Privacy Policy
Beanstalk's Governance Studio - Beanstalk Web Solutions LLC · Effective: January 2026 · Governing Law: Missouri, USA
Short version: We collect only what is strictly necessary to authenticate you and manage concurrent sessions. We do not collect, transmit, or store any content from the websites you audit. Your audit data stays on your machine.
1. Who We Are
Beanstalk Web Solutions LLC is a US LLC operating Beanstalk's Governance Studio, a professional desktop application for digital quality and accessibility assessment. We are the data controller for the limited personal information described in this policy.
Contact: beanstalkwebsolutions.com
2. What We Collect
| Data | Why We Collect It | Where Stored |
| Email address | Account authentication via Firebase | Google Firebase (our project) |
| Device identifier | A locally-generated UUID stored on your machine to identify your device for concurrent session tracking. Never tied to hardware identifiers. | Your machine only (userData folder) |
| Session metadata | Device hostname, OS platform, app version, session start time, last active time. Used to enforce the 5-user concurrent session limit. | Google Firestore (our project) - deleted within 15 minutes of app close |
| Authentication session token | Firebase-issued token to keep you signed in between app launches. | Your machine only (userData folder) |
3. What We Do NOT Collect
- Audit content and results - Websites you audit, violations found, reports generated, and scan data are stored locally on your machine only. None of this is transmitted to Beanstalk Web Solutions LLC servers.
- Website credentials or headers - Authentication headers you enter for auditing password-protected sites are used only for the duration of that audit session and are never written to disk or transmitted to us.
- Payment information - Billing is handled externally via QuickBooks. We do not store payment card details or banking information.
- Browsing history - We do not track which websites you audit or how often.
- Usage analytics - We do not track which features you use, how long you use the app, or any behavioural data.
- Crash reports - We do not automatically collect crash data or error reports.
4. How We Use What We Collect
- Email address: Used solely for authentication (signing in) and sending password reset emails. We do not send marketing emails unless you have separately opted in.
- Device identifier + session metadata: Used solely to enforce the concurrent session limit (maximum 5 simultaneous users per account). Session records are automatically deleted when you sign out or within 15 minutes of the app closing.
- Authentication token: Used to keep you signed in between app launches. Stored locally, used to verify your session with Firebase on each app start.
We do not use any collected data for advertising, profiling, or sale to third parties.
5. Third-Party Services
| Service | Purpose | What They Receive | Their Privacy Policy |
| Google Firebase | Authentication and session database | Email address, session metadata, authentication tokens | policies.google.com/privacy |
| ZeptoMail (Zoho) | Password reset emails only | Your email address (only when reset is triggered) | zoho.com/privacy |
We do not use advertising networks, analytics platforms (Google Analytics, Mixpanel, etc.), or any other third-party data services.
6. Data Retention
- Session records (Firestore): Automatically deleted when you sign out. If the app closes without sign-out (crash, power loss), records are automatically deleted within 15 minutes via the heartbeat expiry mechanism.
- Firebase Auth account: Your email address is retained in Firebase Auth for as long as your subscription is active. When your account is deleted by an administrator, your Firebase Auth record is removed.
- Local session file: Stored on your machine at
%APPDATA%\beanstalk-governance-studio\wqs_session.json. Deleted when you sign out. You can manually delete this file at any time.
- Local device ID: Stored at
%APPDATA%\beanstalk-governance-studio\wqs_device.json. Persists across sessions to maintain a stable device identity. You can delete this file - a new ID will be generated on next launch.
7. Data Security
- All communication with Firebase and Firestore uses HTTPS/TLS encryption in transit
- Firebase Auth tokens are short-lived (1 hour) and automatically refreshed
- No audit data or report content is ever transmitted to Beanstalk Web Solutions LLC servers
- The Software executable uses integrity verification to prevent tampering
- We do not have access to your local files, audit results, or report content
8. Your Rights
- Access: You may request confirmation of what personal data we hold about you (limited to email and session metadata as described above).
- Deletion: You may request deletion of your account and associated data by contacting us. We will remove your Firebase Auth account and any remaining Firestore session records.
- Correction: If your email address changes, contact us to update your account.
- Portability: Given the minimal nature of data we hold, formal data export is not applicable. Your audit data is already on your own machine.
To exercise these rights, contact us at beanstalkwebsolutions.com
9. Children's Privacy
Beanstalk's Governance Studio is a professional tool intended for use by adults in a business context. We do not knowingly collect data from persons under 18 years of age.
10. International Users
Beanstalk's Governance Studio is operated from the United States. By using the Software, you consent to the processing of your limited personal data in the United States and in the locations where Google Firebase operates its infrastructure (Google Cloud, nam5 multi-region). We take appropriate measures to ensure data is handled in accordance with this Privacy Policy regardless of location.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or via a notice in the Software. The effective date at the top of this document will reflect the most recent revision. Continued use of the Software after changes constitutes acceptance of the revised policy.
12. Governing Law
This Privacy Policy is governed by the laws of the State of Missouri, United States, with jurisdiction in St. Louis, Missouri.
13. Contact
For privacy-related questions, requests, or concerns, please contact Beanstalk Web Solutions LLC at beanstalkwebsolutions.com