write. PostHog derives a city-level area from your network address so we can see roughly where the app is used; the address itself is not kept with events. When the app or our server hits an error, the error and a stack trace are sent to PostHog too. There is no session replay, no advertising identifier, and no ad or attribution software in the app.

Who else receives data

We run Beacons on a small number of providers. Each receives only what it needs, under its own terms, and none is permitted to use your data for its own purposes.

  • Google Firebase receives your phone number to send the sign-in code and verify it, and delivers push notifications, so it also sees the text of each notification.
  • Apple delivers push notifications on iPhone and likewise sees their text.
  • Supabase hosts our database. Everything described above is stored there.
  • Render hosts our server. Its request logs carry your internal account id and the type of request, not your IP address.
  • PostHog (United States) receives the analytics events and error reports described above.
  • Google Maps Platform provides place search; the app draws no map. When you search for a place, Google receives what you typed and a position rounded to about 1 km so results are local to you. It also receives a position rounded the same way when we turn your area into a neighborhood name for the Me tab. Both go through our server, never straight from your phone.
  • Google Fonts serves the typefaces on this website, so each page you load here sends your IP address and browser details to Google. The app bundles its own fonts and makes no such request.

We do not sell your data, show ads, or share anything with data brokers.

What other people see

  • Your name, once there is a connection between you: one of you asked, the other accepted.
  • Your beacons, only to the audience you chose for each one, including the pin.
  • In a beacon chat, your name and what you write, to the host and the people who joined.
  • Whether you accepted or declined a connection request is not shown to the sender.
  • Your phone number is never shown to anyone, and neither is your location.

Retention

  • Chat is deleted 48 hours after the beacon ends.
  • Background location is one latest point per device, overwritten each time and cleared when you turn sharing off.
  • Ended beacons are kept so you can see your history.
  • Reports are kept as long as needed for safety.
  • Invites you send are kept (your id and the hash of the number) so the two of you are connected whenever that person joins. They do not expire.
  • Everything else is kept until you delete your account.

Your choices and rights

  • Location. Nearby alerts and background location are off until you turn them on, and you can turn them off in the app or in your phone’s settings at any time.
  • Notifications. Turn them off in your phone’s settings. Muting a connection stops their notifications without disconnecting.
  • Contacts. Contact access is optional. You can revoke it in your phone’s settings; the app keeps working.
  • Delete your account. In the app, go to Account → Manage → Delete account. It is a hard delete with no waiting period. If you can no longer sign in, follow the deletion page and email hi@sendbeacons.com; we delete within 7 days of confirming it is you. Either way your analytics data at PostHog is deleted with the account. Four things outlive it: messages you wrote in other people’s beacon chats stay, with no name on them, until that chat’s 48-hour deletion; if someone invited you before you joined, their invite record keeps the hash of your number; reports you filed are kept as long as needed for safety, with your name removed; and if someone blocked you, their block keeps the hash of your number so that it still applies if you sign up again with it.

There is no export feature yet. If you want a copy of what we hold about you, email us and we will send it.

This website

The website sets no cookies and stores nothing in your browser. The invite and beacon-link pages send one anonymous event per visit to PostHog, with a random id that is not kept, so we can tell whether the links work; the beacon-link page also asks our server for the beacon’s name and host. The sign-in helper pages that Firebase serves under this domain during phone verification are Firebase’s own, and Firebase’s terms apply there.

Age

Beacons is for adults. You confirm that you are 18 or older when you sign in, and we delete accounts we learn belong to anyone younger. We do not knowingly collect information from children under 13.

Changes

When the code changes what we collect, this page changes with it and the date above moves. Beacons is in private beta, so expect that to happen.

Contact

Questions about privacy: hi@sendbeacons.com.