Privacy Policy
Last updated 5 September 2026
This policy explains what Begin collects, why we collect it, who we share it with, and what you can do about it. It covers both the website and the product.
1. Two different kinds of data
Begin holds two separate kinds of thing, and almost every question about privacy here has a different answer depending on which one you mean.
Your workspace data is specific to you: your account, the prompts you write, the projects built from them, and the code and previews we generate. Nobody outside your workspace can see it.
Fetched source material is what we retrieve when you ask for a clone: the public pages at a URL you give us, and the styles, structure and assets on them. We fetch it because you instructed us to, we use it to produce your build, and it is not shared into anyone else’s workspace.
2. What we collect about you
Your account. Your email address, and your name and profile picture if they come from Google when you sign in that way. You can sign in with Google or with a one-time link sent to your email. We do not create or store passwords, so there is no password of yours on our side.
What you build. The prompts and URLs you send, the target you chose (website, iOS, Android or Chrome extension), the generated code, the previews, and the history of changes you asked for. This is the product; it is kept so that a project you come back to next month is still there.
Credits and billing. Your subscription status, your plan and your credit ledger — what each build cost and what was refunded. Card details go directly to Stripe and never touch our servers.
Basic technical logs. IP address, browser and timestamps, kept for security and debugging.
We do not train models on your prompts or your code. They are used to run your builds and to answer your support questions, and for nothing else.
3. Material we fetch on your instruction
This is the part worth reading carefully, because it is the part most policies in this category leave out.
When you ask Begin to clone a site, we fetch what is publicly visible at that address, the way any logged-out visitor sees it: the markup, the stylesheets, the layout, the fonts and colours, and the text on the page. We do not sign in to anything to do it, we do not ask you for someone else’s credentials, and we could not use them if you offered.
That material can contain personal data — a founder’s name in an about section, a team photograph, a contact address published on a contact page. It reaches us because you pointed us at it. In the build we produce, the copy is rewritten rather than reproduced and the imagery is generated rather than downloaded, which removes most of it; what survives is whatever your own later edits put back.
You are the one who decides what gets fetched, which is why the Terms require you to own the source or have the right to copy it. If you are the owner of a site somebody has cloned through Begin and you want to raise it with us, write to [email protected] — tell us the URL and we will look into it, remove what we hold, and act on the account if it broke our acceptable use rules.
4. Why we collect it
- To run the product you signed up for, which is the bulk of it.
- To bill you correctly, and to keep an account inside the plan it pays for.
- To meter credits honestly — recording what each build cost is how a failed build gets refunded automatically.
- To keep the service up and to investigate abuse.
- To send you service email. We do not sell your data to anyone, ever.
5. Who else sees it, and data processing
We use a small number of processors, and only where the work genuinely requires it. Each one processes data on our documented instructions and is bound by its own terms with us; this section, together with our Terms, is what we currently offer as our data processing commitment. If your organisation needs a signed DPA on your own paper, write to [email protected].
- Stripe — payments and subscriptions.
- Google — only if you choose to sign in with a Google account.
- Our model providers — the services that generate code, copy and imagery from your prompt. They receive the prompt and the material needed to answer it, under terms that forbid training on it.
- UseSend — the service that delivers our sign-in links and service email.
- Our hosting, database and object-storage providers — where the application runs and your projects are stored.
We run no third-party analytics on this site: no analytics script, no advertising pixel, no session recording, no heatmap. Nothing about your visit is sent to an analytics vendor, because we do not use one.
We also disclose data where the law requires it, and we will tell you when we are permitted to.
6. How long we keep it
Your account and everything under it stay until you delete them. Deleting a project deletes its builds, its previews and its prompt history. Ask us to close your account and we will delete your personal data and your projects; we keep the minimum billing records that tax law requires.
Fetched source material is kept only as long as it is needed to produce and re-produce your build, and goes when the project does. We are not, at this stage, committing to a fixed retention period in days; we would rather say that plainly than publish a number the system does not enforce.
7. Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to how we are using it. Email us and we will action it — normally within a few days, and always within a month. If you are in the UK or EU you also have the right to complain to your data protection authority.
9. Security
Traffic to the site and the API is served over HTTPS, and the managed database and object storage we use encrypt what they hold at rest. Each workspace’s projects are scoped to that workspace, and internal access is limited to the people who need it. No system is perfect; if a breach affects you we will tell you promptly. What we do and do not claim is set out on our security page.
10. Changes
If we change this policy materially we will email you before it takes effect. The date at the top always reflects the current version.
11. Contact
Questions about any of this, and removal requests: [email protected].