Privacy Policy — Beam Audits

Last updated: 17 August 2026

Beam Audits ("the app") is made by CXC Group Limited, a company registered in England and Wales ("we", "us"). This policy explains what data the app handles and where it goes. The short version: your data stays on your device unless you choose to share it.

What the app stores

Everything you create in Beam Audits — audits, item details, photos, client contact details, site addresses, notes and settings — is stored locally on your device in the app's own database. Photos you capture are saved as files inside the app's private storage.

What we collect

Very little, and never your audit content without your say-so. The app has no user accounts and no sign-in, and your day-to-day audit work never reaches our servers. Three things leave your device: an audit's content when you choose to publish it as a Beam Link (see below); subscription receipt checks handled by RevenueCat when the app starts (see Subscriptions); and anonymised crash reports and basic app-stability signals (see the next section). The app does not use advertising, marketing analytics or tracking of any kind.

Crash reports and diagnostics

If the app crashes or hits an unexpected error, it sends a technical crash report to Sentry (Functional Software, Inc. d/b/a Sentry), a crash-reporting service. We host our Sentry account in the European Union (Germany), and our agreement with Sentry incorporates the EU standard contractual clauses and the UK addendum. Before anything is sent, the report is reduced on your device to a strict allowlist of technical fields, such as the type of error, where in the app's code it happened, the app version, iOS version and device model. Your audit content, photos, names, addresses, notes, link details and device name are never included, and we have configured Sentry not to store IP addresses. Crash reports carry a random identifier created by Sentry so repeat crashes from the same installation can be grouped; it is not connected to your audits, your subscription or your Beam Links. Alongside crash reports, the Sentry software also sends basic, anonymous stability signals — counts of app starts and ends, app hangs and terminations by iOS — with the same protections and the same random identifier. We use these reports for one thing: finding and fixing bugs. See Sentry's privacy policy for details.

Camera, microphone and media

Beam uses your camera for photos and video during an audit, and your microphone for the video's audio. You can also add only the photos you select from your library. Captured media is stored in the app's private storage. Embedded location data is removed from photos before they are saved. Media leaves your device only when you choose to include it in a backup or publish it as part of a Beam Link.

Backups

You can export a backup of your audits, photos and videos as a single file. The backup is created on your device and handed to your device's share sheet — you choose where it goes (for example AirDrop, iCloud Drive or email). We never receive a copy. Any service you choose to store a backup in is governed by that service's own privacy policy.

Website launch list

Before launch this website offered a "tell me when it's live" list. Beam launched on 17 August 2026 and the list closed that day; no addresses from it are held.

Business contacts we email (prospect data)

We introduce Beam to UK businesses that survey, clear, clean, fit out or maintain sites — by email, in small volumes, from our own mailboxes. If you have received one of those emails, this is what we hold about you and why.

What we hold: your company's registered and trading names, company number, town and postcode, website, a business email address, and the name of a director or the person the mailbox is addressed to. Nothing else — no browsing data, no tracking.

Where it came from: your company's own website and the Companies House public register. We do not buy lists.

Who we email: limited companies and LLPs only ("corporate subscribers" in the Privacy and Electronic Communications Regulations). We do not email sole traders, partnerships or anyone at a personal address.

Lawful basis: our legitimate interest in telling relevant businesses about a product built for their work (UK GDPR Article 6(1)(f)), balanced against yours — which is why the volume is small, the emails are short and plain, there are no tracking pixels or tracked links, and any reply of "no thanks" stops everything immediately.

How long we keep it: twelve months from our last contact with you, after which the record is deleted or anonymised. If you opt out we keep just enough (your email address) to make sure we never contact you again.

Who processes it for us: our email tooling — Smartlead (sending and reply handling), MillionVerifier (checking an address is live before we send) and Google Workspace (the mailboxes) — under contract, on our instructions.

Your rights: you can object at any time by replying "no thanks", using the opt-out link in any email, or writing to hello@beamaudits.app; we act on it straight away. You can also ask what we hold, ask us to correct or delete it, and complain to the Information Commissioner's Office (ico.org.uk).

Reports

PDF and Excel reports are generated entirely on your device. Sharing a report with a client is your choice, made through your device's share sheet — or as a Beam Link, described below.

Beam Links (shared audit links)

"Beam it" publishes a read-only copy of one audit to a web link you can send to a client. This only ever happens when you tap it. Publishing uploads that audit's content to our sharing service, hosted on Cloudflare: item details and notes, the site address, client and site contact details, access notes (the field the app marks "shown on links and reports"), surveyor and sign-off names — including a handwritten signature if the report has been signed — photos, site videos (including their audio), your company name and logo if you have set them, and the PDF and Excel reports. If you use the "hide client" option, client identity, access notes and sign-off details are left out of the published copy.

You choose how long a link stays live when you publish it — 30, 60 or 90 days — and you can extend a live link from the app, up to a maximum of 90 days from the day it was first published. When a link expires, the published content is deleted. You can revoke a link from the app at any time, which makes it inaccessible immediately. The publish request also carries a random identifier generated by your app installation (not your device's advertising or hardware ID). We use it to prevent abuse of the sharing service and to organise your published links in storage; the same identifier is used to validate your subscription, as described below. Our servers briefly hold the publishing connection's IP address — for about two days — as part of rate limiting. People who view a Beam Link are not tracked, profiled or required to sign in.

Subscriptions

If you purchase a subscription, payment is handled by Apple through your App Store account — we do not see or store your payment details. We use RevenueCat, a subscription management service, to validate purchases; it processes an app-generated identifier (the same random installation identifier used for Beam Links) and purchase receipt data for this purpose. See RevenueCat's privacy policy for details.

Your data, your responsibility

Because your data never leaves your device unless you share or back it up yourself, you are in control of it. Deleting the app deletes all data stored in it. If your audits contain other people's personal information (such as client contact details), you are responsible for handling that information in line with the data protection law that applies to you — including when you publish it as a Beam Link.

Data protection rights

For data stored on your device, use Beam to edit or delete it, or delete the app to remove all local data. For a published Beam Link, revoke the link to make it inaccessible immediately; otherwise its content is deleted automatically when the link expires — 30, 60 or 90 days after publishing, depending on the duration you chose. Our sharing service retains the publishing IP address for about two days for rate limiting; RevenueCat processes the subscription data, and Sentry the crash reports, described above. For access, correction or deletion questions, email hello@beamaudits.app.

Changes to this policy

If a future version of the app adds features that change how data is handled (for example optional accounts or sync), we will update this policy and note the changes here before those features go live.

Contact

CXC Group Limited · Registered in England and Wales no. 14770351 · Registered office: 4 Gordon Smith Close, Aston Clinton, Aylesbury, HP22 5ZW

hello@beamaudits.app