Privacy Policy
Last updated: September 22, 2026
Beacon (“the app,” “we,” “us”) is a tool that helps students draft and send research-outreach emails to professors from their own Gmail account. This page explains what data we collect, why, and how it's used.
What we collect
- Your Google profile — name, email address, and profile picture, when you sign in with Google.
- OAuth tokens— used to send email on your behalf. We never see or store your Google password; sign-in happens entirely through Google's own sign-in page.
- Profile details you provide — school, grade level or year, area of study, and a short bio, used to personalize your outreach drafts.
- Professors you add — name, email, school, department, research area, and any notes or drafts you write or generate for them.
- Saved prompts (templates) — the outreach templates you create and edit.
- Send status — whether and when an email was sent.
How your Gmail access is used
Beacon requests one Gmail permission — the ability to send email— used only when you click “Send” on a specific, individually-reviewed draft. Beacon never sends email automatically or in bulk without your explicit action on that email, and it never requests read access to your inbox.
AI features and third-party services
When you use AI-assisted drafting or Discover's researcher database, limited context (such as a professor's name, school, and research area, or your outreach template) is sent to:
- Groq, an AI inference API, to generate draft text or extract researcher information from public web sources. Groq is contractually prohibited from using this data to train or fine-tune any AI model.
- Exa, a web search API, to find publicly available information about a professor's research.
We never send your Gmail contents, your password, or other users' data to these services — only information you entered yourself (your profile, saved templates) or public information about a professor's research. Discover's researcher database is built from public web sources and is not guaranteed to be accurate — the app always asks you to verify a professor's identity and email before contacting them.
Google User Data & Limited Use
Beacon's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Beacon requests only the Gmail gmail.sendscope — never read access to your inbox — and no data obtained through a Google Workspace API is ever transferred to a third-party service for the purpose of training or improving that service's AI or ML models.
What we don't do
- We don't sell or rent your data to anyone.
- We don't show ads or use your data for advertising.
- We don't send email on your behalf without you personally reviewing and approving that specific email first.
- We don't request or have access to read your inbox at all — only permission to send email on your behalf.
Data security
We take reasonable and appropriate measures to protect the confidentiality, integrity, and security of your data. All traffic between your browser and Beacon is encrypted with TLS/HTTPS. Your data is stored in a managed PostgreSQL database that encrypts data at rest and only accepts encrypted (SSL) connections; the database is reachable only by Beacon's own server, using a private credential that is never exposed to your browser or any third party. Your Google OAuth token is stored securely and used only to send an email you have personally reviewed and approved.
Data storage and retention
Your data is stored in a hosted database used only by this app. It's retained for as long as your account exists, or until you delete individual professors or templates yourself within the app. To request full deletion of your account and all associated data, contact us at the email below.
Contact
Questions about this policy or your data? Email angad18.bhatia@gmail.com.
See also our Terms of Service.