BlackBeeDevs CloudPrivacyTermsData collectionSign in
ON THIS PAGEScopeInformation collectedHow it is usedDisclosuresAI featuresRetentionYour rightsSecurityContact

Legal / Privacy

Privacy Policy

This policy explains how BlackBeeDevs Cloud handles personal information when you create a workspace, audit a site, connect developer tooling, use AI features, or purchase a plan.

Effective: August 5, 2026Last updated: August 5, 2026
Short version: we use data to provide and secure the Service. We do not sell personal information or use it for cross-context behavioural advertising. Some features intentionally send data to processors or providers you select.

1. Scope and responsibility

This Privacy Policy applies to the BlackBeeDevs Cloud website, dashboard, APIs, command-line tools, audit services, email communications, billing, integrations, and related support (the “Service”). “BlackBeeDevs,” “we,” and “us” refer to the operator of BlackBeeDevs Cloud. For account and platform data, BlackBeeDevs generally acts as the controller or business deciding why and how information is processed. For content submitted by an organisation and processed on its instructions, BlackBeeDevs may act as its processor or service provider.

If your employer or another organisation provides your workspace, that organisation controls membership, projects, and access and may administer or delete workspace data. Its privacy notices may also apply.

2. Information we collect

Account and identity

We collect your name, email address, password hash, email-verification status, workspace membership, and role. Verification codes, session tokens, invitation tokens, and API credentials are stored as hashes where the Service only needs to validate them. We do not retain your plain-text account password.

Workspace and project content

We process workspace names, invitations, project names and URLs, domain-verification records, audit settings and results, deployment checks, findings, reports, report branding, webhook configuration, notification preferences, usage, agent tasks, repository labels, and related timestamps.

Audit target data

When an authorised user starts an audit, the Service requests pages and technical resources from the target URL and records observations such as status, redirects, headers, certificate information, performance measurements, accessibility results, page metadata, issues, and—where supported—page captures. Target credentials such as bearer tokens, basic-auth credentials, or session cookies are accepted only to access a target the user is authorised to test. The platform records the authentication method used but is designed not to persist the target credential in the audit record.

Developer tools and agents

We process API-key hashes, scopes, project assignments, last-used timestamps, device-code authorisations, agent connection state, repository name, task instructions, task status, and user-submitted commit or pull-request references. A newly created API key may be displayed once; the platform stores its hash for validation.

Billing, email, and support

We receive subscription status, plan, Stripe customer and subscription identifiers, invoice references, billing events, and related dates. Payment card details are collected by Stripe, not stored by BlackBeeDevs Cloud. For transactional email, we process recipient address, message purpose, and delivery identifiers through Resend. If you contact us, we process the content and contact details you provide.

Usage and device information

Servers and infrastructure providers may process IP address, user agent, request path, time, error, and security-event data. BlackBeeDevs structured logs use a shortened hash of a request client identifier. Rate-limit and operational records help prevent abuse and diagnose reliability problems.

3. Why we use information

  • Provide accounts, workspaces, roles, invitations, audits, reports, deployment checks, APIs, agents, AI workspaces, billing, and support.
  • Authenticate users, enforce permissions and plan limits, verify domain control, prevent fraud and abuse, and investigate security events.
  • Send verification codes, invitations, product-critical notices, invoices, and user-configured notifications.
  • Operate, troubleshoot, measure, and improve the Service and develop related functionality.
  • Comply with law, enforce our Terms, resolve disputes, and protect users, BlackBeeDevs, and the public.

Where applicable, our legal bases include performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where law requires it. Withdrawal of consent applies prospectively and does not affect prior lawful processing.

4. How we disclose information

  • Infrastructure and storage: Vercel hosts the application and may process request and deployment logs; Supabase stores application state.
  • Communications: Resend sends verification and invitation emails.
  • Payments: Stripe processes checkout, subscriptions, invoices, and the customer portal.
  • User-selected AI providers: OpenAI or Anthropic receives the content described below only when an authorised user invokes that connection.
  • Workspace users and recipients: content is visible according to role; reports or invitations are disclosed when a user shares them.
  • Legal and safety: we may disclose information when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or establish legal claims.
  • Business changes: information may transfer as part of a merger, financing, acquisition, reorganisation, or sale, subject to appropriate confidentiality and notice where required.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

5. Bring-your-own AI features

You choose whether to connect an AI provider and supply its API key. The key is encrypted at rest using authenticated encryption and is not returned through the API after storage. When you send an AI request, BlackBeeDevs decrypts the key only to call your selected provider. The request may include your prompt, selected project metadata, up to 20 relevant open findings, and recent conversation context. Responses and conversation history are stored in the workspace.

OpenAI and Anthropic process requests under their own agreements and privacy practices. Their retention, regional processing, and account settings are outside BlackBeeDevs’ control. Do not submit secrets, regulated data, personal information, or proprietary source content unless you and your organisation are authorised to disclose it.

6. Cookies and browser storage

The Service uses a strictly necessary, HttpOnly session cookie to keep you signed in and apply workspace permissions. It is configured with SameSite=Strict and Secure in production. Browser session storage may temporarily hold invitation or CLI return information, and local preferences may retain interface settings such as theme. We do not currently use advertising cookies.

7. Retention and deletion

We retain account and workspace content while the account is active and afterwards only as reasonably necessary to provide requested exports, maintain security and audit records, resolve disputes, enforce agreements, satisfy legal obligations, or complete backup cycles. Verification codes expire after two minutes; ordinary web sessions expire after seven days; invitation links expire after seven days unless replaced or revoked. Audit and AI history remains until deleted through the Service, the owning workspace or account is deleted, or an applicable retention need ends.

Deleting an account removes that user’s data and, when the user owns a workspace, associated operational collections from active application state. Limited records may remain in backups, processor systems, fraud-prevention records, or legally required archives until their normal deletion cycle ends.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; or appeal a decision. California residents may also request categories or specific pieces collected and information about disclosure. We will not discriminate against you for exercising an applicable right.

You can update profile data and delete your account in Settings. For other requests, email hello@blackbeedev.com. We may verify identity and authority before acting. If an organisation controls your workspace, direct your request to it first. You may complain to your local data-protection authority.

9. Security

We use safeguards appropriate to the Service, including TLS in transit, password and token hashing, encrypted user-supplied AI credentials, HttpOnly session cookies, CSRF controls, role-based access, scoped API keys, rate limits, private-network restrictions for scanners, and redirect revalidation. No system is perfectly secure. You are responsible for keeping credentials confidential, granting only necessary access, rotating exposed keys, and using short-lived target credentials.

10. International processing

BlackBeeDevs and its providers may process information outside your country. Those locations may have different data-protection laws. Where required, we use legally recognised transfer mechanisms or rely on providers’ contractual safeguards. Your organisation is responsible for confirming that its selected AI provider and configuration meet its transfer requirements.

11. Children

The Service is intended for developers and organisations and is not directed to children under 16. We do not knowingly collect personal information from children under 16. Contact us if you believe a child has provided information so we can review and remove it.

12. Changes

We may update this policy as the Service or law changes. We will change the date above and provide additional notice for material changes when required.

13. Contact

Privacy requests: hello@blackbeedev.com
Legal notices: hello@blackbeedev.com
Service: cloud.blackbeedev.com

© 2026 BlackBeeDevs · Terms · Data Collection Policy