Privacy policy

What CommonBeat collects, how long it keeps it, who else sees it, and how to get it back or have it deleted.

Version 2026-09-16 · effective 2026-09-16 · British Columbia, Canada · 25692bb2b55b · versions

This is a draft. It takes effect when CommonBeat opens to people outside the closed test, and it has not yet been through a British Columbia lawyer or been signed by the founder. It is published now so that anybody taking part in the closed test can read what we intend to hold ourselves to.

The short version

This section is a summary. The sections below it are the policy.

  • We collect a phone number, a first name, a date of birth, a private gender answer you can skip, and a rough idea of where you are. We do not ask for a photo. That is nearly all of it.
  • Your location is coarse, always. We snap it to a 500-metre grid with an offset that is yours, and we never store a precise position.
  • Messages in a room are deleted 48 hours after the room closes.
  • When you delete your account, a small pseudonymous safety record stays for up to two years. We say exactly what, and why.
  • There is no profile photo and no selfie at this stage, and chat is text only.
  • Every company that touches your data is named below, with the country it holds it in.
  • You can ask us for a copy of what we hold. Write to info@commonbeat.ca and we answer within 30 days.

The law this follows

CommonBeat is operated from Vancouver, British Columbia. Two privacy laws apply to it: the federal Personal Information Protection and Electronic Documents Act (PIPEDA), and British Columbia's Personal Information Protection Act (PIPA). Where the two differ we follow whichever gives you more.

Both laws work the same way in the part that matters here. We may collect only what a reasonable person would consider appropriate, only for purposes we have told you about, and only with your knowledge and consent. If a purpose is not on this page, we are not allowed to do it, and adding one means changing this page first.

Our privacy contact is info@commonbeat.ca. A person reads it, and that person is Ali Moallemi, who runs CommonBeat personally, as a sole proprietor, and is accountable for the personal information it holds. CommonBeat is operated by one person.

What we collect, and why

To have an account

WhatWhyCan you skip it
Phone numberIt is how you sign in, and it is the one identifier that makes a ban mean something.No
First nameSo the people in a group know what to call each other.No
Date of birthTo enforce 18 and, for a beat for a drink, British Columbia's drinking age of 19. We store the date, not an age that goes stale.No
GenderOnly to run women-only rooms, which are not part of this version. It is never shown to anyone, never used for matching, and has a "prefer not to say" answer.Yes
Time zoneSo a window you are free in means the same clock time to everyone.No
One line about yourselfIt is the only free text on a profile. It is checked against a fixed set of rules.Yes

Your date of birth and your gender answer live in a separate table that the app itself cannot read. Nothing in the product reads them except the two rules that need them.

When you put a beat out, we store the window you are free in, the kind of thing you want to do, and a coarse origin. See the location section below for what "coarse" means here, because it is stricter than the word usually is.

While a room is open

Messages, who joined, who acknowledged, who left, and when. The room and what was said in it are deleted on the schedule in the retention table below.

Around a meeting

CommonBeat does not arrange meetings, so at this stage it collects nothing about them: no check-ins, no shared plans, no trusted contacts and no duress records.

When something goes wrong

Reports, blocks, the evidence snapshot taken at the moment a report is filed, and what a moderator decided and why.

Location: coarse, always

This is the section people ask about, so it is the longest one.

The app asks Android only for approximate location. It does not ask for precise location, and the permission to do so is blocked in the app's manifest — not merely unused, but absent, and a check in our build fails if it ever appears. Android's approximate location is already accurate to roughly one to two kilometres.

We then make it coarser. Before anything is stored, your position is snapped to a 500-metre grid, and the grid is shifted by an offset that belongs to your account and nobody else's. Two people standing together get different cells. We never store the position the phone reported, not even briefly.

The consequence is that we cannot tell you where another member is, and neither can anybody who takes our database. There is no map in this product, and that is why.

At this stage there are no exceptions. Nothing in CommonBeat sends or stores a position more precise than that cell. The earlier version of this policy described two exceptions, a duress message and an arrival check-in. Both belonged to arranged meetings, which CommonBeat does not do, and neither runs.

No company other than Supabase ever receives a location from us, approximate or otherwise.

No photos

At this stage CommonBeat does not ask for a profile photo or a selfie, and a chat cannot carry an image. Other members see your first name. If photos ever return, this page changes first, with a new version.

Messages

Messages in a room become read-only the moment the room closes, and are deleted 48 hours after that. That is long enough to read what was said, and to file a report about it. It is not long enough to become an archive of what strangers said to each other.

Message text is checked as it is sent against a fixed list of rules for phone numbers, links and social handles. No outside company reads it. Nothing automated reads messages for harassment, threats or sexual content. A person sees those when a member reports them.

Who else touches your data

Every company is named here, with what it receives and the country it holds it in. This table is generated from the product's own processor register, so it cannot drift away from what the software actually does. Adding a company means changing that register, which regenerates this table in the same change.

Some of these companies are in the United States. PIPEDA permits that and requires us to tell you, which is what this table is. While data is held outside Canada it is subject to the laws of that country, including lawful access by its courts and agencies.

Some rows below are marked Dormant or Deferred: those companies receive nothing at this stage. Where a row names a feature that does not run at this stage, the row itself says it is dormant, and nothing is sent for it.

CompanyWhat it does for usWhat it receivesWhere it holds it
SupabaseDatabase, Auth, Storage, Realtime, Edge Functions. The system of record.Phone number, first name, profile one line, birth date, private gender, time zone, coarse location cell, beats, text-only room messages, reports and their evidence snapshots, blocks, device push tokens, waitlist email addresses. No photo, selfie, check-in, shared plan, trusted contact or duress record is collected at this stage (Amendment A2 and A5).Canada. Edge Functions run at the project's region.
Expo (EAS Build and EAS Update)Android builds, over-the-air JavaScript updates, build credentials including the FCM v1 service-account key.No end-user personal data. Build artefacts, source fingerprints, the founder's account.United States. Being confirmed before launch.
Expo push serviceRelays a push notification from the backend to FCM.Expo push token, notification title and body.United States. Being confirmed before launch.
Firebase Cloud Messaging (Google)Delivers Android push notifications to the device.Device registration token, notification payload (room opened, ladder step). Meet reminders and safety messages are dormant with the meet layer (Amendment A2) and are not sent.Canada. FCM delivery infrastructure is global.
TwilioSMS one-time codes for sign-in and for account deletion, and the severity-3 pager: a voice call and an SMS to the founder's phone, and the founder's OK reply acknowledging it. Pages go to the founder alone; an unacknowledged page is logged and shown on the console, never sent to a second person (Amendment A8). Trusted-contact and safety messages are dormant with the meet layer (Amendment A2).A member's phone number and the one-time code message; for a page, the founder's phone number, a message naming only the kind of incident and a reference, and from the second ring its round number (the text says "Escalation round 2", supabase/functions/page-founder/handler.ts:79; under A8 a later round re-rings the founder's own phone — pager.backup is the same number — and never reaches a second person) — never a member's name or words — plus delivery status and call metadata. No trusted contact's number is sent while those messages are dormant.United States. Message routing is carrier-dependent. The sender number is Canadian.
OpenAIDormant — not used (Amendment A5 and A7, 2026-09-14). No user-generated image exists to scan, and text moderation is free and deterministic with no paid model call. The omni-moderation hook is kept in the code, unscheduled.Nothing. No request is made while it is dormant.United States.
AnthropicDormant — not used (Amendment A7, 2026-09-14). Text moderation is free and deterministic with no paid model call. The solicitation-classifier hook is kept in the code, unscheduled.Nothing. No request is made while it is dormant.United States.
Cloudflare — TurnstileBot check on the website's two forms: the waitlist sign-up and the web /delete-account form (in use since 2026-09-16). The app's sign-in screen does not use it yet.IP address, browser/device signals, a challenge token. No account identifiers.Not settled yet. The region is being chosen before launch and will be named here.
OVHcloud — Object Storage (S3 API)Encrypted nightly database and Storage backups, and the hourly safety-table export. Replaced Cloudflare R2 on 2026-09-14 (decision A10).Everything in the database, but only as an age-encrypted blob that OVHcloud cannot read.Canada. The bucket is created in OVHcloud's bhs region; the nightly job refuses any endpoint other than exactly s3.bhs.io.cloud.ovh.net, and the endpoint, region and bucket name live only in the secret store, never in the repository.
SentryDeferred — not used yet (Amendment A10, 2026-09-14). When adopted: crash and error reporting from the app, the Edge Functions, the console and the site.Nothing yet. When adopted: stack traces, device model, OS version, app version, a hashed user id. PII off: sendDefaultPii false, no IP capture, no request bodies, scrubbers on.Not settled yet. The region is being chosen before launch and will be named here.
PostHogDeferred — not used yet (Amendment A10, 2026-09-14). Analytics is not part of the link-only launch path; the backend's event feed stays behind its absent key. When adopted: which screens are used, whether a beat became a room.Nothing yet. When adopted: a hashed distinct id, zone id, event name, ladder step. No free text, no message content, no names. Cookieless, no session replay, no autocapture. Property allowlist enforced in packages/config.Not settled yet. The region is being chosen before launch and will be named here.
Cloudflare — PagesHosts the website commonbeat.ca (founder decision, 2026-09-16; Vercel had been planned and was never used). The static pages are served from Cloudflare's network; the server-rendered pages — waitlist progress, invite and unsubscribe links, and web account deletion — run there as a Pages Function. The moderation console's host is not chosen.Request logs including IP address. The server-rendered pages read an invite token, an unsubscribe token and a zone slug, each a random string that identifies nobody outside our own database, and each in a URL, which means in a request log. The web account-deletion page passes a phone number and a one-time code through to Supabase and stores neither.Canada. Nothing the site handles is stored there; the database and everything it holds stays in Canada (Supabase, ca-central-1).
ResendDeferred — not used yet (Amendment A10, 2026-09-14): email is deferred with the website and the domain. When adopted: one transactional email, the zone go-live notice to consented waitlist rows.Nothing yet. When adopted: email address, neighbourhood name, the person's own invite token and their own unsubscribe token — random strings that identify no person outside our own database — and, as the idempotency key, the waitlist row's own internal id. That last one is the price of never sending the same person the same message twice, and it is stable, so it is named here rather than left to be discovered.United States. Being confirmed before launch.
Project Arachnid Shield (Canadian Centre for Child Protection)Dormant — not used (Amendment A5, 2026-09-14). No user-generated image exists anywhere in the product, so there is nothing to hash-match. The pipeline that would match every uploaded photo against known child sexual abuse material before it could be served is kept in the code, switched off.Nothing. No image exists to send.Canada.
Better StackDeferred — not used yet (Amendment A10, 2026-09-14), and out of the near-term path. Near launch one uptime alarm watches the cron heartbeats; which monitor is not chosen, and it gets its own row here before it receives anything. No monitor pages anyone: the severity-3 pager runs through Twilio to the founder alone (Amendment A8).Nothing. No phone number goes to a monitor, and there is no second operator whose number could (Amendment A8).Not settled yet. The region is being chosen before launch and will be named here.

What no company receives

  • No precise location, because there is none to send.
  • No date of birth and no gender answer. Those columns have no path out of the database.
  • No message content. Chat is checked against fixed rules, and no outside company reads it.
  • Nothing goes to an advertising, attribution or marketing company. There is no such company in this product and there cannot be one without this page changing first.

How long we keep things

Generated from the product's retention specification, which is the same document the hourly deletion job is built from.

Some rows cover records, or parts of records, CommonBeat does not collect at this stage, such as photos, selfies, venues, check-ins, shared plans, trusted contacts and duress records. Their rules stand unchanged, but there is nothing for them to apply to.

WhatHow long we keep itWhy that long
Room messagesRead-only from the moment the room closes. Deleted 48 hours after close.The chat is the product's whole surface after the link (Amendment A6, 2026-09-14), so the window is two days rather than one: long enough to read what was said and to file a report about it. Still not long enough to become an archive of what strangers said to each other.
Rooms and their metadata30 daysEnough to investigate a report filed days later.
Raw beatsRolled up to hourly statistics, then purged at 7 daysThe individual beat says where somebody was and when. The hourly count says whether the neighbourhood is busy. Only the second is worth keeping.
Beat notesScrubbed as soon as the beat leaves openThe note is cut from v1 anyway (decision D10). The rule stands for when it returns.
Beat events30 days, with the roomThe append-only trail of what the matcher did.
Saved usualsFor the life of the account. Removed on account deletion.The shape of a beat a member sends again with one tap: a label, a mood, a thing to do, when, for how long, how far and how big a group. No position is stored in one. They are data held about the account, so they go with it.
Duress records90 daysLong enough for an investigation or a police request; not a standing map of where somebody once needed help.
Check-in positionsPosition data purged at 90 days; the fact of the check-in stays with the roomArrival check-in stores no coordinates at all (decision D11). This rule covers the columns that exist for future use.
Safety plansDeleted 7 days after the plan expiresNo new plan can be sent at this stage; the rule covers any plan sent before. The row survives a week in case a contact asks what they were sent.
Verification selfiesDeleted the moment the founder approves or rejects. A sweep catches any that a failed deletion left behind.This is biometric-adjacent processing under PIPEDA and BC PIPA (decision D7). The only defensible retention is none.
Profile photosFor the life of the account. Removed on deletion. A photo a legal hold kept is removed once the hold lifts or expires.No profile photo is accepted at this stage, none is shown to anybody, and other members see a first name only. The rule applies when photos return.
Photos in the inbox bucketDeleted when the photo is approved and copied to its final key, or when it is rejectedThe staging area is not a store.
Quarantined photosNever deleted while a hold is open. Minimum 21 days.Canada's Mandatory Reporting Act requires preservation, and deleting evidence is its own offence. docs/runbooks/csae.md.
Media scan resultsWith the photoThe audit trail of what was checked and what it said.
Notification outbox14 daysEnough to answer "did that message actually send?" from the Notification health screen.
ReportsFor the life of the account, then as belowA report is the record that somebody said something happened.
Report evidence12 months, unless heldThe snapshot taken at filing time: the message, the room's recent messages, the member list. Long enough for a slow process; not indefinite.
Moderation actionsFor the life of the account, then as below. Append-only.Why somebody was warned, limited, suspended or banned. Without it, the same decision gets made twice differently.
Held names and one linesKept while a person here has still to read it. Deleted 7 days after it is shown, refused or replaced.When the automatic check is unsure about a first name or a one line, nobody else is shown it until a person here has read the words, so the words are kept for that person to read. A week afterwards is long enough to answer "why is my name not shown?" with the words in front of you. The decision and its reason are kept with the moderation actions, without the words.
BlocksPermanent blocks are permanent. Blocks from leaving a room without naming a person expire after 30 days.A block is the user's decision, not ours, and it is not ours to expire. The 30-day one is the bystander case: leaving a room should not permanently block three people who did nothing.
Identity ledgerUp to 2 years after account deletionSee below.
ConsentsFor the life of the account, plus 2 yearsThe record that consent was given is the evidence that processing was lawful. Deleting it would destroy the proof, not the processing.
Page log12 monthsWhether a page was delivered and acknowledged is what the published service level is measured on.
Law-enforcement requests7 yearsA legal record, not a product record.
Trusted contactsUntil removed by the user, or account deletion
Trusted-contact attempt countersReset weeklyRate-limiting state, not data about a person.
SMS suppressionsIndefinitelySomebody replied STOP. Forgetting that would mean messaging them again, which is the one thing the record exists to prevent.
Device push tokensUntil the device unregisters, or account deletion
WaitlistA period after the invitation is sent (waitlist.invited_at), long enough that the unsubscribe link in that message outlives our obligation to honour it — period not yet set, and the purge is not yet implementedThe rule that stood here until 0079 said "until the invitation is sent", which would have deleted the unsubscribe token inside the window in which the opt-out must still work. invited_at has also only been written since 0079 (public.record_email_result sets it on sent), so the old rule was never a query anybody could run.
Waitlist retry keys8 days from when the signup arrived, whether or not the signup is still on the listA random identifier the app sends with a waitlist signup, so that sending it again after a lost answer changes nothing. It holds no email address, only which signup it made, and only while that signup exists. The app stops retrying after 7 days, and the key is kept one day longer, even when the signup has been removed, so that a retry still on its way cannot put somebody back on the list they asked to leave.
Analytics eventsPer the plan's retention — see docs/processors.mdA hashed distinct id, a zone, an event name, a step. No free text, no names.
Crash reportsPer the plan's retention — see docs/processors.mdPII off.
Nightly backups30 days, by bucket lifecycle ruleA backup older than a month restores a world that no longer exists, and holds data a user asked to delete.

A legal hold pauses every rule in that table. A hold is placed when material involving a child is found, when law enforcement serves a preservation demand, or when a serious report is being investigated and the evidence would otherwise expire. Every hold has a reason and an expiry date.

Deleting your account

You can delete your account from the app, or from commonbeat.ca/delete-account with the app uninstalled. Both do exactly the same thing. It is immediate, there is no grace period, and nothing tries to talk you out of it.

This is the same text the app shows you before you press the button, generated from the same source, so that the two cannot say different things.

CommonBeat does not collect a profile photo, and does not let anybody add a trusted contact, at this stage. The lines about your photo and your trusted contacts apply only if a record like that exists.

Deleting is immediate. There is no grace period and nothing here will try to talk you out of it. You will be signed out when it is done.

What goes

  • Your first name becomes "Deleted", and your one line goes.
  • Your photo is removed from storage, not just unlinked.
  • Your birthday, your gender and your timezone are dropped.
  • Your device tokens go, so notifications stop.
  • Your trusted contacts go.
  • Your saved usuals go.
  • Your beats and your seats go, and the rooms they belong to age out on the schedule in the privacy policy.
  • Your waitlist row goes.

What stays, for up to 2 years

  • A one-way hash of your phone number, in the identity ledger.
  • Any ban attached to that hash.
  • Blocks other people made, carried on that hash.
  • The moderation actions taken, with their reasons.
  • Reports filed about you, and the evidence snapshot.

Somebody banned for harming another member would otherwise be back the next morning on the same number, with every block against them gone. The hash cannot be turned back into a phone number.

If some of your records are under a legal hold, the deletion runs as far as it can — your name and your private details go — and the held records stay until the hold lifts. The confirmation tells you so.

Getting a copy of what we hold

Under PIPEDA and BC PIPA you can ask what personal information we hold about you, what we have used it for, and who we have disclosed it to. Write to info@commonbeat.ca from the number or with enough detail that we can find your account, and we will answer within 30 days. If we need longer we will tell you why, within those 30 days.

What you get is a machine-readable file of your own rows. It will not contain other people's identifiers or names. A group has other members in it, and their information is not yours to receive, so those parts are redacted. If a redaction means the answer is hard to read, ask and we will explain it.

You can also ask us to correct something that is wrong. If we disagree that it is wrong, we record that you asked.

There is no charge.

Complaining

If we have not dealt with you properly, tell us first — info@commonbeat.ca — because we would rather fix it than be told to.

If that does not resolve it, you can complain to either regulator:

  • The Office of the Privacy Commissioner of Canada, at priv.gc.ca, for the federal law.
  • The Office of the Information and Privacy Commissioner for British Columbia, at oipc.bc.ca, for the provincial one.

Neither costs anything and neither requires a lawyer.

Children

CommonBeat is for adults. We do not knowingly collect anything from anyone under 18, and an account we find belongs to a minor is closed. Where we find material involving a child, we preserve it and report it, as the terms describe and as Canadian law requires.

Security

Everything is behind row-level rules in the database, which means a request reaches nothing unless a rule says so by name. The site you are reading reaches the database in only two ways: one public, read-only call for a neighbourhood's status, and, on the delete-account page, your own sign-in code and the deletion you ask for, made as you. The shared-plan page that used to make a second public read is retired (Amendment 1 A1/A2). Backups are encrypted before they are stored, and the key is not held by the company that stores them.

We are a small operation and we will not claim more than that. If you find a hole, write to info@commonbeat.ca with "security" in the subject line and we will answer.

Changes to this policy

When this policy changes in a way that affects you, the version at the top changes and the app asks you to read it. The version and a hash of the exact text are published at /legal/versions.json.

What changed from the first version

The first published version was dated 2026-09-13. This version, dated 2026-09-15, follows CommonBeat's change to linking a group into a text chat and stopping there.

So this version no longer describes a photo, a selfie, check-ins, shared plans, trusted contacts or duress as anything we collect, because none of them is collected at this stage (Amendment 1 A1/A2/A5). Their retention and deletion rules are still listed, marked as applying only if such a record exists. The two location exceptions went with them. It also no longer says that message text goes to an outside moderation service, because at this stage none does.

The draft that circulated before the first version listed processors without their countries. Every version since has named them.


This document is version 2026-09-16, hash 25692bb2b55b. The machine-readable record is at /legal/versions.json, which is what the app's acceptance record points at.