Personalized tool results require a Beard Insider account, but questionnaire answers, ingredient lists, photo previews, experiments, and shelf-life records stay in your browser and are not attached to that account. Email access uses a short-lived one-time code. Beard Insider stores the account email, a randomly generated internal credential hash, and necessary login and security data; it does not store the readable verification code. Beard Notes remains a separate optional choice. We do not use behavioral advertising, sell personal information, or share it for cross-context behavioral advertising.
Scope and who operates this site
This policy explains how Beard Insider (?Beard Insider,? ?we,? ?us?) handles information on beardinsider.com. Beard Insider is an independent grooming publication and decision-tool site. Questions and privacy requests can be submitted through the contact, corrections, and data-request form.
Information you choose to provide
Tool-result accounts
After you complete a tool, its personalized result remains hidden until the server confirms an authenticated account. Email access sends a six-digit one-time code without disclosing whether an account exists. The connection-bound challenge stores only HMAC fingerprints, expiry, and attempt data, and is rate limited and single use.
Only after verification does Beard Insider, under an atomic email-fingerprint lock, sign in an existing low-privilege customer or subscriber, or create a customer with a strong random internal password that is never shown or emailed. Standard authentication restrictions run and a same-origin request confirms the login cookie before reveal. Privileged, roleless, or restricted accounts must use standard My Account sign-in. Tool answers and results remain browser-local and account creation does not subscribe you to Beard Notes.
Google, Amazon, and Microsoft account options are shown, but each remains unavailable until its social-login connection is configured and verified. Global auto-link and login guards deny privileged accounts.
Beard Notes waitlist
If you join the waitlist, Beard Insider stores your email address, signup time, and the version of the consent notice shown at signup. The current form is a waitlist; it does not create an account and no automated marketing campaign is currently being sent.
Contact, correction, and data requests
If you send a message, Beard Insider stores your optional name, email address, selected reason, optional relevant page URL, message, submission time, and consent-notice version in a private administration area. The site owner uses this information to review, respond, investigate a correction, or complete a request. An administrative email may announce that a private message is waiting, but the notification does not include your full message.
Information that stays on your device
Routine builder and product handoff
The ten routine-builder answers, calculated plan, and any ingredient or allergen name you type remain in the current page?s browser memory. They are not sent to Beard Insider, saved in local storage, or attached to an email record. A ?Find this product? link places an allowlisted subset?length, texture, skin response, product job, scent preference, budget default, and whether stricter evidence or verified impact criteria were selected?after the # in the product-finder URL. URL fragments are not sent in the normal request to the web server. The finder validates the allowed values and removes the fragment from the visible URL on arrival.
Photo-assisted beard tools
The photo tools create a temporary local preview in your browser. The file input is not sent to Beard Insider. Beard Insider does not upload, store, identify, recognize, score, or analyze the photo or its pixels. Remove the preview with the tool?s ?Remove photo? control or close or refresh the page.
Experiment and shelf-life records
The one-change experiment can save a plan and daily check-ins under the local browser-storage key beardInsiderOneChangeExperimentV1. The shelf-life tool can save up to 12 product records under beardInsiderShelfRecordsV1. Beard Insider does not receive those records. Delete them in the tool or clear site data in your browser.
Technical and security data
Like most websites, the hosting, content-delivery, security, and mail infrastructure may automatically process ordinary request information such as IP address, date and time, browser and device type, requested URL, referrer, response status, and security events. Beard Insider?s public forms briefly use a one-way hash derived from the connection address to limit spam; the plugin does not save the raw address in a reader record, and the rate-limit record expires after about 10 minutes or one hour depending on the form.
How information is used
- Provide the page, tool, security control, or response you requested.
- Create and authenticate the account required to reveal personalized tool results without storing the questionnaire answers.
- Manage the Beard Notes waitlist and preserve consent context.
- Review messages, corrections, accessibility reports, and data requests.
- Protect the site from spam, abuse, malicious traffic, and technical failure.
- Maintain a de-identified public correction record when a verified correction affects published work.
- Meet applicable legal obligations and establish or defend legal claims when necessary.
Service providers and outside destinations
Hostinger provides hosting and related infrastructure and processes site traffic and stored site records on Beard Insider?s behalf. the site and WooCommerce software power the site; WooCommerce may use functional browser storage on commerce pages even though on-site checkout is not active. Page fonts are currently requested from Google Fonts, so Google can receive ordinary request information such as an IP address, browser details, and the requested font resource. Product, source, and retailer links open third-party sites only when you choose them; those sites control their own privacy, cookies, prices, transactions, shipping, and returns.
Beard Insider does not authorize these providers to use private contact, routine-unlock, or waitlist records for their own behavioral advertising. We may disclose information if required by law, needed to protect rights or safety, or involved in a future reorganization or transfer of the site, subject to applicable notice and protections.
Retention
- Reader accounts: kept until you delete the account, complete a verified deletion request, or the account is removed under the Terms.
- Historical routine-only unlock records: records created by the retired email-unlock flow are deleted within 30 days under the prior schedule.
- Waitlist records: kept until you ask for removal or the waitlist closes. If the program closes, records will be removed when they are no longer needed for that purpose, subject to legal requirements.
- Private messages: normally deleted or de-identified after 24 months once resolved or closed. An unresolved safety, legal, abuse, or correction matter may be kept longer when reasonably necessary. A de-identified public correction summary may remain as part of the editorial record.
- Email-code security records: readable codes are never stored. HMAC-only challenges expire after about 10 minutes and fixed-window account-code counters expire after about 15 minutes; expired atomic rows are removed by bounded cleanup.
- Other rate limits: waitlist attempts expire after about 10 minutes and contact attempts after about one hour.
- Hosting and security logs: retained according to the relevant provider?s security and operational schedule.
- Local tool records: remain in your browser until you remove them or clear browser site data.
Your choices and requests
You may ask to access, correct, export, or delete a routine-unlock, waitlist, or contact record through the privacy-request option in the contact form. We may need to verify that the requesting email matches the record and may keep limited information when the law or a legitimate unresolved matter requires it. Built-in privacy tools are available to the site administrator to export or erase matching records. You may also clear cookies and local storage through your browser.
California and other regional rights
Beard Insider does not sell personal information and does not share it for cross-context behavioral advertising. It does not use advertising technology to follow visitors over time across unaffiliated websites. Optional Google Analytics measures use of this site only after Statistics consent and is not used here for cross-context behavioral advertising. Because current site behavior does not sell or share personal information for cross-context behavioral advertising, Global Privacy Control or ?Do Not Track? signals do not change how the public site operates. If these practices change, the policy and any required opt-out or consent controls will be updated before the new technology is enabled.
Depending on where you live and which law applies, you may have rights to information, access, correction, deletion, restriction, portability, objection, withdrawal of consent, or appeal. Beard Insider will review a request under the law that applies and will not discriminate against a person for making a valid privacy request.
Legal bases for certain visitors
Where a data-protection law requires a legal basis, Beard Insider relies on steps taken at your request to complete the routine unlock, your separate consent for Beard Notes, legitimate interests in responding to messages, legitimate interests in security and editorial integrity, and legal obligations where applicable. You can withdraw Beard Notes consent or request deletion through the contact form.
Children
This general-audience site is not directed to children under 13, and we do not knowingly request personal information from them. A child under 13 should not submit the routine email gate, join the waitlist, or send the contact form. If you believe a child submitted personal information, use the privacy-request form so it can be reviewed and deleted as appropriate. Photo files remain local and are not collected by Beard Insider.
Security
We use reasonable administrative, technical, and organizational measures appropriate to the limited information collected, including private site records, nonce and consent checks, honeypots, rate limits, and restricted administration access. No website or transmission method can guarantee absolute security.
Changes to this policy
Material changes will be posted on this page with a new effective date and, when appropriate, a notice on the site or at the affected collection point. The research update log records material site-policy changes. Read the Cookie Policy & Choices for the current storage inventory.
Saved research accounts
The account required for personalized tool results uses Beard Insider account services. Email-code access verifies the address before an eligible customer is signed in or created with a random internal credential. Beard Insider stores the account email, credential hash, necessary authentication and security data, and the IDs of product research profiles you choose to save. Tool answers, ingredient searches, research filters, and product comparisons are not added to your account. Saved profile IDs remain until you remove them, delete the account, or complete a verified privacy request.
July 15, 2026 account-gate update
Personalized tool answers now appear only after authenticated account access. Tool answers, calculated results, ingredient text, photo files, experiment notes, and shelf-life records are not added to the account. A one-use browser session record may preserve non-file answers across a social sign-in redirect while excluding sensitive fields and photos.
July 15, 2026 passwordless email-code update
Email access now uses a short-lived six-digit code before Beard Insider signs in an eligible customer or creates a customer with a random internal credential. Challenges store only HMAC fingerprints, are connection-bound, rate limited, attempt limited, and atomically single use. An email-fingerprint mutex prevents duplicate account creation and a follow-up request confirms the login cookie before reveal. Privileged or restricted accounts continue through standard sign-in. Google, Amazon, and Microsoft sign-in options retain global low-privilege guards and remain unavailable until each connection is individually configured and verified.
Optional site analytics and consent
Google Analytics is connected through Google Site Kit to measure site use. Google Consent Mode starts with analytics and advertising storage denied, and the Google tag is blocked until the visitor grants the optional Statistics category through Complianz. The visitor can reject optional storage or later withdraw or change the choice from the persistent Manage Consent control. See the Cookie Policy & Choices for the current technology inventory and live controls.