Privacy
Last updated 24 August 2026.
Beatrice is built by one person, Brian Long. It holds notes about the people in your life and the running of your home, which is unusually personal material for an app to carry. This page is written to be read rather than agreed to.
The short version.
Your data is yours. It is not sold, it is not shared with advertisers, and it is not used to generate sales leads. You can export it and you can delete it. Nothing here is a business model built on your information.
Only what you enter, plus what is needed to run the app.
| What | Why |
|---|---|
| Account Email address, or an Apple Sign In identifier |
To sign you in and keep your data attached to you |
| People Names, photos, birthdays, contact details, notes, and the answers you give to questions about them |
This is the app. It is what lets Beatrice tell you something specific rather than generic |
| Household Tasks, lists, pets, vehicles, appliances, shared reference notes |
Shared with the other members of your household, and nobody else |
| Journal Entries you write, and daily prompt answers |
Yours to read back. Entries you mark private are never read by any other part of the app |
| Health Cycle and infant tracking entries, if you use those tools |
To show you your own history and to make predictions from it |
| Photos See below. The images themselves never leave your phone |
To resurface a moment with someone you have not spoken to lately |
| Calendar Event titles, times and attendees, if you connect Google Calendar |
To notice when you are about to see someone. The connection is read-only |
| Diagnostics Crash and error records, and counts of which features get used |
To find and fix things that break |
If you grant photo access, Beatrice scans your library on the device. What gets stored on the server is an opaque local identifier that means nothing anywhere else, a date, and a numeric score. The image is never uploaded, never sent to any third party, and cannot be reconstructed from what is stored.
If a photo carries location data, Beatrice may look up the place name to write a caption like "in Brighton". The coordinates are not kept.
Some of what Beatrice writes is generated by Anthropic's Claude model. When that happens, the relevant text is sent to Anthropic's API over an encrypted connection and the response comes back. Anthropic does not train its models on data submitted through its API.
What is deliberately kept out of those requests:
These exclusions are enforced by automated checks that fail the build if something crosses the line, rather than being left to memory.
Usage events record counts, yes-or-no flags and short fixed labels. They do not carry names, identifiers for specific people, free text, journal content, or health readings. A record of the shape a task was completed is kept. Which task, and for whom, is not.
Beatrice can create a link you send to someone, so they can answer a question, pick a time, or sign a group card without installing anything.
Data is stored with Supabase, which hosts the database, encrypted in transit and at rest. Access rules are enforced at the database itself, scoped to your account, so one person's rows are not reachable from another's session. Household data is readable by the members of that household.
On your phone, your sign-in session is encrypted with a key held in the iOS keychain.
Three processors, and no one else:
Nothing is sold. There are no advertising networks, no analytics brokers, and no data resellers. Home and appliance details are specifically never used to generate sales leads for anybody, which is how much of that category is funded.
Beatrice is not for children and is not directed at anyone under 13. Infant tracking records information about a baby entered by a caregiver, which is the caregiver's own data.
If this page changes in a way that affects what is collected or who sees it, the change will be announced in the app rather than quietly published here.
hello@beatriceapp.com. It reaches one person and gets an answer.