Legal · Privacy
Privacy.
We collect the minimum we need, explain it plainly, and let you delete it. UK and EU data subject rights are honoured.
What we collect
- Account — email, display name, hashed password (never the raw value).
- Usage — which endpoints you call and when, so we can show you charts and bill correctly. Not the request content unless you opt in.
- Cookies — only essentials by default. See the cookie notice or /legal/cookies.
What we don't do
- We don't train on your content without explicit consent.
- We don't sell data to advertisers or brokers.
- We don't share with third parties beyond the providers we name below.
Subprocessors
Firebase / Google Cloud (auth, hosting, Firestore, Cloud Run) and Stripe (payments). The list is updated whenever we add or remove a provider.
Your rights
Email privacy@beyond-the-box.uk to access, correct, or delete your data. We respond within one calendar month per UK GDPR.