1. Scope
This Privacy Policy explains how AstralBeam collects, uses, shares, and retains personal information when you visit our websites, create an account, join an organization, use our hosted services, or communicate with us. An organization may separately control Customer Content processed through its account; contact that organization about its own privacy practices.
2. Information we collect
- Account information: name, email address, email-verification status, profile image received from Google, GitHub, or Gravatar, a hashed password credential when you use email and password, and account identifiers and profile information received from Google or GitHub when you use those sign-in methods.
- Authentication and security information: linked sign-in methods, OAuth scopes and token records, the date and time you accepted the Terms of Service and Privacy Policy at signup, session identifiers, active-organization selection, verification and password-reset records, rate-limit records, and sign-in or other security events.
- Organization information: organization name, membership, role, invitations, settings, and related administrative activity. If an organization invites someone, we collect the invitee's email address and the inviter's account information before the invitee creates or joins an account.
- Customer Content: prompts, messages, files, tool inputs and outputs, agent configurations, and other information submitted through the Services.
- Usage and technical information: IP address, browser and device information, timestamps, session information, diagnostics, security events, and interactions with the Services.
- Communications: messages, support requests, feedback, information submitted through our waitlist or other forms, and account-verification, password-reset, password-change, security, and organization-invitation emails we send.
3. How we use information
We use information to provide and personalize the Services; create and authenticate accounts; verify email addresses; link sign-in methods; maintain and revoke sessions; deliver account, security, password-reset, and organization-invitation messages; manage organizations, memberships, roles, and invitations; process requested agent and tool operations; detect compromised passwords; enforce rate limits; maintain security and prevent abuse; monitor reliability and usage; provide support; comply with law; and improve our products. We may use aggregated or de-identified information for analytics and product development where it cannot reasonably identify you.
4. Authentication and identity providers
When you use email and password, we store a cryptographic hash of the password rather than the plaintext password. We use your email address to verify the account and, when requested or triggered by account activity, to send password-reset and password-change messages. Verification and reset links contain short-lived authentication data and should not be shared.
When you create, change, or reset a password, we screen it against Have I Been Pwned's Pwned Passwords service. The check sends only the first five characters of a SHA-1 hash derived from the password—not the password or its full hash—to retrieve a range of possible matches, which our authentication service checks locally. We use the result only to reject passwords reported as compromised. Learn more about the Pwned Passwords privacy-preserving range search.
When you choose Google or GitHub, the provider authenticates you and returns the account identifier, verified email address, name, profile image, and authorization information permitted by the requested scopes. AstralBeam uses these records to create or authenticate your account and, when the verified email matches, to link sign-in methods to the same account. Stored OAuth tokens are encrypted. We do not request access to Google Drive, Gmail, GitHub repositories, or organization administration through these sign-in flows. Google and GitHub process your interaction with their authorization services under their own privacy policies.
When a profile image is not available from your sign-in method, AstralBeam may request a Gravatar associated with your email address. We normalize the email address and send Gravatar only its SHA-256 hash, not the plaintext address. Because the image is loaded from Gravatar, Gravatar receives the hash and ordinary request information such as your IP address and browser details under Automattic's privacy policy.
GitHub sign-in uses the user:email scope so GitHub can provide a verified address, including when your primary address is private. This scope provides read-only access to your GitHub email addresses; AstralBeam uses the verified address for authentication and account linking, not to access repository content. You can review GitHub's OAuth scope documentation and privacy statement.
5. Google user data
When you choose Google sign-in, AstralBeam requests only the openid, email, and profile scopes. We use the resulting account identifier, name, email address, profile image, and authentication information to create or authenticate your account, display your profile, secure your session, and support account administration.
We do not sell Google user data, use it for advertising or credit decisions, or use it to train generalized AI models. We share it only with service providers acting for us, when needed to secure or operate the Services, when you direct us to, or when required by law. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. How we share information
We may share information with infrastructure, hosting, identity, analytics, communications, payment, model, and tool providers that process it for us; with connected services you choose to use; with organization owners or administrators; to investigate abuse or protect rights and safety; in connection with a business transaction; or when required by law. Authentication-related recipients include Google or GitHub when you choose their sign-in method, Gravatar when we request a fallback profile image, our configured transactional-email provider (such as Amazon Simple Email Service or Resend) for account and invitation messages, and Have I Been Pwned for the partial password-hash range check described above. We do not sell personal information.
7. Cookies and similar technologies
We use cookies and similar technologies that are necessary to authenticate users, maintain sessions, remember preferences, protect the Services, and understand operation and usage. Browser settings may let you block cookies, but essential features may stop working.
8. Retention and deletion
We retain information for as long as needed to provide the Services, maintain security and business records, resolve disputes, and meet legal obligations. Retention depends on the type of information, why it was collected, and applicable requirements. You may request account or personal-data deletion by contacting us. Organization-controlled information may need to be handled by the organization administrator. We may retain limited information where legally required or necessary to protect the Services.
9. Security
We use administrative, technical, and organizational measures designed to protect personal information. These measures include hashed password credentials, encrypted stored OAuth tokens, time-limited verification and reset links, session controls, and authentication rate limits. No system is completely secure, so we cannot guarantee that information will never be accessed, altered, or lost without authorization.
10. International processing
AstralBeam and its service providers may process information in countries other than where you live. Where required, we use appropriate safeguards for cross-border transfers.
11. Your choices and rights
You may update certain profile information, review or revoke active sessions, and manage linked sign-in methods through the Services where those controls are available. You can also revoke AstralBeam's access through Google or GitHub, although doing so does not by itself delete information already held by AstralBeam. Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. Contact us to make a request. We may need to verify your identity and may retain information where an exception applies.
12. Children
The Services are intended for businesses and developers and are not directed to children. Do not use the Services if you lack legal capacity to agree to the applicable terms.
13. Changes to this policy
We may update this policy as our practices or legal requirements change. We will post the revised policy with a new effective date and provide additional notice when required.
14. Contact
For privacy questions or requests, email hello@astralbeam.ai.