Legal · Privacy

Privacy.

We collect the minimum we need, explain it plainly, and let you delete it. UK and EU data subject rights are honoured.

What we collect

  • Account — email, display name, hashed password (never the raw value).
  • Usage — which endpoints you call and when, so we can show you charts and bill correctly. Not the request content unless you opt in.
  • Cookies — only essentials by default. See the cookie notice or /legal/cookies.

What we don't do

  • We don't train on your content without explicit consent.
  • We don't sell data to advertisers or brokers.
  • We don't share with third parties beyond the providers we name below.

Subprocessors

Firebase / Google Cloud (auth, hosting, Firestore, Cloud Run) and Stripe (payments). The list is updated whenever we add or remove a provider.

Your rights

Email privacy@beyond-the-box.uk to access, correct, or delete your data. We respond within one calendar month per UK GDPR.