Privacy
Your quiz content stays under your control.
Quiz drafts and spreadsheet imports stay in your browser. Only the normalized quiz is sent to BeanNest when you explicitly publish or save online.
Last updated August 15, 2026. BeanNest is published by Bean Nest Studio. Contact: Contact page.
Files and local processing
The tools do not send file bytes, filenames, page text, thumbnails, document metadata, image contents, or file fingerprints to BeanNest. Results and previews use temporary browser data that is removed when you replace files, reset a tool, close an Editor workspace, or leave the page. The AI Image Upscaler downloads static model files, but your image and generated pixels are not included in those requests.
Quiz Creator
When Quiz Creator is enabled, draft quiz editing and CSV/XLSX import or export happen in your browser. BeanNest does not upload the source spreadsheet. Publishing or saving online sends the normalized quiz title, description, questions, choices, correct answers, and optional explanations to a dedicated Cloudflare D1 database so the share link can work across devices.
Published creator quizzes use a random public ID and a separate private editing capability. The application database stores a cryptographic hash of the editing capability rather than the raw secret, plus the quiz document, revision, status, visibility, and timestamps. Creator quizzes start unlisted and noindex. Player answers and scores remain in the browser and are not stored as Quiz attempt history in this version.
If you explicitly request a recovery email, the email address is sent to the configured transactional email provider only to deliver that message; it is not stored in the Quiz D1 schema. The email contains a separate one-time recovery token rather than the permanent editing secret. Using the token rotates the private editing capability. Quiz reports may store a fixed report reason and an optional short note in D1 for moderation; the report form does not ask for reporter identity.
Analytics
BeanNest may use aggregate Cloudflare traffic reporting to understand visits, requests, popular paths, countries, device categories, and data transfer. BeanNest has no visitor accounts and does not use its local management dashboard to build visitor profiles.
Google Analytics is currently enabled automatically on public production pages. When enabled, it helps BeanNest understand page use, internal navigation, and whether a tool is started, completed, cancelled, failed, or followed by a download.
Analytics may receive a page title, a path without its query or fragment, a broad site area, sanitized internal-link paths, and coarse tool events. They do not send filenames, file contents, document text, images, thumbnails, metadata, hashes, object URLs, precise dimensions, exact byte counts, quiz question/answer text, private quiz or recovery secrets, recovery email addresses, player answers or scores, user-entered values, or raw error messages. Advertising storage, personalization, Google signals, User-ID, and cross-domain tracking are not enabled through this analytics setup.
Analytics providers may process standard technical data needed to offer their service, such as timestamps, first-party identifiers, browser and device information, language, screen size, and IP-derived location.
Product feedback
After a tool successfully produces a result, BeanNest may show a small optional feedback prompt. A rating uses only the tool ID and one of five fixed rating categories. If you choose to write a note, that note is sent to BeanNest's same-origin feedback endpoint and stored in a dedicated Cloudflare D1 database so the publisher can review what should be improved.
The feedback form does not ask for your name, email address, account, filename, or file contents. Please do not put personal or sensitive information in the optional note. Written feedback is not sent to Google Analytics. The application feedback schema stores a generated response ID, time, tool ID, rating, optional note, and schema version. Rows older than 180 days are scheduled for opportunistic cleanup when new feedback arrives.
Advertising
Advertising is currently disabled. When enabled, only configured ad slots load the approved provider script. File processing stays separate, and the tools do not provide PDF or image contents to the advertising service.
Contact messages
Messages sent through the Contact page are handled through Gmail. The sender address and message are used to reply, investigate a report, or handle a privacy or security request. They are not added to a newsletter or marketing list.
Google processes and stores those messages as the email provider. Do not send private files, passwords, identity documents, financial records, medical information, or other sensitive content. Messages are kept only as long as reasonably needed for the inquiry, security, recordkeeping, or legal requirements. You may use the same address to request access, correction, or deletion, subject to applicable retention requirements.
Device and output limits
Browser processing uses your device memory, CPU, and, for the AI Image Upscaler, graphics hardware. Safety limits may reject large jobs before they destabilize the browser. Some PDF operations rasterize pages or can remove selectable text, forms, links, annotations, signatures, bookmarks, or accessibility structure. Keep every original and check the result before relying on it.
