BlackBeeDevs CloudPrivacyTermsData collectionSign in
ON THIS PAGENotice at collectionData inventoryAudit boundariesCredentialsAI data flowProvidersYour controls

Legal / Data transparency

Data Collection Policy

A product-level inventory of what BlackBeeDevs Cloud collects, where it comes from, why it is needed, and the handling rules for audits, credentials, agents, and AI.

Effective: August 5, 2026Last updated: August 5, 2026

1. Notice at collection

At or before account creation and use of product features, BlackBeeDevs Cloud may collect the categories below for the stated business purposes. We do not sell these categories or share them for cross-context behavioural advertising. We retain each category only for the period reasonably necessary for its purpose, security, legal compliance, dispute resolution, and backup completion. For legal bases, rights, and disclosures, read our Privacy Policy.

2. Data inventory

CategoryExamples and sourcePurposeStorage / handlingRecipients
Identity and accountName, email, password submitted by you; verification statusCreate, authenticate, recover, and administer accountsPassword is salted and hashed; verification code is hashed and expires in 2 minutesSupabase; Resend receives email and verification message
Session and securitySession, CSRF, invitation and API tokens; IP/request signalsAuthentication, permissions, abuse prevention, audit loggingTokens are hashed where only validation is needed; web session expires in 7 days; structured client ID is shortened and hashedSupabase, Vercel; Redis if configured
Workspace and teamWorkspace name, members, roles, invitations, report brandingCollaboration, access control, reportingStored in workspace state until removed or workspace/account deletionSupabase; authorised users; Resend for invitations
Projects and domainsProject name, production URL, verification token and resultOrganise targets and establish technical controlStored with project. DNS/HTTP verification may expose a token publicly by designSupabase; DNS or hosting provider when proof is published
Audit and deployment resultsURLs, status, redirects, headers, TLS, metadata, performance, accessibility, screenshots, findingsRun and report requested technical analysisResults stored in workspace history; scanner contacts submitted target and in-scope pagesSupabase; Vercel runtime; target host; authorised report recipients
Protected-target credentialsBearer token, basic username/password, or session-cookie header supplied per scanAccess an authorised protected target during that scanUsed in memory. Audit record stores authentication type, not credential. Logs and errors must not include itTarget host; runtime processing needed for scan
CLI/API/agentKey hash and scope, repository label, connection state, task text, status, commit/PR linksAuthenticate tools and coordinate approved workAPI secret shown once; hash stored. Task records persist in workspace historySupabase; connected tool or agent; repository provider when used
AI provider and conversationsProvider, model, encrypted API key, prompt, recent messages, project metadata, up to 20 findings, response, usage metadataGenerate analysis and agent handoffs at user requestKey uses AES-256-GCM authenticated encryption. Conversations are stored. Key is decrypted only for provider requestSupabase; user-selected OpenAI or Anthropic
BillingPlan, Stripe customer/subscription IDs, invoice and event recordsCheckout, renewal, entitlements, portal, accountingWe store billing identifiers and state, not full card detailsStripe; Supabase; authorised workspace owner
CommunicationsEmail, invitation/verification content, delivery ID, support messagesTransactional delivery and supportStored as needed for account state and troubleshootingResend; Supabase; support personnel
Preferences and usageNotification settings, plan consumption, theme/browser settingsPersonalise interface, enforce limits, send noticesServer state for settings; browser storage for temporary return links and preferencesSupabase; local browser; Vercel runtime

3. Website-audit collection boundaries

  • The scanner starts from the URL and page/depth limits you choose. It may follow in-scope links and redirects and fetch public technical assets required to analyse a page.
  • Private network destinations are blocked and redirects are revalidated to reduce server-side request-forgery risk.
  • Audits may observe text and metadata delivered by the target. Do not scan pages containing personal or regulated data unless your organisation has approved that processing.
  • Browser analysis and screenshots run only where the deployment environment supports them. A screenshot may capture content visible to the authenticated test session.
  • Audit results are point-in-time evidence. Shared report links disclose results to anyone with the link until revoked; treat the link as confidential.

4. Credential-handling rules

Account and API credentials

Passwords and validation-only tokens are stored as one-way hashes. API keys are displayed only when created. Use separate keys per integration, select the narrowest scope, bind to one project when supported, store keys in a deployment secret manager, and rotate after exposure or personnel changes.

Target credentials

Use a dedicated, least-privileged test identity and short-lived token or cookie. Never paste credentials into project names, URLs, terminal history, agent tasks, reports, or support messages. Revoke the session after the audit. BlackBeeDevs records that authentication was used but is designed not to save the submitted secret with the audit.

AI API credentials

Provider keys are encrypted rather than hashed because the Service must retrieve them to call the provider. They are never returned after storage. Workspace owners and administrators can replace or remove providers. Use a dedicated provider project with spend limits and no unrelated privileges.

5. AI request data flow

  1. An authorised user selects a provider, project, and prompt.
  2. The server retrieves and decrypts the workspace provider key in memory.
  3. It constructs a request that may contain the prompt, recent conversation, selected project metadata, and up to 20 open findings.
  4. The request is sent directly to OpenAI or Anthropic using that key. Provider processing is governed by the workspace’s provider account and terms.
  5. The response and conversation are stored in BlackBeeDevs Cloud. An agent handoff can be copied into a coding tool by the user.

Source repositories are not automatically uploaded by this feature. A connected coding agent may receive task text through the user-approved agent workflow. Users must review displayed context and remove secrets or unnecessary personal information before sending.

6. Service-provider map

ProviderRoleData involved
VercelApplication hosting and runtimeRequests, network/device metadata, runtime logs, content processed by server functions
SupabasePersistent application storageAccount, workspace, projects, results, configuration, billing and collaboration state
ResendTransactional emailRecipient, sender, subject, message content, delivery metadata
StripePayments and subscription managementCustomer details, payment information, subscription, invoice, tax and fraud signals
OpenAI / AnthropicOptional user-selected AI inferencePrompt, selected context/findings, conversation, API authentication, response and usage metadata
Target and repository providersSystems the user directs the Service or agent to contactAudit requests and credentials; user-approved repository operations

Providers may use subprocessors and process data in multiple regions. Their agreements and notices apply to independent processing. We may replace a provider with a functionally similar service and will update this page for material changes.

7. User and workspace controls

  • Access and correction: update your name and workspace settings in Settings; contact us for a broader export or correction.
  • Deletion: delete your account in Settings. Workspace owners should export needed reports first.
  • Sharing: revoke shared audit links and remove members who no longer need access.
  • Credentials: revoke API keys, disconnect agents, replace AI keys, and expire target-site test sessions.
  • Minimisation: scan the fewest pages needed, use public targets where possible, and avoid secrets or personal information in prompts and tasks.
  • Privacy requests: email hello@blackbeedev.com. We may verify identity and workspace authority.

8. Changes

We update this inventory when collection practices materially change. This policy supplements, and does not replace, the Privacy Policy or Terms.

© 2026 BlackBeeDevs · Privacy · Terms