BetaBots
PrivacyTermsService AgreementManaged review
BetaBots legal

Privacy Policy

How BetaBots handles information for managed review requests, delivery, safety, and limited site analytics.

Effective
22 July 2026
Operator
Self Degree Education Educational Technologies – FZCO
Location
Dubai, United Arab Emirates
Legal review notice

These are contractual product terms intended for the BetaBots managed service. They should receive qualified legal review before large-scale sales, enterprise contracting, or expansion into additional jurisdictions.

1. Who this policy covers

This policy applies to the BetaBots website and managed review service operated by Self Degree Education Educational Technologies – FZCO. It does not govern a customer's own privacy practices or a separately operated third-party service.

2. Form and product data we collect

When you request a review, we collect the public product URL, agreed scenario, intended audience, safe authentication constraints, actions to avoid, contact email, acceptance records, a request ID, source path, timestamps, email delivery status, and, when present on the first page of a browser session, bounded paid-attribution fields: UTM source, medium, campaign, term, and content plus Google click identifiers (gclid, gbraid, and wbraid). We use attribution to measure paid-search lead acquisition, diagnose campaign quality, and retain it with the request record under the routine retention period below. If a request proceeds, we also process the test environment content visible during the agreed sessions and the resulting screenshots, action logs, notes, and report material.

Do not submit or paste passwords, API keys, tokens, payment details, or personal customer data. Arrange any safe test account separately. Remove or replace real personal data before providing access.

3. Abuse prevention and technical data

We use timing signals, a hidden honeypot field, request-size limits, public-host checks, and rate limits. A client IP may be used transiently to create a keyed one-way rate-limit hash, but we do not store the raw IP solely for rate limiting. The configured bot provider is either Cloudflare Turnstile, which receives information needed to assess automation, or self-hosted ALTCHA, which verifies local proof of work and stores a one-way accepted-solution hash temporarily to prevent replay. The hash is removed after challenge expiry with a one-hour safety margin. Network infrastructure still receives transport IP information.

4. Analytics

PostHog receives only allowlisted custom events for page, offer, legal-page, navigation, installation, and request states. Immediately before sending, we rebuild each event to contain only its event name, event UUID, timestamp, public project token, anonymous distinct ID, a controlled false person-profile-processing flag, fixed product product=betabots, fixed surface surface=marketing_site, and bounded properties specifically allowed for that event. Unknown or incomplete events are dropped.

Only the homepage may evaluate the launch-authorized BetaBots — Agent feedback loop positioning v1 (PostHog experiment ID 388285; flag ID 781937) through the betabots-agent-feedback-loop-positioning-v1 flag. Enrollment occurs only while the PostHog experiment has a start date and the flag is active; otherwise no visitor is enrolled. Eligible homepage sessions are randomized equally between control and test. The browser first reads, writes, and re-reads a random anonymous identifier in session storage and, after an exact assignment, records the bounded control or test variant there too; both last only until the browser tab or session closes. If that storage cannot be established or verified, ordinary bounded analytics continue but the experiment is disabled and the hero shows its control message. When the experiment is enabled and the hero evaluates the flag, PostHog receives a rebuilt $feature_flag_called exposure containing only that flag, its control or test response, the anonymous distinct ID, project token, fixed product and surface, and disabled person-profile processing. Other allowlisted funnel events receive that exact variant only after that exposure is accepted and stored.

URL query strings, referrers, browser and device details, screen dimensions, arbitrary properties, person-property mutations, and UTM values are removed from PostHog. Bounded UTM source, medium, campaign, term, and content remain only with the managed-review request record. Google click identifiers are never sent to PostHog. Autocapture, automatic page events, rage and dead clicks, exceptions, heatmaps, performance capture, session recording, surveys, product tours, conversations, person profiles, and external dependency loading are disabled. Visual web experiments are disabled; the named hero test is a code experiment that uses the feature-flag evaluation above. Submitted form content, product URLs, request IDs, and email addresses are not sent to analytics.

The browser event envelope deliberately does not include an IP property. The analytics network request still exposes its transport IP to PostHog unless the operator enables and verifies a project-side discard-IP transformation; that production control cannot be configured or verified from this codebase.

5. Why we use the data

We use data to review eligibility and authorization, prevent abuse, communicate about the request, perform the agreed work, produce evidence and reports, operate and secure the service, diagnose delivery, meet legal obligations, and improve the commercial funnel using aggregate non-content analytics.

6. Email delivery and processors

The configured email provider is Resend, an authenticated SMTP provider such as Google Workspace, or OneSignal; it processes owner notifications and customer acknowledgements. When OneSignal is selected, it receives the email address required to register its email subscription and a product-prefixed hashed external ID; provider acceptance is not a claim of inbox delivery. Cloudflare processes verification only when Turnstile is selected; ALTCHA proof-of-work verification is self-hosted. PostHog processes limited analytics events when enabled. If configured, Google Ads receives only a post-storage conversion event with its configured destination, not form content, contact email, URLs, or click identifiers. Database, hosting, network, infrastructure, and professional-service providers process data only as needed to operate the service. These processors may handle data, including transport IP information, in other countries under their own safeguards and contractual terms.

7. Retention and deletion

Routine request and delivery records are scheduled for deletion once they reach 24 months after request submission, unless an accepted proposal requires a different period or law requires longer retention. A monitored daily cleanup may complete deletion up to 24 hours after that threshold. Rate-limit buckets are deleted through the approved purge process. Expired ALTCHA replay-prevention hashes use a separate short cutoff based on challenge expiry. Research artifacts follow the accepted proposal and are deleted or anonymized when no longer needed for delivery, support, disputes, security, or legal obligations.

You may request access, correction, or deletion through the contact below. We will verify the request and may retain limited records where required for contracts, fraud prevention, disputes, tax, or law.

8. Security and your choices

We use reasonable technical and organizational controls, but no online service is risk-free. Use a safe, isolated test account with the least privilege needed. You may avoid optional analytics by using browser blocking controls; the review form still requires operational and anti-abuse processing.

9. Changes

Material changes will be posted with a new effective date. An accepted proposal may add project-specific data handling terms; where it expressly conflicts, the accepted proposal controls for that engagement.

Contact

BetaBots is the customer-facing brand of Self Degree Education Educational Technologies – FZCO, Dubai, United Arab Emirates.

Legal and privacy requests: yev@quested.io.

BetaBots

Operated by Self Degree Education Educational Technologies – FZCO, Dubai, UAE.

Product

Managed reviewPublic demoDocumentation

Project

GitHubLicenseChangelog

Legal

PrivacyTermsService Agreement
© 2026 BetaBotsAGPLv3 projectCommercial service terms apply