Skip to content
Beamfall
HomePricingAccountLink
Join the beta

Privacy Policy

What beamfall.com and the Beamfall Account know about you — and the hard line the design draws around your library and viewing.

Last updated July 2026. This is a beta-period policy and will be reviewed with legal counsel before general availability.

1. The privacy line

The Beamfall Account knows what you bought, never what you watch. No library, playback, or server data ever reaches Beamfall's cloud. Your viewing history, titles, and library live only on the server you host.

This boundary is enforced in the product design, not just this policy: account systems are scoped away from library and playback data.

2. What the Account stores

A Beamfall Account stores your email, your purchase/entitlement state, and the list of devices you have signed in — nothing about your media. The website also processes a waitlist email address and standard security metadata (such as CSRF tokens and rate-limit counters) needed to operate the site safely.

3. What the Hosted Relay can and cannot see

If you use the optional Beamfall Hosted Relay, it is a byte-blind SNI relay: it can observe the SNI hostname, connection metadata, traffic volume, region/node, and duration needed to route and operate the tunnel. It cannot see media content, titles, or your library. Relay observability is metadata-only and is not joined to your account or entitlement ledger. See the Acceptable Use Policy for the fair-use figures.

4. Retention

Transient relay operational logs have a published maximum retention window measured in days, not months. For a deleted account, identity-linkable AccountID and PaymentSourceID values in the entitlement ledger are retained for the default 7-year (7y) statutory financial-record window, under GDPR Art. 6(1)(c) read with Art. 17(3)(b); after that window, the identifiers are crypto-shredded in place. For historical viewing behavior our answer is simple: we do not have it, because it never leaves your server.

5. Your choices

You can delete your Beamfall Account and its data from the Account page at any time. Because your library and viewing never reach us, there is no viewing history for us to export or erase.

6. Lawful bases (GDPR Art. 6)

For EU/UK users we rely on these lawful bases: performance of a contract to provision your Beamfall Account and Premium entitlement; legitimate interests to keep the site and Hosted Relay secure (CSRF tokens, rate-limit counters, abuse prevention) and to operate the byte-blind relay; and consent, where required, for the marketing waitlist email you volunteer.

We do not use your personal data for automated decision-making or profiling, and we never process library, playback, or viewing data because it never reaches us.

7. International data transfers

Beamfall Account and website infrastructure is operated on Render and AWS, which may process data in the United States. Transfers of EU/UK personal data are covered by the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum) in our Data Processing Agreements with those processors. A list of sub-processors and the transfer mechanism is available on request at privacy@beamfall.com.

8. California & US-state privacy rights (CCPA/CPRA)

California and other US-state residents have the right to know, access, delete, and correct the personal information we hold, and to be free from discrimination for exercising those rights. We do not sell or share your personal information, and we do not process sensitive personal information for inferring characteristics. Exercise any of these rights through the data-request channel below.

Cookies & local storage

beamfall.com and the Beamfall Account use a small number of strictly necessary, first-party cookies to run the site and keep you signed in. We set no advertising, analytics, or third-party tracking cookies, and the site uses no browser local storage or session storage. The cookies we set are:

  • A session cookie that keeps you signed in to your Beamfall Account. It is first-party, HttpOnly, and sent only to our own servers; it carries no library or viewing data.
  • A CSRF-protection token (bf_csrf) that guards Account form submissions against cross-site request forgery.

Both cookies are strictly necessary to provide the Account service you asked for, so under the ePrivacy Directive and GDPR they do not require prior consent. Because they are essential, there is no non-essential tracking to opt out of.

If we ever add non-essential cookies (for example analytics), we will ask for your consent first through a consent notice and will not set them until you agree. You can also block or delete cookies in your browser, though signing in to your Account will not work without the strictly necessary ones.

Data-subject & consumer requests (DSAR)

You can ask us to access, export, correct, or delete the personal data the Beamfall Account and website hold about you — this covers GDPR/UK-GDPR data-subject rights and CCPA/CPRA consumer rights. To make a request:

  1. Email privacy@beamfall.com with the subject line “Data request”, or use the “My account data” export and delete controls on the Account page.
  2. Tell us which right you are exercising (access/export, correction, deletion, or opt-out) and the email address on your Beamfall Account so we can verify you.
  3. We verify your identity against your Account, then action the request and confirm in writing.

We respond within 30 days (GDPR) / 45 days (CCPA), and may extend once where the law allows, telling you why. You may authorize an agent to act for you, and you can lodge a complaint with your supervisory authority (EU/UK) or state Attorney General. Because your library and viewing never reach us, there is no viewing history for us to export or erase.

9. Contact

Privacy questions and DSAR requests can be sent to privacy@beamfall.com. This is a beta-period policy and will be reviewed with counsel before general availability.

BeamfallCore and the self-hosted Web UI are AGPL and free from day one.
PricingAccountTermsPrivacyCookiesData requestsAccessibilityAcceptable UseCopyright / DMCACSAM Policy