BeanPool Icon BeanPool
How It Works The Rules Features Help Get Started

Privacy Policy

Last Updated: September 18, 2026

1. Your Keys, and What Recovery Costs You

BeanPool is a peer-to-peer (P2P) localized protocol natively bypassing centralized tracking silos. Our systems are mathematically verifiable, functioning without a central corporate authority tracking your personal data. Your Ed25519 keypair is generated on your own device and never leaves it. Where it is kept differs by app, and we would rather say so than round it up: on the phone apps it is held in the operating system's secure storage (Android Keystore / iOS Keychain, via SecureStore), and you can put an optional biometric lock on the app itself; in the browser app it is held in that browser's own local database on your device, which is not hardware-protected. Your 12-word recovery phrase is the only recovery path that depends on nobody, and it is the only one the browser app has.

Sign-in recovery is custodial, by design. If you link an Apple, Google, Facebook or GitHub sign-in on the phone app, your community's node keeps one half of your recovery seed in its own database and the other half sealed to that sign-in account. Together they can rebuild your account for anyone who passes that provider's sign-in, which means the operator of your community's node is able to restore your account. We chose that deliberately: it is the difference between a way back in and none at all for members who lose a phone. If you do not want anyone but you to hold a way in, do not link a sign-in account, and keep your 12 words safe. Those halves live on that node's disk, and they die with it — they are not held by us.

2. Location: You Place Every Pin

BeanPool does not track your location. There is no background location tracking of any kind, and the app never follows or records where a member is; the phone apps ask for location only while you are using them.

Location exists in BeanPool only as a pin you place yourself, on a post, an enterprise or an event. You can use your device's location once, at the moment you place that pin, or drop the pin by hand anywhere on the map. Enterprise and event pins can be marked Approximate, which rounds the coordinate to roughly 100 metres before it is saved, so a pin near home need not be your front door.

Pins are public within your community. Anyone who can open your community's map can see them, which is what makes local discovery work — so place a pin where you are willing to be found, and use Approximate when it is at someone's house.

3. Data Collection Restrictions

We do not capture analytical telemetry, behavior-tracking metrics, or third-party marketing metadata. Your application communicates directly with the community nodes that you explicitly join and trust. Any marketplace Needs or Offers you create are broadcast strictly to the specific community ledger tied to your cryptographic callsign.

4. Account Eradication & Data Portability

You retain complete control to erase your identity at any point via the Settings -> Reset / Wipe Identity option. Deleting your local keys renders all your historical transactions cryptographically untamperable and your local identity permanently closed.

5. Moderation & Safety Compliance

Because the platform enables users to broadcast public Needs and Offers within neighborhood networks, we enforce strict client-side blocking and reporting tools. Verified participants can sever, block, and report inappropriate content, which transmits signed cryptographic flags directly to community moderators to maintain safe, healthy local exchanges.

6. Member-Connected Channels & Platform Data (TikTok, Instagram & Video Feeds)

Members may optionally connect their external publishing accounts (such as TikTok, Instagram, YouTube, SoundCloud, or RSS feeds) to syndicate their public posts into the community Pulse feed. Connecting a platform is entirely voluntary and member-initiated.

When connecting an account via OAuth (TikTok or Instagram):

  • Device-Side Token Storage: You authorize your account directly with the platform provider. Platform OAuth access and refresh tokens are stored exclusively on your own device in secure hardware storage. Access tokens are never stored on or held by the community node database.
  • Limited Scope & No Private Data Access: BeanPool requests only the basic public profile permissions needed to verify channel ownership (such as username and public identifier) and list public videos or posts. The system does not access, read, or store your private messages, direct messages (DMs), follower or following lists, or private/unlisted content.
  • What the Node Stores: When public posts are syndicated to the feed, the community node stores only public post metadata: the platform name, your channel identifier and member public key, the platform post identifier, the canonical post URL, the public post title or caption snippet, the preview thumbnail image URL, the publication timestamp, and your selected category. The node also keeps a cached copy of each post's preview image, described below.
  • Preview Images Only — No Video or Audio Hosting: So that the feed loads on slow connections, and keeps working after a platform's image link expires, the community node fetches each post's preview thumbnail image and keeps a cached copy, which it can serve to the feed itself. Only still images are cached (JPEG, PNG, WebP, GIF or AVIF, at most 2 MB each), in memory (up to 20 MB, cleared when the node restarts) and on the node's disk (up to 100 MB in total, with the least recently viewed images removed first when that limit is reached). Cached images are not copied to other nodes. Both the web app and the phone app load preview images through the node, so your device does not contact the platform's image servers when it shows a preview; if the node cannot supply an image, the card shows a plain platform placeholder instead. Video and audio are never downloaded, copied, or re-hosted on the community node: content is played through each platform's official player or opened via an external link.
  • Retention & Scrubbing: The node keeps the 20 most recently published items from each connected channel. Items beyond those 20 are automatically pruned, typically within minutes of newer posts arriving; items are not removed on age alone. Curated learning content that BeanPool supplies to every node is exempt from this limit and contains no member data. When an item is pruned or deleted, the node records a tombstone deletion timestamp and immediately scrubs the post URL, title, and thumbnail URL to NULL, permanently erasing that data from the database. From that moment the node stops serving the item's cached preview image. The cached image goes with the item on every path that removes it — deleting a single post, deleting a channel, deleting your account, the automatic retention pruning, the inactivity prune, and an operator takedown — and is deleted from the node's memory and disk at that moment, not on its next request.
  • Disconnecting & Deleting Channels: You can disconnect an OAuth account at any time in the app, which immediately deletes the stored access token from your device and clears verification on the node (existing imported items remain until you delete them or the channel, or until newer posts from the same channel push them out of the 20 kept). If you delete a channel entirely, the channel link and handle are immediately scrubbed to NULL and all associated imported feed items are scrubbed from the node.

7. Events, RSVPs & Event Chat

Members can post an event to their own community or to one of its groups. The community node stores what you type into the event — its title and description, the start and end times, the place name, the map pin you drop, any photos, and the private note for people going — together with each RSVP: which member marked themselves Going or Interested, and when. The host sees who has replied. Members marked Going can see each other in the event chat. Everyone else sees only the counts.

  • The private note: shown only to the host and to members marked Going. It is never part of a public listing.
  • The event chat: open to the host and everyone marked Going. It is not end-to-end encrypted, unlike a direct message: the node stores these messages in a form it can read, so that the host can remove a message and so that membership can follow the RSVPs. Your node's operator can read an event chat. The app says so on the chat screen.
  • It stays in your community: an event is always local. The event, its RSVPs, the private note and the chat are never sent to another community's node — they stay on your own node and in that node's own backup.
  • Thirty days after the event ends: the RSVPs, the chat messages and the private note are deleted from the node. The event post itself remains, inactive, as other finished posts do.

Contact Administrator

For protocol inquiries or privacy concerns regarding your specific local community node, please contact your local node operator or email [email protected].

BeanPool Icon BeanPool

Decentralized mutual credit & federated community exchange.

Help Centre GitHub YouTube Reddit How It Works Getting Started The Rules Child Safety Privacy Policy Terms of Service

Open source under MIT license. Made with love by communities, for communities.