Privacy Policy — Homebrew Hero
Effective Date: 11 August 2026
Homebrew Hero ("the App", "we", "us") is developed by a solo, UK-based developer. This Privacy Policy explains what personal data the App collects, why, and what your rights are.
If you have questions about this policy or your data, contact: homebrew.hero.app@gmail.com
1. Who this policy applies to
This policy applies to anyone who downloads or uses Homebrew Hero on iOS or Android, including during the current closed beta testing period.
2. What personal data we collect
2.1 Account and sign-in data
To use the App you must sign in with either Google Sign-In or Sign in with Apple. We receive:
- Your email address (or, for Apple, the private relay email address if you choose to hide your real one)
- A unique account identifier issued by our authentication provider (Supabase Auth, built on top of your Google/Apple identity)
We do not receive or store your Google/Apple password.
2.2 Display name (public)
On your first sign-in, we automatically create a public profile with a placeholder display name (derived from your email, never your full name), which you're prompted to change to a nickname of your choosing. This display name is shown next to anything you post in the Forum or chat — see Section 7 on public content.
2.3 Device identifier
The App generates and stores a device identifier (Android's ANDROID_ID or iOS's identifierForVendor, where available, otherwise a random ID). This is not used for advertising profiling by us directly — it's used to:
- Enforce a fair-use daily limit on AI feature calls, to prevent abuse of the AI service
- Enforce a one-free-tier-per-physical-device rule (see Section 8 and our Terms of Service), so the same device can't repeatedly claim a new free-tier allowance by signing out and creating a new account
2.4 Brewing data
Everything you enter about your brews — recipe names, styles, ingredients, batch sizes, fermentation temperatures, gravity/pH readings, tasting notes, schedules, and any photos you choose to submit for AI kit-box scanning or recipe scanning — is stored so the App can function and so it can sync across your devices when you're signed in. Brewing data is private to your account unless you deliberately share or post it (see Section 7).
2.5 Data sent to our AI provider (Anthropic)
Certain features — AI recipe generation, AI recipe tweaking, kit-box/instruction photo scanning, brand logo lookup — send data to Anthropic (the maker of Claude) via our own backend, which we operate so that our Anthropic API key is never embedded in the App itself. Depending on the feature, this may include:
- Text you enter (e.g. a beer style, a commercial brand name to clone, brewing questions)
- Photos you submit for scanning (e.g. a kit box or its instructions)
- Non-personal brewing context (batch size, equipment you own, unit preferences) needed to generate a relevant answer
We do not send your email address, real name, or account credentials to Anthropic. Requests are tagged with your device identifier only (not your email) so our backend can apply rate limits.
2.6 Usage and cost logs (server-side)
Our backend logs, per device identifier: which AI feature was used, the model used, an estimated token count/cost, and the date — used only for fair-use rate-limiting and for us to monitor our own operating costs. It is not used for advertising.
2.7 Marketing preference (optional)
During profile setup you can opt in to occasional brewing offers/deals emails. If you opt in, your email address and opt-in status are stored in a separate, private table only we can access. This is off by default and can be changed anytime in Settings.
2.8 Advertising data (free-tier users only)
Free-tier users are shown ads via Google AdMob. On iOS, the App will ask for App Tracking Transparency (ATT) permission before requesting a tracking identifier for more relevant ads — you can decline this and still use the App; ads will simply be less personalized. Google AdMob's own data collection is governed by Google's privacy policy, linked at the point the ATT prompt is shown and in Google's own disclosures.
2.9 Purchase data
Subscription purchases go through Apple's App Store or Google Play. We do not receive or store your payment card details — Apple/Google handle billing directly, and we only learn that a purchase was made and, once real in-app billing is wired up, receipt information used to validate your subscription tier.
3. Why we collect this data
We collect and use your personal data for the following purposes:
- To create and operate your account, and to let your brewing data sync across your devices when you're signed in — necessary to provide the App.
- To power AI features you actively use (recipe generation, tweaking, kit-box scanning) by sending the relevant data to our AI provider, Anthropic — necessary to provide the App.
- To enforce fair-use daily limits and the one-free-tier-per-device rule, to keep the free tier fair to everyone and prevent abuse of paid AI services — our legitimate interest in operating a sustainable service.
- To send you optional marketing emails about brewing offers, only if you opt in — based on your consent, which you can withdraw at any time.
- To display ads to free-tier users via Google AdMob — necessary to operate a free tier without a subscription.
- To monitor and improve the App's reliability and operating costs — our legitimate interest.
We do not use your personal data for any purpose beyond those described in this policy.
4. Who we share data with
We do not sell your personal data. We share data with the following third parties, strictly to operate the App:
- Supabase — our backend hosting provider, for authentication, database storage, and serverless functions. Your account data, brewing data, and forum content are stored on Supabase's infrastructure.
- Anthropic — processes the content described in Section 2.5 to power AI features. See Anthropic's own privacy policy for how they handle API data.
- Google (Google Sign-In, Google Play billing) and Apple (Sign in with Apple, App Store billing) — used to authenticate you and, for paid tiers, to process your subscription.
- Google AdMob — shows ads to free-tier users and may collect an advertising identifier if you grant ATT permission on iOS.
We do not share your brewing data, email address, or AI conversation content with any other third party, and we do not use your data for purposes unrelated to operating the App.
5. Your rights
If you are in the UK or EU, you have rights under UK GDPR / EU GDPR, including the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data ("right to erasure")
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent (e.g. the marketing opt-in) at any time
These same rights are, as a matter of practice, offered to all users regardless of location. To exercise any of these rights, email homebrew.hero.app@gmail.com. Deleting your account removes your private brewing data, settings, and marketing preference record from our systems; content you posted publicly (see Section 7) may be retained in anonymized/aggregate form as described below.
You may also delete your account directly from within the App's Settings screen, where available, or by request via email.
6. Data retention
- Account and brewing data is retained for as long as your account is active. If you delete your account, we delete your private data within a reasonable period, except where retention is required for legal, security, or fraud-prevention purposes (e.g. the device-eligibility record described in Section 8, which is retained in a form that does not identify you personally beyond linking a device to whichever account first used its free tier).
- AI usage/cost logs are retained for a limited operational period for rate-limiting and cost-monitoring purposes.
- Forum posts, chat messages, and contributed kit-recognition/logo data (see Section 7) may persist after account deletion, since they are shared, aggregate community content by design — we will remove your display-name association with them on request where technically feasible.
7. Public and shared content — please read
Some data in Homebrew Hero is not private. Specifically:
- Forum posts, replies, and chat messages you submit are visible to any other user of the App (and, for the Forum, potentially anyone who is signed in), alongside your chosen display name. Do not post anything in the Forum or chat that you don't want other users to see.
- Recipe ratings and notes you leave on shared/clone recipes contribute to a public aggregate rating (e.g. "4.2 stars from 12 brewers") visible to all users. Individual written notes may be visible depending on the feature.
- Kit-box instructions and brand logos you scan may be contributed anonymously (keyed to a device identifier, not your account or display name) to a shared, crowd-sourced database so that other brewers who scan the same product don't have to re-scan it. This contributed data is not linked to your name or email and is intended to benefit the whole community.
- Recipes you explicitly share (e.g. via the app's native share feature to send a recipe to another brewer) are, by design, transmitted outside your private account data.
Anything you enter in your own private brew records, notes, or settings is not shared with other users unless you take one of the actions above.
8. The device-eligibility check
To keep the free tier fair, the App checks — via a secure server-side function — whether a physical device has already used the free tier's one-time allowance under a different account. This check only tells our system "has this device claimed a free tier before, and under which account" — it does not expose this information to other users, and it is not used for any purpose beyond preventing repeated free-tier claims via sign-out/sign-in cycles on the same device. See our Terms of Service for more detail.
9. Children's privacy
Homebrew Hero is not directed at, marketed to, or intended for use by children. Because the App is used to plan and track the production of alcoholic beverages, it is not appropriate for anyone under the legal drinking/purchasing age in their country, and in any event is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at homebrew.hero.app@gmail.com and we will delete it.
10. Security
We take reasonable technical measures to protect your data (e.g. encrypted connections, database-level access controls restricting each user to their own private data). No system is 100% secure, and we cannot guarantee absolute security.
11. International data transfers
Our service providers (Supabase, Anthropic, Google, Apple) may process data outside the UK/EU, including in the United States. Where this occurs, we rely on those providers' own compliance mechanisms (such as standard contractual clauses) for lawful international transfer.
12. Changes to this policy
We may update this Privacy Policy from time to time, for example as the App adds features or as real in-app billing replaces the current placeholder premium toggle. We will update the "Effective Date" above when we do. Continued use of the App after a change constitutes acceptance of the updated policy.
13. Contact us
For any privacy question, data request, or concern, email: homebrew.hero.app@gmail.com
If you are in the UK and believe we have not adequately addressed your concern, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.