Privacy Policy
Last updated: October 1, 2026
Beacon audits the web page you are looking at and reports what is wrong with it. This policy explains what Beacon collects when you use the Chrome extension and the Beacon portal at beacon.kandr.io, why it collects it, and who it is shared with.
The short version
Beacon reads the page you ask it to audit and sends what it read to Beacon's servers to be analyzed. It stores your account, your sites, and your findings so you can come back to them. Beacon does not sell your data, does not use it for advertising, and does not use it to determine creditworthiness or lending eligibility. It reads a page's content only when you ask it to audit that page.
Who we are
Beacon is operated by Kandr. For any question about this policy or your data, or to exercise any of the rights below, contact info@kandr.io.
What Beacon collects
Content from the pages you audit
When you run an audit, Beacon reads the page in front of you and records what it finds there. That includes:
- The page's visible text, headings, links, and button labels
- Image and media elements, and their alternative text
- Form fields, including their labels and placeholder text
- Markup and structure, and the accessibility results for the page
- Measurements taken as the page runs, such as layout shift, element size and position, text and background colours, and whether a consent banner appeared
- The page's URL and title
This content is sent to Beacon's servers and analyzed to produce findings. A copy is stored with the finding so you can review the evidence later. Beacon collects and sends this content only for pages you audit.
Your account
Beacon uses Google Firebase Authentication. When you sign in, either with Google or with an email address and password, Beacon receives and stores your email address, your display name if your sign-in provides one, and an account identifier. Passwords are handled by Firebase Authentication and are never received or stored by Beacon.
Your workspace and its history
Beacon stores what you and the other members of your workspace create: the sites you add and their addresses, crawl settings and results, the policies and scoring settings you change, your content guide and term list, dismissals, ticket submissions, and a record of administrative changes.
Technical and session data
The extension stores your session in your own browser profile so you do not have to sign in on every click. That storage is local to your browser; it is not synced to other devices. When you connect an issue tracker or a repository, Beacon stores the token or identifier that connection needs, encrypted.
What Beacon does not collect
- Your browsing history. Beacon never records the address of a page you did not audit, and never reads a page's content unless you audit it.
- Your passwords.
- Payment or financial information. Beacon does not take payments.
- Your location, your contacts, or any health information.
How Beacon uses what it collects
- To run the audit and produce the findings and fixes you asked for.
- To store your results so your workspace can read them again.
- To authenticate you and enforce your workspace's permissions.
- To operate, secure, and debug the service.
Beacon does not sell your data, does not share it with advertising networks, and does not use it to determine creditworthiness or lending eligibility. Beacon does not use the content of the pages you audit to train models.
Who Beacon shares it with
Beacon uses the following service providers to run. Each receives only what it needs for the function described.
| Provider | What it does | What it receives |
|---|---|---|
| Google Firebase and Google Cloud | Sign-in, database, file storage, hosting, and the audit service | All data described above, stored and processed on Beacon's behalf |
| Google (Gemini) | Evaluates page content against Beacon's policy library | The page content being audited |
| TypeSafe (Jev) | Scores the findings for a page | The collected page content and the findings for that page |
| Your own model provider | Only if your workspace supplies its own key | The page content being audited |
| Linear, Jira, or GitHub | Only the services your workspace chooses to connect | What you send them: a ticket's contents, or a request to read a repository |
If your workspace stores its own model key, that provider's terms govern the page content sent to it. Beacon additionally discloses data where the law requires it, and to protect the rights and safety of Beacon and its users.
The Chrome extension
One small script runs on web pages as they load. The scripts that read a page are not installed on the sites you visit — they run only on a tab you have asked Beacon to audit.
- A measuring script runs on pages as they load. It is about 10 KB. It registers a layout-shift observer and does nothing else: it reads no page content and sends nothing. Page facts are read out of it only when you run an audit. It has to start that early because cumulative layout shift accumulates from the first paint, and a measurement started later reports a zero that means "not measured" rather than "the page did not move."
- The scripts that read a page are not installed on sites you visit. The collector and the tools are injected into one tab only, after you open the side panel there and start an audit, using the access your click on the Beacon icon grants. Nothing reads a page's content before that point.
- Page content goes only to Beacon's own servers. Every script is bundled inside the extension; it downloads and runs no remote code.
- Beacon can ask for standing access to one site, named in the browser's own prompt. It asks for that one site only, and only when a re-run is refused for lack of access. It never asks for access to every site.
- It never modifies the pages it audits.
How long Beacon keeps it
Findings, snapshots, and workspace data are kept until you delete them or ask us to. Deleting a site or a page removes its stored results. Account information is kept while your account exists. If you want your account and its data removed, email info@kandr.io and we will do it.
How Beacon protects it
Data is encrypted in transit and at rest. Access to a workspace's data is enforced by security rules on the server, not only in the interface, and every write goes through an authenticated server function. Credentials your workspace stores are encrypted with a managed key.
Your choices and rights
- Disconnect an issue tracker or repository at any time from your settings.
- Remove a stored model key at any time from your settings.
- Sign out to clear the session held in your browser.
- Email info@kandr.io to request a copy of your data, to correct it, or to have it deleted.
Children
Beacon is a tool for professional use and is not directed to children under 13. We do not knowingly collect data from them.
Changes to this policy
If this policy changes, the date at the top changes with it. If a change materially affects how your data is handled, we will say so in the product before it takes effect.
Contact
Questions about this policy or about your data: info@kandr.io.