Last updated: 10 July 2026. This Privacy Policy explains what Northbeams Inc. ("Northbeams", "we", "us") collects, how we use it, and the choices you have. It covers the Northbeams marketing site at northbeams.com and the Northbeams application at monitor.northbeams.com, together with the browser extension and desktop apps that make up the product.
Northbeams inspects AI activity on the device. It is not a proxy, and it does not install a man in the middle certificate. By default, raw prompts, MCP argument values, keystrokes, and your non-AI browsing never leave the machine. Only category labels, counts, severity, a redacted and hashed snippet, and the per-user attribution needed to show an admin who did what leave the device. Your admin can turn on optional capture modes, described below, that send prompt text to our contextual PII scanner or store the full prompt or an uploaded file for flagged events. These modes are off by default.
The browser extension and desktop apps classify AI activity on the device. From that inspection, only the following leaves the endpoint and reaches your organization's Northbeams tenant:
By default, the following never leaves the device: raw prompt text, MCP argument values, keystrokes, and your non-AI browsing history. There is no proxy and no MITM certificate, so traffic is not decrypted in the network path. See Optional capture modes below for the off-by-default settings an admin can enable.
By default, raw prompt text and uploaded files never leave the device. Your organization's admin can turn on optional modes, each off by default and controlled separately, that change this for your organization:
These are choices made by your organization's admin, who is the controller of your organization's data. What each mode collects, and how long it is kept, is described in our Data Retention notice and Data Processing Addendum.
Within a customer organization, the organization is the controller of its users' product data, and Northbeams is the processor acting on its instructions.
We use a limited set of vendors to run the service, including Google Cloud for infrastructure and Stripe for payments. The current list, with purpose and location, is on our Sub-processors page.
Customer data is stored on Google Cloud (Firestore and Cloud Storage), in the United States.
Event history, meaning the record of AI tool use, prompt findings, and model and MCP calls, is retained for 13 months, so that admins keep a rolling audit trail covering a full year and the reporting month after it. Admin action audit logs are retained for 24 months. Network Control records are retained for 90 days. Enterprise plans can agree longer retention, up to a maximum of 7 years. Account and billing records are kept while your account is active, and for the period afterward required by law. When you close your account, we delete customer product data within 30 days, unless the law requires us to keep it longer. The full table is in our Data Retention notice, which is the source of truth if this summary and it ever disagree.
If your admin turns on forwarding to your own security tools, such as Splunk, Microsoft Sentinel or Elastic, we keep a short-lived copy of each event we send you, so that a delivery can be retried if your system is briefly unavailable. A copy that has been delivered is deleted after 30 days. A copy we could not deliver is kept for up to a year as a record of the attempt. Full detail is in our Data Retention notice.
Depending on where you live, you may have rights under the GDPR, the UK GDPR, and the CCPA and CPRA, including the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Where Northbeams processes data on behalf of a customer, we route requests to that customer as the controller. To exercise a right, or to ask who the controller is for your data, email [email protected].
We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under California law.
Where personal data is transferred out of the EEA or the UK, we rely on appropriate safeguards, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
How we protect data (encryption in transit and at rest, on-device inspection, access controls, signed logs, and independent penetration testing) is described on our Security page.
Northbeams is a workplace product and is not directed to children. We do not knowingly collect data from anyone under 16.
We will update this policy as the product and the law change, and we will post the new version here with a fresh "last updated" date. We will tell account admins about material changes.
Northbeams Inc. is a Delaware C-corporation, with a US mailing address at 301 Howard St #910, San Francisco, CA 94105. For privacy questions, or to reach our data protection contact, email [email protected].