HoneyBeacon Privacy Policy

Version 1.5 · 8 September 2026

Who is responsible for your information

HONEYBEACON LIMITED, company number 17440812, is the controller for the personal information described here. Our registered office is 5 Semaphore Road, Guildford, GU1 3PS, United Kingdom. Contact hello@honeybeacon.app for privacy questions, support, complaints or to exercise your rights.

This is a privacy notice, not a contract or a request to waive your rights. Our Terms of Use explain the service agreement. This notice covers the HoneyBeacon app, optional cloud and family features, our website and early-access or beta forms, and information we receive to administer Kickstarter rewards.

The essentials

Core focus sessions, Screen Time blocking, schedules, rewards and Wake alarms operate on your device. Optional cloud accounts support backup, Family Hive and Bee Together. The updated launch app does not send third-party product analytics or session recordings and does not use AI text generation. Setup answers stay on your device unless you separately choose to share your own answers for adult research.

Family and Bee Together features share information with the people you join. Family, Bee Together and hive photos are stored in private object-storage buckets. Authorised members receive short-lived signed URLs to view them. Anonymous public bucket access is disabled. A URL can still be copied from a group display, shared by a recipient or retained in a cache, and replacing or removing a photo cannot recall copies someone has already made. Prefer an illustration instead of a face photo for children. Do not upload a child’s photograph or identifying image without considering that visibility.

Information used on your device

We process your focus settings, schedules, permitted-app selections, session history, Honey, streaks and reward progress to provide the functions you select. Apple’s Family Controls and Screen Time frameworks use opaque selection tokens. We do not receive a readable installed-app inventory for advertising. Device Activity reports show permitted usage insights through Apple’s protected reporting facilities.

Location and Bluetooth permissions allow your phone to detect a HoneyBeacon or a partner phone for proximity features, including background detection where enabled. We do not collect a GPS route history. Relevant session or presence status may be shared with a household or Bee Together group through the cloud. Turning off these permissions prevents the associated proximity functions from working.

The camera scans pairing QR codes. The photo picker supplies images you select for profiles or sharing. Local notifications communicate session events; optional remote notifications support group features. Wake uses alarm permission and local alarm settings on supported versions of iOS. Device permissions can be changed in iOS Settings. They are separate from any consent to optional research or marketing.

Short operational logs, local preferences and identifiers help the app function and diagnose faults. Device credentials and a migration identifier may be stored in Keychain. None of these local operations requires you to share optional research answers.

Optional accounts, Family Hive and Bee Together

When you sign in with Apple, we process the identifiers and any account information Apple supplies, our user identifier, profile and reward information, display name, device migration identifier and the information needed to restore your account. We do not receive your Apple password or full payment-card details.

Family Hive processes household membership, organiser and member roles, invitations, agreed supervision settings, schedules, session requests and responses, and group progress. Bee Together processes circle membership, invitations, agreed session windows and relevant status or proximity coordination. Push tokens allow us to deliver requested service notifications.

Other members can see information needed for these features, such as your chosen name and picture, shared progress, session or request status and supervision settings. A Beekeeper is a product role, not proof of parental responsibility. Adults must not use the app to coerce or secretly monitor others. Please read the Family privacy information before joining a group.

Family, Bee Together and hive photos are stored in private object-storage buckets and shown to authorised members via short-lived signed URLs. Anonymous public access to those buckets is disabled. A URL can be copied from a group display, shared by a recipient or retained in a cache. Replacing or removing a photo cannot recall copies someone has already made. The updated app refuses to load legacy public object paths once signed URLs are in use.

Setup answers and optional research

Answers about goals, approximate daily phone use, household type and commitment personalise your experience locally. Skipping does not upload optional answers. In Privacy & legal / Optional research settings, adults aged 18 or over can choose to send their own setup answers, app version and submission time to improve HoneyBeacon. The choice is off by default and is not required to use or pay for the app. Do not use this option to submit a child’s answers.

Turn the option off to stop future research uploads. This does not undo processing that was lawful before withdrawal. Contact us about answers already submitted. Some earlier or unsigned-in submissions are not attached to an account; if we cannot reasonably identify a record, we will explain this rather than collect extra identifiers solely to link it to you.

Website, messages and Kickstarter

For early access, we use the email address you provide to send the launch updates you requested. Beta applications may also include city/country and household information to organise testing. Optional newsletters and offers require a separate choice. You can unsubscribe or email us at any time. Essential replies, beta administration and reward-fulfilment messages are kept separate from promotional subscriptions.

Our website and service providers process technical connection information, such as IP address and request logs, to deliver and protect their services. Invite URLs can contain a code; treat that code as private. Any optional website cookies or analytics must be explained and controlled at the website collection point. The app’s analytics setting does not control Framer’s website services.

If you back our Kickstarter campaign, Kickstarter provides the information needed to administer your pledge and fulfil rewards, such as your name, contact details, reward selection and delivery details. We use this for campaign administration, fulfilment and support. A pledge does not automatically subscribe you to unrelated marketing. Kickstarter and its payment providers have their own privacy notices. Included 12-month membership starts when you redeem your code in the app; it is not an automatic App Store renewal.

Why we process information

We rely on legitimate interests to provide the local functions you choose, protect the service, respond to general enquiries, and enable proportionate participation in family features where a contract with the individual is not appropriate. Those interests are providing the requested focus tool and safeguarding users; we must balance them against your rights, particularly a child’s interests.

We rely on contract to provide the account and paid services requested by the person who enters the service agreement, administer purchases and fulfil campaign commitments. Essential service messages form part of those services. We rely on consent for optional adult research and requested promotional emails. We rely on legal obligation for records the law requires us to keep, and legitimate interests to establish, exercise or defend legal claims.

Providing account, purchase or delivery details may be necessary to provide the feature or fulfil the reward you request. Without those details we cannot provide that particular service. Optional research and marketing information is not a condition of using core features. We do not ask you for health diagnoses or other sensitive information; avoid putting these in reward names or support messages unless needed for your request.

Children and families

HoneyBeacon supports family use, including teenagers. There is no minimum age for local focus tools, subject to Apple’s platform requirements. A parent or legal guardian should arrange and supervise a child’s use and be involved in setting up optional cloud and paid services. An in-app Beekeeper label does not verify age or legal authority. Declared Age Range APIs are prepared but not live product controls in this build.

We explain sharing and supervision to members, keep optional research off, do not use advertising tracking or AI text in this launch app, and do not ask children to opt into research or marketing. Where processing relies on consent and the law requires a parent’s permission, we must obtain the necessary parental consent. We do not claim that this notice itself verifies a parent, that an Apple permission prompt establishes parental responsibility, or that the app guarantees a child’s safety.

If you believe a child’s information has been provided without appropriate authority, contact hello@honeybeacon.app. We will investigate and take appropriate action. Parents’ requests must also take account of the child’s own rights and maturity.

Who receives information and international processing

Supabase provides cloud authentication, databases, storage and server functions. The project’s saved connection configuration points to Supabase’s eu-west-1 region in Ireland. Framer provides the website and associated forms. GoDaddy provides the domain and Microsoft 365 email for hello@honeybeacon.app (confirm the exact GoDaddy / Microsoft 365 service label in admin if needed). Their subprocessors or support teams may process information in other countries. We check processor terms and applicable international-transfer arrangements for the services we use. Contact us for information about recipients, processing locations and applicable safeguards.

Where UK data is transferred to a country without an applicable adequacy arrangement, the transfer must have a lawful safeguard, such as the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with any required assessment. An EU hosting region alone does not rule out international access.

Apple independently processes information for its platform, Sign in with Apple and App Store services. Kickstarter independently operates its crowdfunding platform. Other household or circle members and sharing destinations receive information you choose to share with them. We may disclose information where required by law or for a business transfer with appropriate protection.

PostHog was used in earlier builds. It is disabled in the updated launch app, including replay. We do not send new app events to it. Existing records remain subject to applicable retention and erasure obligations. No Google Gemini or OpenAI text requests are made by this launch app.

How long information is kept

Ordinary local information remains until you clear it or remove the app. Keychain, shared containers or device backups may retain some information according to their lifecycle and your device settings. Signing out or deleting a cloud account does not automatically clear local Honey and settings.

Cloud account and membership information is kept while needed to provide the account or group service. On a valid deletion request, we remove the account and associated information without undue delay, with a target of 30 days for completing associated erasure, unless a specific legal requirement or valid exception applies. We explain any exception rather than keeping everything indefinitely. Backup copies must expire under the provider’s applicable backup schedule and must not be restored into active use without reapplying deletion requests.

Optional research answers are retained for up to 12 months. Rate-limit identifiers are retained for up to 24 hours. Closed routine support enquiries are retained for up to 12 months. Early-access details are reviewed when the launch invitation programme ends and removed within 12 months after the final launch invitation unless you have separately subscribed to ongoing updates. Beta application details are kept for up to 12 months after the beta programme ends.

For ongoing marketing subscriptions, we retain contact details until you unsubscribe or the list is closed; a minimal suppression record may be retained to honour your opt-out. Accounting and transaction records that we are legally required to hold are retained for the applicable statutory period, normally six years from the end of the relevant company financial year. Specific dispute records may be retained for the relevant claim period. We review whether information is still necessary; a lack of deletion requests is not a reason to retain it indefinitely.

Your rights and account deletion

Depending on the processing and applicable law, you can request access, correction, erasure, restriction or portability, withdraw consent and object to processing based on legitimate interests. You can object to legitimate-interests processing, and you can stop direct marketing at any time. Contact hello@honeybeacon.app. We may need proportionate information to verify a request. We normally respond within one month and explain any lawful extension.

In the app, use Settings → Cloud backup → Delete account to start account deletion. This does not cancel an Apple subscription: manage that separately in your Apple subscription settings. It does not erase Honey or settings already on your phone. Sign in with Apple token revocation is attempted where configured; email us if you cannot use the in-app route or need help with associated information. A parent is not automatically entitled to every detail of a child’s account; we consider authority and the child’s rights.

You can complain to the Information Commissioner’s Office at https://ico.org.uk or contact us first. We do not make solely automated decisions producing legal or similarly significant effects about you. Blocking and subscription checks carry out the app functions you request.

Security and changes

We use security measures appropriate to the information and risks, including encrypted connections and access controls. Photos use private storage with short-lived signed URLs for authorised members, as explained above. No service is perfectly secure; protect your device, account and invite codes.

We update this notice when practices change and provide prominent information about material changes. New optional processing requiring consent will not begin simply because you continue using the app.