Privacy
Counts, not contents.
Last updated: September 5, 2026
OXbeat reads the vitals of the apps you run (user counts, revenue totals, installs, error counts, CI status) and turns them into one daily readout. This policy says exactly what we collect, what we cannot see, and what we never do. OXbeat is operated by RADLAB LLC, a Wyoming limited liability company (the data controller).
What we collect
- Account: the email address and the identity your sign-in provider returns (email and password, Apple, Google, Microsoft, GitLab or Bitbucket), plus a record of which version of these terms and this policy you accepted and when.
- Workspace configuration: the apps you declare and the provider identifiers that bind them (project ids, bucket names, package names, vendor numbers). Routing context, not content.
- Provider keys: the read-only keys you paste in, stored encrypted in a vault and resolved only for your own workspace at sync time. Where a provider offers no read-only key, OXbeat enforces read-only in code and tells you so before it accepts the key.
- Metrics: one daily aggregate number per metric: user totals, active users, MRR and revenue totals, installs, ratings, ad spend, error counts, runner status, package downloads. Never rows, never events, never customer records.
- Billing: a Stripe customer id, subscription id and plan. Card numbers never reach OXbeat; Stripe holds them.
- Agent tokens and notes: API tokens you mint (stored hashed; the plain token is shown once) and the flag annotations your agents write.
- Support mail: whatever you send to [email protected].
- This website: product analytics through PostHog (page views and clicks, with a visitor profile), and Cloudflare Turnstile on the Ask box for bot protection. Questions typed into the Ask box are answered by a model at Anthropic under our account and are not stored by OXbeat; do not put keys or customer data in them.
- Pre-launch waitlist (closed): email, an optional app count and request metadata (IP, user agent, country) collected before self-serve signup opened. We are deleting these records; email us and yours goes now.
What we cannot see
Every connector's scope is published in the public catalog and they are narrow on purpose: user counts from your database, never row contents; error counts from Sentry, never stack traces; runner status from CI, never your code; revenue totals, never a customer's card or name. Money-adjacent providers are accepted on restricted read-only keys only, and where a provider issues no read-only key you have to acknowledge that before OXbeat will store it. Narration of your own digest runs on your own model key: your numbers go to the provider you chose, under your agreement with them, not through a model account we run.
How we use it
To operate the service: run your daily sync, build your dashboard and digest, deliver it over the channels you choose, bill your plan, answer your support mail, and keep the product working. Nothing else.
Sub-processors
| Cloudflare | this site, the Ask box (Turnstile and the answer service), and the closed waitlist store |
| Vercel | app hosting (app.oxbeat.ai) |
| Supabase | app database, encrypted key vault, and authentication (api.oxbeat.ai) |
| Stripe | billing: checkout, subscriptions, invoices |
| Resend | digest email delivery |
| Anthropic | answers for the Ask box on this site only; never your metrics or digest |
| PostHog | product analytics on this site |
Your connected providers act on your own keys, under your existing agreements with them; connecting them to OXbeat creates no new relationship between you and those services.
Retention
- Metric snapshots: kept while your account exists. Your plan governs how far back you can read (14 days on Free, 90 days on Pro, unlimited above); deleting an app deletes its snapshots from your panel, and deleting your account deletes them all.
- Provider keys: deleted immediately when you disconnect a connector or delete the app, and you can revoke them at the source any time.
- Account: deleted in full when you delete it (below). Billing records Stripe must keep for tax and accounting law stay with Stripe for as long as that law requires.
- Waitlist records: being deleted; on request, immediately.
What we never do
- No selling or renting your data. Ever.
- No ad tracking, no ad SDKs, no data brokers.
- No reselling inference: your digest is narrated on your key, at your provider's price.
- No writes to your providers. The connector contract has no write verb.
Your rights
Delete your account yourself at app.oxbeat.ai/delete (also under Settings in the app). Deletion cancels any subscription, deletes your Stripe customer, destroys every stored key, and erases your workspace; it fails loudly rather than reporting success while anything remains. For a copy of your data, a correction, or any other request, write to [email protected].
Children
OXbeat is for people 13+ (16+ in the EEA). It is a business tool; we do not knowingly collect data from children.
International transfers
We are a US company and our sub-processors run primarily on US infrastructure. If you use OXbeat from elsewhere, your data is processed in the US under this policy.
Changes
Material changes bump the date at the top and get a notice to the email we hold for you, and the app asks you to accept the new version before you continue. We do not silently rewrite this document.
Contact
RADLAB LLC, a Wyoming limited liability company · [email protected]