Privacy

Last updated: 2026-05-08

Your coffee log is yours. We are bound to GDPR (we are EU-based) and apply the same standards everywhere.

What we collect

  • Account data: email or Apple ID identity. We never store passwords.
  • Coffee data you create: bags, brews, café visits, voice notes, conversations with the AI.
  • Device + analytics: app version, OS version, anonymised usage events. IPs are truncated.
  • Subscription: status only, billed via Apple. We never see your card.

Where it lives

All data is stored in the EU (Frankfurt) with our database provider Supabase. Photos sit in EU storage too.

Sub-processors

  • Anthropic: powers Ask Brewist. Zero-retention agreement requested. Your conversations are not used for training.
  • OpenAI: text embeddings for semantic search. Same no-training guarantee.
  • Supabase: database, auth, storage, edge functions.
  • RevenueCat: subscription management on top of Apple's billing.
  • PostHog (EU): product analytics. IPs truncated.
  • Sentry (EU): crash and error tracking.
  • Resend: transactional email.
  • Apple: app distribution, Sign in with Apple, push notifications.

Your rights

  • Export everything as JSON, in app at Settings > Data > Export.
  • Delete your account, in app at Settings > Data > Delete account. Everything is purged within 24 hours.
  • Object to processing or request a correction by emailing privacy@brewist.app.

AI and your data

Conversations and bag scans use Claude (Anthropic). We have a data processing agreement with Anthropic that prohibits training on customer data. Your coffee history stays your coffee history.

Cookies

The website uses one analytics cookie (PostHog) for anonymised usage measurement. No advertising or tracking cookies. The app uses no cookies.

Contact

privacy@brewist.app