Skip to main content

$ head -4 PRIVACY.md

The short version

  • Only what you send

    We store what you choose to send us — a project brief or a newsletter sign-up — plus the technical basics any website needs to run.

  • No ad tracking

    No advertising trackers or pixels, and we never sell your data. Page speed is measured anonymously.

  • Our Meta app stays in its lane

    It only publishes to our own Facebook Page and Instagram account, and it doesn’t collect or store data about other users.

  • Deleted on request

    Email us with the subject “Delete my data” and we delete it within 30 days. How it works

Who we are

Beard Byte Labs is an independent studio that builds agentic systems, software and creative work. In this policy, “we”, “us” and “our” mean Beard Byte Labs, and “the site” means beardbytelabs.com. The policy covers the site, the forms on it, and how we publish to our own social media accounts.

Questions about privacy go to sean@beardbytelabs.com.

What we collect and why

We collect as little as we can. Here is what the site collects, where it goes, and why.

Project briefs (the form on /start)

When you send a brief through /start, we store:

  • your name and email address;
  • your company or site, if you add one;
  • what you’re looking for, your budget range and your timeline, if you pick them;
  • your message;
  • the address of the page you sent it from, and which of our offers (if any) sent you there;
  • your browser’s user-agent string (cut to 300 characters), which we keep only to investigate abuse.

Each brief gets a receipt number (INQ-…), and we add our own status and notes as we work on it. We use all of this only to reply to you and to scope any work together. We also email ourselves a copy of each new brief, delivered by Resend. The form shows your receipt on screen — it doesn’t send you an automated confirmation email — and sending a brief doesn’t sign you up for anything. If you email us instead, we keep your message and address so we can reply.

The form also has a hidden anti-spam field and notes how long it was open. Both are checked when the brief arrives and then discarded; neither is stored.

Newsletter sign-ups

If you subscribe, we store your email address, that it came from this site, when you signed up, and whether you’re still subscribed. That’s all. Signing up doesn’t trigger an automated email, and we use the address only to send you our newsletter. To unsubscribe at any time, email sean@beardbytelabs.com — we’ll mark your address as unsubscribed, or delete it outright if you’d rather.

Our do-not-contact list

If you ask us not to contact you, or an email to you bounces or is reported as spam, we put your email address on a do-not-contact list with the reason, the date, where the request came from, and sometimes a short note. It applies to everything we do: the brief form and the newsletter sign-up check it before storing anything and quietly store nothing for an address on it, and we check it before any outreach. It has to remember your address in order to leave you alone, so the entry stays until you ask us to remove it.

Businesses we may contact

We keep a private list of businesses we may offer our services to. For each, we record what the business publishes about itself — its name, website, country or region, and its published way to be reached (such as a contact form, email address or phone number) — plus the page where we found it, when, and why we think we could help. We record a person’s name only when the business publishes it. If we get in touch, we log what happened (sent, replied, opted out) as short summaries rather than copies of messages, and we keep records of any work we agree on. Nothing on the site sends messages to this list automatically. If you’d like your business removed, email sean@beardbytelabs.com.

Spam and abuse protection

To stop floods of automated submissions, our forms only accept requests sent from our own pages, and they count recent requests from each IP address and, on some forms, each email address. Those counters live only in the server’s memory, each covers a window of one to fifteen minutes, and they’re never written to our database — they disappear whenever the server restarts.

Cookies and sign-in

The site’s own code sets no cookies on its public pages. Cookies are used only in the studio’s private admin area, which only the studio uses: a sign-in cookie that page scripts can’t read and that expires after two hours, plus the admin’s display preferences (theme and language). The owner signs in with a password, a passkey or a single-use link emailed to an approved address — for any other address, nothing is saved and no email goes out. There are no visitor accounts and no social logins such as “Log in with Facebook”.

Analytics and performance

We don’t use Google Analytics, advertising pixels, or any advertising or cross-site tracking. The only measurement tool on our pages is Vercel Speed Insights: on each page view, a small script reports how quickly the page loaded and responded, together with the page address, browser, device type, operating system, network speed and country. Vercel says these data points are anonymous and aren’t tied to any individual visitor or IP address. We look at them only in aggregate, to find and fix slow pages.

Hosting logs

Like every website, ours receives technical details with each request: your IP address, your browser’s user-agent string, the page you asked for, and when. Our host, Vercel, uses them to deliver pages and protect the site, and keeps request and error logs for a limited time under its own retention settings. We use those logs only to fix problems and deal with abuse.

The terminal lab and site search

If you start a live session on /terminal, your browser connects to our terminal service on Fly.io, which starts a disposable sandbox just for you. What you type runs inside that sandbox; we don’t record it, and the sandbox is destroyed when the session ends. The service checks your IP address, in memory only, to limit how often new sessions can start. The offline version of the terminal runs entirely in your browser and only remembers, on your device, whether you solved its challenge.

Site search downloads a list of our pages and filters it on your device, so what you type into search never reaches us.

Social media and our Meta app

We publish our own posts to our own accounts on platforms including Facebook, Instagram, Threads, Bluesky, X, Pinterest and YouTube — sometimes by hand, sometimes through each platform’s official API, and sometimes with automation that works inside our own signed-in accounts. We use these tools to publish and check our own posts, not to gather information about other people.

Our Meta app. “Beard Byte Labs Autopilot” is used only to publish to our own Facebook Page and our own Instagram account. It creates our posts there and reads back the status, link and text of the posts it has just published, to confirm they went live. It doesn’t read comments, messages, followers or anyone else’s profile, and it doesn’t collect or store data about other Facebook or Instagram users.

Links to our profiles. The links to our profiles in the footer and on /community are ordinary links. We don’t embed social media widgets, like buttons or tracking pixels, so a social network only learns about your visit if you click through — and from then on, its own privacy policy applies.

Services we rely on

We don’t sell your personal information, and we don’t share it with advertisers or data brokers. We rely on a few service providers, which process data on our behalf:

  • Vercel — hosts the site, runs its code, keeps its request logs, provides Speed Insights, and stores the images we upload.
  • Neon — hosts our PostgreSQL database, where briefs, newsletter sign-ups, the do-not-contact list and our business records are kept.
  • Resend — delivers our notification emails about new briefs (to us) and the owner’s sign-in links.
  • OpenRouter — connects us to the AI models we use to research and draft our own content and to run our posting tools. We never send it anything you submit through the site.
  • Slack — delivers internal notifications to us about our own scheduled posts. They contain no visitor data.
  • Fly.io — runs the terminal lab’s disposable sandboxes.

These providers may process data in the United States and other countries. Beyond them, we’d disclose personal information only if the law required it.

How long we keep it

  • Briefs — while we talk and, if we work together, for as long as the work and our records need them. They don’t expire automatically; we delete them whenever you ask.
  • Newsletter sign-ups — until you unsubscribe or ask us to delete your address.
  • Do-not-contact entries — for as long as the request stands. We remove an entry only when the person it protects asks us to.
  • Business records — until they’re no longer useful to us, or the business asks us to remove them.
  • Anti-spam counters — in server memory only, for windows of one to fifteen minutes.
  • Hosting logs and Speed Insights data — under Vercel’s retention settings.
  • Terminal sandboxes — destroyed when the session ends.

Security

  • Inside the site, everything we store about you can be read only by the studio owner. Every request is checked against an owner allowlist, and if that list is ever empty, nobody gets in.
  • Emailed sign-in links work once and expire after 15 minutes, and we store only a hash of each one, never the link itself.
  • The site is served over HTTPS, and the sign-in cookie is hidden from page scripts.

No system is perfectly secure, but collecting little means there is little to lose.

Your rights and choices

Whatever you’ve sent us, you can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct anything that’s wrong;
  • delete it (see How to delete your data);
  • stop emailing you — unsubscribe you from the newsletter, or add you to our do-not-contact list.

Email sean@beardbytelabs.com. It’s free, and we’ll respond within 30 days. We may ask you to write from the address you used with us, so we don’t hand your information to someone else. Depending on where you live (for example the EU, the UK or California), you may have further rights — such as to object to or restrict how we use your data — and you can complain to your local data-protection authority.

How to delete your data

Email sean@beardbytelabs.com with the subject “Delete my data”, and include the email address you used with us. We’ll confirm we’ve received your request, delete your brief, newsletter sign-up and any other records we hold about you — including our copies of any notification emails — within 30 days, and email you when it’s done.

If you also want us never to contact you again, say so. We’ll then keep only your email address on our do-not-contact list, so that we can honor it.

Facebook and Instagram. We don’t store any Facebook or Instagram user data from our Meta app — it only publishes to our own Page and Instagram account — so there is nothing to delete. If you’d like us to confirm that, email us and we’ll confirm by email.

Copies in our providers’ logs (for example Vercel’s request logs and Resend’s delivery records) expire on those providers’ own schedules.

Children

The site isn’t directed to children under 13, and we don’t knowingly collect personal information from them. If you believe a child has sent us information, email sean@beardbytelabs.com and we’ll delete it.

Changes to this policy

When our practices change, we’ll update this page and the “Last updated” date at the top.

// questions

Something unclear, or something we missed? Email sean@beardbytelabs.com. Here to talk about a project instead? Send a brief.