Privacy Policy
Effective from your acceptance. Last updated: 2026-05-19. Version 2026-05-19.
Draft text. Final version pending review by qualified UK counsel. For the working long-form version see docs/planning/PRIVACY_POLICY.md in the repository.
1. Who we are
Brewyard is operated by Fincard Ltd, a company registered in England and Wales. We act as the data controller for personal data processed through Brewyard. We are registered with the UK Information Commissioner's Office (ICO), registration number ZC229340.
Contact: privacy@brewyard.ai
2. The short version
We collect the minimum personal data needed to run your account, bill you correctly, and operate the service. We do not sell your data. Your project descriptions and agent conversations are kept private to your account. We use anonymised, aggregated insights to improve the product, and you can switch that off at any time.
3. What we collect
- Identifiers: email address, account ID, IP address, user-agent.
- Authentication: argon2 password hash, session tokens (we never store plaintext passwords).
- Billing: last 4 digits of card, country, billing email, Stripe customer ID, invoice history (full card data stays with Stripe).
- API credentials: a reference to your Anthropic API key stored encrypted in Azure Key Vault. The plaintext value never appears in our database.
- Project content: project descriptions, agent prompts, agent responses, audit logs.
- Service usage: page views, button clicks, errors, model usage counts, latency metrics.
4. Why we collect it
We process personal data on the following legal bases: contract (operating your account), legitimate interests (preventing abuse, improving the service), legal obligation (tax records, security investigations), and consent (where we ask for it explicitly).
5. Sharing
We share personal data only with sub-processors needed to run the service: Microsoft Azure (hosting + Key Vault), Stripe (billing), Resend (transactional email), and Anthropic (model inference on your behalf, via your own API key). A current list of sub-processors is maintained on this page.
6. Retention
We keep your data for as long as your account is active. Cancelling your account deletes personal data within 30 days, with two exceptions: financial records we are legally required to retain (typically 6 years in the UK), and security/audit logs kept for up to 12 months. Backups roll off within 35 days.
7. Your rights
Under UK GDPR you have the right to access, correct, delete, port, restrict, and object to processing of your personal data. To exercise these rights, email privacy@brewyard.ai. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).
8. International transfers
Brewyard data is stored in Azure UK South (London). Some sub-processors operate globally; we use Standard Contractual Clauses or equivalent safeguards for transfers outside the UK/EEA.
9. Cookies
We use a small number of essential cookies to keep you signed in. We do not use advertising cookies. Optional analytics cookies (PostHog Cloud EU, pseudonymous) are off by default and only set after you accept them on the cookie banner; you can withdraw that choice at any time on the Cookie Policy page. Key account actions are additionally measured server-side (pseudonymised, via PostHog Cloud EU); that sets nothing on and reads nothing from your device.
10. Changes
We may update this policy. Material changes will bump the version number; you will be asked to re-accept on next login.