Beta
Beta and data handling
Streams is early software and you are one of a small number of people using it. This page says what that means in practice, what protects your data today, and what is not finished. It is written to be checked rather than believed, so where something is missing it says so.
Last reviewed 7 August 2026
What being in beta actually means
Features change, occasionally without notice. You may find bugs, and some screens are unfinished. We may need to migrate data as the product develops, and we take real care over that.
Your data is backed up daily. We would still gently suggest that, while we are in beta, Streams is not the only place a business-critical record lives — not because we expect to lose anything, but because early software changes quickly and it is simply good practice.
There is no uptime guarantee or service level agreement during the beta. If something breaks, tell us and we will fix it quickly.
Who can see your data
Each business is a sealed workspace. Your records, documents and history are scoped to your workspace, and that separation is enforced by the database itself rather than by the application remembering to filter — every table carries the workspace it belongs to, and the rules are applied on every read and write.
Inside a workspace you control who is invited and what they can reach. Fields you mark as sensitive — a landlord’s phone number, for example — are held separately again and shown only to people entitled to see them. Where a colleague is not entitled, the app says the value is concealed rather than showing you a blank, so you are never left guessing whether the data is missing or withheld.
We do not share one customer’s data with another, and we do not pool your records into a shared dataset. Data you import stays yours.
How it is protected
Traffic is encrypted in transit, and data is encrypted at rest by our hosting provider (Supabase, on AWS). Access requires a password with a 12-character minimum and a confirmed email address. Sign-up is invite only — nobody can create an account without one.
Two-factor authentication is available and we recommend turning it on. Uploaded documents are stored privately: they are never served from a public link, and each view generates a short-lived URL that expires after five minutes.
Administrative actions are recorded in an audit log, including permanent deletions.
What is not finished yet
We would rather tell you this than have you assume otherwise:
- Our database is backed up daily by our hosting provider. Restoring a backup rolls the whole database back to a point in time, so it is a recovery route for us, not an undo button for a single record — permanent deletion is still permanent.
- Streams has not been independently penetration tested or audited, and holds no security certification.
- We review security ourselves and fix what we find. The most recent review was 7 August 2026.
Deleting your data
Archiving a record hides it and can be undone. Permanent deletion is separate, is restricted to workspace owners and admins, and removes the record together with its activity history, tasks, field history, concealed fields and uploaded documents — including the files themselves.
Two things are deliberately kept: publicly registered property transactions, which are public record rather than your personal data, and meeting notes, which usually reference more than one record. Both are detached from the deleted record.
You can delete an entire business yourself, from its General settings. Only its owner can, the name has to be typed to confirm, and it removes every record, document, stream and task in it, plus everyone else's access. Your account and any other businesses you belong to are untouched.
Personal data and the law
A CRM exists to hold contact details and deal history, and that is a normal and lawful purpose. We apply data minimisation: we do not collect attributes the product does not need, and we deliberately do not store nationality.
We do not add people’s contact details from scraped or purchased sources. Contacts are added by the people who have actually spoken to them.
This page is a plain-English summary, not a contract or legal advice. If you need a data processing agreement or have a specific compliance question, get in touch and we will deal with it directly.
Telling us about a problem
If you find a security issue, please report it before sharing it anywhere else, and we will confirm receipt and keep you posted on the fix. Nothing on this page is intended to discourage you from reporting something.