BeanPool Icon BeanPool
How It Works The Rules Features Get Started

Privacy Policy

Last Updated: April 1, 2026

1. Zero Knowledge & Decentralization

BeanPool is a peer-to-peer (P2P) localized protocol natively bypassing centralized tracking silos. Our systems are mathematically verifiable, functioning without a central corporate authority tracking your personal data. All cryptographic keypairs (your Ed25519 identity) are generated and stored securely within your device's hardware SecureStore / Secure Enclave. If you choose our encrypted SSO cloud backup, your private key shard is encrypted client-side before upload, ensuring no central operator can access your identity or funds.

2. 4-Tier Location Privacy

Your physical home address is never broadcast in plain text. BeanPool provides four location privacy tiers: Ghost (no GPS at all — you drop a pin by hand), Post-Only (a coordinate saved once, when you post), Zone (your position offset by up to ~2km), and Live (real-time, foreground only). You can participate in marketplace discovery and trade coordination without exposing your exact residence.

3. Data Collection Restrictions

We do not capture analytical telemetry, behavior-tracking metrics, or third-party marketing metadata. Your application communicates directly with the community nodes that you explicitly join and trust. Any marketplace Needs or Offers you create are broadcast strictly to the specific community ledger tied to your cryptographic callsign.

4. Account Eradication & Data Portability

You retain complete control to erase your identity at any point via the Settings -> Reset / Wipe Identity option. Deleting your local keys renders all your historical transactions cryptographically untamperable and your local identity permanently closed.

5. Moderation & Safety Compliance

Because the platform enables users to broadcast public Needs and Offers within neighborhood networks, we enforce strict client-side blocking and reporting tools. Verified participants can sever, block, and report inappropriate content, which transmits signed cryptographic flags directly to community moderators to maintain safe, healthy local exchanges.

6. Member-Connected Channels & Platform Data (TikTok, Instagram & Video Feeds)

Members may optionally connect their external publishing accounts (such as TikTok, Instagram, YouTube, SoundCloud, or RSS feeds) to syndicate their public posts into the community Pulse feed. Connecting a platform is entirely voluntary and member-initiated.

When connecting an account via OAuth (TikTok or Instagram):

  • Device-Side Token Storage: You authorize your account directly with the platform provider. Platform OAuth access and refresh tokens are stored exclusively on your own device in secure hardware storage. Access tokens are never stored on or held by the community node database.
  • Limited Scope & No Private Data Access: BeanPool requests only the basic public profile permissions needed to verify channel ownership (such as username and public identifier) and list public videos or posts. The system does not access, read, or store your private messages, direct messages (DMs), follower or following lists, or private/unlisted content.
  • What the Node Stores: When public posts are syndicated to the feed, the community node stores only public post metadata: the platform name, your channel identifier and member public key, the platform post identifier, the canonical post URL, the public post title or caption snippet, the preview thumbnail image URL, the publication timestamp, and your selected category.
  • No Media Hosting: Audio, video, and image media are never downloaded, copied, or re-hosted on the community node. Content is embedded and played directly through each platform's official player or external link.
  • 30-Day Retention & Scrubbing: Feed items are retained for a 30-day window. After 30 days, expired items are automatically pruned. When an item is pruned or deleted, the node records a tombstone deletion timestamp and immediately scrubs the post URL, title, and thumbnail URL to NULL, permanently erasing that data from the database.
  • Disconnecting & Deleting Channels: You can disconnect an OAuth account at any time in the app, which immediately deletes the stored access token from your device and clears verification on the node (existing imported items remain until manually deleted or pruned after 30 days). If you delete a channel entirely, the channel link and handle are immediately scrubbed to NULL and all associated imported feed items are scrubbed from the node.

Contact Administrator

For protocol inquiries or privacy concerns regarding your specific local community node, please contact your local node operator or email [email protected].

BeanPool Icon BeanPool

Decentralized mutual credit & federated community exchange.

GitHub YouTube Reddit How It Works Getting Started The Rules Child Safety Privacy Policy Terms of Service

Open source under MIT license. Made with love by communities, for communities.