Legal

Privacy Policy

Effective December 5, 2025 · Last updated December 5, 2025 · v1.0

On this page

Your privacy matters

At Brewly, we believe transparency is as important as a perfectly pulled espresso. This Privacy Policy explains how we collect, use, protect, and share your personal data when you use our coffee tracking platform.

We're committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Quick summary: We collect minimal data needed to provide our service. You own your brewing records. We never sell your data. You have full control and can delete your account anytime.

Data we collect

1. Account information

When you create an account, we collect:

  • Email address — from your Google account, for sign-in and important communications
  • Name — from your Google account, to personalize your experience
  • Profile picture — if your Google account provides one, or if you set one yourself (optional)

Sign-in is handled by Google OAuth. Brewly never sees or stores a password for your account.

2. Coffee & brewing data

The heart of Brewly — your brewing records:

  • Coffee beans — name, brand, origin, roast level, ratings, tasting notes
  • Brewing recipes — water temperature, grind size, brew time, notes
  • Preferences — theme settings, favorite brewing methods

3. Automatically collected data

  • Usage data — pages visited, features used, collected through privacy-friendly analytics
  • Device information — browser type, operating system, screen size
  • IP address — for security and fraud prevention

How we use your data

We use your personal data for the following purposes, all based on legitimate legal grounds under GDPR:

Service delivery (legal basis: contract performance)

  • Create and manage your account
  • Store and display your coffee beans and brewing recipes
  • Enable community features (sharing favorite recipes)

Communication (legal basis: legitimate interest & consent)

  • Send important service updates and security alerts
  • Respond to your support requests
  • Send product emails only if you have enabled them — you can opt out anytime in Settings

Improvement & analytics (legal basis: legitimate interest)

  • Analyze usage patterns to improve our platform
  • Fix bugs and optimize performance

Legal compliance (legal basis: legal obligation)

  • Comply with applicable laws and regulations
  • Respond to legal requests from authorities
  • Enforce our Terms of Service

How we protect your data

Security is fundamental to everything we do. We implement industry-standard measures:

  • Encryption — all data transmitted using TLS/SSL encryption
  • No passwords stored — authentication is delegated to Google OAuth
  • Access controls — limited access on a need-to-know basis
  • Regular backups — automated backups stored securely

Data retention

We retain your data only as long as necessary:

  • Active accounts — data retained while your account is active
  • Deleted accounts — data permanently deleted within 30 days
  • Legal requirements — some data may be retained longer if required by law

International transfers

If we transfer data outside the EU, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission
  • Your explicit consent

Your GDPR rights

Under GDPR, you have comprehensive rights over your personal data:

Right to access

Request a copy of all personal data we hold about you. We'll provide it in a portable format.

Settings → Export data

Right to rectification

Correct any inaccurate or incomplete personal data.

Edit your profile and data directly in the app

Right to erasure ('right to be forgotten')

Request deletion of your personal data. We'll delete everything within 30 days.

Settings → Delete account

Right to restrict processing

Limit how we process your data while we address your concerns.

Contact privacy@brewly.app

Right to data portability

Receive your data in a machine-readable format to transfer to another service.

Settings → Export data (JSON format)

Right to object

Object to processing based on legitimate interests or for marketing purposes.

Contact privacy@brewly.app or disable emails in Settings

Right to withdraw consent

Withdraw consent at any time where processing is based on consent.

Update preferences in Settings

Response time: We respond to all requests within 30 days as required by GDPR. For complex requests, we may extend this by an additional 60 days and will notify you.

Cookies & analytics

Essential cookies (always active)

These cookies are necessary for the website to function:

  • Authentication — keep you signed in securely
  • Security — prevent fraud and abuse

Analytics

We use privacy-friendly analytics (Umami) to understand how people use Brewly — page views, popular features, performance. It does not use cookies and does not track you across other sites.

Your theme preference is stored locally in your browser.

Contact

Questions about privacy? We're here to help:

Data protection

privacy@brewly.app

Supervisory authority

You have the right to lodge a complaint with your local data protection authority if you believe we've mishandled your personal data.

Changes to this policy

We may update this Privacy Policy from time to time. We'll notify you of significant changes via email or a prominent notice in the app. Your continued use after changes constitutes acceptance of the updated policy.