Legal

Privacy Policy

How we collect, use, and protect your personal information.

Last updated: March 1, 2026

Contents

  1. 01Introduction
  2. 02Information We Collect
  3. 03How We Use Your Information
  4. 04Information Sharing
  5. 05Data Retention
  6. 06Cookies & Storage
  7. 07Security
  8. 08Your Rights
  9. 09Children's Privacy
  10. 10Changes
01

Introduction

BetaSpotter ("we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use betaspotter.com.

By using BetaSpotter you agree to this policy. If you do not agree, please do not use our service.

02

Information We Collect

Account information

  • Name and email address
  • Username
  • Password (bcrypt-hashed — we never see the plaintext)
  • Optional profile data: bio, website, Twitter handle, avatar

Activity data

  • Products you upvote, apply to, or submit
  • Feedback you write for betas
  • Applications you send or receive
  • Notifications read/unread state

Technical data

  • IP address (rate-limiting only, not stored long-term)
  • Browser and device info
  • Server logs retained for 30 days
03

How We Use Your Information

  • Create and maintain your account
  • Match Spotters with relevant beta products
  • Send transactional emails: verification, application updates, feedback alerts
  • Enforce rate limits and prevent abuse
  • Improve the platform via aggregate usage patterns
  • Respond to support requests

We do not sell your data or use it for advertising.

04

Information Sharing

  • Founders see your username, bio, and expertise when you apply to their beta
  • Your founder profile (name, username, avatar, bio) is visible to Spotters on listed betas
  • Service providers: Resend (email), Railway and Vercel (hosting) — under data processing agreements
  • Legal obligations: when required by law or to protect safety
05

Data Retention

Data is retained while your account is active. On deletion:

  • Profile data deleted immediately
  • Submitted feedback anonymised (not deleted — founders rely on it)
  • Server logs purged within 30 days
06

Cookies & Storage

  • We use localStorage (not cookies) to store your JWT refresh token — cleared on logout
  • No third-party tracking or advertising cookies
  • No Google Analytics or similar cookie-based tools
07

Security

  • Passwords hashed with bcrypt (cost factor 12)
  • All traffic encrypted via TLS
  • Access tokens expire in 15 minutes; refresh tokens rotate on each use
  • Database not publicly exposed

Found a vulnerability? Email security@betaspotter.com.

08

Your Rights

You may have the right to access, correct, delete, or export your data. Most corrections can be made in Settings. For other requests, email hello@betaspotter.com with subject "Privacy Request" — we respond within 30 days.

09

Children's Privacy

BetaSpotter is not intended for anyone under 13. If you believe we have collected data from a child, contact us and we will delete it promptly.

10

Changes

We may update this policy. Significant changes will be emailed and the "Last updated" date will change. Continued use after changes constitutes acceptance.

Questions? Email us at hello@betaspotter.com

PrivacyTermsAbout