BEAMMEUP PRIVACY POLICY STARDATE 77415.2 NO DATA COLLECTED
01 · OVERVIEW

Nothing collected, one exception you control

BeamMeUp collects no data and contacts no external server during normal use. The one exception is the optional remote web access feature, which you must explicitly enable; when active, terminal content travels unencrypted over your local network. The details are below.

Last updated: 2026-10-08 ·  Applies to all versions of BeamMeUp.

02 · ALERT

Telemetry and diagnostics

BeamMeUp transmits no telemetry, no crash reports, no usage statistics, and no diagnostic data to BREIZHZION or any other party. The application makes no outbound network connections on its own.

03 · PROTOCOL

Remote web access

Remote web access (beammeup web on) is off by default and must be explicitly started by you. When active:

Plain HTTP, No TLS

The authentication token and all terminal content travel unencrypted. Over Tailscale or a VPN the underlying tunnel (WireGuard) already encrypts everything; over a plain LAN or Wi-Fi, any observer on that network segment can read the token and session output.

Token, Persisted to Disk

The bind address, token, and an autostart flag are saved to remote.json every time you run beammeup web on, so the server can come back automatically on the next launch. This file lives at %APPDATA%\beammeup\remote.json on Windows and ~/.config/beammeup/remote.json on Linux. On Linux it is written with owner-only permissions (0600), including on a file created by an older version. On Windows no additional permissions are set beyond the profile's own default: %APPDATA% is already restricted by Windows to the account that owns it, not to other non-administrator local accounts.

Bind Address, Your Call

You choose the bind address. BeamMeUp does not validate or restrict it.

No Rate Limiting

Token attempts are not rate-limited in the current version; an attacker with network access to the bind address can try tokens as fast as the network allows. A random 128-bit token is not brute-forceable in practice, but this is a documented gap.

Removing the Token

beammeup web off stops the server and turns off autostart, but it does not delete the token from remote.json: the file and its contents remain on disk. To remove the token and settings entirely, delete remote.json at the path above. There is currently no CLI command that does this for you.

The web interface gives full read/write access to every open session. Treat the access token like the password to this machine's shell.

04 · SYSTEMS

Local storage

Beyond the remote-access settings covered above, this is everything BeamMeUp writes to disk. Only the web engine data and the working files below appear without you asking: the rest happens when you run the command that does it.

Snippets

Plain command text you explicitly save via the CLI, not a secret by design, stored at %APPDATA%\beammeup\snippets.json on Windows and ~/.config/beammeup/snippets.json on Linux.

Files You Ask For

Three commands write what you point them at, and they are the only way session content reaches the disk. beammeup export writes the terminal content of a session to the file you name. beammeup screenshot writes a PNG of the window: without --out it lands as beammeup-screenshot.png in the system temporary folder, which BeamMeUp never cleans up. beammeup remote read --out copies a remote file to the local path you name. Delete these files yourself when you are done.

Web Engine Data

BeamMeUp's window is a web view, and its engine keeps its own standard profile (cache, crash reports) at %LOCALAPPDATA%\com.breizhzion.beammeup on Windows, and in the user's data and cache directories on Linux. That data is managed by the engine, not by BeamMeUp, and the interface itself uses no localStorage, cookies or IndexedDB. Delete the folder to remove it.

Working Files

On Windows, beammeup_relance_elevation.marker in the temporary folder holds a single character and stops a second elevation prompt within 60 seconds. On Linux, the control socket beammeup-<uid>.sock sits in your runtime directory, or in a private 0700 folder under the temporary folder when none exists. It is a control channel, not a data file, and a stale one left behind is replaced at the next start.

Application Files

The binary and the uninstaller placed by the installer (%LOCALAPPDATA%\beammeup on Windows; system package paths on Linux).

BeamMeUp keeps no command history, no log of what you type, and stores no SSH credentials: authentication stays with the tools already configured on your machine.

05 · TRANSMISSIONS

Third parties & contact

No telemetry vendor, analytics service, or other third party receives data from BeamMeUp. SSH sessions connect to the servers you configure; anything exchanged in those sessions is between you and those servers.

Questions about this policy: open an issue on GitHub or email beammeup@breizhzion.com.