Last updated 26 August 2026
This notice explains what information Beacon uses, why it is needed and the choices and rights available to you. It is not a request for consent.
Version 2026-08-26
Who is responsible
Beacon is the controller for personal information used to operate bcon.uk. Send privacy questions or rights requests to the @beacon administrator account.
Information we use
This includes account and profile details; posts, replies, media, reactions, follows, reports and moderation records; and limited session, device and security information. Beacon Alert administrators may also hold private referrer and coordination details.
Why we use it
We use information to provide the service you request, show public conversations, protect accounts, moderate harmful activity, operate verified alerts and meet legal obligations. We rely on the service agreement, legitimate interests in a safe and secure community, and legal obligations—not bundled data-processing consent.
Who can see it
Your profile and public activity can be seen outside Beacon. Organisation Pages may also choose to publish a separate contact email, phone number, website and social links on their public profile. The email used to sign in is not published as Page contact information. Anything deliberately published on a Page may be copied or indexed outside Beacon. Direct communications have restricted visibility inside the service. Information may also be processed by infrastructure providers or disclosed where the law, safeguarding or an official investigation requires it. Beacon does not sell personal information.
The optional “How are you?” check-in is visible as an emoji only to you and signed-in members who follow you. It is not included on signed-out profiles and is not shared with signed-in non-followers.
Optional push notifications
Web Push is optional and is enabled only after you choose to turn on notifications and allow them in your browser or device settings. Notifications can arrive while Beacon is closed. Their title and message may be visible on a lock screen, wearable, shared computer or other device surface, depending on your settings, so consider whether previews are safe on that device.
Your browser or operating-system provider uses its external push service to route notifications to the device and may process delivery, network and device information under its own privacy terms. Notification content is encrypted in transit. Beacon stores the endpoint and cryptographic keys together as an encrypted subscription capability, plus a one-way endpoint fingerprint and limited device metadata such as the browser description, timestamps, optional expiry and delivery status.
Each subscription is tied to the signed-in browser session that enabled it. Turning notifications off removes the server subscription and asks the browser to unsubscribe. Signing out deletes that session and its server-side subscription; expired or revoked sessions are not eligible for delivery and are removed. You can also withdraw notification permission at any time in your browser or device settings.
Account recovery and email summaries
If you request a password reset, Beacon sends a short-lived, single-use recovery link to your private sign-in email. The account remains usable without an email-confirmation step, and Beacon does not send an email merely because an account was created.
By default, Beacon may send one plain-text summary after you have not actively used the service for at least two days and have unread activity. It contains discreet notification descriptions, active Beacon Alert titles, and a small selection of public popular posts, followed by one link back to Beacon. A further summary is sent no more than once in each later 48-hour period, and only when there is new unread activity since the previous summary. You can turn these summaries off from profile settings.
Beacon currently uses Gmail to deliver these messages. Google therefore processes the sender and recipient addresses, message content, delivery metadata and ordinary network information needed to route the email. Beacon does not put private communications, report notes, warning text, missing-person names, locations or images into summary emails, and does not use email tracking pixels. Limited delivery, retry and suppression records are retained to operate and protect the service.
Installed app status
When you open Beacon as an installed app, Beacon records the first and most recent confirmation times against your account. This helps us understand setup progress without storing a device fingerprint, browser description or network address for installation tracking. Web browsers do not reliably tell Beacon when an app is uninstalled.
Usage analytics for signed-in members
When you are signed in, Beacon uses Google Analytics 4 to understand broad usage such as visits, sessions, approximate location, device and browser type, and which parts of the service people use. Google Analytics uses first-party identifiers such as the _ga cookie.
Beacon loads the Google-hosted tag file on public pages so the installation can be verified, but analytics storage and page measurement are disabled for logged-out visitors. Loading that file gives Google the ordinary connection information needed to serve it, such as an IP address and browser details. Beacon does not send Google an internal account ID, email address or call sign as an Analytics user ID.
Advertising storage, Google signals and advertising-personalisation signals are disabled. Signing out stops Analytics on Beacon and removes accessible Google Analytics cookies from this site.
Public Community Health statistics
Beacon publishes a Community Health page using coarse, anonymous percentages about community connection, wellbeing and public posting activity. It never publishes member totals, profiles or individual responses. Percentages are rounded into a daily snapshot, and small groups are combined or withheld to reduce the risk that a person could be identified from the statistics.
For this community-level view only, people who have not selected a wellbeing response are counted as Okay. Organisation Pages are excluded from wellbeing statistics. The posting chart shows each day's relative share of a seven-day period rather than a number of posts.
How long we keep it
Information is kept only while it is needed to provide Beacon, protect the community, handle reports or meet legal requirements. Resolved alerts remove identifying information from live surfaces; limited records and backups may take longer to expire securely.
Your choices and rights
You can edit profile information and download a copy of your data from profile settings as portable JSON after confirming your current password. Profile settings also provide a deliberately low-key permanent account-deletion control. It requires your current password and the exact word DELETE. Deletion removes your profile and the content you created in Beacon's community spaces, cannot be undone and cannot be recovered.
A still-active Beacon Alert request may be retained as a de-identified safeguarding case rather than being silently abandoned; its requester account link and private contact details are removed. Limited safety, moderation, legal and backup records may also take longer to expire where retention remains necessary and proportionate. You may ask for access, correction, deletion, restriction or portability, or object to some uses. You can complain to the UK Information Commissioner's Office if a concern is not resolved.