Privacy Policy
What data we collect, how we use it, and the choices you have.
Last updated: July 4, 2026
Plain-language summary
- We collect what we need to run the platform — your email and first name for an account; the production records you enter; sensor data from devices you connect; payment info when you subscribe (handled by Stripe; we never see your card number).
- Hobby users give us almost nothing. Email, first name, an age attestation. No last name, no address, no phone, no ID. That's deliberate.
- Commercial customers provide additional identifying information because federal alcohol regulations require operator identification in production records.
- We don't sell your data. No advertising cookies, no cross-site tracking, no data brokers, no training third-party AI on your data.
- You can leave with your data. Full export, machine-readable, any time. No data jail.
- You can delete your account. Hobby: full deletion. Commercial: we delete everything except the compliance records alcohol regulations legally require us to retain — and we tell you exactly what's kept and why.
- You must be at least 21 to use Brewstiller in the US.
- Story Pages track almost nothing about the consumers who scan them: country/region, device class, timestamp. No tracking cookies (only the age-confirmation cookie the visitor sets), no IP retention, no identification.
- Our vendors: Clerk (sign-in), DigitalOcean (hosting, database, file storage), Resend (email), Sentry (error tracking), and Stripe (payments, once paid tiers launch). Full list with details: the Subprocessor List.
1. Who this policy applies to
This Privacy Policy applies to Brewstiller — the brewing, winemaking, and distilling production-management platform operated by Brewstiller LLC, a Utah limited liability company ("Brewstiller," "we," "us," "our").
It applies to: hobby users; commercial workspaces and their authorized users; end consumers who scan QR codes and view Story Pages; and prospective customers who interact with our marketing site.
It does not apply to: third-party sites we link to; our commercial customers' own privacy practices (they are independent controllers of personal data they enter about their employees, customers, and vendors — see §12); or what commercial customers do with their Story Page aggregate analytics.
2. Geographic scope
Brewstiller is currently available only to customers located in the United States, and this policy's compliance commitments are scoped to US federal and state privacy law. If you are outside the US, please do not provide us personal information; we are not currently set up to process it under the laws that apply to you. International expansion will come with an updated policy (GDPR, UK GDPR, PIPEDA, etc.) and notice per §15.
3. Age requirements
You must be at least 21 years of age to use Brewstiller — older than typical services because this is an alcohol-production platform. (When international support ships: 18 or the local minimum, whichever is higher.)
If we learn we have collected personal information from someone under the age requirement, we will delete it promptly; contact us per §16 if you believe this has happened.
We verify age at signup through your attestation (date of birth plus confirmation). We store only a verified yes/no flag and the verification date — not your date of birth. We may require additional verification if we doubt an attestation.
4. What we collect
4.1 From hobby users — the minimum
- Email address — account creation, authentication, notifications.
- First name — so messages can address you. A display name (optional pseudonym) may be used anywhere your name appears in-product; you are never required to use a legal name.
- Age attestation — per §3 (stored as a flag, not a birthdate).
- Authentication credentials — handled by Clerk, our identity provider (§10); Brewstiller never stores your password in any form. Social sign-in (Google, Apple, etc.) shares the basic profile those providers disclose by default.
You are not required to provide: last name, legal name, mailing address, phone number, government ID, or payment information (until you choose a paid tier). This minimum-PII default is a deliberate platform commitment.
4.2 From commercial workspace users
Federal and state alcohol regulations require operator identification in production records. Beyond the hobby set, commercial workspaces collect per authorized user: full legal name, mailing address, phone number, role, and (optionally) an internal employee identifier. This regulatory PII is scoped to the specific workspace — each workspace holds its own copy; it is not shared across workspaces.
The workspace also captures entity information: legal entity name, TTB and state permit numbers, premises address, billing address, and tax identification number where needed.
4.3 Collected automatically from all users
- Account and session data — login events, session tokens (Clerk), workspace context.
- Device information — device type, browser, OS, screen size; no persistent device identifiers beyond what security requires.
- Approximate location — derived from IP for security (new-location sign-in flags) and analytics at country / US-state granularity. Raw IP is not retained beyond the immediate security context, except in the security-relevant audit log (§7.6).
- Usage information — routes visited, actions taken, for first-party product analytics stored in our own database (no third-party analytics service).
- Error and performance data — when the application errors, technical context is captured for debugging via Sentry (§10), with sensitive fields scrubbed before transmission. Error tracking operates only in our environment-gated production/staging environments; it is not embedded in a way that tracks you across sites.
- Cookies and similar technologies — first-party, functional only; see §10 and the Cookie Notice.
4.4 What you enter as you use the platform
Recipes, batches, ingredient lots, equipment, cooperage, sensor configurations, production stages, gauging records, compliance records, packages, notes, photos, attachments, and Story Page content. Some of these contain personal data (e.g., an operator's name on a regulated gauging record); most do not. Sensor readings are operational data about equipment and processes, not personal data about people.
4.5 Billing (paid tiers only)
Billing address; tax IDs where applicable; payment method details captured directly by Stripe (we receive only Stripe tokens and metadata — brand, last four, expiration — never your card number or CVC); subscription and invoice history.
4.6 From end consumers via Story Pages — deliberate minimization
When a consumer scans a QR code and views a Story Page, we collect aggregate analytics only: country and US state (derived from IP at scan time; the IP is not retained), referrer class (scan/link/NFC/unknown), device class (mobile/tablet/desktop), and timestamp.
We deliberately do not collect: the visitor's IP address, cookies or persistent identifiers (Story Pages set no tracking cookies), full user-agent strings, or anything that could identify an individual consumer. End consumers have no accounts, and we have no other information about them. The aggregate analytics is available to the publishing customer; we do not use it for our own marketing.
4.7 From third parties
- Sign-in providers (social sign-in) — basic OAuth profile (name, email, avatar URL).
- Sensor vendors' cloud APIs (if you connect one) — the sensor data you authorize; no personal information beyond what identifies the sensor as yours.
- Stripe — payment metadata, invoices, tax results (once paid tiers are live).
- Resend — delivery/bounce/unsubscribe events for email we send you.
- Referrals — an inviter provides your email so we can extend the invitation.
We do not purchase personal data from data brokers or list providers.
5. How we use information
5.1 Operating the service
Authentication and sessions; provisioning and operating workspaces; storing and retrieving your data; ingesting sensor readings; preparing the outputs you request (draft filings, Story Pages, invoices, reports); backups; applying documented retention policies.
5.2 Communicating with you
- Transactional — billing, password resets, security notices, account changes, alert-rule notifications, system status. Operationally necessary; not opt-out-able while you hold an active account.
- Product communications (announcements, tips, surveys) — opt-in; never auto-enrolled; every such email carries an unsubscribe mechanism.
- Support — when you contact us or we respond.
We use Resend for email delivery. We do not use marketing-automation platforms; if we add one, this policy will be updated first.
5.3 Improving the service
First-party, in-database usage analytics; error and performance reports; session replay only with your explicit opt-in via support (never silently enabled). We do not sell aggregated or anonymized data.
5.4 Security, fraud prevention, abuse detection
Suspicious sign-in detection; sensor-ingest rate limiting; payment-fraud controls (Stripe Radar plus platform-side checks); investigating AUP violations.
5.5 Legal compliance
Federal alcohol regulations (TTB record-keeping under 27 CFR parts 19, 24, 25 and related provisions), state alcohol regulations, FSMA 204 traceability where applicable, tax law (billing records), and litigation holds may each require retaining data beyond your subscription — see §7. These obligations can override deletion requests for specific categories; we always tell you what is retained and why, and delete everything else.
5.6 Aggregate analytics and benchmarking
We may produce aggregate, de-identified statistics across the platform (e.g., average fermentation duration by style) for research, product improvement, and public reporting. Aggregate statistics never identify your workspace, your recipes, your customers, or any person, and never single out an individual customer's performance.
6. How and when we share information
We share information only as described here. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising (as California law uses those terms).
6.1 With subprocessors
Third-party providers operate parts of the platform under contracts limiting their use of data to providing their service to us. Current subprocessors and the exact data categories each handles are in the Subprocessor List — summary: Clerk (authentication), DigitalOcean (application hosting, database, object storage), Resend (transactional email), Sentry (error tracking), and Stripe (payments and tax, from the launch of paid tiers). We provide at least 30 days' notice before adding a new subprocessor that handles personal data; commercial customers may object and terminate per the DPA.
6.2 Within your workspace
Your activity in a commercial workspace is visible to its other authorized users per the workspace's role configuration, which the workspace owner controls. Hobby data is visible only to you (and Brewstiller staff per §6.5).
6.3 With transfer counterparties
Regulated transfer records (transfer-in-bond) include the counterparty information regulation requires. We do not automatically share data across workspace boundaries; each workspace controls its own records.
6.4 With end consumers (Story Pages)
Only the content you chose to publish. Consumers never see your operational data.
6.5 With Brewstiller staff
A limited, role-gated, audited set of personnel may access your data to provide requested support, investigate incidents, diagnose reported bugs, comply with legal obligations, or investigate suspected AUP violations.
6.6 In a corporate transaction
If Brewstiller is acquired or its assets transferred, your information may transfer with notice before it occurs and, where law requires, the opportunity to object or terminate. The acquirer is bound by this policy for your data unless and until it provides a new policy with notice and the same termination right.
6.7 Legal process
We may disclose information when required by valid legal process, regulatory inquiry (TTB, FDA, state alcohol or tax authorities), to protect safety or rights, or to defend ourselves. Where legally permitted, we give the affected customer notice before disclosing so they can challenge it. (Some processes — grand jury subpoenas, certain national-security orders — legally prohibit notice.)
6.8 With your consent
Anything else, only if we ask and you agree.
7. Data retention
7.1 General principle
We retain information as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements — then delete or de-identify it. The commitments below are the retention outcomes we stand behind; the storage mechanics behind them (which tiers data lives in, at what age) are internal implementation that will evolve as the platform matures, without changing the commitments.
7.2 Retention periods by category
Defaults for commercial workspaces (hobby workspaces have no regulatory retention obligations for most categories):
| Category | Default retention | Notes |
|---|---|---|
| Production records (batches, stages, lots, gauges, packages) | 7 years from creation | Exceeds the federal TTB baseline with cushion |
| COLA records and approved label images | While the SKU is active + 3 years after retirement | Non-shortenable |
| Transfer-in-bond records | 7 years | Federal regulation |
| Compliance filings (federal and state) | 7 years | Federal and state regulation |
| FSMA 204 traceability records (where applicable) | 7 years | Federal floor is lower; 7 for consistency |
| Sensor readings (raw) | 90 days | Downsampled aggregates carry forward |
| Sensor readings (aggregated) | 7 years | Aggregates may inform compliance records |
| Audit log — compliance-relevant entities | 7 years | Matches the underlying entity |
| Audit log — other entities | 3 years | Operational |
| Story Pages | While the SKU is active + 3 years | Matches the COLA pattern |
| Story Page scan events (raw) | 13 months | Aggregates summarize monthly; raw events drop |
| Workspace, user, membership data | While active; 7 years post-termination (commercial); 30 days post-termination (hobby) | |
| Subscription billing records | 7 years | Tax-records retention norms |
Commercial Growth and Enterprise customers may extend specific retention periods up to 15 years by configuration. Regulatory floors cannot be reduced; COLA retention cannot be shortened. Cold-stored records needed for a compliance audit are restorable on request.
7.3 Export — no data jail
A complete, machine-readable export of your data is available at any time during your subscription and proactively at termination. This is the platform's "no data jail" commitment, and it is also your tool: keep your own copies of anything your compliance depends on.
7.4 Account termination — hobby
If you delete your hobby workspace or account, deletion requests are fulfilled by our operations team within 30 days of a verified request submitted per §8.5. We are building self-service deletion; until it ships, email is the supported path. Deletion covers your account data (email, name, credentials via Clerk), recipes, batches, sensor data, notes, and attachments; audit-log entries are anonymized (operation records remain for platform-operations history with personally-identifying actor fields removed); aggregate de-identified statistics may persist. Billing records, if you ever paid, are retained for the 7-year tax period with identifying information beyond tax requirements removed.
7.5 Account termination — commercial
Federal and state alcohol regulations require retaining certain compliance records after termination:
- Authorized users' personal account data — de-identified within 30 days; identifying fields on records we must retain are replaced with anonymized references.
- Recipes, sensor data, internal notes, attachments, Story Page content — deleted within 30 days, subject only to active litigation hold.
- Compliance records (production, gauging, transfer-in-bond, COLA references, tax determinations, filings, related audit entries) — retained for the legally-required periods in §7.2, then deleted as each record's period expires. We will: give you a complete export including the retained records; use retained records solely to comply with the retention obligation; and confirm in writing exactly which categories are retained and until when.
This is the asymmetric model: everything we can delete, we delete; what the law requires us to keep, we keep exactly that long and no longer. If you believe the carve-out was applied too broadly, request review per §16.
7.6 Audit log and security data
The audit log records who did what to regulated and significant records, including the acting user's identity and the client IP address of the action, plus before/after snapshots of changed records. This exists for regulatory audit defense, security investigation, and tamper-evidence, and follows the §7.2 audit-log retention periods. On account deletion, audit actor fields are anonymized per §7.4/§7.5; the operational fact of the change remains.
7.7 Litigation hold
A subpoena, regulatory inquiry, preservation letter, or similar hold can require retaining otherwise-deletable data until released. We inform you of a hold affecting your workspace unless legally prohibited, and resume normal timelines when permitted.
8. Your privacy rights
8.1 Everyone, regardless of jurisdiction
Access; correction; deletion (subject to §7's regulatory carve-outs and litigation holds); export/portability; marketing opt-out; account closure. Exercise them per §8.5.
8.2 California residents (CCPA/CPRA)
Right to know; delete; correct; opt out of "sale"/"sharing" (we do neither — the right isn't actionable in practice); limit sensitive-PI use (we use it only to provide the service and meet legal obligations); non-discrimination; authorized agents. We respond to verified requests within 45 days (one 45-day extension with notice).
8.3 Utah residents (UCPA)
To the extent the UCPA applies to Brewstiller's processing: confirm/access; delete; portable copy; opt out of sale (we don't sell) and targeted advertising (we don't do it). The UCPA lacks a correction right; contact us and we will accommodate corrections anyway. Response within 45 days.
8.4 Other states
Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other state privacy laws provide similar rights. We honor the rights granted by your state of residence, processed under the framework most favorable to you.
8.5 How to exercise
- In-app — account settings, where supported (export, marketing opt-out, account closure).
- Email — [email protected] with enough to verify you (your account email; workspace name if applicable; the request).
- Authorized agent — with your written authorization; we may verify with you directly.
We acknowledge within 5 business days and respond within the applicable statutory timeline (typically 30–45 days). Denials (e.g., regulatory retention) come with an explanation and any appeal rights.
8.6 What we cannot do
Delete data the law requires us to retain; delete data subprocessors must keep for their own compliance (e.g., Stripe's financial-regulation records); alter filings already in a regulator's possession; or act on someone else's workspace data at your request without authority.
9. Security
9.1 Technical safeguards
TLS 1.2+ in transit; encryption at rest (DigitalOcean managed database and object storage); authentication via Clerk (MFA supported; required for commercial workspace admins per workspace configuration); database-layer workspace isolation via PostgreSQL row-level security on top of application-layer controls; append-only audit logging; encrypted backups; managed network protections via our hosting platform.
9.2 Organizational safeguards
Role-gated, audited internal access on a need-to-know basis; security training for staff with data access; subprocessor security diligence; dependency vulnerability monitoring with severity-based patching; a documented incident-response procedure.
Brewstiller is an early-stage company and does not yet hold SOC 2 or ISO 27001 certification. We say so when asked, and this policy does not claim certifications we do not have.
9.3 Your role
Strong unique passwords or passkeys; enable MFA; secure your devices; expect that we will never ask for your password by email or phone; report suspicious activity promptly.
9.4 Breach notification
If we determine that an unauthorized party obtained access to your personal information, we will: investigate scope and cause; contain it; notify affected users and the authorities without unreasonable delay, within the timelines and with the content applicable state and federal breach-notification laws require (and faster where we reasonably can); and tell you what happened, what data was involved, what we are doing, and what you can do. Contractual notice to commercial customers as controllers is governed by the DPA (72-hour processor-notice commitment there). If law enforcement asks us to delay notice for an investigation, we may comply.
10. Cookies and tracking — summary
Full detail lives in the Cookie Notice. Summary:
10.1 What we use
First-party, functional only: authentication/session cookies (Clerk; strictly necessary); UI preference storage (localStorage / sessionStorage — theme, density, active workspace); the Story Page age-attestation cookie; and first-party, in-database product analytics not linked to any advertising identity.
10.2 What we don't use
No advertising cookies, no retargeting, no cross-site tracking pixels (no Facebook Pixel, Google Ads tag, LinkedIn Insight), no third-party analytics scripts, and no cookies at all on Story Pages other than the age-attestation cookie the visitor sets by confirming their age.
10.3 Global Privacy Control and Do Not Track
Because we do not sell or share personal information as state privacy laws define those terms, there is no sale or sharing for a Global Privacy Control (GPC) signal to opt you out of; we will formally recognize the signal when legally required of our processing. We do not respond to the older "Do Not Track" header, which lacks a settled meaning; our practices are consistent with what most users intend by it.
10.4 Controls
Browser settings control cookies; blocking strictly-necessary cookies prevents sign-in. See the Cookie Notice for the current inventory.
11. International transfers
Service and infrastructure are US-only at v1; we do not routinely transfer personal information internationally. Narrow incidental cases: your own international travel; a staff member temporarily working abroad accessing US-hosted systems under §9.2 controls; subprocessor multi-region infrastructure per their standard practices. International expansion will bring transfer mechanisms (SCCs, UK IDTA, adequacy) and a policy update.
12. Controllers and processors (commercial customers)
- Brewstiller is the controller of the personal information it collects about you as a user (account email, name, sign-in metadata, billing, usage). This policy governs that.
- The commercial customer is the controller — and Brewstiller the processor — for personal data the customer enters about its own people (employees, customers, vendors, counterparties, end consumers). The DPA governs that processing.
- If you are an employee/customer/vendor of a Brewstiller commercial customer and want to exercise rights over data in their workspace, contact them — they are the controller; we assist them per the DPA. We respond directly to you only for data we control.
13. Aggregated and de-identified information
Aggregated (combined so individuals aren't identifiable) or de-identified (identifiers removed, with technical and organizational measures against re-identification, and a commitment not to attempt re-identification) data is no longer personal information under this policy. We use it for research, product improvement, benchmarking, and public reporting — never to single out an individual customer's performance or reverse-engineer a specific operation.
14. Beta period
During the invite-only, hobby-only beta: feedback collection per the Beta Addendum (not shared publicly without permission); beta-program communications are operationally necessary for participants; no contractual data-migration commitment (export before transition if in doubt — Beta Addendum §7). Beta data follows the hobby rules in this policy.
15. Changes to this policy
Material changes (new data categories, new purposes, new sharing) — at least 30 days' notice via in-app banner, email, and a prominent notice on the policy, before effect. Non-material changes (clarity, corrections, subprocessor swaps without expanded data flows) — updated "Last updated" date.
Grandfathering: material changes that would degrade the data-handling protections you signed up under are not applied retroactively to your existing account without your explicit consent — parallel to the Terms §6.4 commitment, and equally one-way (improvements flow to you automatically).
Prior versions are archived and available on request.
16. Contact
Brewstiller LLC — Privacy [email protected] · DPA requests: [email protected] · Security: [email protected]
We acknowledge privacy requests within 5 business days. If unsatisfied with our response: California residents may contact the CPPA or the California AG; other states' residents their state AG; federal complaints, the FTC.
17. Effective date and version history
Effective date: July 4, 2026 · Last updated: July 4, 2026 · Version: v1.1
| Version | Effective date | Summary |
|---|---|---|
| v1.0 | — (never published) | Initial draft. |
| v1.1 | July 4, 2026 | Promises scoped to implemented capability; Cookie Notice split out; GPC and breach-notice language made accurate; audit-log disclosure added. |