Skip to main content
Effective date: September 14, 2026 Previous version: October 3, 2022 Smartshare, Inc., doing business as Beam (“Beam”, “we”, “us”), provides a serverless platform for running AI and compute workloads. This Privacy Policy explains how we collect, use, share, and protect personal information when you visit our websites, create an account, use the Beam platform, or communicate with us. It applies to beam.cloud, docs.beam.cloud, platform.beam.cloud, the Beam API, the Beam CLI and SDK when used with our hosted platform, and our support, sales, and community channels (together, the “Sites and Services”).

1. Who we are and what this policy covers

Beam is the controller (or, under US state privacy laws, the “business”) for the personal information described in this policy. This policy does not cover Customer Data. If you are a Beam customer, the code, container images, models, datasets, secrets, task inputs and outputs, application logs, and other content you run or store on Beam is Customer Data. We process Customer Data only on your instructions, as your processor or service provider, under our Terms of Service and Data Processing Addendum. If you are an end user of an application that a Beam customer built and runs on our platform, that customer decides how your data is collected and used. Please contact them with privacy questions; Beam does not have a direct relationship with end users and will refer requests to the customer where we can identify them.

2. Information we collect

Information you give us

  • Account information. Your name, email address, password (stored as a hash) or the identity we receive if you sign in with GitHub, Google, or an email magic link, company and workspace names, role, and profile details.
  • Billing information. Billing name and address, tax identifiers, and your plan and purchase history. Card and bank details are entered directly into forms hosted by Stripe, our payment processor. Beam receives limited payment information from Stripe, such as card brand, last four digits, expiration date, and payment status, but never your full card number.
  • Communications. Support requests, emails, in-app chat messages, messages in shared or community Slack channels, sales and demo inquiries, feedback, survey responses, and event or newsletter sign-ups.
  • Workspace configuration. Names and settings you give to apps, deployments, volumes, secrets, and other resources. Secret values themselves are Customer Data and are encrypted.

Information we collect automatically

  • Platform, API, and CLI usage. Pages and actions in the dashboard; CLI and SDK version and the names of the commands you run; API requests, including endpoint, timestamp, status code, and request identifiers; deployment, task, and container identifiers; and resource usage such as compute seconds, GPU type, and storage, which we use for metering and billing.
  • Device and connection data. IP address, browser and operating system, device identifiers, referring URL, language, and approximate location derived from your IP address.
  • System logs. Authentication events, errors and crash reports, and performance data about our own systems.
  • Application logs. Logs emitted by your workloads are Customer Data. They are retained for 30 days on the Developer and Team plans and for 1 year on the Growth plan, or as set out in your Order Form, and are governed by the Terms of Service and DPA.
  • Analytics and session replay. On our Sites and Services we use Google Analytics 4 and PostHog. PostHog may record how you interact with our pages (session replay), aggregate interactions into heatmaps, measure feature usage, and show in-product surveys. Session replay is configured to mask all text and form inputs, so recordings show page structure and interactions but not the content you see or type. See Section 5 for cookies and your choices.

Information from other sources

  • Sign-in providers. If you sign in through a third-party identity provider, we receive your name, email address, avatar, and an account identifier from that provider.
  • Stripe. Payment status, fraud-risk signals, chargeback and dispute information.
  • Business sources. For sales and account verification, we may receive business contact details from referral partners or public sources such as company websites. We do not use contact enrichment or data broker services.

3. How we use information

We do not make decisions about you that have legal or similarly significant effects solely by automated means. Stripe performs automated fraud screening on payments; if a payment is declined, contact support@beam.cloud and we will review it.

4. How we share information

  • Service providers and subprocessors. Companies that process information on our behalf and under our instructions, including cloud hosting (Amazon Web Services, Google Cloud), payment processing (Stripe), error monitoring (Sentry), product and web analytics (PostHog, Google Analytics), documentation hosting (Mintlify), support and messaging (Pylon, Slack), and email delivery (Loops). The current list is published in our Subprocessor list.
  • Affiliates. Companies under common control with Beam, for the purposes described in this policy.
  • Business transfers. A buyer, successor, or investor in connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business, subject to this policy.
  • Legal and safety. Courts, regulators, law enforcement, and other parties when we believe disclosure is required by law or legal process, or is reasonably necessary to protect the rights, property, or safety of Beam, our customers, or others, or to enforce our agreements.
  • At your direction. Third parties you ask us to share with, such as integrations you connect to your workspace.
  • Aggregated or de-identified data. Information that cannot reasonably be used to identify you, such as usage statistics.
We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under California law. We do not use advertising pixels or the advertising features of our analytics tools. If that changes, we will update this policy and provide an opt-out before doing so.

5. Cookies and analytics

We and our analytics providers use cookies and similar technologies (such as local storage and pixels) on the Sites and Services. We do not use advertising cookies. Your choices.
  • Browser settings. You can block or delete cookies in your browser. Blocking strictly necessary cookies may prevent you from signing in.
  • Visitors in the EEA, the UK, and Switzerland. For visitors from these regions, we run Google Analytics and PostHog in a cookieless mode that does not store cookies or other identifiers on your device, so no consent banner is shown.
  • Google Analytics. You can install the Google Analytics opt-out browser add-on.
  • Global Privacy Control. We treat a Global Privacy Control signal from your browser as a request to opt out of any sale or sharing of personal information where applicable law gives you that right. We do not respond to “Do Not Track” signals because there is no accepted standard for them.
  • Email. Marketing emails may contain pixels that tell us whether the email was opened or a link clicked. Unsubscribing stops these emails.

6. How long we keep information

We keep personal information for as long as needed for the purposes described in this policy, and then delete or de-identify it.

7. How we protect information

We maintain a security program designed to protect personal information, including encryption in transit and at rest, isolation between customer workloads, least-privilege access controls with multi-factor authentication for our staff, logging and monitoring, and review of our vendors. Beam’s controls are audited under SOC 2 Type II by Advantage Partners; the most recent report is available to customers on request under a non-disclosure agreement. The Security overview describes our practices in more detail. No system is completely secure. Please protect your credentials and API tokens and tell us at security@beam.cloud if you believe your account has been compromised. If a security incident affects your personal information, we will notify you and any regulators as required by law. Incidents involving Customer Data are handled as described in the DPA.

8. International data transfers

Beam is based in the United States, and we process personal information in the United States and in the other locations where our subprocessors operate, as listed in the Subprocessor list. When we transfer personal information from the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the adaptations required for Switzerland, or on another mechanism recognized under applicable law. For our customers, these clauses are incorporated into our DPA. Beam is not certified under the EU-U.S. Data Privacy Framework. You can request a copy of the relevant transfer mechanism at privacy@beam.cloud.

9. Your rights and choices

Depending on where you live, you may have the right to:
  • access the personal information we hold about you and receive a copy in a portable format;
  • correct inaccurate or incomplete information;
  • delete your information;
  • restrict or object to certain processing, including processing for direct marketing, which you can always object to;
  • withdraw consent where our processing is based on consent, without affecting processing that took place before withdrawal;
  • opt out of sale, sharing, or targeted advertising (we do not engage in these practices);
  • not be discriminated against for exercising your rights; and
  • lodge a complaint with a data protection authority (see Section 11).
How to exercise your rights. You can update your profile and billing details in your account settings. To delete your account, or for any other request, email privacy@beam.cloud with the subject line “Privacy request”. We will verify your identity, usually by confirming control of the email address associated with your account, and may ask for more information where necessary. An authorized agent may submit a request on your behalf if they provide proof of your written authorization. We will respond within the time required by applicable law. If we deny your request, you may appeal by replying to our response; we will review the appeal and tell you the outcome, and you may also contact your state attorney general or data protection authority. End users of our customers. If your request concerns data that a Beam customer processes through our platform, we will refer your request to that customer and help them respond as required by our DPA. Marketing choices. You can stop marketing emails by using the unsubscribe link in any message or by emailing privacy@beam.cloud. We will continue to send transactional messages about your account, billing, security, and changes to our terms.

10. Additional information for US residents

This section applies to residents of California and of other US states with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states as their laws take effect. Categories of personal information. In the 12 months before the effective date, we collected the following categories of personal information, from the sources and for the purposes described in Sections 2 and 3, and disclosed them to the categories of service providers described in Section 4. We use sensitive personal information only to provide the Sites and Services, secure them, and prevent fraud, which are purposes for which a right to limit does not apply. We do not sell personal information or share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not disclose personal information to third parties for their own direct marketing purposes. Your rights. You may request to know or access the personal information we hold about you, to delete it, to correct it, and to receive it in a portable format, and you have the right not to be discriminated against for exercising these rights. Submit requests as described in Section 9. We honor Global Privacy Control signals as described in Section 5. Retention. See Section 6.

11. Additional information for EEA, UK, and Swiss users

Smartshare, Inc. is the controller for the personal information described in this policy. You can reach us at privacy@beam.cloud. Our lawful bases are listed in Section 3. Where we rely on legitimate interests, we have balanced those interests against your rights; you can request more information about that assessment. Where we rely on consent, you can withdraw it at any time. In addition to the rights in Section 9, you have the right to lodge a complaint with the supervisory authority in the country where you live or work, or where an alleged infringement occurred. In the UK, this is the Information Commissioner’s Office. In Switzerland, it is the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concerns first. International transfers are described in Section 8.

12. Children

The Sites and Services are intended for business users and are not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact privacy@beam.cloud and we will delete it.

13. Third-party sites and services

Our Sites and Services link to and interoperate with services we do not control, including GitHub, Stripe’s checkout pages, cloud providers, and our community Slack workspace, which is governed by Slack’s terms and privacy policy in addition to this one. Those services have their own privacy practices, and we encourage you to review them.

14. Changes to this policy

We may update this policy from time to time. If we make a material change, we will notify you at least 30 days before it takes effect by emailing the address associated with your account, by posting a notice on our Sites and Services, or both, and we will update the effective date at the top of this page. Changes apply prospectively from their effective date. Prior versions are listed in the Version History below.

15. Contact us

Smartshare, Inc. d/b/a Beam 1 Broadway, 14th Floor, Cambridge, MA 02142, United States

Version History

  • September 14, 2026: Current version. Rewritten to describe the Beam platform rather than a generic website; added the Customer Data scope statement, named analytics and session replay vendors, cookie categories and consent controls, lawful bases, retention periods, transfer mechanisms, US state privacy rights beyond California, and a version history.
  • October 3, 2022: Previous version.