Privacy

Your records remain yours.

This self-hosted application stores account and apiary data in the database configured by the site operator.

What is stored

Account identity and residency, beekeeper registration details, apiary and hive operations, uploaded evidence, email delivery records, security attempts, login IP intelligence and an audit history.

How it is used

Data is used to provide the record-keeping service, secure user accounts, send transactional email, support audit history and present jurisdiction-specific guidance. It is not sold by the application.

IP intelligence

A successful login records the client IP and caches VPN, proxy, Tor and location results in the database. Fresh cached results are reused before the VPNAPI.io service is contacted. The operator should publish the applicable retention period and rotate the API key if it is disclosed.

Payments

PayPal handles paid subscription checkout. The application stores a PayPal subscription reference and webhook status, not card numbers or payment credentials.

Access and exports

Normal record queries are restricted to the signed-in owner. Administrators can manage accounts and troubleshoot the service. Users can export operational sections as CSV and should contact the operator for correction or account-removal requests.

Retention and deletion

Operational records use archive markers so legally significant history is not silently destroyed. The operator must set a retention policy that meets the applicable Code, state law, food-safety, tax and incident requirements. Private uploads are served only after an ownership check.

Security

The application uses password hashing, CSRF tokens, prepared database queries, session cookies, login throttling and audit logs. The operator remains responsible for HTTPS, updates, backups, mail security, database access and cPanel account protection.