Privacy policy
Privacy policy
Last updated: 25 August 2026 · effective from the date of publication
This policy explains what personal data ReefBeacon (“the system”) collects, for what purposes, for how long, and what rights you have. We follow a data-minimisation principle: we collect only what is necessary to run the alerting service. This policy applies to all pages of the website and console.
What we collect
The system serves institutional users and offers no public sign-up. Depending on how you sign in and use it, we may collect:
- Account data: your email, a one-way bcrypt hash of your password (plaintext is never stored), and your role (coordinator / researcher / etc.). If your organisation enables single sign-on (Google Workspace / Microsoft Entra), we record your email and group memberships (used for role mapping) at first sign-in; your password is verified by your identity provider and never touches this system.
- Session data: after sign-in, the browser holds a session cookie (a JWT) used solely to keep you signed in; it expires on sign-out or timeout.
- Delivery and read receipts: email delivery receipts for alerts and read states of in-app notifications (which account acknowledged which alert, and when), used for audit and traceability.
- Error telemetry: when Sentry is configured, the system automatically reports errors and performance events to diagnose faults. Every event passes through a unified redaction net before it is sent — passwords, tokens and keys are replaced with ***, and never leave the system.
- Local preference: your console language preference is kept in your browser’s localStorage; it stays on your device and can be deleted at any time.
How we use the data
We use the data only for the purposes below; we do not sell your data, and we do not use it for advertising, profiling, or any purpose unrelated to the service:
- To authenticate sign-in and control access to features and data by role;
- To send alert emails and in-app notifications to the registered recipient addresses when heat-stress thresholds are breached;
- To produce auditable delivery/read logs (retained for at least 1 year);
- To diagnose faults and keep the service stable (error telemetry).
AI and your data
The AI models in this system (Gemini) process only marine-monitoring data (temperature readings, survey photos, the bleaching-event library) and system content, for pipeline orchestration and narrative generation. Your account data is never sent to the AI service as model input.
Cookies and local storage
- Session cookie (essential): keeps you signed in; deleting it signs you out.
- Language preference (localStorage): remembers the language you chose in the console; it never leaves your browser.
- The system uses no advertising cookies and no third-party analytics or tracking cookies.
Third-party services
- Sentry (error monitoring): receives redacted error and performance events.
- Resend (email delivery): used only to send alert emails, to the registered alert-recipient addresses.
- Institutional single-sign-on providers (Google / Microsoft): involved only when you choose SSO sign-in.
- NOAA Coral Reef Watch, the AFCD and other data-source agencies are not data processors of this system — we consume their public data.
Data retention
- Audit logs (alert triggers, deliveries, acknowledgements) are retained for at least 1 year;
- Account data is retained while the service relationship lasts; after an account is deactivated, we delete or anonymise personal data such as your email (subject to statutory retention obligations).
Your rights
You may request access to, correction of, or deletion of the personal data we hold about you. Institutional users should make the request through their organisation’s liaison channel; we will respond within a reasonable time. This policy follows the data-protection principles of Hong Kong’s Personal Data (Privacy) Ordinance.
Data security
- HTTPS/TLS everywhere; encryption at rest for the database;
- Passwords stored as bcrypt hashes; secrets held via secret management, never in the repository or logs;
- Role-based, least-privilege access control;
- Logs and telemetry pass through the same redaction net before persistence or outbound delivery.
Minors
The system serves professional conservation and research institutions; it is not directed at minors, and we do not knowingly collect personal data from minors.
Changes to this policy
When this policy is updated we will publish it here and update the “last updated” date; material changes will be announced to institutional users by in-app notification or email. Continued use of the system constitutes acceptance of the updated policy.