Privacy Policy
Privacy Policy V2.2 · Beta Version · Version date: 4 September 2026
1. About this Privacy Policy
Project Beacon (“Beacon,” “we,” “us,” or “our”) is a gaming social and connection platform operated from Ontario, Canada. This Privacy Policy explains what personal information Beacon collects, why we collect it, how it is used and disclosed, how long we keep it, and the choices available to members and Beta applicants.
This Policy applies to Beacon’s website, Closed Beta, member features, Beta waitlist, support and safety processes, and related services. Beacon is currently intended for people aged 18 or older.
Because Beacon is an evolving service, features and data practices may change. If we make a material change to this Policy, we will update the effective date and provide notice where required or appropriate.
2. Privacy at a glance
- Beacon does not sell personal information.
- Beacon currently does not use advertising networks, behavioural advertising, marketing pixels, cross-site tracking, or product analytics tools.
- Member profiles are not public on the open web. Profile visibility inside Beacon is controlled by member privacy settings.
- Gamer DNA is optional.
- Favourites are private to the member who creates them, and blocks are not disclosed to the blocked member.
- Private messages are not end-to-end encrypted. Beacon’s ordinary admin interface does not provide a tool for casually browsing private conversations; message content may be preserved for review when a member files a report.
- Deleting an account removes most account and profile information, but does not erase messages already sent to another member or safety evidence that Beacon must retain under the rules described below.
- Beacon uses service providers to operate the platform, including Supabase, Cloudflare, Resend, Google (when Google sign-in is used), and Wikidata/Wikimedia for game-title lookup.
3. Information we collect
3.1 Account and authentication information
To create and secure an account, Beacon collects your email address and authentication information. If you use email and password, your password is handled by our authentication provider and is not stored by Beacon in readable form. If you choose Google sign-in, Beacon receives the email address and authentication identifier needed to link your Google identity to your Beacon account; Beacon does not use Google sign-in to import your Google profile photo, contacts, or other unrelated Google profile information.
3.2 Profile information
Your Beacon profile may include your display name, @handle, About text, country or region, time zone, preferred language, primary and additional gaming platforms, avatar, and privacy settings. Some information is required to complete profile setup, while other fields are optional.
Beacon also stores your overall profile-visibility choice and field-level visibility choices. Depending on your settings, individual fields can be visible to Everyone on Beacon, Connections only, or Only Me. “Everyone” in this context means other authenticated Beacon members who are permitted to view your profile; it does not mean the public Internet.
3.3 Gamer DNA
If you choose to complete Gamer DNA, Beacon collects your answers about gaming motivations, team roles, competitive intensity, social gaming style, communication preferences, pressure style, social openness, genre preferences, availability, and connection goals. Beacon derives trait tags, a synopsis, and an ideal-match description from those answers.
Gamer DNA is optional. We use it to provide your gaming-personality snapshot and to support matching and recommendation features such as People Worth Knowing.
3.4 Games and platforms
Beacon stores games you add to your “Games I’m Playing” list and the platform or platforms you use for those games. This information supports discovery and matching. Game visibility follows your member privacy settings.
3.5 Connections, favourites, blocks and matching information
When you use Beacon’s social features, we store connection requests and relationship status, who initiated the connection, matching information associated with the connection, favourites, and blocks.
Favourites are one-directional and private: the person you favourite is not told that you favourited them. Blocks are also directional and are not disclosed to the blocked member. Beacon uses this information to operate relationships, messaging permissions, safety controls, recommendations and matching.
3.6 Private messages
When Connected members message each other, Beacon stores message content, sender information, timestamps, and thread information. Beacon also stores a short preview of the most recent message so conversation lists can be displayed.
Private messages are not end-to-end encrypted. They are protected by access controls and are transmitted over encrypted connections, but authorized infrastructure administrators or service providers may technically be able to access stored data where necessary to operate, secure or troubleshoot the service.
Beacon’s ordinary admin interface does not provide a feature for browsing members’ private conversations. If a member reports a conversation, Beacon may preserve up to the last 50 messages from that conversation as a frozen evidence snapshot for Trust & Safety review.
3.7 Reports, safety evidence and moderation
If you report a member or conversation, Beacon may collect the report reason, an optional written note, report timestamps and status, and a frozen evidence snapshot. For conversation reports, that snapshot may include up to the last 50 messages. For member/profile reports, it may include the profile information that was visible to the reporting member at the time of the report.
Beacon may also store the moderation outcome, reviewer information, internal administrative notes, and links between a report and resulting enforcement actions. This information is used to investigate reports, enforce Beacon’s rules, protect members, support appeals or review, identify repeat misconduct, and maintain an audit trail.
The reported member is not told who submitted a report. Internal admin notes and moderator identity are not displayed to members through the normal product.
3.8 Suspensions, bans and ban-evasion protection
Beacon stores account-status information and an audit history when an account is suspended, reinstated, banned or unbanned. Records can include reason codes, internal notes, dates, the administrator who took the action, and notification-delivery status.
If a currently banned member deletes their account, Beacon may retain a minimized enforcement record for up to 24 months. Beacon may also retain a one-way keyed cryptographic digest derived from the deleted account’s email address. Beacon does not retain the plaintext email in this ban-evasion record.
When a later signup produces the same keyed digest, Beacon may create a flag for human administrative review. This process does not automatically block or ban the new account.
3.9 Closed Beta waitlist and invitations
If you apply to Beacon’s Closed Beta, we collect your email address, primary platform, confirmation that you are 18 or older, and consent to receive Beta-related communications. You may also choose to provide a preferred name, additional platforms, games, country or region, time zone, and feedback.
Beacon records your Beta status, such as waitlisted, invited, activated, declined or departed. Invitation links use secure single-use tokens. Beacon stores a cryptographic hash of the invitation token rather than the raw token.
Beacon also records the IP address associated with Beta application submissions and invite-token validation attempts for spam, abuse and rate-limit protection.
3.10 Technical and browser information
Beacon’s hosting and security providers necessarily process technical information such as IP addresses and request information when you connect to the service. Beacon deliberately stores IP addresses in its own application database only for the narrow Beta rate-limiting purpose described above.
Beacon stores authentication/session tokens in your browser’s local storage so you can remain signed in. Session storage is used temporarily for Beta invitation processing and for non-personal interface functions such as restoring scroll position. Beacon’s application does not currently use advertising or analytics cookies.
4. How we use personal information
Beacon uses personal information only for purposes reasonably connected to operating, securing and improving the service, including to:
- create, authenticate and secure member accounts;
- create and display member profiles according to privacy settings;
- provide Gamer DNA, matching, discovery and recommendation features;
- operate Connections, favourites, blocks and private messaging;
- administer the Closed Beta, invitations and capacity controls;
- send account, security, Beta, moderation and support communications;
- respond to support, privacy and legal requests;
- investigate reports, enforce Community Standards, manage appeals and protect members;
- prevent spam, abuse, fraud and ban evasion;
- maintain operational and security records; and
- comply with applicable legal obligations and protect Beacon’s legal rights.
5. When we disclose information
Beacon does not sell personal information. We disclose or make information available only where reasonably necessary to operate the service, at your direction, for safety and security, or where required or permitted by law.
5.1 Other Beacon members
Information you place on your profile may be shown to other authenticated Beacon members according to your profile and field-level privacy settings. Connections can see information you have chosen to make visible to Connections. Favourites remain private to you, and blocks are not disclosed to the blocked member.
5.2 Service providers
Beacon currently relies on the following service providers:
| Provider | Purpose | Information involved |
|---|---|---|
| Supabase | Database, authentication and private file storage | Account, profile, Gamer DNA, social, messaging, safety/enforcement data and avatars |
| Cloudflare | Hosting, edge delivery, security and DDoS/bot protection | Web traffic and network-level information such as IP address |
| Resend | Transactional email delivery | Recipient email address, subject and email content needed to send account, Beta and moderation messages |
| Optional Google OAuth sign-in | Authentication exchange, email address and identity information needed for sign-in | |
| Wikidata / Wikimedia | Game-title search and catalogue lookup | Game-search text you submit; Beacon stores the resulting canonical game record, not the search query itself |
These providers may process information in jurisdictions outside Canada under their own infrastructure and contractual arrangements. Beacon’s primary Supabase production database is hosted in the United States (AWS us-east-2, Ohio). As a result, personal information processed outside Canada may be subject to the laws of the jurisdiction where it is processed.
5.3 Legal, safety and business requirements
Beacon may disclose information where reasonably necessary to comply with law, respond to lawful process, protect the rights or safety of members or others, investigate fraud or security incidents, enforce our agreements, or establish, exercise or defend legal claims. If Beacon’s business or assets are reorganized, transferred or acquired, information may be transferred as part of that transaction subject to applicable law.
6. Data retention
Beacon keeps personal information only for as long as reasonably necessary for the purposes described in this Policy, subject to safety, legal and operational requirements. Current automated retention rules include:
| Category | Current retention approach |
|---|---|
| Closed private-message threads | Eligible for deletion 90 days after the thread is closed. Active, never-closed conversations do not currently have an automatic expiry. |
| Reports resolved without enforcement | Eligible for deletion 12 months after review, unless linked to an enforcement action or subject to a retention hold. |
| Reports linked to suspension or ban | Eligible for deletion 24 months after the later of the report review date or relevant enforcement action, subject to retention holds. |
| Deleted-member enforcement tombstones / ban-evasion records | Eligible for deletion 24 months after the most recent relevant event, subject to retention holds where applicable. |
| Beta rate-limit IP/attempt records | Deleted after 90 days. |
| Departed Beta applicants | Deleted 24 months after departure. |
| Declined Beta applicants | Deleted 12 months after the decline date. |
| Waitlisted, invited and activated Beta applicants | Retained while operationally necessary for the Closed Beta lifecycle and access controls. |
A retention hold may pause deletion of certain Trust & Safety records when preservation is reasonably necessary, for example for an active legal, safety or dispute matter. Once the hold is released, the ordinary retention rule applies.
When a declined Beta application is deleted after 12 months, a later application using that email is treated as a new application.
7. What happens when you delete your account
Beacon provides self-service account deletion. Deleting your account removes your authentication account and most information directly associated with your membership, including your profile, avatar files, Gamer DNA, games list, Connections, favourites, blocks, admin notes, and current account-status records, subject to the exceptions below.
Deleting your account does not erase messages you already sent to another member. Those messages remain in the conversation and your sender identity is removed so you appear as a former member. This preserves the other participant’s conversation history and supports safety and evidentiary integrity.
Reports and frozen safety evidence may also remain for the retention periods described above. Direct account identifiers in those records may be removed when the related account is deleted.
If you were an activated Beta member, your Beta record becomes “departed” and may be retained for up to 24 months. If you were currently banned when you deleted your account, Beacon may create the minimized enforcement and keyed-email-digest records described in Section 3.8 for up to 24 months.
8. Your choices and privacy controls
Beacon gives members controls to manage how their information is used and displayed. Depending on the feature, you can:
- view and edit your profile information;
- control overall profile visibility and field-level visibility;
- choose whether to complete Gamer DNA and retake it later;
- manage your games list, Connections, favourites and blocks;
- opt out of being included in recommended Fits;
- report members or conversations;
- delete your Beacon account through Settings; and
- contact Beacon for access, correction or other privacy requests that are not available through self-service controls.
Beacon does not currently provide an automated “download my data” feature. Requests for a copy of personal information or other privacy assistance can be sent to privacy@joinprojectbeacon.com. We may need to verify your identity before fulfilling a request.
9. Security
Beacon uses technical and organizational safeguards intended to protect personal information. These include private storage for avatars, Row Level Security and restricted database functions, server-side permission checks, role-based administrative access, rate limits, secure invitation tokens, and keeping privileged service credentials out of browser code.
No online service can guarantee absolute security. You are responsible for keeping your account credentials secure and for notifying Beacon if you believe your account or information has been compromised.
10. International processing
Beacon is operated from Ontario, Canada, but some service providers process or store information outside Canada. In particular, Beacon’s Supabase production database is hosted in Ohio, United States. Cloudflare, Google, Resend and Wikimedia may also process information through infrastructure in other jurisdictions.
When personal information is processed outside Canada, it may be accessible to courts, law-enforcement authorities or other government bodies under the laws of those jurisdictions.
11. Children and age eligibility
Beacon’s Closed Beta is intended for adults aged 18 or older. Beta applicants must confirm that they are at least 18. If we learn that an ineligible person has provided personal information contrary to our age requirements, we may take steps to remove the account or information as appropriate.
12. Advertising, analytics and marketing
Beacon does not currently sell personal information or use third-party advertising networks, behavioural advertising, cross-site tracking, marketing pixels, or product analytics tools.
Beacon sends required service-related communications, and required Beta-related communications needed to operate the Beta program (for example, your invitation or account activation notices). These continue regardless of the optional preferences described below.
Beacon also offers optional email communications, separate from the above and from each other:
- A general Project Beacon news and product-update preference — for example, new features, community events, and occasional Beacon news — available to members. This preference is off by default and can be turned on or off anytime from Account Settings.
- Occasional Beta-related news or re-engagement messages, sent only to Beta applicants who affirmatively agreed to Beta-related communications when applying.
You can unsubscribe from optional Beta communications or Project Beacon news and updates at any time using the link in those emails or, where available, from your account settings. Unsubscribing from one does not affect the other, and does not affect account, security, or other required service communications. If Beacon later introduces advertising, analytics, or new tracking technologies, we will update our practices and disclosures and obtain consent where required.
13. Changes to this Policy
We may update this Privacy Policy as Beacon evolves, as our service providers or features change, or as legal requirements develop. The current version will identify its effective date. Where a change is material, we will provide additional notice where required or appropriate.
14. Contact Project Beacon
For privacy questions, access or correction requests, or questions about this Policy:
- Privacy & Member Data: privacy@joinprojectbeacon.com
- For account or technical support: support@joinprojectbeacon.com
- For safety concerns or reports: report@joinprojectbeacon.com
- For legal notices or legal inquiries: legal@joinprojectbeacon.com
Project Beacon is operated from Ontario, Canada.