Privacy Policy

Last updated:

Share Beam (“we,” “the extension”) is a screen-sharing Chrome extension and companion viewer webpage. This page explains what data moves through Share Beam, what we store, and what we never see.

The short version

Your screen, camera, microphone audio, chat messages, and files travel directly between browsers using WebRTC — a peer-to-peer connection. None of that content ever passes through, or is stored by, any server we operate. Separately, to run the service at all, we collect a small amount of account and session metadata — described in full below — which is stored and visible to us via an internal, password-protected admin panel. We do not use analytics, tracking pixels, or advertising SDKs anywhere in the extension, viewer page, or this website, and we never sell or share this data with third parties.

Email verification

Before hosting or joining a share, you must provide an email address and verify it by clicking a link we send. This is required for both hosts and viewers, for accountability — it's a meaningful deterrent against abuse of a tool that broadcasts a screen to strangers with a simple 6-digit code — and is not used for marketing. Once verified, that email is remembered (in your browser's local storage, or the extension's local storage for hosts) so you won't be asked to re-verify next time from the same browser. An address only ever needs to verify once, total, whether you use it to host or to join.

Location and device information

We ask for permission to use your browser's precise location (GPS or Wi-Fi based) when you host or join a share. This is optional — declining the browser's permission prompt doesn't stop you from sharing or joining; we simply fall back to the coarser, IP-derived location described below. Precise coordinates, when granted, are stored and shown to the site administrator as a map link — we don't resolve them to a place name ourselves, so no location data is sent to a third-party geocoding service.

We also record basic device information — your browser name/version, operating system, and device type — parsed from the standard User-Agent header your browser already sends with every request. This isn't a fingerprinting technique or anything unusual; it's the same header every website receives, we just keep a record of it.

What we collect and store

Every time someone hosts or joins a session, we record the following in a database on our server:

This is separate from, and much narrower than, the actual content of your call — your screen, audio, chat, and files are never captured or stored this way; only who connected, from roughly where, on what, and for how long. This data is retained indefinitely and is visible only to the site administrator through a password-protected internal panel — it is never sold, never used for advertising, and never shared with any third party.

IP-derived location uses a self-hosted, offline lookup database — your IP address is never sent to any third-party geolocation service to answer that question.

The WebRTC handshake messages themselves (session descriptions and ICE candidates) still only ever pass through our signaling server in memory, for the moment it takes to open the direct peer-to-peer connection — those are not persisted.

What's stored on your device

DataWherePurpose
Current session state (name, toggles, participants, chat)chrome.storage.sessionLets the popup close and reopen without losing your session — cleared when your browser fully closes.
Session history (code, viewer names, duration, message counts)chrome.storage.localA private log of your own past sessions, visible only to you, on your device.
Verified emails (extension)chrome.storage.localLets a host skip re-verifying an email they've already confirmed on this browser installation.
Verified emails (viewer webpage)browser localStorageSame idea for viewers joining via the webpage — scoped to your browser, not the extension.

None of this is transmitted anywhere beyond what's described above. Uninstalling the extension, or clearing this site's data, removes it from your device.

Permissions we request, and why

PermissionWhy
offscreenRuns the screen-capture and peer-connection logic in a hidden document that survives the popup closing.
storageThe device-local state and history described above.
downloadsSaves a recording or screenshot you take of your own share to your Downloads folder.
tabsOpens a one-time tab to request microphone permission, and builds the "Copy Join Link" URL.

Third parties

Share Beam uses a public STUN server (Google's stun.l.google.com) solely to help browsers discover their own network address for the peer-to-peer connection — standard practice for any WebRTC application. No media or personal data is sent to it; STUN only exchanges network address information.

Children's privacy

Share Beam is not directed at children under 13 and does not knowingly collect information from them.

Changes to this policy

If this policy changes, we'll update the date at the top of this page. Continued use of Share Beam after a change means you accept the updated policy.

Contact

Questions about this policy or how Share Beam handles data? Use our contact form — we read every message.