Who helps Beaamprovide the service.

Every third party in the path, what it actually receives, and where. Not a generic vendor list — the specific data each one sees.

How to read this

A subprocessor list is only useful if it says what each provider receives. Several below never see your monitoring data at all: Vonage sees a phone number and a sentence, Polar sees a billing identity and never your infrastructure. Listing them together without that distinction would be technically complete and practically useless.

ProviderPurposeWhat it receivesLocationDPA
CloudflareApplication and marketing hosting, edge security, the scheduled work that drives collection, and object storageRequest logs and structured diagnostics. No credentials, alert destinations or raw telemetry are logged.Global edgeStandard ToS; DPA available
SupabaseAuthentication and the control-plane database — your account, organizations, integrations, services, incidents and alertsIdentity, encrypted integration credentials, monitoring configuration and historyUnited States (us-east-1)Available and accepted
TinybirdTelemetry storage for OpenTelemetry metrics you push to BeaamMetric samples, expiring after 30 daysManaged serviceAvailable
ResendEmail — alerts, the daily heartbeat, and account mail such as confirmation and password resetYour email address and the alert content sent to itUnited StatesAvailable
LoopsLifecycle email — the welcome message, onboarding nudges and product updates. Never alerts, which stay on a separate provider and a separate sending domain.Your email address, and where you got to in setup: which onboarding milestones you have reached, your plan, how you first found Beaam, and when you signed up. No monitoring data, service names, incident details or credentials.United StatesAvailable
VonageSMS alert delivery (Solo plan)Your phone number and the alert textUnited States, global carrier deliveryAvailable
ExpoMobile push notification deliveryDevice push tokens and notification contentUnited States, global deliveryStandard terms
PolarMerchant of record — checkout, subscriptions, invoicing and taxBilling identity and payment records. Beaam never sees your card details.European Union / United StatesStandard merchant-of-record terms
Amazon Web ServicesEmail delivery for the independent watchdog only — deliberately a different provider from the main alert pathThe founder's contact address and watchdog alert contentAustralia (ap-southeast-2)Standard terms
AnthropicAI incident explanations — used only if your organization turns them on (off by default)When enabled, a short incident evidence summary: affected service names, timings, and detected changes. No raw metrics, credentials, or personal data; not used for training.United StatesAvailable
PlausibleTraffic analytics for the beaam.app marketing site only — never the applicationPage URL, referrer, and coarse browser, OS and country. Cookieless, with no cross-site identifier and no IP address stored. Signed-in application activity is not sent here.European UnionAvailable
Google AnalyticsOptional analytics for the public beaam.app marketing site and completed account signupsAfter explicit consent in the EU/EEA, UK and Switzerland, and unless declined elsewhere: public page URL, referrer/campaign, device/browser information, coarse location, scrolls, outbound clicks, downloads and one completed-signup event. No email address or signed-in product activity is sent.Global / United StatesGoogle Ads Data Processing Terms
Google AdsOptional measurement of whether a Beaam advertisement led to a completed account signupAfter explicit consent in the EU/EEA, UK and Switzerland, and unless declined elsewhere: the ad click identifier, page URL, device/browser information, and a signup conversion event. Beaam does not enable enhanced conversions and does not send your email address or signed-in product activity.Global / United StatesGoogle Ads Data Processing Terms

Notable choices

The watchdog uses a different email provider on purpose. If Beaam's alert path fails because Resend is down, an alert about that failure sent through Resend would not arrive. The watchdog runs on a separate cloud account and sends through AWS, so the thing telling you Beaam is broken does not depend on the parts of Beaam that might be broken.

Lifecycle email is a separate provider and a separate sending domain from alerts. Welcome and onboarding mail goes through Loops; alerts and the daily heartbeat go through Resend, on their own domain. Marketing mail attracts complaints and unsubscribes in a way alerts never should, and letting the two share a sending reputation would put the one message that must not land in spam at the mercy of the one that sometimes will. Loops receives your address and your setup progress — never a service name, an incident, or anything you are monitoring.

Your credentials are encrypted before they reach Supabase. Integration credentials are encrypted with AES-256-GCM using a key held as a deploy secret, so the database holds ciphertext. A Supabase compromise would not by itself yield access to your AWS account.

Google measurement can be declined. Plausible continues to count public-site visits without cookies, a cross-site identifier or a stored IP address. Google Analytics and Google Ads are not requested until a visitor explicitly allows measurement where the law requires prior consent (the EU, the wider EEA, the UK and Switzerland); elsewhere they run unless the visitor declines, and a decline is honoured on beaam.app and app.beaam.app alike. Analytics then measures the public marketing journey and one completed-signup event; Ads may attribute that event to Beaam's own campaign. Google signals, advertising personalization and enhanced conversions are off, so no email address or signed-in product activity is sent. There is no Segment or session recording. Product analytics remain first-party in Beaam's database.

Card details never touch Beaam. Polar is the merchant of record, which also means they handle sales tax and VAT for your jurisdiction rather than a solo founder filing in forty of them.

Data residency

The control-plane database is in the United States (us-east-1); the application runs on Cloudflare's global edge. Beaam does not currently offer regional data residency, EU-only processing, or a choice of database region. If that is a hard requirement, Beaam is not the right fit today — and that is a limitation worth knowing before you connect anything rather than after.

Regulatory posture, stated plainly

The data Beaam holds about you is minimal and yours: an email address, optionally a phone number, your monitoring configuration, and telemetry from systems you connected. Raw metric samples expire after 30 days. Deleting your account removes your identity and control-plane records immediately; processors retain what their own legal obligations require.

Beaam is not SOC 2 or ISO 27001 certified and does not claim to be. Formal GDPR posture is "sufficient, not certified" — minimal user-owned data and no cross-site tracking, which covers most of what the regulation is concerned with, without an audit to prove it. If you need a signed DPA of your own or a compliance questionnaire completed, email support@beaam.app and you will get an honest answer about what can and cannot be provided today.

Changes

This list is maintained alongside the retention inventory in the codebase, so it changes in the same commit as the thing it describes. Adding a processor that receives customer data is a change we will announce on the changelog, not one that appears quietly here.