Privacy Policy
Beckon is a small app for letting friends know you are free to hang out. This policy describes exactly what it stores, who can see it, and how to get rid of it. It is written to be read, not to be survived.
Last updated:
The short version. Beckon holds your name, an optional bio, an optional profile photo, and whatever you type into a beckon, including a free-text location, a message, and an optional map pin if you drop one. Your beckons are visible only to people you are connected to; your name, bio and photo are visible to anyone holding your invite link. We do not track you, we run no analytics, we show no ads, and we sell nothing to anybody. You can delete your account, and everything above, from inside the app.
Who we are
Beckon is operated by JustBeckon LLC. If you have a question about this policy, or about data we hold about you, write to [email protected].
What we collect
- How you sign in. You can sign in three ways: with Apple, with a one-time code we email you, or with a passkey. With Sign in with Apple, Apple sends us an account identifier and, on a first sign-in from an iPhone, your name. If you use an email code, the address you type lets our authentication provider send the code — by way of the email delivery service listed below — and recognise you next time. However you sign in, we keep your email address on your account so we can contact you about your account and the service — things like sign-in help, support, security notices, and important service updates. Only we can see it: it is never shown to your friends, and we do not sell it or use it for advertising. A passkey is created and kept on your own device and unlocked with Face ID or your screen lock — we only ever hold its public half, never anything that could sign in as you.
- Your profile. A display name and an optional short bio, both of which you can edit or clear at any time.
- Your profile photo, if you set one. You can pick one from your photo library or take one with the camera. iOS asks your permission first, and Beckon receives only the single image you choose. We never read the rest of your library. It is cropped and shrunk on your phone before it is uploaded, and then stored at a public web address, because that is how your friends' phones fetch it. Treat it as public: anyone holding your invite link can see it, exactly as they can see your name and bio. You can remove it at any time in Settings, and it is deleted when you delete your account.
- Your beckons. When you send a beckon, we store whether you are free, the timeframe, an emoji, and two free-text fields you fill in yourself: a location and a message. Both are optional. Both are visible to your friends. See the warning below.
- A map pin, if you add one. When composing a beckon you can optionally drop a pin on a map, by dragging to a spot, searching for a place, or tapping “locate me” to use your device's current position. Placing a pin is the only thing in Beckon that asks your phone for location access, and it only asks in that moment: your position is read once, when you tap “locate me,” never in the background and never continuously. On Android you may grant either precise or approximate location; Beckon works with whichever you choose and asks for nothing more. When you place a pin, Beckon also looks up and stores its street address, so the friends who can see the beckon can copy it. A pin and its address are visible to exactly the same friends who can see the rest of that beckon, and to no one else. You can remove a pin, or the whole beckon, at any time.
- A repeating beckon's pin, for as long as you keep the repeat. If you set a beckon to repeat, the pin, its street address and the details you typed are saved with the rule itself, so each occurrence can be created from them — the same way a saved address works. That copy lasts as long as the rule does rather than expiring with any one occurrence, and ending the repeat deletes it immediately. If you stop using Beckon entirely, we clear the pin and street address from a repeating beckon after 60 days.
- Your quick replies. When you answer a friend's beckon with one of the preset replies (“I'm down”, “Next time”, “Maybe”), we store which reply you sent on which beckon. Your reply is shown to the friend whose beckon it is, and to friends of yours who can also see that beckon. We keep a reply for about 30 days. For that time the person whose beckon it is can look back at their recent beckons and the replies each one drew, on a page only they can see — including for a beckon they removed. Nobody else sees anything they could not see already.
- Your friends. Who you are connected to, who has a pending request to connect with you (or you with them), and who you have blocked. Opening someone's invite link sends them a request they choose to approve or decline, so a pending connection is a real thing in Beckon. Scanning a code in person, while it is live on their screen, connects you right away. Either way the other person is told, and can remove or block you.
- Friend suggestions. A friend can suggest one of their friends to you as someone to connect with, and you can do the same. We store who suggested whom to whom, and which suggestions you have dismissed, so a dismissed suggestion stays dismissed. The person a suggestion is made to can see it came from you.
- Your friend groups. The names you give your groups (“Close friends”, “Climbing”), which friends you put in each one, and which groups your beckon is currently limited to. Groups are private to you: the people in a group are never told they are in it, and no one else can see your groups or their names.
- A device token for notifications, if you allow them, plus what you have muted: which kinds of notification, and which friends or individual beckons you have silenced. A muted friend is never told. Stored alongside the token: your app version, your operating system version and your device model — so we can tell which build a problem is coming from. None of it is used to track you or shared with anyone.
- Safety reports. If you report someone, or someone reports you, we keep the report. See Safety reports below, because it is the one thing here that outlives your account.
What we do NOT collect
- Your location in the background, or without asking. Beckon reads your device's position only if you tap “locate me” while placing a map pin, and only once, right then. It never tracks you, never watches your location in the background, and never asks for permission to. The typed “location” on a beckon ("The Anchor", "my place") is separate: it is a line of text you write, and always has been.
- Analytics, tracking or advertising. There is no analytics SDK, no advertising identifier, and no third-party tracking of any kind in this app. Nothing you do here is used to follow you across other apps or websites, and nothing is sold or shared with data brokers. (We do collect a crash or error report when something goes wrong — see “Crash and error reports” below.)
- Your contacts or microphone. Beckon never asks for either.
- Anything the camera sees. The camera is used for two things and two things only: taking a profile photo, and reading a friend's invite QR code. When you scan a code, it is decoded on your phone: no image, no video frame, and no camera data of any kind is uploaded, stored or transmitted, ever. All that leaves your phone is the short code the QR stands for: either an invite code — the same one a tapped invite link carries — or a live, in-person code that connects you on the spot. And we never read your photo library: if you set a profile photo, Beckon receives only the one image you choose or take, and nothing else from your library or camera.
Two things worth knowing, plainly
Your beckon message and location are sent as push notifications. When you send a beckon, your friends' phones show it on the lock screen, including the location and message you typed. They travel through Apple's Push Notification service on an iPhone, or Google's Firebase Cloud Messaging on an Android phone, to get there. Do not put anything in a beckon you would not want on someone else's lock screen. A map pin is not part of that lock-screen text (moving a pin alone does not send a new notification), but it is still visible in the app to the same friends as the rest of the beckon.
An invite link reveals your name to whoever holds it. Your invite link has to name you; otherwise the person opening it is being asked to connect with a stranger. That means anyone who has your link, including someone you have blocked, can see your name, avatar and bio by opening it, even without signing in. Blocking someone hides your beckons, stops their notifications, and removes any path back to being your friend. It does not hide your name from someone already holding your link.
Who can see what
- Your beckons: only people you are connected to. Not the public, not other Beckon users, not people who have merely opened your invite link. A beckon whose time is up stops showing you as free, and stays visible under “Earlier today” to the people you share it with — still only people you are connected to — dropping out of that list at the end of the day. We delete the beckon itself about 30 days after you last change it, and in the meantime your recent ones stay visible to you, on a page only you can see. Removing a beckon instead takes it out of their app straight away. A repeating beckon is a rule rather than a single beckon, so it lasts until you end it; see the map-pin note above for what we clear if you stop using Beckon.
- Your name, avatar and bio: your friends, and anyone holding your invite link (see above).
- Your blocks: only you. The other person is never told.
Safety reports
Beckon lets people report a user for harassment, spam, inappropriate content or impersonation. Reporting someone also blocks them. A report records who filed it, who it was about, the reason, anything you chose to write, and a snapshot of the reported person's profile and their beckon at that moment.
Reports are kept for up to 12 months, and they survive the deletion of either account. This is deliberate: without it, someone could abuse another user and then erase the evidence by deleting their account. Reports are readable only by us, never by other users, including the person who was reported, who is never told a report exists.
Moderation records
When we act on a report — reviewing it, removing content, or suspending or restoring an account — we keep a short internal record of the action for up to 12 months, so moderation stays accountable. That record can name the account the action concerned, and, like a safety report, it survives the deletion of that account, for the same reason: so no one can erase what they did, or what was done about them, simply by leaving. If nothing was ever done in connection with your account, there is no such record about you. It is readable only by us.
Crash and error reports
When something in Beckon goes wrong — the app crashes, or hits an error it can recover from — we collect a report so we can fix it. It records the technical details: what failed and where (the error and its stack), and your device model, OS version and app version. These go two places. Most go to Sentry (see below), which holds them without your name, account, email or IP address — it is the app failing, not a picture of you. We also keep a short-lived copy on our own backend for day-to-day triage and, so we can tell one person's reports apart while we investigate, that copy is tagged with your account. It holds nothing else about you, is deleted automatically after 30 days, and is removed when you delete your account. We use all of this only to find and fix problems, never for analytics, advertising or tracking.
Who else touches your data
- Supabase: hosts the database and the backend. Our main processor — everything you store in Beckon lives there.
- Resend: delivers the one-time sign-in code to your inbox. If you use the email sign-in door, Resend receives your email address and that code, so it can send the message — nothing else, and nothing about your friends or your beckons.
- Apple: Sign in with Apple, the Push Notification service that carries notifications to your friends' iPhones, and, only while you have the map picker open, Apple Maps, which draws the map and looks up places and addresses for a pin.
- Google: Firebase Cloud Messaging, which carries notifications to your friends' Android phones — the same content Apple's service carries on an iPhone, including the friend's name and the beckon's message and location. It is used for delivery only, and only for people on Android.
- Cloudflare: serves this page and the invite links, and relays a crash summary from Sentry to the channel below.
- Sentry: receives the crash reports described above — the technical details of a crash, not linked to your identity. Used only to diagnose crashes.
- Discord: private channels where we receive the bug reports and feedback you send us, a summary of each crash, a note when a new account is created — that one includes the name and email address on the account, so we can tell who has joined — and a note when someone files a safety report, so we see it in time to act. The safety-report note carries only the reason chosen, whether it is still open, and a reference number: it does not name who filed it, who it is about, or anything written in the report itself. Only we see any of it; no other user does.
That is the complete list. There is no advertising network and no analytics vendor.
Deleting your account
Settings → Delete account. It removes your profile, your beckons, your friendships, your notification token, your preferences, and any feedback or error reports tied to you; and, if you signed in with Apple, it revokes that grant so Apple no longer lists us. It is immediate and there is no undo. Two things are deliberately kept, both for up to 12 months and both described above: safety reports you are involved in, and, if we ever acted on your account, the moderation record of that action.
Deletion also cannot reach a message we have already received. The notes described above — the note when your account was created, which includes your name and email address; anything you sent us as feedback or a bug report; and crash summaries — are delivered to our private Discord channels, and removing your account does not remove a message that already arrived there. Only we can see those channels. If you want those messages deleted too, write to us and we will remove them.
Children
Beckon is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has an account, write to us and we will remove it.
Changes
If this policy changes in a way that affects what we collect or who can see it, we will update the date at the top and, where the change is significant, say so in the app.