We use identity data to run your account, project content to provide creative tools, and technical and usage data to secure and operate Beancat. We do not sell personal information or use it for targeted advertising. Features you choose may send prompts, files, or outputs to the AI and media providers needed to perform that work.
Scope
This Privacy Policy describes how BeanCat, Inc., a Delaware corporation (“Beancat,” “we,” “us,” or “our”), collects, uses, discloses, and otherwise processes personal information when you visit beancat.ai, use the Beancat application, communicate with us, or otherwise interact with our creative-agent workspace (collectively, the “Service”).
This policy does not govern third-party websites or services that have their own privacy policies. If you use Beancat for an organization, that organization may also control information associated with its projects and members.
Information we collect
Name, email address, verified-email status, profile image, Google account identifier, membership and permission status, and account preferences.
Prompts, chats, agent instructions, project names, uploaded files, images, video, audio, generated results, edits, selections, and associated metadata.
Feature and model usage, tool activity, provider request identifiers, cost estimates, credit balances, credit holds, usage receipts, and audit records.
IP address, browser and device information, session timestamps, request IDs, service logs, errors, diagnostics, and security or abuse signals.
Information you include when you request support, report a problem, respond to a survey, or otherwise communicate with us.
Invitations, shared agent configurations, project access, and other information another authorized user provides about or makes available to you.
Creative content may contain personal information. Please upload another person’s image, voice, likeness, or other data only when you have the right to do so and the processing is appropriate for your use case.
How we use information
We process information to:
- create and maintain accounts, sessions, projects, agents, chats, and files;
- run the models, tools, searches, transformations, and workflows you request;
- store, display, organize, and deliver uploaded and generated assets;
- calculate usage, administer credits, prevent duplicate charges, and audit costs;
- authenticate users, enforce permissions, rate-limit requests, and prevent abuse;
- monitor reliability, diagnose errors, recover interrupted work, and improve the Service;
- respond to support requests and communicate operational or policy changes; and
- comply with law, enforce our Terms, and protect users, Beancat, and others.
Beancat does not currently train its own foundation models on private project content. If our use of private content for model training materially changes, we will update this policy and obtain consent where required.
AI and service providers
Beancat coordinates third-party services to provide text, image, video, audio, transcription, search, storage, and editing capabilities. Depending on the feature, model, and agent configuration you choose, we may transmit relevant prompts, instructions, reference assets, media, or prior conversation context to providers such as Anthropic, OpenAI, OpenRouter, fal.ai, Atlas Cloud, ElevenLabs, Exa, and Shotstack. We use Amazon Web Services for portions of our infrastructure and Google for authentication.
We send providers the information reasonably needed to perform the selected task. Provider handling and retention vary by service and configuration. Some providers create temporary copies; some provider interfaces do not offer Beancat an immediate deletion operation after successful processing. Their processing is also governed by their applicable terms and privacy commitments.
Your choice of agent, model, capability, and referenced assets determines which providers receive content. Do not submit content to a feature unless you are comfortable with the providers needed to perform it.
Google sign-in
Google is the current sign-in provider. Beancat requests only OpenID Connect identity, email, and basic profile scopes. We use that information to verify your identity, create or match your invited account, display account information, and maintain your session. We do not use Google sign-in to access Google Drive, Gmail, Calendar, or other Google product content.
OAuth credentials are handled by the server and are not exposed as application access tokens to the browser. Beancat’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.
Retention
We retain account information and project content while your account is active and for as long as reasonably necessary to provide the Service, preserve project history, resolve disputes, enforce agreements, maintain security, and satisfy legal, accounting, or audit requirements. Different records may have different retention periods.
Deleting or archiving an item in the interface may first mark it as deleted before its bytes and related records are removed. Residual copies may remain temporarily in backups, logs, recovery systems, and provider systems. We may retain de-identified or aggregated information that can no longer reasonably identify you.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including HTTPS in production, server-managed authentication, access controls, private asset storage, bounded signed asset links, and operational logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Keep your Google account secure and contact us promptly if you believe your Beancat account or content has been accessed without authorization.
Your choices and rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information; to object to or restrict certain processing; or to appeal a decision about a privacy request. You may also revoke Beancat’s Google connection through your Google account settings.
To make a request, email privacy@beancat.ai. We may need to verify your identity and authority. Some information may be retained or excluded where permitted by law, including security, fraud-prevention, billing, legal, and backup records. Authorized agents may submit requests where applicable.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Account holders must also satisfy the eligibility requirements in our Terms of Service. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.
International processing
Beancat and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws than your home country. Where required, we use appropriate legal mechanisms for international transfers.
Changes to this policy
We may update this policy as the Service, providers, or legal requirements change. We will post the updated version here and revise the “Last updated” date. If a change is material, we may provide additional notice through the Service or by email when appropriate.
Contact us
Questions or requests about this policy and the privacy practices of BeanCat, Inc. can be sent to: