Plans
Dashboard
Support

Privacy Policy

Last updated: February 23, 2026

1. Introduction

Bewns ("we", "our", "us") operates the website bewns.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using Bewns, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and a securely hashed version of your password. We never store passwords in plain text.

2.2 Uploaded Files

Files you upload are stored in secure object storage. We store metadata (filename, size, file type, upload date) in an edge database (SQLite). Images are automatically optimized using WASM-based compression.

2.3 IP Address

For legal compliance and abuse prevention, we log the IP address of the uploader when a file is uploaded. This is stored in our database alongside the file metadata.

2.4 Session Data

We use HTTP-only cookies to manage your login session. Session IDs are stored in our edge database. We track session creation time, last activity, and expiration.

3. How We Use Your Information

  • To provide, maintain, and improve the Service
  • To authenticate your identity and manage your sessions
  • To store and deliver your files via our global edge network
  • To enforce storage quotas and plan limits
  • To send transactional emails (e.g., welcome email on signup)
  • To detect and prevent abuse, fraud, and unauthorized access
  • To comply with legal obligations

4. Cookies

Bewns uses a single HTTP-only session cookie (bewns_session) to maintain your logged-in state. This cookie is marked Secure in production (transmitted over HTTPS only) and uses SameSite=Lax to prevent CSRF attacks. We do not use advertising or tracking cookies.

5. Data Storage & Infrastructure

All data is processed and stored on our global edge network. Files are stored in secure object storage, and metadata is stored in an edge database (SQLite at the edge). Your data may be replicated across multiple data centers for performance and redundancy. Our infrastructure complies with SOC 2, ISO 27001, and GDPR.

6. Data Sharing

We do not sell your personal data. We may share information only in the following cases:

  • Service providers: CDN and edge infrastructure providers (hosting, storage, delivery), ZeptoMail (transactional email)
  • Legal requirements: When required by law, court order, or governmental authority
  • Shared content: Files in shared Bewns are accessible via their unique share link

7. Data Retention

Your account data is retained as long as your account is active. Uploaded files may have expiration dates set by you or determined by your plan. File metadata (including uploader IP) is retained indefinitely for legal compliance even after the file itself expires from R2 storage.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact us at support@bewns.com.

9. Security

We use industry-standard measures to protect your data, including bcrypt password hashing, HTTP-only secure cookies, login lockout after 5 failed attempts, and encrypted data transmission via HTTPS. However, no method of transmission over the Internet is 100% secure.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Bewns

Email: support@bewns.com

Website: bewns.com