Legal / Privacy
Privacy Policy
This policy explains how BlackBeeDevs Cloud handles personal information when you create a workspace, audit a site, connect developer tooling, use AI features, or purchase a plan.
1. Scope and responsibility
This Privacy Policy applies to the BlackBeeDevs Cloud website, dashboard, APIs, command-line tools, audit services, email communications, billing, integrations, and related support (the “Service”). “BlackBeeDevs,” “we,” and “us” refer to the operator of BlackBeeDevs Cloud. For account and platform data, BlackBeeDevs generally acts as the controller or business deciding why and how information is processed. For content submitted by an organisation and processed on its instructions, BlackBeeDevs may act as its processor or service provider.
If your employer or another organisation provides your workspace, that organisation controls membership, projects, and access and may administer or delete workspace data. Its privacy notices may also apply.
2. Information we collect
Account and identity
We collect your name, email address, password hash, email-verification status, workspace membership, and role. Verification codes, session tokens, invitation tokens, and API credentials are stored as hashes where the Service only needs to validate them. We do not retain your plain-text account password.
Workspace and project content
We process workspace names, invitations, project names and URLs, domain-verification records, audit settings and results, deployment checks, findings, reports, report branding, webhook configuration, notification preferences, usage, agent tasks, repository labels, and related timestamps.
Audit target data
When an authorised user starts an audit, the Service requests pages and technical resources from the target URL and records observations such as status, redirects, headers, certificate information, performance measurements, accessibility results, page metadata, issues, and—where supported—page captures. Target credentials such as bearer tokens, basic-auth credentials, or session cookies are accepted only to access a target the user is authorised to test. The platform records the authentication method used but is designed not to persist the target credential in the audit record.
Developer tools and agents
We process API-key hashes, scopes, project assignments, last-used timestamps, device-code authorisations, agent connection state, repository name, task instructions, task status, and user-submitted commit or pull-request references. A newly created API key may be displayed once; the platform stores its hash for validation.
Billing, email, and support
We receive subscription status, plan, Stripe customer and subscription identifiers, invoice references, billing events, and related dates. Payment card details are collected by Stripe, not stored by BlackBeeDevs Cloud. For transactional email, we process recipient address, message purpose, and delivery identifiers through Resend. If you contact us, we process the content and contact details you provide.
Usage and device information
Servers and infrastructure providers may process IP address, user agent, request path, time, error, and security-event data. BlackBeeDevs structured logs use a shortened hash of a request client identifier. Rate-limit and operational records help prevent abuse and diagnose reliability problems.
3. Why we use information
- Provide accounts, workspaces, roles, invitations, audits, reports, deployment checks, APIs, agents, AI workspaces, billing, and support.
- Authenticate users, enforce permissions and plan limits, verify domain control, prevent fraud and abuse, and investigate security events.
- Send verification codes, invitations, product-critical notices, invoices, and user-configured notifications.
- Operate, troubleshoot, measure, and improve the Service and develop related functionality.
- Comply with law, enforce our Terms, resolve disputes, and protect users, BlackBeeDevs, and the public.
Where applicable, our legal bases include performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where law requires it. Withdrawal of consent applies prospectively and does not affect prior lawful processing.
5. Bring-your-own AI features
You choose whether to connect an AI provider and supply its API key. The key is encrypted at rest using authenticated encryption and is not returned through the API after storage. When you send an AI request, BlackBeeDevs decrypts the key only to call your selected provider. The request may include your prompt, selected project metadata, up to 20 relevant open findings, and recent conversation context. Responses and conversation history are stored in the workspace.
OpenAI and Anthropic process requests under their own agreements and privacy practices. Their retention, regional processing, and account settings are outside BlackBeeDevs’ control. Do not submit secrets, regulated data, personal information, or proprietary source content unless you and your organisation are authorised to disclose it.
7. Retention and deletion
We retain account and workspace content while the account is active and afterwards only as reasonably necessary to provide requested exports, maintain security and audit records, resolve disputes, enforce agreements, satisfy legal obligations, or complete backup cycles. Verification codes expire after two minutes; ordinary web sessions expire after seven days; invitation links expire after seven days unless replaced or revoked. Audit and AI history remains until deleted through the Service, the owning workspace or account is deleted, or an applicable retention need ends.
Deleting an account removes that user’s data and, when the user owns a workspace, associated operational collections from active application state. Limited records may remain in backups, processor systems, fraud-prevention records, or legally required archives until their normal deletion cycle ends.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; or appeal a decision. California residents may also request categories or specific pieces collected and information about disclosure. We will not discriminate against you for exercising an applicable right.
You can update profile data and delete your account in Settings. For other requests, email hello@blackbeedev.com. We may verify identity and authority before acting. If an organisation controls your workspace, direct your request to it first. You may complain to your local data-protection authority.
9. Security
We use safeguards appropriate to the Service, including TLS in transit, password and token hashing, encrypted user-supplied AI credentials, HttpOnly session cookies, CSRF controls, role-based access, scoped API keys, rate limits, private-network restrictions for scanners, and redirect revalidation. No system is perfectly secure. You are responsible for keeping credentials confidential, granting only necessary access, rotating exposed keys, and using short-lived target credentials.
10. International processing
BlackBeeDevs and its providers may process information outside your country. Those locations may have different data-protection laws. Where required, we use legally recognised transfer mechanisms or rely on providers’ contractual safeguards. Your organisation is responsible for confirming that its selected AI provider and configuration meet its transfer requirements.
11. Children
The Service is intended for developers and organisations and is not directed to children under 16. We do not knowingly collect personal information from children under 16. Contact us if you believe a child has provided information so we can review and remove it.
12. Changes
We may update this policy as the Service or law changes. We will change the date above and provide additional notice for material changes when required.
13. Contact
Privacy requests: hello@blackbeedev.com
Legal notices: hello@blackbeedev.com
Service: cloud.blackbeedev.com