Privacy Policy
Privacy Policy
Last updated: August 20, 2026
Overview
Seamark Labs (“we”, “us”, or “Seamark”) operates Seamark Beacon, a control plane for Kafka Connect and Debezium pipelines. This policy explains what information we collect through the service, how we use it, and the choices you have. It applies to everyone who signs in or otherwise uses Seamark Beacon.
Seamark Beacon is an early-stage service. We are working to keep these practices simple and clear, and we will update this policy as the product evolves. If we make material changes, we will post the updated policy on this page.
What we collect
We collect only the information needed to run the service:
- Account and authentication data. If you register with email and password, we store your email, a password hash (Argon2id, not the password), and optional MFA material (encrypted TOTP secret and hashed recovery codes). If you sign in with GitHub, Google, or Microsoft, we receive your name, email address, and avatar from that provider, along with an identifier that lets you sign in again. We do not receive or store your provider password.
- Workspace data. The workspaces you create, the members you add, and the roles assigned to each member.
- Cluster connection metadata. The Kafka Connect endpoint you register, connector names and configurations, and observed state such as connector and task health. If you supply basic-auth credentials for a cluster, they are encrypted at rest before storage.
- Logs and audit data. A record of actions taken in the product, such as starting, pausing, or restarting a connector, along with who performed the action and when. This powers the audit trail the service provides.
- Cookies and session data. Session cookies and related technical data (such as request times, IP addresses, and error logs) that keep you signed in and help us keep the service reliable and secure.
How we use the information
- Provide, operate, and maintain Seamark Beacon.
- Authenticate you and authorize actions in your workspaces.
- Store and display the clusters, connectors, and audit history you configure.
- Diagnose issues, prevent abuse, and keep the service secure.
- Communicate with you about the service when you reach out to us.
We do not sell your personal information, and we do not use your workspace or cluster data to advertise to you.
Cookies and sessions
Seamark Beacon uses session cookies to keep you signed in. Sessions are managed by Auth.js as signed JWTs in a cookie (not stored as session rows in the database). You can sign out at any time, which ends your session. We do not use cookies for advertising or cross-site tracking.
Third-party services
We rely on a small number of service providers to run Seamark Beacon. They process data on our behalf and only to the extent needed to provide their part of the service:
- MongoDB Atlas hosts the database that stores accounts, workspaces, clusters, and audit records.
- Vercel hosts the application and serves the pages and APIs you use.
- GitHub, Google, and Microsoft provide optional sign-in identities. We receive only the profile details described above. Email delivery (verification, password reset, MFA codes) is sent through Resend when configured.
Data retention
We keep account data for as long as your account is active and reasonably needed to provide the service. Telemetry (status-check samples) is kept raw for your plan's window and then rolled up into aggregate hourly buckets that are kept much longer; audit records are kept raw to preserve the historical trail the service provides. Downgrading a plan restricts access to older history — it never destroys it, and upgrading restores it. If you delete a workspace or ask us to delete your account, the associated data is permanently removed regardless of plan or retention, including the telemetry rollups. We may retain data where we are required to keep it for legal, security, or billing reasons.
Security
We take reasonable measures to protect the data you entrust to us. Cluster basic-auth credentials are encrypted at rest, passwords are stored as Argon2id hashes, API keys are stored as one-way hashes, TOTP secrets are encrypted at rest, and access to production infrastructure is limited and logged. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your choices and rights
You can update or remove workspace data from the product at any time, and you can sign out or close your account. Depending on where you live, you may also have rights to access, correct, export, or delete your personal data. To exercise any of these rights, contact us using the details below.
Children
Seamark Beacon is a professional tool and is not directed at children. We do not knowingly collect personal information from children under the age of 16.
Changes to this policy
As an early-stage service, our practices will evolve. We may update this policy from time to time, and the “last updated” date at the top of this page will reflect the most recent change. Your continued use of the service after changes are posted means you accept the updated policy.
Contact
Questions or requests about this policy can be sent to hello@seamarklabs.io.

