Privacy Policy

Effective date: September 17, 2026

1. Who we are

beejARC is provided by beejAUM Technology Group, Inc., located in New Jersey, United States. This Privacy Policy explains how we handle information when you use beejARC. Questions and privacy requests may be sent to privacy@beejarc.com.

2. Information we process

We process account and authentication information needed to create and secure your access, such as your user identifier, email address and verification status, session information, and account security state.

When you request an analysis, we process the engineering, technical, or business document you submit and the text extracted from it. We also process the resulting findings, risks, recommendations, priority assessment, confidence assessment, evidence relationships, and report presentation needed to return the generated analysis to you.

We process limited operational and security metadata, including generated run and document identifiers, analysis stage and outcome, timestamps and duration, bounded page, character, action, and result counts, retry state, error categories, entitlement and usage status, and technical diagnostics. We do not intend this metadata to contain document text or generated report content.

When you select or purchase a commercial plan, we process the selected plan, entitlement and access status, billing-period state, analysis usage and allowance information, payment and subscription status, cancellation status, and Stripe-associated customer or subscription references where operationally necessary. We do not directly store full payment-card numbers or card security codes; payment-card details are handled by Stripe.

We may maintain records showing that you accepted or acknowledged applicable Terms of Service and Privacy Policy, including the policy versions, acceptance timestamp, and relevant transaction or plan context. We do not collect an IP address, device fingerprint, or user agent specifically for this policy-acceptance record.

3. Default Non-Retention

beejARC uses a Default Non-Retention model for submitted documents and completed analyses. beejARC does not maintain a customer-accessible history of completed analyses, and the application does not intentionally persist submitted document content or completed analysis content after the active request and browser session. You are responsible for printing, downloading, or otherwise saving results that you need to retain.

Limited content-free operational metadata may be retained to control access and usage, maintain security, diagnose reliability, and document whether an analysis succeeded or failed. Current operational records include renewable active-run information, short-lived daily usage counts, and bounded terminal status records. Account status and entitlement records remain while needed to administer access.

Account, entitlement, usage, billing, subscription, cancellation, security, and policy-acceptance records are separate from submitted document and generated report content. These operational and commercial records may be retained while needed to operate an account and administer purchases or subscriptions, and as reasonably necessary for fraud and security, dispute handling, accounting and tax, and legal or regulatory obligations. We do not assign a fixed retention period where one has not been established.

Temporary processing may still occur in application memory, browser state, network transit, hosting systems, security systems, and third-party service infrastructure. Service providers may handle or retain information under their applicable terms, security practices, and legal obligations.

4. AI processing

beejARC sends submitted document text and analysis instructions to OpenAI to generate the requested engineering review. When required by subsequent stages of the analysis workflow, OpenAI may also receive generated or intermediate analysis context, including findings, risks, recommendations, evidence relationships, and related content. Current requests use the OpenAI Responses API with the request option store: false. beejARC does not currently opt in to voluntary sharing of OpenAI API inputs or outputs for model improvement.

These settings do not mean that all provider-side processing or retention is eliminated. beejARC has not obtained or represented that a special provider retention exemption applies. OpenAI may process information according to its applicable API terms, policies, security practices, and legal obligations.

5. Other service providers

beejARC uses Clerk for authentication and account security, Upstash for limited operational and account-control storage, and Vercel for application hosting and runtime processing.

beejARC uses Stripe for payment processing, Checkout, subscription billing, invoices and payment status, operational billing and customer references, cancellation and billing management, and payment-related fraud and security functions. Payment-card details are submitted to and handled by Stripe rather than directly stored by beejARC.

These providers process information as needed to deliver their services and may retain information under their own applicable terms, policies, security practices, and legal or operational obligations.

6. Essential authentication and session technology

beejARC and Clerk use essential authentication and session technologies, including cookies or similar browser storage, to sign users in, maintain authenticated sessions, and protect account and service security. These technologies are necessary for authenticated service operation.

7. Appropriate documents and use

beejARC is intended for ordinary confidential engineering, technical, construction, and business documents that you are authorized to submit. You retain your rights in submitted documents and are responsible for having all ownership, permission, confidentiality, and other authority required to upload and process them.

Unless beejARC expressly authorizes it in writing for a particular use, do not submit specialized sensitive or regulated information, including protected health information, payment-card data, government identification numbers, financial account credentials, export-controlled information, classified information, criminal-justice records, or similarly regulated personal data. Remove unnecessary personal information and secrets before submission.

8. How we use information

We use information to authenticate users, determine account eligibility, process requested analyses, display results, enforce usage and sequencing controls, secure and operate the service, administer plans, payments, subscriptions and cancellations, document policy acceptance, troubleshoot failures, prevent misuse, comply with law, and communicate about service or privacy matters.

beejAUM does not sell personal information or use or share personal information for targeted or behavioral advertising.

9. Security

We use administrative, technical, and operational safeguards designed to protect information, including authenticated access, verified-email and account-state checks, server-side entitlement controls, encrypted network connections, restrictive browser security headers, bounded operational records, and environment separation. No system, transmission, or storage method is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

10. Account deletion

beejARC provides an authenticated mechanism for requesting deletion of your account. When an authenticated deletion request is accepted, applicable beejARC-controlled account information is deactivated and processed for deletion under the service's deletion process, with deletion intended within 48 hours under normal circumstances.

We may retain limited information when reasonably necessary for security, fraud prevention, abuse investigation, legal claims, regulatory or court obligations, billing, accounting, tax, audit, dispute resolution, or enforcement of agreements. Deleting a beejARC account does not necessarily delete records maintained independently by service providers. Stripe and other providers may retain payment, subscription, transaction, security, or other records under their applicable terms and legal or operational obligations. Deletion cannot remove copies you or others printed, downloaded, exported, or otherwise saved outside beejARC.

11. Professional users and age

beejARC is a professional and business service intended only for users who are at least 18 years old. It is not directed to children.

12. Privacy requests

To ask about this policy or request access, correction, or deletion relating to applicable beejARC-controlled account information, email privacy@beejarc.com. We may need to verify your identity and authority before acting on a request.

13. Policy changes

We may update this Privacy Policy as beejARC, our service providers, or applicable requirements change. We will publish the revised policy with an updated effective date and provide additional notice when appropriate.