Skip to content

Privacy Policy

Last updated 27 July 2026

What we collect

  • Account data: your email address and a bcrypt hash of your password. If you sign in with Google we receive your email address and profile name, never your Google password.
  • Usage records: which tool you called, when, and how many units, so we can enforce plan limits and show your usage. Kept 180 days.
  • Files you submit: images and HTML you send for processing, plus the generated output.
  • Scan data for dynamic QR codes: timestamp, IP address, and user-agent of each scan, shown to you as analytics. Kept 12 months.
  • Payment data: handled entirely by Stripe. We store only a Stripe customer reference — never card numbers.

How long we keep files

Files processed synchronously are held in memory and discarded as soon as the response is sent. Files produced by async jobs are stored so you can download them and are deleted automatically after 3 days. We do not use your files to train models, and no human at Toolbeam reviews them unless you explicitly send us one for support.

Cookies and analytics

We store your login token in your browser so you stay signed in — that is required for the service to work. We also use Google Analytics 4 to understand which pages and tools people use. It is configured with IP anonymisation and with advertising and personalisation signals disabled, but it does set its own cookies. You can block them with your browser or an extension without losing any functionality.

Who we share data with

We do not sell your data. We share only what is necessary with the providers that run the service: Stripe for payments, Amazon SES for transactional email, our hosting provider for infrastructure, and Google Analytics as described above.

Your rights

You can access, correct, export, or delete your data. Deleting your account removes your profile and immediately revokes your API keys, so nothing can be called with them again. Dynamic QR codes you created stop being editable but are not erased in the same step — email privacy@toolbeam.app if you want them and their scan history deleted outright, and we will do it within 30 days. Scan history is deleted automatically after 12 months regardless. If you are in the EU or UK you also have the right to complain to your local data protection authority.

Security

Traffic is encrypted with HTTPS throughout — the .app domain is on the HSTS preload list, so browsers refuse unencrypted connections entirely. Passwords are hashed with bcrypt and API keys are stored only as SHA-256 digests, so we cannot recover either in plain text.

Changes and contact

We will update the date at the top when this policy changes and notify account holders of material changes by email. Questions: privacy@toolbeam.app

The data controller is CIRCLEGROUPTECH LTD, registered in England and Wales, company number 13671203.

This policy describes how the platform is built, but it is a template rather than legal advice. If you serve EU users at scale, have counsel confirm your GDPR basis and whether you need a cookie consent banner for Google Analytics.