Beyond AI ("Beyond AI," "we," "us") is operated by Beyond The Checkout Inc., a Delaware corporation. This Privacy Policy explains how we collect, use, and share information in connection with our website (beyondai.help), our consulting services, and the custom AI applications we build and operate on behalf of our business clients, including social media publishing tools that interact with Meta's Facebook and Instagram platforms and with LinkedIn on a client's behalf.
1. Scope of this Policy
This policy covers two audiences:
- Visitors to beyondai.help — people browsing our marketing site or contacting us about services.
- Authorized users of client-facing applications we build — for example, dashboards we operate for a specific client where their team signs in to plan and publish content. In those cases, we act as a data processor on behalf of the client; the client is the data controller.
When we integrate with third-party platforms on a client's behalf (for example, posting to a client's own Facebook Page or Instagram Business Account via the Meta Graph API), we access those platforms only with the client's explicit authorization and only to perform the tasks the client has asked us to perform.
LinkedIn. When a client authorizes us to manage their LinkedIn Company Page, we use the LinkedIn APIs (including the Community Management API and Sign In with LinkedIn via OpenID Connect) to authenticate the authorizing Page administrator and to publish, manage, and moderate organic content and engagement that the client has reviewed and approved. This includes creating posts, reading, replying to, editing, moderating, and deleting comments, and adding or removing reactions on the client's Company Page posts. We access only the specific LinkedIn organization (Company Page) the client authorizes, using OAuth access tokens granted by a Page administrator. To enable comment and engagement management, we process limited personal data of LinkedIn members who publicly engage with the client's Company Page (such as a commenter's name, profile identifier, comment content, and reactions), solely to display, respond to, and moderate that engagement on the client's behalf. We do not use this information for any other purpose, we do not sell it, and we do not use it to build independent profiles of members. Access tokens and any member engagement data are stored encrypted and retained only for as long as needed to provide the service, and in no case longer than ninety days after the data is retrieved or after the client engagement ends, whichever comes first, after which it is deleted. All LinkedIn data is handled in accordance with the LinkedIn API Terms of Use and the LinkedIn Platform Guidelines.
2. Information We Collect
2.1 Information clients and their authorized users provide
- Name, email address, phone number, and company information.
- Content created or uploaded into our applications (text, images, marketing drafts, campaign copy).
- Access credentials or tokens a client provides so that we can operate on their behalf — for example, Meta system-user tokens for their own Facebook Pages and Instagram accounts, Klaviyo Private API Keys, or review-platform API keys. We never ask for a client's personal Facebook password; access is granted via Meta's Business Portfolio partner-access flow.
- Business assets a client assigns to us for processing, such as their own product photos, customer reviews they own, and their own email subscriber lists.
2.2 Information we collect automatically
- Standard server and application logs: IP address, browser type, timestamps, pages requested, and error traces. Used for security, debugging, and service reliability.
- Authentication events (sign-in times, MFA events) in client dashboards we operate.
- Aggregate traffic analytics on beyondai.help. Our website is hosted on Cloudflare, which provides privacy-friendly, cookieless analytics (page views, country-level geography, referrer). We do not use Google Analytics, advertising pixels, or tracking cookies on our marketing site, and we do not build individual visitor profiles.
2.3 Information received from third-party platforms
When a client authorizes us to operate on their accounts on third-party platforms (for example, Meta's Facebook and Instagram, Google Workspace, Klaviyo, or review platforms), we may receive data from those platforms' APIs to perform the tasks the client has asked us to perform.
Specifically, when a client authorizes us to operate on their Meta-owned assets, we may receive from Meta's Graph API:
- Public metadata about the client's own Facebook Page or Instagram Business Account (page ID, account ID, display name).
- Posts, captions, images, and comments associated with the client's own assets, to the extent needed to schedule, publish, or respond to that content on the client's behalf.
We do not collect data about the client's followers, fans, or the general public beyond what Meta exposes through standard Page and Instagram Business API endpoints, and we do not use any such data for advertising, profiling, or resale.
3. How We Use Information
- Deliver the specific services a client has engaged us to build — for example, generating draft social posts, scheduling publishing, drafting email campaigns, or analyzing customer reviews.
- Authenticate authorized users and keep the applications secure.
- Communicate with clients about projects, invoices, and support.
- Improve our products and services in aggregate (bug fixes, performance, reliability). We do not use client content to train public AI models.
- Comply with legal obligations and enforce our terms.
4. How We Share Information
We do not sell personal information. We share information only as described below:
- Infrastructure providers (sub-processors) that host, compute, or transmit data on our behalf: Amazon Web Services (hosting, storage, authentication), Cloudflare (website hosting, CDN, and cookieless analytics for beyondai.help), Anthropic (Claude large-language-model processing), Calendly (scheduling when a visitor books a call through our website), Meta Platforms (when posting to a client's authorized Facebook/Instagram assets), LinkedIn Corporation (publishing and managing organic content, and reading, moderating, and reacting to comments and engagement, on a client's LinkedIn Company Page, and authenticating Page administrators, on the client's behalf, via the LinkedIn APIs), Google (Drive and Sheets integration where a client has explicitly connected them), Klaviyo (email delivery when a client has connected their Klaviyo account), and review platforms a client has connected (for example, Stamped.io).
- With the client — content and logs associated with their own workspace are visible to the client's authorized users. A client's data is not shared with any other client.
- When required by law — to comply with a valid legal request, or to protect the rights, property, or safety of Beyond AI, our clients, or the public.
- In a business transfer — if Beyond The Checkout Inc. is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to the terms of this policy.
5. Meta Platform Data Handling
When we access a client's Facebook Page or Instagram Business Account on their behalf:
- Access is always granted by the client through Meta's official Business Portfolio partner-access flow. We do not store or request any user's Facebook login credentials.
- We use Meta-issued system-user tokens scoped to the specific permissions the client has granted (for example,
pages_manage_posts,instagram_content_publish,instagram_manage_comments). - Data obtained from Meta is used only to operate the specific features the client has engaged us for — publishing content, reading comments for reply drafting, and related workflows.
- We do not combine Meta platform data with data from other sources for advertising profiles, do not sell Meta platform data, and do not use Meta platform data to build independent databases.
- Clients may revoke our access at any time by removing Beyond AI's partner access from their Meta Business Portfolio. Upon revocation, we cease access immediately and delete associated tokens and cached platform metadata.
6. Data Retention
We retain client content and configuration for as long as the client maintains an active engagement with us, plus a limited period afterward for backup, legal, and audit purposes (typically 90 days). Server logs are retained for up to 90 days. Access tokens are retained only while the corresponding integration is active; when an integration is disconnected or an engagement ends, we revoke and delete the token.
7. Data Security
We use industry-standard measures to protect information, including encryption in transit (HTTPS/TLS), encryption at rest on our infrastructure providers, multi-factor authentication for client dashboards we operate, least-privilege access controls, and secrets-manager storage for third-party credentials. No system is perfectly secure, and we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your personal information, subject to limited exceptions for legal or legitimate-business reasons.
- Object to or restrict certain processing.
- Data portability, where applicable.
If you are an end user of a client's application and your information is processed by us on that client's behalf, please direct your request to the client in the first instance; we will support the client in responding.
9. How to Request Data Deletion
To request deletion of personal information that Beyond AI holds about you, email oliver@beyondai.help with the subject line "Data Deletion Request" and a description of the data you want deleted. We will respond within 30 days. If you are a Meta user whose data reached us only through a client's authorized connection, deletion requests are best directed to the client; we will assist them in honoring the request.
10. Children's Privacy
Our services are intended for businesses and their authorized personnel, not for children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will promptly delete it.
11. International Transfers
Beyond AI is based in the United States and our services are intended for U.S.-based businesses and their personnel. Our infrastructure providers may store and process data in the United States and other jurisdictions where they operate data centers. If you access our services from outside the United States, your information will be transferred to, stored, and processed in the United States, which may have data-protection laws different from those of your country. If you are located in a jurisdiction with specific cross-border transfer requirements (for example, the EU, UK, or Switzerland), please contact us before using our services so we can discuss whether an appropriate transfer mechanism is needed.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated policy at this URL and update the "Effective" date. Material changes will be highlighted. Continued use of our services after changes become effective constitutes acceptance of the revised Policy.
Contact Us
Beyond AI
A service of Beyond The Checkout Inc., a Delaware corporation
Email: oliver@beyondai.help
Website: https://beyondai.help
For privacy-specific inquiries, please use the subject line "Privacy" so we can route your message quickly.