Privacy Policy

Last updated: 2026-07-28

This Privacy Policy explains how Beatra ("we", "us") collects, uses, shares, and protects your information when you use beatra.ai, docs.beatra.ai, console.beatra.ai, the Beatra API, MCP service, and related skills and tools (together, the "Service"), and the rights you have.

1. Information we collect

We collect only what running the Service requires:

  • Account and sign-in information: your email address; basic Google profile data (identifier and email) when you sign in with Google; your phone number when you sign in by phone; WeChat open identifiers (openid/unionid) when you sign in with WeChat. Verification codes are stored briefly as cryptographic hashes.
  • Sign-in and security records: time, method, IP address, edge-inferred country/region, language preference, and the device name your agent environment reports when connecting (shown in your console device list), used for account security and abuse prevention.
  • Tasks and content: the prompts, reference files, and other inputs you submit; task parameters and status; and the media artifacts generated.
  • Feedback and support content: messages and screenshots you choose to submit in the in-product feedback conversation, and replies from the support team. Email support remains a separate channel and is not added to that conversation.
  • Developer credentials: API keys and agent credentials (stored hashed or encrypted), and the callback URLs and signing keys you configure.
  • Transaction information: orders, subscription state, and the credit ledger. Card numbers and wallet credentials are handled by third-party payment providers; we do not store them.
  • Collected automatically: a session cookie (to keep you signed in), browser language, and IP address with its inferred country/region. Our sites use no third-party advertising or analytics trackers.

2. How we use information

We use the information above to:

  • provide the Service: run your generation tasks, store and deliver artifacts, and maintain your session and preferences;
  • bill and settle: deduct and refund credits, and manage orders and subscriptions;
  • keep the Service secure: sign-in risk control, rate limiting, anomaly detection, and fraud prevention;
  • send service notices, such as sign-in verification codes, to your email;
  • comply with legal obligations.

We do not sell your personal information and do not use it for third-party advertising.

3. How we share information

We share information only as needed to provide the Service, with these categories of third parties:

  • AI model providers: your task inputs are transmitted to the third-party model provider executing the task in order to generate output;
  • infrastructure providers: cloud hosting, object storage and content delivery networks (serving global and mainland-China access respectively), and email delivery;
  • payment and messaging channels: third-party payment providers, and a mainland-China gateway service that relays SMS verification codes, WeChat sign-in, and WeChat Pay for users in mainland China;
  • sign-in providers: the provider of any third-party sign-in method you choose (such as Google or WeChat);
  • legal requirements: where necessary to comply with law, judicial or administrative process, or to protect our or our users' legitimate rights.

4. Cross-border transfers

The Service is hosted outside mainland China. If you use the Service from mainland China, your information is transferred abroad for processing; SMS verification codes, WeChat sign-in, and WeChat Pay are relayed through a domestic gateway service. By using the Service you acknowledge and consent to this cross-border processing. Data in transit is protected with encryption.

5. Retention and deletion

  • Account data is kept for the life of the account; sign-in codes expire after a short validity window and become unusable.
  • You may close your account at any time in console settings. On closure: your sign-in identities are anonymized so no one — including you — can sign in to the account again; API keys and agent credentials are revoked; and any credit balance is zeroed with a ledger entry recording why.
  • Task records, artifacts, and financial ledgers are retained after closure as required for audit and tax purposes; the sign-in information that identifies you personally has been anonymized.
  • In-product feedback conversations, messages, and screenshots remain retained after closure to preserve the support record; sign-in identity is anonymized as described above, and support can no longer reply to the closed account.

6. Your rights

You can view your account information, change your country/region and language preferences, and close your account in console settings. Under applicable law (including personal-information protection laws), you may have rights of access, correction, deletion, restriction of processing, and withdrawal of consent. To exercise them, or for any privacy question, contact [email protected]; we will respond within the timeframe applicable law requires.

7. Security

We protect your information with measures proportionate to risk, including encryption in transit (TLS), hashed storage of verification codes and keys, and least-privilege access. No system is absolutely secure; please keep your sign-in credentials and API keys safe.

8. Cookies

We use only cookies that are necessary for the Service to function (such as the sign-in session). We use no advertising cookies and no third-party analytics trackers.

9. Minors

The Service is intended for users aged 18 and over. We do not knowingly collect personal information from minors; if we learn we have done so, we will delete it promptly.

10. Changes to this policy

We may update this policy from time to time. Updates are published on this page with a revised date; we will provide reasonable notice of material changes.

11. Contact

For any question about this policy or your personal information: [email protected].

This policy is offered in multiple languages; if versions diverge, the English version controls.