legal
Privacy Policy
Effective 26 August 2026
brewd is a coffee journal built to keep to itself. This page sets out exactly what the app and this website collect, why, who else is involved, and how to get rid of it.
the short version
- Your journal lives on your phone. Entries, photos, taste tags and punchcards are stored on your device, and they stay there unless you turn on sync.
- An account is optional. You can use brewd without one. If you make one, we hold your email address, a name, and a little about how you signed in.
- Sync is opt-in and part of brewd+. Turn it on and a copy of your journal is kept on our server, encrypted in transit and at rest. It is not encrypted in a way that locks us out, so we will not tell you it is.
- Crash reports and anonymous usage counts, both on by default and both switchable off in Settings. Neither carries your name, your email or your account. No ads, no tracking, nothing that follows you around the internet.
- Location is used to find cafés, not to follow you. We keep no history of what you have searched for. A café you save to an entry is part of that entry, and travels with it if you sync.
- You can get rid of everything. Delete the app to erase the journal on your phone, and delete your account, in the app or from the form on this site, to erase what we hold on our server.
That is a summary for reading, not the policy. The sections below are the policy.
1. Who we are
brewd is made by two people: Jordon de Hoog, in Ontario, Canada, and Madison Kirby, in Portland, Oregon. Jordon is the individual accountable for how brewd handles your information: the "data controller" under the GDPR, and the accountable individual under Canada's PIPEDA. Madison works on brewd under that accountability, and everything on this page binds us both.
For anything on this page, write to privacy@getbrewd.app. A postal address is available on request.
2. Your journal
Everything you actually write in brewd is stored in a database on your phone: your entries (the drink, how you took it, taste tags, how much you loved it, your note and the time), the café details attached to an entry, your photos, your wishlist and your punchcard progress.
If you do not sync, none of it is sent to us. Nothing is copied to our server unless you have an account and brewd+ and you turn sync on. Section 4 is the whole of what changes when you do.
Punchcards are worked out on your phone from your own journal. Only the blank card definitions come from our server. How far along a card you are is never sent to us, sync or no sync. Which cards you have picked, and how you styled them, are sent if you sync, so that they follow you between devices.
If you have never synced and you delete the app, that data is gone. We have no copy to hand back to you, which is the honest trade-off for us not having a copy at all.
3. Your account
brewd works without an account. You can log cups, keep a wishlist and fill punchcards without telling us anything about yourself. An account exists for one reason: it is what sync attaches to.
An email address is what an account is made of, so we cannot give you one without it. You do not have to give us one at all. Without an account brewd works exactly as it does now, and sync is the only thing you cannot reach.
If you make one, this is what we hold:
- Your email address. You give it to us when you sign up, or Apple or Google hands it to us when you use their sign-in button. If you use Sign in with Apple and choose to hide your address, what reaches us and what we store is Apple's relay address, not your real one.
- A name. If you sign up with an email address and a password, we take the part of your address in front of the @ and use that. If you sign in with Google, we store the name Google gives us. Apple gives us none. It is there so the app can say hello, and for nothing else. It is a different thing from the name in Settings, which stays on your phone.
- A profile picture, if you signed in with Google and Google gave us a link to one. Apple does not provide one.
- How you signed in. Which method you used, and the id the provider knows you by if it was Google or Apple. If you signed up with a password, we store a scrambled form of it that cannot be turned back into the password, never the password itself.
- Your sessions. Staying signed in means a row on our server holding a token, when it expires, and the IP address and the device description your app sent at the moment you signed in. A session lasts seven days and renews while you keep using the app. Signing out deletes it, and it expires on its own within seven days either way.
- Sign-in codes. When you confirm your address or reset a password we email you a six-digit code. We store your address and a scrambled form of the code rather than the code itself, and it is good for ten minutes and three attempts. brewd will never ask you for that code.
We never see your Google or Apple password, and we hold nothing from Google that would let us reach into your account there.
Sign in with Apple is the one exception, and only in one direction. When you sign in that way Apple gives us a token we use for one thing only: to tell Apple you are done with brewd. We keep it so that removing Apple as a way to sign in, or deleting your account outright, also withdraws brewd's access on Apple's side, rather than leaving it standing after everything else is gone. It reaches nothing else of yours at Apple: no photos, no files, no contacts. It is spent and gone at whichever of those two comes first.
4. Sync, if you turn it on
Sync is part of brewd+, it needs an account, and nothing is copied unless you turn it on. With it on, brewd keeps a copy of your journal on our server so that it can reach your other devices.
What is copied: your entries, your wishlist, the punchcards you have picked and how you styled them. An entry travels whole, which means the drink, your note, your taste tags, how much you loved it, and the café attached to it including its coordinates. Photos are copied too, and they go straight from your phone into our storage over a short-lived link, so the image itself never passes through our server.
That copy is encrypted in transit, and Cloudflare, who store it for us, encrypt it at rest. It is not end-to-end encrypted, which would mean a key only you hold. There is no such key, so we are technically able to read what is in there. We could tell you we cannot and it would read better, but it would not be true. What we can tell you is what we do with it: nothing. We do not go looking through journals, we do not use what you write for any purpose of our own, and none of it is sold, shared or used to train anything.
Turning sync off, or letting brewd+ lapse, stops the copy changing. Neither one deletes it. Section 15 is how to get rid of it.
5. What our server sees
Account or no account, the app talks to our server for the drink catalog, map tiles, app settings and café lookups. Those requests carry three things:
- An anonymous id. The first time you open brewd, our payments provider RevenueCat generates a random id for your install, in the shape
$RCAnonymousID:6f21…. It is not tied to your name, your email or your device's advertising id. You can see it, and copy it, in the you card at the top of Settings. If you sign in, your account takes over that role and the purchases you have already made come with you. - A subscription record. Against that id we store whether you have brewd+, which store the purchase came from, the country your store account is registered in, which product you bought and on what billing period, why a subscription ended if it did, which entitlements you hold and when they run out, and when RevenueCat last told us any of it. Nothing else, and nothing you wrote.
- Your IP address. Like any web server, ours receives it. We use it to rate limit abuse. Cloudflare keeps request logs for a few days (currently up to seven) and then discards them. We keep no log of IP addresses ourselves, and we do not link them to your anonymous id. The exceptions are all to do with accounts: the counter that rate limits every account request is kept against the IP address making it, a second counter sits against a scrambled form of any address we are asked to mail, whether for a sign-in code or an account deletion link, so that nobody can flood one inbox, and a session row records the address you signed in from, as section 3 describes. If one of those mails fails to send, the address it was going to appears in the short-lived server log with the failure.
We call that id anonymous because it is not built from anything about you, but it is stable for as long as the app stays installed. So we treat it as personal information and give you the rights in section 14 over it. We would rather be precise than flattering.
6. Finding cafés near you
When you look for a café nearby, your device sends its coordinates to our server, which searches for cafés and sends the results back. We do not write down where you were, and we keep no history of the places you have searched for.
- The coordinates are as precise as your device provides, because a rounded position returns the wrong cafés.
- To keep things quick we cache results against a coarse grid of roughly 110 metres, with no id attached, so a cached result cannot be traced back to whoever asked for it.
A café you save to an entry is a different thing from a search. It becomes part of that entry, so if you sync, it travels to our server with it, coordinates included. Section 4 covers that.
Many searches are answered entirely by our own café index, built from OpenStreetMap data and hosted on our server. Where that index is thin, smaller towns especially, the lookup is passed to an outside provider. Section 11 names them. Map tiles are served from our own storage rather than a third-party map service, so no map company builds a record of where you pan and zoom.
Location is only ever requested while you are using the app, and you can say no. If you do, the map and nearby search still work by name.
7. Photos
If you add a photo to an entry, the app asks for your camera or photo library, saves the image on your device and stores a reference to it in your journal. Without sync that is the whole story, and the image stays on the phone. With sync on, a copy goes to our storage in the way section 4 describes.
8. Analytics and crash reports
brewd now collects both, in the smallest shape we could make useful. Each has its own switch in Settings, under privacy, and each starts on. An earlier version of this page said we collected neither, and promised that if that changed the page would change first, with a new effective date and a switch in Settings to turn it off. This is that change.
Crash reports go to Sentry. When brewd falls over, it sends the error and its stack trace, the breadcrumbs the app left itself on the way there, which is roughly which screens you moved through, and your app version, device model and OS version.
Usage counts go to PostHog. It receives event names such as an entry being saved, the names of the screens you move between, and numbers bucketed into ranges, so it is told you have between ten and fifty entries rather than how many you have. It is never sent what you wrote, the photos you added, the cafés you saved or the drinks you logged.
Neither is tied to your account. We never tell PostHog who you are, and the setting that would have it build a profile of a person is off. Sentry is given no user at all, and the setting that would attach your IP address is off. What each holds is a random id its own SDK made up on this install, and we have no way to match that back to your email address or to your journal.
There is no advertising either. There is no advertising SDK, we do not use your device's advertising identifier, we build no profile of you, and there is nothing about you for us to sell or share.
Turn a switch off and the app stops sending that kind of report from that moment, and throws away anything it had saved up to send later.
9. Purchases and brewd+
Purchases go through Apple and Google, so we never see your card details. RevenueCat tells our server which entitlements you hold, so the app knows what to unlock. That is the whole of our involvement in the payment.
10. This website
getbrewd.app is a set of plain static pages. It sets no cookies, runs no analytics of its own and loads nothing from anywhere else: the fonts are served from this domain rather than from Google, and there is no tracking pixel, embedded video or social widget on any page. When the site does send something it goes to our own API and nowhere else, and only because you pressed a button: the beta form on the front page, and the two account deletion pages described below. Nothing is sent until you press it. That is why you have not been shown a cookie banner, there is genuinely nothing to consent to.
What that form joins is the beta invite list. We keep the address you gave us and the date you gave it, and nothing else. We use it to send you one invite when the beta opens, and for nothing else. Write toprivacy@getbrewd.app and we will take you off it.
The other two are the deletion pages. When you submit theaccount deletion form, the address you type goes to our own server at api.getbrewd.app, so that we can email you the confirmation link. When you press the button on the page that link opens, the code from the link goes to the same server, so that we know whose account to delete. No third party is involved in either, the pages still load nothing from anywhere else, and your address is not kept in your browser afterwards. That code travels in the link itself, so it does sit in your browser history, like any other page you open.
Cloudflare receives your IP address in order to serve you the page, and keeps the same short-lived logs described in section 5.
11. Who else handles your information
A short list, and it is the whole list. Apple and Google act for themselves when they sell you a subscription or sign you in, under their own privacy policies. Everyone else here acts on our instructions and on nothing else, and none of them is a partner we hand you over to.
| Who | What they get | Where | Why |
|---|---|---|---|
| Cloudflare | Your IP address and request metadata. Your account details, if you have an account. Your journal and your photos, if you sync | Global network, company based in the US | Hosts this website, our API, the café index and the map tiles, stores accounts, synced journals and the beta invite list, and sends our sign-in emails |
| RevenueCat | Your anonymous id, or your account id once you sign in, plus purchase and entitlement history | United States | Runs subscriptions and tells our server what you have unlocked |
| Apple, Google | Purchase and payment details, and, if you use their sign-in button, the fact that you signed in to brewd | United States | Sell and bill the subscription, distribute the app, and provide the optional sign-in buttons |
| Sentry | Crash reports: the error and its stack trace, the breadcrumbs the app left itself on the way there, your app version, device model and OS version, against a random install id | United States | Tells us when brewd falls over on your phone, so we can fix it. Switchable off in Settings |
| PostHog | Event and screen names, with counts bucketed into ranges rather than sent as numbers, against a random install id | United States | Counts which parts of the app get used, so we know what to look after. Switchable off in Settings |
| Geoapify | The coordinates or text of a café lookup, with no id attached | Germany | Café search where our own index is thin. This is the provider in use today |
| HERE | Same as above | Netherlands and the US | An alternative café provider we may switch to. We will update this page if we do |
Your account and your synced journal sit on Cloudflare because that is where our own server runs. We do not hand either to an outside identity or backup company: there is no third party in between you and us on that part of it.
We do not sell your information, we do not share it for advertising, and there is no data broker anywhere on that list.
Some of these providers are outside Canada, so your information may be handled in the United States or the European Union under those countries' laws, including access by their authorities in the cases their law allows. If you are in the EEA or the UK, it also reaches us here in Canada. Where a transfer needs safeguards it relies on the standard contractual clauses in our agreement with that provider, and you can ask us for a copy at privacy@getbrewd.app.
12. Why we are allowed to use it
For people in the EEA and the UK, the GDPR asks us to name a lawful basis for each use:
- Running the app you asked for (contract). The anonymous id, the subscription record and café lookups. Your account, and the synced copy of your journal, once you have asked for those. Without these, the parts of brewd they belong to do not work.
- Keeping the service standing up and improving it (legitimate interests). Rate limiting, abuse prevention, short-lived server logs, and the IP address and device description held against a session, which is what would let us tell a stolen session from a real one and end it. We have weighed that against your privacy: it is a handful of fields, it carries nothing you wrote, and none of it is used for anything else.
- Your permission (consent). Access to your location, camera and photos. You grant these in your operating system's own prompt, and you can withdraw them at any time in your device settings without losing your journal. Joining the beta invite list is consent too: you give it by pressing the button on the front page, and you can withdraw it at any time by writing to us.
13. How long we keep it
- The journal on your phone: until you delete it or delete the app.
- A synced journal: for as long as the account it belongs to exists, whether or not sync is still switched on. Deleting your account deletes it, as section 15 describes.
- An entry you deleted: when you delete an entry on one device, what you wrote is erased from our copy and a small marker is left in its place, so your other devices know to remove it too. The marker records that a record once existed and when it last changed, and nothing of what was in it. It stays until you delete your account.
- A photo belonging to a deleted entry: cleared by a job that runs on our server every day. It removes a photo once no entry in our copy has referred to it for about a month. The wait is deliberate: a device that has been offline for a while can still be carrying the entry that photo belongs to, and we would rather keep the picture than lose it. Treat that as a floor rather than a timetable, because the waiting period is a setting we can change and the job works through accounts in turn. Deleting your account removes it along with everything else, and if you would rather clear a photo sooner than that, write to us and we will.
- Your account: until you delete it, from Settings in the app or with the account deletion form on this site.
- Sessions: seven days from the last time you used the app, renewed while you keep using it. Signing out deletes the row there and then, and an expired one is cleared the next time it is presented to us.
- Sign-in codes: ten minutes, after which the code no longer works. The row holding it is deleted when the code is used or the three attempts run out, and otherwise sits expired and unusable until the next code for that address replaces it.
- Rate limit counters: a count against an IP address, or against a scrambled address, with the time it was last seen. A counter is cleared the next time the same one is checked after its window has passed, so one never touched again sits there holding a number.
- The subscription record: for as long as you use brewd. We do not currently expire it automatically. Ask us and we will delete it.
- The beta invite list: the address you gave us and the date, kept until the beta invites go out or you ask to be removed. There is no unsubscribe link because there is nothing being sent for you to unsubscribe from. Emailprivacy@getbrewd.app and we delete the row.
- Server logs: a few days, currently up to seven at Cloudflare, then discarded automatically.
- Café search caches: from five minutes to thirty days, and never keyed to you.
14. Your rights and choices
Wherever you live, you can ask us to tell you what we hold about you, give you a copy of it, correct it, or delete it. If you are in the EEA or the UK you can also object to or restrict how we use it, and ask for it in a portable format.
The honest scope of that. Without an account, the only things we hold tied to you are the subscription record in section 5 and, if you joined the beta invite list, the address you gave us, so that is what those requests cover. With an account, they also cover your account details and your sessions, and, if you have ever synced, the copy of your journal on our server, which we can produce for you in full.
To ask for any of this, email privacy@getbrewd.app. If you have an account, write from the address it uses. If you do not, send the anonymous id from the you card at the top of Settings, and please do not post that id publicly, because anyone holding it could make a request about it. We will reply within 30 days, and we do not charge for it.
15. Deleting your data
Four separate things, deleted four different ways.
- The journal on your phone. Delete the app. Everything on the device goes with it, immediately and entirely.
- Your account, and anything you synced. In the app: open Settings and tap delete your account, in the you card at the top. It runs as soon as you confirm. Without the app: theaccount deletion form on this site, which emails you a link to confirm the address is yours. Either way we remove the account, how you signed in, its sessions, any unused sign-in code, the synced copy of your journal and the photos that went with it. You can also email privacy@getbrewd.app from the address on the account and have us do it.
- The subscription record on our server. Copy your id from the you card at the top of Settings, and email privacy@getbrewd.app asking us to delete it. We will do it and confirm.
- Your place on the beta invite list. Emailprivacy@getbrewd.app from the address you signed up with and ask us to take it off. We delete the row and confirm.
Deleting the app removes what is on the phone and nothing else. If you have synced, our copy is untouched by it, so send the email as well.
Step-by-step instructions live on the data deletion page.
Deleting your data does not cancel a paid subscription, and cancelling a subscription does not delete your data. Apple and Google also keep their own record of your purchase to meet their tax and refund obligations. We cannot delete that for you, so you would need to ask them.
16. Children
brewd is not built for children. You need to be at least 13 to use it, or at least 16 if you are in the EEA or the UK. We do not knowingly collect information from anyone younger. If you believe a child has given us something, write to privacy@getbrewd.app and we will delete it.
17. Changes to this policy
If we change how brewd handles your information, we will update this page and change the effective date at the top. Anything significant will also be announced in the app.
18. Complaints
Please try us first at privacy@getbrewd.app. If we do not put it right, you can complain to a regulator:
- In Canada, the Office of the Privacy Commissioner of Canada, at priv.gc.ca.
- In the EEA, your national data protection authority.
- In the UK, the Information Commissioner's Office, at ico.org.uk.
See also our Terms of Service and how to delete your data.