Privacy Policy | Beeko AI
How Beeko AI handles account data, email and username lookups, public-source results, AI summaries, and your privacy choices.
Last updated: 2026-08-26
This Privacy Policy explains how Beeko AI (also called “Beeko,” “we,” “us,” or “our”) handles information when you use beeko.ai, our email- and username-search reports, APIs, and related services.
What Beeko Does
Beeko checks authorized email addresses against DNS records and a fixed allowlist of quiet public account signals, derives no more than two candidate usernames, and checks those usernames against a bounded set of public profiles using the open-source Sherlock project. Account-existence and username matches are leads, not proof that accounts belong to the same person. Beeko excludes loud checks that notify the target and does not access private accounts, search credential or breach databases, or perform face recognition.
Information We Collect
We may collect:
- Account information: name, email address, authentication method, account preferences, and support communications.
- Search inputs: email addresses or usernames you submit, timestamps, task status, and private report history. Email lookups require authentication. Email addresses are normalized and encrypted before database storage; reports retain a masked address, domain, and keyed hash used for rate limiting and abuse prevention.
- Public-source results: DNS state, platform name, public profile URL, normalized response status, confidence label, and limited public profile fields. We do not intentionally store complete source-page bodies, recovery phone numbers, or unrelated contact fields.
- AI summaries: normalized evidence, masked address, domain, and candidate usernames may be sent to the configured OpenRouter model. The plaintext email address is not sent to the AI model. AI output and model name are stored with the private report.
- Guest identifiers: a random browser identifier used to enforce free limits and restrict access to an anonymous report. It is not used to build an advertising profile.
- Usage and security data: IP address, browser and device information, logs, rate-limit events, and actions needed to prevent abuse.
- Billing information: plan, order, subscription, and transaction identifiers. Stripe processes card details; Beeko does not store full card numbers.
- Cookies and similar technologies: essential session, locale, security, and guest-report cookies. Analytics cookies are used only if the relevant analytics service is enabled.
How We Use Information
We use information to create and secure reports; authenticate users; provide API access, billing, credits, support, and notices; detect abuse and fraud; debug failures; improve reliability; comply with law; and protect users, the public, and our rights.
Search Privacy and Retention
Signed-in reports are associated with your account and visible only to authorized requests for that account. The encrypted email lookup input is erased after a terminal scan result; the masked address, domain, keyed hash, normalized evidence, and AI summary remain until you delete the report or our retention process removes it. You can delete saved reports from search history. Anonymous username previews use a random HttpOnly browser identifier; email lookups are not anonymous.
Deleting a report removes it from normal product access. Limited records may remain temporarily in encrypted backups, security logs, billing records, or legal holds where required. We retain information only as long as reasonably necessary for the purposes described here.
Public Sources and Service Providers
Beeko sends the submitted email address to the specifically allowlisted account providers needed to perform each requested check and queries public DNS through Cloudflare. Candidate usernames are checked against public profile patterns from Sherlock’s reviewed site catalog. Source websites are independent third parties with their own terms and privacy practices. Opening a source link sends your browser directly to that website.
We may use Cloudflare for hosting, databases, queues, storage, DNS, network security, and email routing; OpenRouter and its selected model provider for evidence summaries; Stripe for payments when enabled; and configured authentication, email, support, and analytics providers. These providers process information only as needed to provide their services. We do not sell personal information or share search history for cross-context behavioral advertising.
Legal Bases and Disclosures
Where applicable, we process information to perform our contract with you, pursue legitimate interests in operating and securing Beeko, comply with law, or act on your consent. We may disclose information when required by valid legal process, to investigate abuse, or to protect rights and safety.
International Processing
Our providers may process information in countries other than yours. Where required, we use appropriate contractual or legal safeguards for international transfers.
Security
We use transport encryption, access controls, secret encryption, private account authorization, and operational monitoring. No online service is completely secure. Protect your credentials and notify us if you suspect unauthorized access.
Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or export personal information. You may withdraw consent where processing is based on consent. Use account settings where available or contact support@beeko.ai. We may verify your identity before fulfilling a request.
Children
Beeko is not directed to children under 18. Do not use the service to investigate, profile, or target minors. If you believe a child has provided account information, contact us.
Changes and Contact
We may update this policy as the service or law changes. We will update the date above and provide additional notice when required. For privacy questions or requests, email support@beeko.ai.