Privacy policy

Last updated: 23 September 2026

Beacon ("we", "us") operates trybeacon.space, the Beacon API relay (api.trybeacon.space), optional hosted chat (chat.trybeacon.space), and the Beacon Chrome extension. This policy describes what we collect, why, how we protect it, and your choices. It applies to the website, extension, MCP integration, and hosted chat together.

What Beacon does

Beacon links your account to Chrome so MCP clients (for example Cursor) or our hosted chat can observe pages and run actions (click, type, scroll, navigate) using stable control IDs. The extension runs only when you install it, link your account, and invoke Beacon or an MCP client calls Beacon tools. Hosted chat is optional and uses the same browser relay when you ask for browser tasks.

Information we collect

Account information. When you sign up, we collect email and display name. Passwords are hashed with bcrypt; we do not store plaintext passwords. We may send verification email via our email provider.

Authentication tokens. We issue MCP API keys (shown once at signup or rotation). We store a hash of the key, not the secret. The Chrome extension stores your link token and account feature flags locally in chrome.storage.local so it can reconnect to the relay and show product features you are entitled to.

Website and page content. When you or your MCP client calls tools such as observe, the extension reads the open page (structure, control labels, URLs, and text needed to ground actions) and sends results through our relay to your client. If you ask to work on Gmail, WhatsApp Web, or other sites, that observe output reflects what is visible in your browser for that request—we do not read those apps in the background without a tool call you initiated. We do not use page content for advertising or unrelated profiling.

Hosted chat (beta). If you use chat on trybeacon.space or in the extension iframe, your messages for that session are processed to run the assistant. We do not persist full chat transcripts on our servers; the chat UI keeps the thread in the browser for that session. For trial hosted models, message content is sent to our LLM provider (DeepSeek) to generate replies. Browser tasks in chat use the same MCP relay as Beacon MCP tools.

Usage and credits. For hosted chat we record per-account trial credits, feature flags (such as whether chat is enabled), and usage metadata (model id, token counts, computed cost, timestamps)—not the full text of every message in a long-term archive.

User activity. Beacon processes interactions you request via MCP or hosted chat (clicks, typing, scrolling, navigation). The extension may keep a short, filtered list of recent network calls on a tab (method, truncated path, status) to help observe responses; analytics and static asset URLs are dropped where possible. Agent session summaries may be stored if you use the legacy sidepanel goal runner.

Technical data. Our servers receive IP address, request timestamps, and similar logs needed to operate the API and WebSocket relay, prevent abuse, and debug outages.

We do not collect health data or payment card numbers through Beacon. We do not log you into third-party sites; your existing Chrome sessions stay yours.

Security

  • MCP secrets and API keys are stored hashed; plaintext keys are shown only once at creation or rotation.
  • Web sessions use signed, HTTP-only cookies over HTTPS in production; relay and MCP use TLS (wss/https).
  • Embed chat uses short-lived handoff tokens tied to your account; MCP calls require your key or an authorized embed token.
  • Per-account feature flags and credit limits are enforced on the server, not only in the client.
  • Access to production databases and secrets is limited to operators; infrastructure providers (hosting, database, email) process data under their own security programs.

No system is perfectly secure. Use a strong password, rotate MCP keys if exposed, and uninstall the extension or log out on shared machines.

Analytics and third-party telemetry

Beacon does not ship PostHog, Sentry, Google Analytics, Segment, Mixpanel, or similar product analytics in the Chrome extension, trybeacon.space web app, or beacon-server relay. We do not fingerprint your browser for ads.

Third parties involved when you use the hosted service: infrastructure (for example hosting and Postgres), email delivery for verification, and DeepSeek when you use hosted chat models. If you connect Beacon MCP to your own client (for example Cursor), that client and any model provider you choose process traffic under their own terms.

Data that can leave your machine on the hosted relay: account email, MCP key hash, observe/act payloads you request (relayed to your client or hosted chat, not sold), usage metering for trial credits, API access logs (IP, timestamps), and optional feedback you submit.

How we use information

  • Provide account login, extension linking, MCP relay, and optional hosted chat
  • Execute observe/act commands you or your MCP client request
  • Meter trial credits and enforce product features per account
  • Secure the service, rotate credentials, and support troubleshooting
  • Respond to support and feedback you send us

Sharing

We do not sell your personal information. We share data only with infrastructure providers that process it on our behalf to run trybeacon.space, the relay, and chat (hosting, database, email, LLM API when you use hosted chat), under confidentiality obligations, and when required by law.

Observe and action results go to your MCP client or hosted chat session because you configured or started that connection; your MCP or model provider's terms apply to how they store agent traffic.

Retention

We keep account data, usage metering, and security logs while your account is active and for a reasonable period afterward for legal and operational needs. You can rotate or revoke MCP keys from your account. Uninstalling the extension removes local extension storage on your device. Hosted chat threads are not stored as long-term archives on our servers.

Your choices

  • Rotate or invalidate MCP keys anytime from your account
  • Log out in the extension to clear the local link token
  • Uninstall the extension to stop page access
  • Use MCP with your own client and models instead of hosted chat
  • Contact us to request access, correction, or deletion of account data

Children

Beacon is not directed at children under 13, and we do not knowingly collect their data.

Changes

We may update this policy. We will post the new date at the top of this page. Continued use after changes means you accept the updated policy.

Contact

Questions or privacy requests: namanrai309@gmail.com

Back to home