Lock Beam
Privacy Policy
Last updated 3 October 2026
Draft: needs Rinor’s review.
Lock Beam lets friends, couples and families beam photos, notes and drawings onto each other’s Lock Screen. This policy explains what we collect, why, who helps us run the service, how long we keep it and the choices you have. Lock Beam is operated by ReApps LLC (“we”, “us”). Questions: [email protected].
The short version
- No email address, phone number or password is needed. Lock Beam creates an anonymous account for your iPhone. Signing in with Apple is optional, and we never ask Apple for your email address.
- Only people you let in can put something on your Lock Screen, and you can revoke them at any time.
- People who beam to you see only what they sent, never your whole screen.
- Every photo and drawing is screened by an automated safety check before it’s delivered.
- No ads, no tracking, and we never sell or share your personal information.
- You can delete your data in the app at any time: Settings → Delete my data.
What we collect and why
Your account
When you first open Lock Beam, the app creates an anonymous account (a random identifier) so beams can reach your iPhone. We don’t ask for your email address, phone number or contacts, and the app never uploads your address book.
Sign in with Apple is optional. If you use it, we keep the user identifier Apple gives Lock Beam for your Apple Account, so you can get your account back on a new iPhone, and the first name you choose to share. We ask Apple for your name only, never your email address. Apple also gives us a token that can end the link: we keep it only for that, and when you delete your data, we use it to revoke Lock Beam’s sign-in with Apple.
Your profile
- First name, if you give one. People you’re connected with and members of your groups see it, for example in “Maya beamed something to your Lock Screen.”
- Your mark, the symbol you pick in a group.
- Your birthday, if you add it: the month and day only, never the year. People you’re connected with and members of your groups see it, so they can plan a birthday takeover. You can remove it at any time.
- Your age range. During setup the app asks Apple for your age range (Apple’s Declared Age Range). We keep only whether you’re 13–17 or 18 and over, so we can apply the right protections. We never receive your date of birth. If the answer is under 13, Lock Beam isn’t available.
What you beam
The photos, drawings, notes, captions, objects and reactions you send, where they sit on the screen, who sent them, to whom and when. We use them to deliver your beams to the people you chose and to show them in their inbox and widget. Photo and drawing files are stored privately. A download link lasts 10 minutes and is created only after we’ve checked that the person asking may see that item.
To keep faces clear of the clock, the sender’s iPhone finds where faces are in a photo using Apple’s on-device Vision framework and sends us only a rectangle (a position). Lock Beam doesn’t recognise or identify anyone, and creates no face templates or other biometric data.
Scheduled beams. When you schedule a beam for later (for the morning, or for someone’s birthday takeover), we keep it until it lands. Nobody but you sees it before then, and you can cancel it until it does. A birthday takeover lands at 00:00 on that person’s birthday, in their time zone.
Invites that carry a beam. When you beam to someone who isn’t on Lock Beam yet, the invite link carries your beam. Anyone who opens the link sees your first name and that something is waiting, never the beam itself. It’s delivered only when they join and let you in, and the link works once.
Connections and groups
Who may beam to your Lock Screen, whose Lock Screens you may beam to, the people you’ve marked as trusted, the groups you’re in, your invite codes, and the people you’ve blocked or reported.
The channels you tune in to. People you’re connected with may see that you tuned in to a channel, by your first name, on that channel in their app. Lock Beam shows no public follower counts.
Your iPhone and screen settings
To draw pictures that fit your phone: its model, screen size and resolution, your Lock Screen layout choices (clock style and where your widgets sit), time zone and app version. To deliver beams: a push notification token from Apple. And your choices in the app, such as showing the newest canvas or a pinned one, pausing, and the channels you subscribe to.
Your Lock Screen picture is put together on your iPhone, and the one-time Shortcut and its automation run on your iPhone. Lock Beam doesn’t upload screenshots of your Lock Screen or Home Screen.
Delivery records
When your phone prepares a new Lock Screen, it sends a short receipt (prepared, handed off or failed, with an error code) so we can find and fix delivery problems. Receipts are deleted after 14 days. A receipt shows that a picture reached your phone, not that anyone looked at it.
Landing receipts. When a beam reaches someone’s Lock Screen, we note the time on that item, and its sender sees that it landed (for example “On Maya’s screen”). In a group, it’s the first member’s phone to put it up. We keep that time with the item for as long as the item exists.
Usage measurements
A few events, sent in batches by the app, tell us whether Lock Beam works and which parts people use, so we can improve it: onboarding started, signed in with Apple, setup completed, first beam sent, first beam received, a beam scheduled, a beam that landed, an invite shared or redeemed, how an invite reached the app (a tapped link, a pasted link or a typed code), a share card shared, a birthday takeover planned or added to, a matching screen made, a channel tuned in to, a drop tried on, and the days you open the app. They’re linked to your account. We use no third-party analytics or advertising tools, and we don’t track you across other companies’ apps or websites.
Your profile also keeps who invited you and how their link reached the app, when a beam from someone else first landed on your Lock Screen, and the days you used Lock Beam in your first two months. That tells us whether invites bring people in and whether Lock Beam works for them. When an invite link is opened on lockbeam.app, we count the visit for that invite, and nothing about who opened it.
Messages to us
If you email us or use the takedown form, we receive your name, email address and what you tell us, and use them to answer you and act on your request. The form also records your IP address, to limit abuse of it.
This website
lockbeam.app sets no cookies on its public pages and uses no analytics. Cloudflare, which hosts the site, processes your IP address and request details to deliver the site and protect it from attacks, and may set a strictly necessary security cookie. When you open an invite link, the page asks our backend what that code shows (first names, marks and whether a beam is waiting, never the beam itself) and nothing about you. Channel pages show what a featured channel publishes. The admin area uses one sign-in cookie for our staff.
Keeping Lock Beam safe
- Automated screening. Before a photo or drawing is delivered, it is sent with its caption to OpenAI’s moderation service, which returns safety scores (for example for sexual content, violence or self-harm). The words in notes and captions are checked the same way, after a word filter. Clearly prohibited images are refused. A flagged one is never applied automatically: the sender sees that it’s waiting, an adult recipient may choose to look at it, and a recipient aged 13–17 never receives it.
- Human review. Our team looks at held photos and at reported content, together with the reason given. We review reports within 24 hours.
- On your iPhone. If you’ve turned on Sensitive Content Warning, or Communication Safety is on (the default for child accounts), Apple’s on-device analysis can blur sensitive images. Its results stay on your iPhone; we never receive them.
- Legal duties. If we find apparent child sexual abuse material, we report it to the National Center for Missing & Exploited Children (NCMEC), as US law requires, and preserve it for one year as the law requires. We may also share information with law enforcement when the law requires it, or to protect someone from serious harm.
Who processes data for us
We use a small number of providers, each only for the job below:
| Provider | What they do | What they receive |
|---|---|---|
| Back4App | Hosts accounts, data and our server code; sends push notifications through Apple | Everything described above, except photo and drawing files |
| Cloudflare | Stores photo and drawing files and channel art (R2); hosts lockbeam.app | Photo and drawing files; website requests |
| OpenAI | Safety screening only | Each photo or drawing (through a link that expires after 5 minutes) with its caption, and the words in notes, at the moment they’re screened. Under OpenAI’s API terms these requests aren’t used to train OpenAI’s models and aren’t kept for abuse monitoring. |
| Apple | The App Store, push notifications, your age range, Sign in with Apple, on-device protections | Your push token and the text of notifications, such as “Maya beamed something to your Lock Screen.” If you sign in with Apple: the sign-in, and when you delete your data, our request to revoke it. |
We don’t sell or rent personal information, and we don’t share it for advertising.
How long we keep it
- Account, profile, connections and settings: until you delete your data.
- Beams: while they’re on someone’s Lock Screen canvas or in an inbox. When you withdraw something you sent, or the recipient removes it, it stops being delivered at once. We keep a record of removed items, and the content of reported ones, for safety reviews and legal duties.
- Scheduled beams: until they land, then as beams above, or until you cancel them.
- Delivery receipts: 14 days. Landing times stay with their item.
- Your birthday: until you remove it or delete your data.
- Sign in with Apple: the identifier and Apple’s token until you delete your data. Then we revoke the token with Apple and delete it.
- Usage events: until you delete your data.
- Reports, blocks and takedown requests: as long as we need them to review and enforce our rules, and longer when the law requires (for example one year for material reported to NCMEC).
Deleting your data
In the app, go to Settings → Delete my data. This deletes your profile, devices, connections, subscriptions and photo and drawing files, and removes what you’ve beamed from every Lock Screen and inbox, including beams that haven’t landed yet. If you signed in with Apple, we also revoke Lock Beam’s sign-in with Apple.
A picture that has already been set as someone’s wallpaper is on their phone, and no app can take it back, but it won’t be delivered again. Content that is part of an open report, or that the law requires us to keep, stays on hold until that ends. You can also email [email protected] to ask for deletion.
Children and teens
Lock Beam is for people aged 13 and over. If Apple’s age range shows someone is under 13, Lock Beam isn’t available to them. If you believe a child under 13 is using Lock Beam, email us and we’ll delete their data.
For people aged 13–17, and for anyone whose age range we don’t know, photos from anyone they haven’t marked as trusted wait for their approval, flagged photos are never delivered, only featured channels are shown, and Apple’s sensitive-content protections apply when they’re on.
Your rights
Depending on where you live (for example the European Economic Area, the UK, California and other US states), you can ask to access, correct, delete or get a copy of your personal data, to object to or restrict some uses of it, and to withdraw consent. You can do most of this in the app; for anything else, email [email protected]. We answer within one month. We won’t treat you differently for using your rights, and you can complain to your data protection authority.
Legal bases (EEA and UK)
- To provide Lock Beam (contract): your account and Sign in with Apple, profile and birthday, beams (including scheduled ones and invites that carry one), delivery and landing receipts, device settings and push notifications.
- Legitimate interests: safety screening, preventing abuse, security, fixing delivery problems, and measuring whether the app works so we can improve it.
- Legal obligations: reporting child sexual abuse material, handling takedown requests, answering lawful requests.
- Consent: notifications, which you allow in iOS and can turn off in Settings.
California
In the last 12 months we have collected these categories: identifiers (the anonymous account, the Apple user identifier if you sign in with Apple, and the push token), personal information you give us (first name, and birthday month and day), age range, user content (photos, drawings, notes), device information and app usage. We use them for the purposes above, keep them for the periods above and disclose them only to the service providers above. We don’t sell or share personal information as the CCPA defines those words, and we don’t use sensitive personal information to infer anything about you.
International transfers
Our providers may process data in the United States and other countries. Where the law requires it, transfers rely on safeguards such as the European Commission’s Standard Contractual Clauses.
Security
Everything travels encrypted (TLS). The app can’t read our database directly: every request goes through server code that checks permissions, and each item can be read only by the owner of the canvas it’s on and its sender (or, in a group, its members). Files are private and reachable only through 10-minute links. No system is perfectly secure; if you find a problem, tell us at [email protected].
Changes
We’ll post any change here and update the date at the top. If a change matters, we’ll tell you in the app before it takes effect.
Contact
ReApps LLC, [email protected]. See also our Terms and Support.