Beacon

Privacy Policy

Last updated: October 1, 2026

Beacon audits the web page you are looking at and reports what is wrong with it. This policy explains what Beacon collects when you use the Chrome extension and the Beacon portal at beacon.kandr.io, why it collects it, and who it is shared with.

The short version

Beacon reads the page you ask it to audit and sends what it read to Beacon's servers to be analyzed. It stores your account, your sites, and your findings so you can come back to them. Beacon does not sell your data, does not use it for advertising, and does not use it to determine creditworthiness or lending eligibility. It reads a page's content only when you ask it to audit that page.

Who we are

Beacon is operated by Kandr. For any question about this policy or your data, or to exercise any of the rights below, contact info@kandr.io.

What Beacon collects

Content from the pages you audit

When you run an audit, Beacon reads the page in front of you and records what it finds there. That includes:

This content is sent to Beacon's servers and analyzed to produce findings. A copy is stored with the finding so you can review the evidence later. Beacon collects and sends this content only for pages you audit.

Your account

Beacon uses Google Firebase Authentication. When you sign in, either with Google or with an email address and password, Beacon receives and stores your email address, your display name if your sign-in provides one, and an account identifier. Passwords are handled by Firebase Authentication and are never received or stored by Beacon.

Your workspace and its history

Beacon stores what you and the other members of your workspace create: the sites you add and their addresses, crawl settings and results, the policies and scoring settings you change, your content guide and term list, dismissals, ticket submissions, and a record of administrative changes.

Technical and session data

The extension stores your session in your own browser profile so you do not have to sign in on every click. That storage is local to your browser; it is not synced to other devices. When you connect an issue tracker or a repository, Beacon stores the token or identifier that connection needs, encrypted.

What Beacon does not collect

How Beacon uses what it collects

Beacon does not sell your data, does not share it with advertising networks, and does not use it to determine creditworthiness or lending eligibility. Beacon does not use the content of the pages you audit to train models.

Who Beacon shares it with

Beacon uses the following service providers to run. Each receives only what it needs for the function described.

Provider What it does What it receives
Google Firebase and Google Cloud Sign-in, database, file storage, hosting, and the audit service All data described above, stored and processed on Beacon's behalf
Google (Gemini) Evaluates page content against Beacon's policy library The page content being audited
TypeSafe (Jev) Scores the findings for a page The collected page content and the findings for that page
Your own model provider Only if your workspace supplies its own key The page content being audited
Linear, Jira, or GitHub Only the services your workspace chooses to connect What you send them: a ticket's contents, or a request to read a repository

If your workspace stores its own model key, that provider's terms govern the page content sent to it. Beacon additionally discloses data where the law requires it, and to protect the rights and safety of Beacon and its users.

The Chrome extension

One small script runs on web pages as they load. The scripts that read a page are not installed on the sites you visit — they run only on a tab you have asked Beacon to audit.

How long Beacon keeps it

Findings, snapshots, and workspace data are kept until you delete them or ask us to. Deleting a site or a page removes its stored results. Account information is kept while your account exists. If you want your account and its data removed, email info@kandr.io and we will do it.

How Beacon protects it

Data is encrypted in transit and at rest. Access to a workspace's data is enforced by security rules on the server, not only in the interface, and every write goes through an authenticated server function. Credentials your workspace stores are encrypted with a managed key.

Your choices and rights

Children

Beacon is a tool for professional use and is not directed to children under 13. We do not knowingly collect data from them.

Changes to this policy

If this policy changes, the date at the top changes with it. If a change materially affects how your data is handled, we will say so in the product before it takes effect.

Contact

Questions about this policy or about your data: info@kandr.io.