Policies
This page applies only to BeeBuzz, the hosted service we operate at beebuzz.app. It explains how BeeBuzz handles personal data, account access, device registration, push delivery, hosted billing status, and the limited cookies required to run the service.
The BeeBuzz source code is separately licensed for self-hosted use. If you self-host BeeBuzz, you control your own deployment, infrastructure, storage, retention, and compliance.
Last updated: September 1, 2026
Questions? Contact us or email hello@beebuzz.app
Privacy Policy
Who we are
BeeBuzz is operated by Luca Corbo, an individual developer based in Italy.
For data protection purposes, Luca Corbo is the controller of personal data processed through the hosted BeeBuzz service operated at beebuzz.app.
In this page, "BeeBuzz", "we", "us", and "our" refer to Luca Corbo as the operator of that hosted service.
You can reach us at hello@beebuzz.app for privacy or data protection questions.
Our approach
BeeBuzz is built to keep data collection narrow.
We do not sell personal data. We do not use advertising trackers on BeeBuzz. We only keep the data needed to run the hosted service: account data, device data, delivery data, billing-status data, and limited operational data.
BeeBuzz is privacy-first, but not metadata-free. Even when notification content is end-to-end encrypted, the hosted service still needs limited metadata to authenticate users, route notifications, enforce limits, operate subscriptions, and prevent abuse.
Information we collect
Depending on how you use BeeBuzz, we may store:
- your email address for sign-in, account access, hosted plan access, and support
- basic account records such as your user ID, account status, plan status, and paired devices
- session records and essential cookies used to keep you signed in securely
- device names you choose and Web Push subscription details used to deliver notifications
- public encryption keys used for end-to-end delivery on paired devices
- API tokens, token metadata, topic configuration, and usage records needed to operate the hosted service
- delivery metadata needed to route messages, remove invalid subscriptions, enforce limits, retry delivery, and debug delivery problems
- limited operational logs and IP-based security data used for abuse prevention, rate limiting, security, reliability, and debugging
- limited billing-status data received from our payment provider, such as customer ID, subscription ID, order ID, plan status, renewal status, cancellation status, and related billing events
BeeBuzz does not intentionally store full payment card details or complete billing records. Payments and billing records are handled by our payment provider.
Messages and delivery
BeeBuzz supports two delivery models.
Server-trusted delivery
In server-trusted delivery, BeeBuzz can process notification payloads and attachments in order to send them to your paired devices.
This mode is used for standard app, webhook, JSON, and multipart delivery paths where BeeBuzz receives the notification content before dispatch.
End-to-end encrypted delivery
In end-to-end encrypted delivery, the sender encrypts the notification payload before sending it to BeeBuzz. BeeBuzz stores and forwards opaque ciphertext, not plaintext message bodies.
In this mode, BeeBuzz cannot read the original encrypted notification body during normal server-side operation.
However, end-to-end encryption does not remove all metadata. BeeBuzz still processes account records, API tokens, topics, device registrations, public encryption keys, delivery state, timestamps, temporary attachment or envelope records, and other metadata required to operate the hosted service.
End-to-end encrypted delivery also does not protect against a compromised endpoint, malicious browser runtime, malicious browser extension, or an actively compromised BeeBuzz server serving malicious client code. BeeBuzz should not be treated as a secure messenger.
Attachments
BeeBuzz supports temporary attachments.
Attachments are stored only for a limited time and are retrieved using opaque tokens. In server-trusted mode, BeeBuzz may process plaintext attachments before encrypting and storing them for delivery. In end-to-end encrypted mode, BeeBuzz stores the encrypted blob without inspecting the original plaintext.
Attachment limits and retention periods may vary by plan or change as the service evolves. BeeBuzz is designed for short-lived notification delivery, not permanent file storage.
Hosted billing and payments
Paid hosted plans are processed by Creem.
Creem acts as the Merchant of Record and payment provider for BeeBuzz paid hosted plans. Creem handles checkout, payment processing, billing details, taxes where applicable, invoices, subscriptions, renewals, cancellations, fraud checks, chargebacks, and transaction records on its own systems.
When you buy or manage a paid hosted plan, Creem may collect and process personal data needed to complete the transaction, manage your subscription, comply with legal obligations, prevent fraud, and maintain billing records. This may include your email address, name, billing address, payment details, order details, tax information, and customer portal data.
BeeBuzz may receive limited billing-status data from Creem so we can activate, maintain, suspend, or cancel hosted plan access. BeeBuzz does not receive or store your full payment card details.
Creem's handling of payment, billing, customer portal data, and related cookies or security technologies is governed by Creem's own buyer terms and privacy policy.
For billing, invoice, payment method, cancellation, chargeback, or payment issue questions, use the Creem customer portal or Creem support flow. For BeeBuzz account access, hosted service issues, or refund requests, contact us at hello@beebuzz.app.
Why we process your data
We process personal data for these purposes:
Service delivery
We process data to create and maintain your account, keep you signed in, pair devices, deliver notifications, provide hosted plan access, enforce plan limits, and operate the core BeeBuzz service. This is necessary to perform our contract with you and provide the hosted service you request.
Billing status
For paid hosted plans, we process limited billing-status data from Creem to activate access, verify subscription status, handle renewal or cancellation events, and keep account entitlements in sync. This is necessary to perform our contract with you and manage your paid hosted plan.
Security and reliability
We process limited data for abuse prevention, rate limiting, security logging, debugging, fraud prevention, and service reliability. We rely on our legitimate interests in protecting and operating the service.
Legal compliance
Where required, we may process or retain limited information to comply with legal obligations, respond to lawful requests, handle disputes, or establish, exercise, or defend legal claims. We rely on compliance with a legal obligation and our legitimate interests in defending legal claims.
We do not currently rely on consent as a legal basis. If that changes in the future, for example if we add optional analytics or marketing emails, we will update this policy and request consent where required before processing.
Third-party services
BeeBuzz uses third-party services where needed to operate the hosted service.
Creem
Creem is used for hosted plan checkout, payment processing, billing, tax handling, subscription management, invoices, renewals, cancellations, fraud checks, chargebacks, and transaction records.
Web Push providers
Browser and platform vendors operate the push infrastructure required to deliver notifications to your devices. Web Push providers such as Google, Mozilla, Apple, and other browser/platform vendors may process technical delivery data required to transport push notifications.
GlitchTip
GlitchTip is used for error monitoring and debugging unexpected service failures. It may process limited technical metadata related to requests and server errors.
BeeBuzz is configured not to intentionally send message contents, email addresses, API tokens, attachment tokens, or other sensitive data to this service.
Resend
Resend is used to send account emails such as sign-in, access-related, and service-related messages. Your email address and basic email delivery metadata are processed by Resend when those messages are sent.
International transfers
Some third-party services used by BeeBuzz, such as Creem, Resend, GlitchTip, and browser push providers, may process data outside the European Economic Area.
Where applicable, those transfers rely on an adequacy decision, Standard Contractual Clauses, or other transfer safeguards made available by the relevant provider in its privacy or data processing terms.
Data retention
We keep data for as long as it is needed to operate BeeBuzz.
Account, plan-status, API token, topic, and device data are kept while your account is active.
Session data is kept until the relevant session expires or is invalidated.
Temporary delivery records, raw event records, attachment blobs, and envelope records are kept only while needed for delivery, expiry, retry, debugging, or abuse prevention.
Per-account usage summaries may be kept to provide usage history, enforce limits, understand hosted service load, and prevent abuse.
Operational logs are kept for a limited period for security, reliability, and debugging.
Billing-status records received from Creem may be kept for as long as needed to manage hosted access, handle account questions, resolve billing disputes, comply with legal obligations, prevent fraud, or establish, exercise, or defend legal claims. Creem may retain billing and transaction records according to its own legal and operational requirements.
If you request account deletion, we will delete the personal data associated with your BeeBuzz account unless we must retain limited information for legal compliance, security, abuse prevention, billing disputes, or legal claims.
Your rights
Under applicable data protection law, you may have the right to:
- access the personal data we hold about you
- request correction of inaccurate data
- request deletion of your account and associated data
- request restriction of processing
- request data portability
- object to processing based on legitimate interests
- lodge a complaint with your local data protection supervisory authority
To exercise these rights for BeeBuzz hosted account data, contact us at hello@beebuzz.app.
BeeBuzz does not currently provide a self-service account deletion button. We may need to verify your identity before acting on a request, and we will respond within the time required by applicable law.
For payment, invoice, chargeback, or billing-record requests, use the Creem customer portal or Creem support flow. For refund requests related to BeeBuzz hosted access, contact us at hello@beebuzz.app.
Required data
A valid email address is required to create and access a BeeBuzz hosted account. Without it, we cannot provide the hosted service.
If you use a paid hosted plan, billing information required by Creem is also necessary to complete checkout and maintain your subscription.
Automated decision-making
BeeBuzz does not use automated decision-making or profiling with legal or similarly significant effects.
We may use automated rate limiting, abuse prevention, subscription status checks, and security controls to protect the service.
Your choices
You can:
- remove paired devices from your account
- delete or rotate API tokens
- cancel a paid hosted subscription through the Creem billing flow
- contact us to request deletion of your BeeBuzz account and associated data
- contact us to request a refund review for BeeBuzz hosted access
- self-host BeeBuzz if you want full control over storage, infrastructure, and retention
Changes to this policy
We may update this Privacy Policy as BeeBuzz evolves. Changes will be posted on this page with an updated "Last updated" date.
Terms of Service
Scope
These terms apply only to the hosted BeeBuzz service we operate at beebuzz.app.
The BeeBuzz source code is separately licensed under AGPL-3.0-only for self-hosted use. Self-hosted deployments are not operated by BeeBuzz, and these hosted service terms do not apply to your own self-hosted instance.
Acceptance
By requesting access, signing in, using the service, creating API tokens, pairing devices, sending notifications, or purchasing a hosted plan, you agree to these terms.
If you use BeeBuzz on behalf of an organization, you confirm that you are authorized to accept these terms for that organization.
Hosted service
BeeBuzz is a hosted notification service for private push notifications, device pairing, API/webhook delivery, and optional end-to-end encrypted delivery.
The hosted service is intended for individual users, developers, technical users, and small-scale personal or project workflows.
BeeBuzz is not an enterprise service. It does not include dedicated support, guaranteed response times, custom support, professional services, or an uptime SLA.
Self-hosting
BeeBuzz can also be self-hosted under its open-source license.
If you self-host BeeBuzz, you are responsible for your own deployment, infrastructure, configuration, security, backups, storage, retention, compliance, and user support.
The paid hosted plan supports use of the BeeBuzz-hosted service. It does not restrict your ability to self-host BeeBuzz under the applicable open-source license.
Account access
You must provide a valid email address that you control in order to access your hosted BeeBuzz account.
You are responsible for maintaining access to that email address and for keeping your sessions, API tokens, paired devices, and local device state secure.
You are responsible for all activity performed through your account, API tokens, topics, and paired devices.
If you believe your account, token, or paired device has been compromised, you should revoke affected tokens, remove affected devices, and contact us if needed.
Paid hosted plans
BeeBuzz may offer paid hosted plans.
Paid hosted plans provide access to hosted BeeBuzz features and limits shown at checkout or on the pricing page. Unless stated otherwise, paid hosted plans are subscription-based and renew automatically until canceled.
Plan names, pricing, limits, and included features may change over time.
A paid hosted plan is for hosted service access. It does not include dedicated support, consulting, custom development, guaranteed response times, enterprise support, or an uptime SLA.
Payments, billing, and Creem
Payments for paid hosted plans are processed by Creem.
Creem acts as the Merchant of Record and payment provider for BeeBuzz paid hosted plans. Creem handles checkout, payment processing, billing details, taxes where applicable, invoices, subscriptions, renewals, cancellations, fraud checks, chargebacks, and transaction records on its own systems.
By purchasing a paid hosted plan, you also agree to the applicable Creem buyer terms, checkout terms, privacy policy, and customer portal terms.
Creem may provide BeeBuzz with limited subscription and billing-status information so we can activate, maintain, suspend, or cancel hosted plan access.
For billing, invoice, payment method, cancellation, chargeback, or payment issue questions, use the Creem customer portal or Creem support flow.
For BeeBuzz account access, hosted service issues, or refund requests, contact us at hello@beebuzz.app.
Cancellation and refunds
You may cancel a paid hosted subscription through the Creem billing flow.
Unless stated otherwise at checkout or required by applicable law, cancellation stops future renewals but does not automatically refund the current billing period. You will normally keep access until the end of the paid billing period.
Refund requests are reviewed case by case unless a specific refund policy is shown on the product page or required by law. If you have a problem with a subscription or hosted service access, contact us first at hello@beebuzz.app.
Payment disputes, chargebacks, or provider-level claims may also be handled through Creem or your payment method provider under their rules.
Nothing in these terms limits any mandatory consumer rights that apply in your country of residence.
Acceptable use
You agree that you will not use BeeBuzz to:
- send unlawful, abusive, harassing, deceptive, harmful, or malicious content
- send spam or unsolicited bulk notifications
- distribute malware, phishing content, credential-harvesting content, or harmful links
- abuse Web Push infrastructure, browser vendors, or third-party services
- overload, disrupt, probe, scan, attack, or attempt to bypass BeeBuzz systems
- evade rate limits, plan limits, access controls, billing controls, or abuse-prevention systems
- use stolen credentials, stolen API tokens, compromised devices, or unauthorized accounts
- interfere with other users or the operation of the hosted service
- use BeeBuzz for emergency, medical, life-safety, or other time-critical notifications where failure or delay could cause harm
You are responsible for the notification content you send through BeeBuzz and for complying with the laws and policies that apply to that content.
Service limits and retention
BeeBuzz may apply limits to messages, topics, API tokens, devices, attachments, request size, retention, delivery rate, webhook usage, and other hosted service resources.
Limits may depend on the plan, technical capacity, abuse-prevention needs, or product changes.
We may rate-limit, reject, delay, drop, or degrade requests that exceed limits or threaten service reliability.
BeeBuzz is designed for short-lived notification delivery, not permanent message or file storage. Attachments, envelopes, delivery records, and encrypted blobs may expire automatically after a limited period.
You should not rely on BeeBuzz as a durable archive.
End-to-end encryption
BeeBuzz supports end-to-end encrypted delivery for compatible clients and paired devices.
In end-to-end encrypted mode, BeeBuzz stores and forwards opaque ciphertext and does not inspect the original encrypted notification body during normal server-side operation.
End-to-end encryption protects notification content against normal server-side access and passive storage compromise, but it does not eliminate all trust in the hosted service.
BeeBuzz still processes metadata needed for account access, routing, devices, topics, delivery, rate limiting, and abuse prevention.
End-to-end encryption does not protect against compromised devices, malicious browser extensions, malware, compromised endpoints, or an actively compromised BeeBuzz server that serves malicious client code or manipulates recipient keys.
You should not use BeeBuzz as a secure messenger or as the only protection layer for highly sensitive, regulated, emergency, or life-safety workflows.
Availability
BeeBuzz is provided on an "as available" and "as is" basis.
We do not guarantee that BeeBuzz will be uninterrupted, timely, secure, error-free, or compatible with every browser, device, network, operating system, or Web Push provider.
Delivery depends on third-party browser, platform, network, and push infrastructure. Notification delivery can fail, be delayed, be blocked by device settings, be affected by browser restrictions, or be limited by platform vendors.
BeeBuzz is not intended for emergency, life-safety, medical, security-critical, or other time-critical notifications.
Our rights
We may operate, maintain, update, modify, limit, suspend, or discontinue the hosted service or specific features.
We may rate-limit, suspend, block, or terminate access when needed to protect the service, enforce these terms, enforce plan limits, respond to misuse, comply with legal obligations, or protect other users.
We may change hosted features, limits, infrastructure, providers, pricing, or plan structure as BeeBuzz evolves.
Where reasonable, we will try to avoid disrupting paid hosted access during an active billing period. However, we may act immediately when required for security, abuse prevention, legal compliance, service integrity, or third-party provider requirements.
Termination
You may stop using BeeBuzz at any time.
If you want your BeeBuzz account deleted, contact us at hello@beebuzz.app.
We may suspend or terminate your access if you violate these terms, exceed acceptable use, fail to maintain a valid subscription where required, create legal or security risk, or if continued access would harm the service or other users.
Account deletion or termination may not automatically delete records that must be retained for legal compliance, security, abuse prevention, billing disputes, or legal claims.
Liability
To the extent permitted by applicable law, BeeBuzz and its operator are not liable for indirect, incidental, special, consequential, exemplary, or punitive damages, including loss of profits, loss of data, loss of business, loss of goodwill, service interruption, failed notification delivery, delayed delivery, or inability to use the service.
To the extent permitted by applicable law, our total liability for claims relating to the hosted service is limited to the amount you paid for BeeBuzz hosted access during the 12 months before the event giving rise to the claim.
Nothing in these terms excludes or limits liability where it cannot be excluded or limited under applicable law.
Governing law and disputes
These terms are governed by the laws of Italy.
Any dispute arising from or relating to these terms or your use of BeeBuzz shall be submitted to the exclusive jurisdiction of the courts of Italy, unless mandatory consumer protection rules in your country of residence provide otherwise.
Changes to these terms
We may update these Terms of Service as BeeBuzz evolves.
Changes will be posted on this page with an updated "Last updated" date. Continued use of BeeBuzz after changes take effect means you accept the updated terms.