the fine print
Privacy Policy
Last updated June 2026Introduction
This Privacy Policy explains how Brygg (“Brygg”, “we”, “us”) collects, uses, stores, and protects your personal data when you use our website and services (the “Service”).
Brygg is an AI coffee-search service operated as a small project based in Sweden: you describe the coffee you want in natural language and we return a grounded list of real products from specialty roasters. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data-protection laws.
Data Controller: Brygg
Contact: hello@brygg.coffee
Data we collect
We collect and process the following types of personal data:
Account information
- Email address — used for magic-link sign-in and, if you choose Google sign-in, provided by Google.
- Name — optional; provided by you or by Google sign-in.
- Account timestamps — when your account was created and last active.
Search & usage data
- Your search queries — the natural-language text you type to describe the coffee you want, and the resulting conversation, so we can return matches and let you return to past searches.
- Approximate location (country) — derived from your IP address to show prices in a sensible currency. We do not store your IP address as part of your profile or collect precise location.
Anonymous sessions
- You can search without creating an account. To do this we create an anonymous session that owns your searches and your rate-limit allowance. If you later sign in, that anonymous activity is linked to your account so your history carries over.
Technical data
- Authentication cookies — set by our authentication system to keep you signed in (see our Cookie Policy).
- Analytics events— see “Analytics” below; these are consent-aware and cookieless until you accept.
How we use your data
Providing the Service (Legal basis: Contract — GDPR Art. 6(1)(b))
- Interpret your search query and return grounded coffee matches.
- Sign you in and keep your session active.
- Save your search history so you can return to it.
- Show prices in an appropriate currency for your country.
Security & abuse prevention (Legal basis: Legitimate interest — GDPR Art. 6(1)(f))
- Apply rate limits (including per-IP limits for anonymous use) to protect the Service and control AI processing costs.
- Detect and prevent abuse and unauthorized access.
Analytics & improvement (Legal basis: Consent for cookie-based analytics; legitimate interest for aggregated insights)
- Understand how the Service is used so we can improve search quality and the experience.
- Produce aggregated, anonymized statistics that cannot identify you (e.g. “fruity Ethiopian is a popular search”).
AI processing of your searches
A core part of the Service uses artificial intelligence. When you submit a search, the text of your query is sent to a third-party large-language-model (LLM) provider (OpenAI) to interpret what you’re looking for. We send only the query text needed to do this — not your email, name, or account identifiers.
- OpenAI processes the query on our behalf as a data processor and, under its API terms, does not use API-submitted content to train its models.
- Please avoid typing personal or sensitive information into the search box — it isn’t needed to find coffee.
See OpenAI’s privacy information at openai.com/policies/privacy-policy.
Analytics
We use PostHog (EU-hosted, GDPR-compliant) to understand product usage. Until you accept analytics cookies, PostHog runs in cookieless mode— it records basic events without storing cookies on your device. If you accept, it uses cookies for more accurate, cross-visit analytics. You can change your choice at any time via “Cookie Settings” in the footer. We do not sell analytics data or share it for third-party marketing. See PostHog’s Privacy Policy and our Cookie Policy.
Third-party services & data processors
To run the Service we use the following providers, each acting as a data processor under appropriate agreements:
- Google Cloud Platform — backend hosting and database (Cloud SQL) for the coffee corpus and search data.
- Vercel — hosting for this website and our authentication service.
- OpenAI — interprets your search query (see above).
- PostHog (EU) — product analytics.
- ipinfo.io — maps your IP address to a country for currency display.
- Resend — sends magic-link sign-in emails.
- Google — if you choose Google sign-in, Google authenticates you and shares your email and name with us.
We do not sell, rent, or trade your personal data, and we never share it with third parties for their own marketing.
International data transfers
We are based in Sweden and prefer to keep data within the European Economic Area (EEA). Some providers (e.g. OpenAI, and parts of Google’s and Vercel’s infrastructure) may process data outside the EEA. Where that happens we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Data retention
- Authentication sessions: until you sign out or the session expires.
- Account & search history: until you delete your account, then removed within 30 days.
- Anonymous sessions: retained to provide continuity and may be cleared periodically if never linked to an account.
- Backups: deleted data may persist in backups for up to 30 days before permanent deletion.
- Aggregated/anonymized data: may be kept indefinitely as it cannot identify you.
Data security
- All traffic is encrypted in transit using HTTPS (TLS).
- Authentication cookies are HTTP-only and marked Secure in production to mitigate XSS and interception.
- Passwordless sign-in means there are no passwords to leak.
- Rate limiting protects against brute-force attacks and abuse.
No method of transmission or storage is 100% secure, but we work continually to protect your data.
Your GDPR rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Eraseyour data (“right to be forgotten”) by deleting your account.
- Port your data in a machine-readable format.
- Object to or restrict certain processing.
- Withdraw consent (e.g. for analytics cookies) at any time, without affecting prior processing.
To exercise any of these, email hello@brygg.coffee. We respond within one month (extendable to two for complex requests) and may need to verify your identity. You also have the right to lodge a complaint with a supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY).
Children's privacy
The Service is intended for users aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact hello@brygg.coffee and we will delete it.
Changes to this policy
We may update this Policy to reflect changes in our practices or the law. We will post the updated version here with a new “Last updated” date and, for material changes, take reasonable steps to notify you. Continued use after changes take effect means you accept the updated Policy.
Questions about your data? We’d genuinely love to help — email hello@brygg.coffee.