Privacy Policy
Last updated: August 26, 2026
1. Overview
Reaver is operated by Bean Local, LLC (“we”, “our”, “us”). This policy explains what personal data we collect, why we collect it, how long we keep it, and your rights. We do not sell personal data.
Reaver is designed to be privacy-friendly: the Software is self-hosted, your backup content stays on infrastructure you control, and any product statistics we receive are minimal, anonymous, and opt-out. We collect only what we need to run accounts, payments, support, and product improvement — never your site files as a hosted vault.
This policy applies to our websites (including reaverbackup.com and related pages), account registration, support/feedback channels, the public Community Q&A, and anonymous product statistics built into the Software.
2. Data We Collect
2.1 Website analytics
We use privacy-friendly analytics (Plausible-compatible) that does not use advertising cookies and is designed to avoid collecting personal identifiers. Aggregate page-view statistics help us understand site usage.
2.2 Launch notify list
If you previously signed up to be notified about launch, we collected:
- Name (first and last)
- Email address
We use this only to send product updates you requested, and to manage the list (including double opt-in where configured). You can unsubscribe at any time.
2.3 Anonymous product statistics
Installs may send a periodic limited, anonymous product heartbeat to help us prioritize development. Statistics default on for all editions (Free and paid). You may opt out at any time by setting anonymous_statistics to false. Free use is install-only (no account); limited stats are also the expected exchange for free access.
- What we collect when enabled: Reaver version, plan label, OS/PHP versions, site/agent/schedule counts, destination types (e.g. local/S3/SFTP — not hostnames or buckets), whether SMTP is configured (boolean only), activity buckets (last backup age, restores/archives ever), coarse failure counts, feature flags, and a random local install id used only to dedupe heartbeats
No hostnames, site URLs, emails, paths, tokens, or error text. Data is stored separately from account databases (local product-stats store) and is not linked to a person or email.
2.4 Accounts and paid editions
When you create an account or purchase a paid license, we collect:
- Name (first and last)
- Email address
- Account credentials (passwords are stored hashed; we do not store plaintext passwords)
- Email confirmation — we send a one-time link so we know the address works and to reduce bot signups
- License and subscription metadata
- Payment information — processed and stored by Stripe. We do not see or store your full card details.
2.5 Support, contact, and feedback
If you contact us or submit product feedback, we collect the content of your message, any attachments you choose to send (e.g. screenshots), and related account or contact details needed to respond.
2.6 Spam protection
Forms may use ALTCHA (proof-of-work) challenge responses to reduce bots. Challenge data is used only to verify the submission and is not used for advertising profiling.
2.7 What we do not collect from self-hosted installs by default
Reaver is self-hosted. Your site content, database dumps, file paths, and backup repositories remain on infrastructure you control unless you deliberately send materials to us (for example, support tickets or feedback attachments).
2.8 Community Q&A
If you post a question or answer on Community Q&A, that content is public. Anyone can read it without an account, including search engines and AI assistants. We store the post (title, body, tags, area), your account id, a public display name (first name and last initial — never your email), votes, and optional screenshots you attach.
Do not post passwords, API tokens, private hostnames, backup logs, or other secrets. We may hide or remove posts that look like spam or that leak credentials. Optional screenshots are stored on object storage (for example DigitalOcean Spaces) and are as public as the post itself.
Email notifications about answers on your questions are off by default. You can opt in on your account page and turn them off anytime.
3. How We Use Your Data
- To operate the website, accounts, and licenses
- To respond to support requests and feedback
- To process payments and manage subscriptions (via Stripe)
- To send transactional email (confirmations, license notices, support replies, and — if you opt in — Community answer notifications) and, where you opted in, product updates
- To operate and moderate the public Community Q&A
- To improve the Software based on aggregate usage patterns and Feedback
- To protect against abuse, spam, and security threats
- To comply with legal obligations
4. Legal bases (EEA/UK and similar)
Where GDPR or similar laws apply, we typically rely on:
- Consent — e.g. optional product-update emails
- Contract — providing accounts, licenses, and support you request
- Legitimate interests — securing our services, improving the product with aggregate analytics, and preventing abuse, balanced against your rights
- Legal obligation — where retention or disclosure is required by law
5. Data Storage and Security
Account and application data are stored in systems we operate or our processors (see below). Passwords are hashed using industry-standard algorithms. We implement reasonable security measures including session hardening, CSP headers, and CSRF protection on the website. No method of transmission or storage is 100% secure.
6. Processors and data sharing
We do not sell personal data and we do not share it for cross-context behavioral advertising. We use service providers only as needed to run the product:
- Email / contact platform (Notifuse or similar) — transactional email, optional product-update lists, double opt-in, and related messaging
- Stripe — payment processing (their privacy policy applies to payment data)
- Hosting / infrastructure providers — storing our website and databases
- Object storage (e.g. DigitalOcean Spaces) — optional feedback and Community screenshot hosting when you upload attachments
- Analytics — privacy-friendly, cookieless-style site analytics
We may disclose information if required by law or to protect our rights, users, or the public.
7. Data Retention
- Notify / product-update list: until you unsubscribe or request deletion, or we shut down that list
- Accounts: while your account is active; deleted or anonymized after a deletion request subject to legal holds
- Support / feedback: as long as needed to resolve issues and improve the product, then deleted or archived in minimized form
- Community Q&A: public posts stay visible until you request deletion or we hide/remove them (spam, secrets, or legal reasons)
- Anonymous usage statistics: retained indefinitely in aggregate form
- Payment records: as required for tax and accounting
8. Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent (without affecting prior lawful processing)
- Opt out of anonymous software statistics collection
- Export your data in a portable format
- Lodge a complaint with a supervisory authority (EEA/UK)
8.1 California (CCPA/CPRA)
We do not sell personal information or share it for cross-context behavioral advertising. California residents may request access, deletion, and correction of personal information we hold. To exercise these rights, contact us using the email below. We will not discriminate against you for exercising privacy rights.
8.2 International transfers
We are based in the United States. If you apply or use our services from elsewhere (including the EEA, UK, or California), your information may be processed in the United States and other countries where we or our processors operate. Where required, we use appropriate safeguards for such transfers.
To exercise these rights, contact us via the contact form.
9. Children
Our services are not directed to children under 16, and we do not knowingly collect personal data from them. If you believe we have done so, contact us and we will delete the data promptly.
10. Third-Party Services
Stripe: Payment processing. Stripe Privacy Policy
11. Changes to This Policy
We may update this policy from time to time. Changes will be posted to this page with an updated revision date. Continued use of the site or forms after the effective date constitutes notice of the update.
12. Contact
Bean Local, LLC
Privacy, support, and general inquiries: use the contact form
so we can track your request in one place.
Related: Terms of Service