Last Updated: September 18, 2026
BeanPool is a peer-to-peer (P2P) localized protocol natively bypassing centralized tracking silos. Our systems are mathematically verifiable, functioning without a central corporate authority tracking your personal data. Your Ed25519 keypair is generated on your own device and never leaves it. Where it is kept differs by app, and we would rather say so than round it up: on the phone apps it is held in the operating system's secure storage (Android Keystore / iOS Keychain, via SecureStore), and you can put an optional biometric lock on the app itself; in the browser app it is held in that browser's own local database on your device, which is not hardware-protected. Your 12-word recovery phrase is the only recovery path that depends on nobody, and it is the only one the browser app has.
Sign-in recovery is custodial, by design. If you link an Apple, Google, Facebook or GitHub sign-in on the phone app, your community's node keeps one half of your recovery seed in its own database and the other half sealed to that sign-in account. Together they can rebuild your account for anyone who passes that provider's sign-in, which means the operator of your community's node is able to restore your account. We chose that deliberately: it is the difference between a way back in and none at all for members who lose a phone. If you do not want anyone but you to hold a way in, do not link a sign-in account, and keep your 12 words safe. Those halves live on that node's disk, and they die with it — they are not held by us.
BeanPool does not track your location. There is no background location tracking of any kind, and the app never follows or records where a member is; the phone apps ask for location only while you are using them.
Location exists in BeanPool only as a pin you place yourself, on a post, an enterprise or an event. You can use your device's location once, at the moment you place that pin, or drop the pin by hand anywhere on the map. Enterprise and event pins can be marked Approximate, which rounds the coordinate to roughly 100 metres before it is saved, so a pin near home need not be your front door.
Pins are public within your community. Anyone who can open your community's map can see them, which is what makes local discovery work — so place a pin where you are willing to be found, and use Approximate when it is at someone's house.
We do not capture analytical telemetry, behavior-tracking metrics, or third-party marketing metadata. Your application communicates directly with the community nodes that you explicitly join and trust. Any marketplace Needs or Offers you create are broadcast strictly to the specific community ledger tied to your cryptographic callsign.
You retain complete control to erase your identity at any point via the Settings -> Reset / Wipe Identity option. Deleting your local keys renders all your historical transactions cryptographically untamperable and your local identity permanently closed.
Because the platform enables users to broadcast public Needs and Offers within neighborhood networks, we enforce strict client-side blocking and reporting tools. Verified participants can sever, block, and report inappropriate content, which transmits signed cryptographic flags directly to community moderators to maintain safe, healthy local exchanges.
Members may optionally connect their external publishing accounts (such as TikTok, Instagram, YouTube, SoundCloud, or RSS feeds) to syndicate their public posts into the community Pulse feed. Connecting a platform is entirely voluntary and member-initiated.
When connecting an account via OAuth (TikTok or Instagram):
NULL, permanently erasing that data from the database. From that moment the node stops serving the item's cached preview image. The cached image goes with the item on every path that removes it — deleting a single post, deleting a channel, deleting your account, the automatic retention pruning, the inactivity prune, and an operator takedown — and is deleted from the node's memory and disk at that moment, not on its next request.NULL and all associated imported feed items are scrubbed from the node.Members can post an event to their own community or to one of its groups. The community node stores what you type into the event — its title and description, the start and end times, the place name, the map pin you drop, any photos, and the private note for people going — together with each RSVP: which member marked themselves Going or Interested, and when. The host sees who has replied. Members marked Going can see each other in the event chat. Everyone else sees only the counts.
For protocol inquiries or privacy concerns regarding your specific local community node, please contact your local node operator or email [email protected].