1. Scope
This Privacy Policy explains how Brewstead handles information when you use the Brewstead application, website, cloud services, account features, Early Access purchase flows, support channels, and related services. Brewstead is presently operated from Texas, United States, and V0.1 Early Access is intended for users in the United States.
Brewstead is a 21+ service. We do not intentionally offer Brewstead to people under 21.
2. Information We Collect
Account and authentication information
- a Brewstead/Firebase user identifier, including an anonymous identifier when anonymous use is enabled;
- verified email address for registered accounts;
- account status, authentication events, entitlement status, acceptance versions, and related account metadata;
- a public username or display name if Brewstead later offers a sharing feature that requires one.
Brewstead does not require your legal name for an ordinary account and does not need your birth date merely to confirm the 21+ requirement. We may record that you affirmed you are at least 21.
User-created brewing content
- recipes, ingredients, recipe directions, measurements, calculations, settings, and related user-entered brewing information;
- brews, logs, readings, media, or other brewing records if and when those features are available;
- an optional recipe or brew image uploaded by the user;
- content included in a share snapshot if the user intentionally creates a sharing link.
Technical, analytics, and crash information
- device model, operating-system version, app version, language, timestamps, IP address, network information, and technical identifiers reasonably needed for authentication, security, sync, analytics, or debugging;
- feature-use and conversion events used to understand how Brewstead is used and how many users choose Pro;
- crash reports, stack traces, performance information, and error context used to diagnose problems.
Where practical, Brewstead uses pseudonymous account or device identifiers for ordinary analytics rather than attaching feature-use events directly to a real name or email address. Brewstead will design crash reporting to avoid including recipe names, free-text notes, email addresses, and other user-entered content unless that information is genuinely necessary to diagnose a specific issue.
Payment and transaction information
Brewstead does not store full credit-card or debit-card numbers. A payment processor handles payment credentials. Brewstead may retain transaction identifiers, customer/account references, purchase date, amount, taxes, product purchased, entitlement dates, refund status, chargeback or dispute status, and other information reasonably necessary to administer the purchase, prevent fraud, and maintain business records.
Support, security, and moderation information
If you contact Brewstead, we may retain your message, email address, troubleshooting information, and our response. We may also create security, fraud, moderation, enforcement, or audit records when necessary to protect Brewstead, users, or others.
3. Information We Do Not Intend to Collect
Brewstead does not currently collect precise GPS location. Brewstead does not sell personal information, does not create third-party behavioral advertising profiles, and does not intend to use advertising trackers such as cross-site ad pixels in the Early Access service. Brewstead does not require a legal name for ordinary use and does not store full payment-card numbers.
Please do not place highly sensitive personal information in recipe names, directions, or other free-text fields unless it is genuinely necessary for your own brewing record.
4. Anonymous Use and Cloud Sync
Brewstead may allow Free users to use the app without registering an email address. In that case, Brewstead may create an anonymous cloud identity so eligible data can sync in the background. An anonymous identity is designed to minimize identifying information, but it is not the same as a recoverable registered account.
If an anonymous user later creates or links a registered account, Brewstead may link the verified credential to the existing account identity so the user can keep the same recipes, brews, and entitlement history instead of creating an empty account.
If an anonymous user loses the device or anonymous credentials, Brewstead may make a reasonable attempt to help, but recovery cannot be guaranteed and may be impossible because Brewstead deliberately does not know who the anonymous user is.
5. How We Use Information
- provide, operate, sync, and maintain Brewstead;
- authenticate users and recover registered accounts;
- activate, restore, verify, refund, or revoke paid entitlements;
- calculate and display brewing information requested by the user;
- diagnose crashes, bugs, performance problems, and sync failures;
- understand product usage, including Free-to-Pro conversion and feature use;
- secure the service, detect abuse, enforce the Terms, and prevent fraud;
- respond to support, privacy, billing, security, or legal requests;
- comply with law and protect the rights, safety, and security of Brewstead, users, or others;
- send transactional and service communications, including authentication links, purchase confirmations, important account notices, material policy changes, and V1 launch/entitlement notices.
Marketing communications, newsletters, or promotional campaigns are not part of the current plan. If Brewstead later offers them, marketing communications will be handled separately and with opt-in or other consent where required.
6. Analytics, Crash Reporting, and Automated Safety Tools
Brewstead may use privacy-conscious analytics and crash-reporting tools to understand product use and find bugs. Brewstead may also use proportionate automated tools to detect malware, fraud, attacks, prohibited abuse, or potentially dangerous misuse. Automated signals may be used to create a review flag; they are not necessarily treated as a final decision by themselves.
Brewstead does not routinely browse private user content. Targeted human review of private content may occur when there is a legitimate, documented reason involving safety, security, support, suspected unlawful activity, fraud, abuse, legal compliance, or operation of the service. Intentional administrative access to private user content is intended to be auditable.
7. Sharing and Public Content
If a user intentionally creates an active Brewstead share link, the shared snapshot may be viewed by anyone who has that link. The user should not include information in shared content that they consider private. Shared snapshots do not automatically update when the private source recipe changes. Disabling the share makes the link unavailable without deleting the user's underlying private recipe.
If usernames are introduced for sharing, the username displayed with a share is public. Account email, transaction records, device information, private account metadata, and private logs are not included in a public share by default.
8. Service Providers and Other Disclosures
Brewstead may disclose information to service providers that perform functions on our behalf, such as authentication, hosting, databases, cloud storage, crash reporting, analytics, email delivery, payment processing, and security. These providers receive information only as reasonably necessary for their function and are subject to their own legal and contractual obligations.
Brewstead currently expects core cloud services to use Google/Firebase technologies. The final payment processor and other providers in use at launch will be reflected in Brewstead's internal provider register and updated in this Policy if a material disclosure is required.
Brewstead may also disclose information:
- at your direction, such as when you create a public sharing link;
- to investigate fraud, abuse, security incidents, credible threats, or serious unlawful conduct;
- when required by valid legal process or otherwise required by law;
- in an emergency when Brewstead reasonably believes disclosure is permitted and necessary to address an imminent risk of death or serious physical harm;
- as part of a lawful merger, acquisition, restructuring, sale, LLC formation, or succession, subject to applicable legal and contractual obligations.
Brewstead does not sell personal information and does not share personal information for third-party behavioral advertising.
9. Website Cookies and Similar Technologies
The Brewstead website is intended to use only essential cookies or similar technologies needed to operate the site, plus limited privacy-conscious traffic analytics if enabled. Brewstead does not currently plan to use advertising pixels or cross-site behavioral tracking. If that practice materially changes, this Policy will be updated and additional consent will be obtained where required.
10. Data Retention
Brewstead retains active account and user-created data for as long as reasonably necessary to provide the service, maintain the account, and meet the purposes described in this Policy.
- Anonymous accounts/data may be automatically deleted after approximately 24 months of inactivity.
- Registered Free user content may be moved to an archived or lower-cost state after approximately 3 years of inactivity and may become eligible for permanent deletion after approximately 7 years of inactivity, with reasonable advance notice where contact information is available.
- An active paid Pro entitlement will not be automatically deleted solely for inactivity while that paid entitlement remains active.
- Transaction, tax, refund, and accounting records may be retained for up to 7 years, or longer if reasonably necessary or required by law.
- Security, fraud, moderation, and audit records may be retained for a reasonable period based on their security, legal, evidentiary, or fraud-prevention purpose.
- Deleted information may remain temporarily in restricted disaster-recovery backups until those backups expire under Brewstead's normal backup cycle. Backup copies are not intended to remain available as active user accounts.
11. Account Deletion
Registered users may request account deletion. Brewstead intends to offer both a recoverable scheduled-deletion option and an immediate permanent-deletion option. A scheduled deletion may remain recoverable for up to 90 days; the user will be shown the scheduled deletion date and may cancel before completion. Immediate permanent deletion is intended for users who do not want the recovery period.
When permanent deletion is completed, Brewstead deletes or de-identifies the account and associated user content from active systems, except for limited records retained for legitimate reasons such as tax/accounting obligations, payment disputes, fraud prevention, security, audit integrity, or other legal requirements. Those retained records are not used as a hidden copy of the user's active recipe library.
More information is provided in the Brewstead Account & Data Deletion Policy.
12. Security
Brewstead uses reasonable administrative, technical, and organizational safeguards appropriate to the service, including server-side authorization for sensitive actions, least-privilege access, protected secrets, audit logging for important administrative actions, and security controls around authentication, payments, and cloud data. No security system can guarantee absolute protection.
If Brewstead becomes aware of a security incident involving personal information, Brewstead will investigate, take reasonable corrective measures, and provide notices to affected users or authorities when applicable law requires it.
13. Your Privacy Choices and Rights
Depending on applicable law and your relationship with Brewstead, you may have rights to request access to personal information, correct inaccurate information, request deletion, and obtain a copy of certain data in a reasonably usable format. Brewstead voluntarily intends to provide a strong baseline of access, correction, export, and deletion controls even where a particular state-law threshold may not apply.
Privacy requests may be submitted to homebrewingapp@gmail.com. Brewstead may verify that you control the relevant account or email before responding to a sensitive request. If Brewstead denies a privacy request, you may appeal by replying to the response and asking Brewstead to reconsider the decision.
Brewstead will not discriminate against you for exercising a legally protected privacy right. This does not prevent Brewstead from enforcing the Terms for unrelated fraud, abuse, security violations, or other misconduct, and some services may be impossible to provide after you delete information needed for the service.
14. Law-Enforcement and Emergency Requests
Outside a genuine emergency, Brewstead generally expects appropriate lawful process before disclosing private account information to law enforcement. Brewstead may preserve information in response to a valid preservation or legal request where appropriate. Where legally permitted and appropriate, Brewstead may notify a user that information has been requested, but Brewstead does not promise notice when law prohibits it or when notice could create danger or interfere with an investigation.
15. Changes to This Policy
Brewstead may update this Privacy Policy as the service evolves. Materially different data practices - for example, introducing precise location collection, behavioral advertising, or materially different sensitive-data uses - will be disclosed and additional consent will be obtained where legally required. Historical versions are maintained in Brewstead's internal legal archive.
16. Contact
Privacy questions or requests may be sent to homebrewingapp@gmail.com.
