Privacy policy

Effective date: 2026-03-07
Last updated: 2026-06-21

This Privacy Policy explains how Tealytics (“Tealytics”, “we”, “us”) collects, uses, shares, and protects personal data when you use our website and web app (the “Service”).

If you have questions, contact: hi@tealytics.app.

1) Who is responsible (Controller)

Controller (data protection law):
Philipp Bochmann
c/o Impressumservice Dein-Impressum, Stettiner Str. 41, 35410 Hungen
hi@tealytics.app

2) What data we collect

2.1 Data you provide

  • Account data: name, email address, password hash (never your plaintext password).
  • Billing data (if paid plans): billing contact details, billing address (if collected), tax IDs (if provided). Payment card details are processed by our payment provider, not stored by us.
  • Support communications: messages you send us, attachments, feedback.

2.2 Data you upload or generate in the Service

  • User Content: data you enter, import, or generate in Tealytics (may include personal data depending on what you upload).

2.3 Data collected automatically

  • Server access logs: our hosting provider (Vercel) may process IP addresses and request timestamps as part of standard server operation.
  • Privacy-friendly web analytics: we use Rybbit, a cookie-free analytics tool we self-host on our own infrastructure, to collect anonymized usage data (page views, referrer, browser type, device type, country, anonymized JavaScript error events, and in-app feature usage events). Rybbit does not use cookies, does not store IP addresses, and does not track users across websites or sessions. See Section 8 for details.
  • Cookies: see Section 8.

3) How we use data (purposes)

We use personal data to:

  • Provide and operate the Service (authentication, core functionality).
  • Secure the Service (fraud prevention, abuse detection, monitoring).
  • Process subscriptions and invoices (if applicable).
  • Communicate with you (support, important notices).
  • Improve the Service (debugging, product analytics, feature development).
  • Meet legal obligations (tax, accounting, compliance).

We do not sell personal information.

4) Legal bases (GDPR/UK GDPR, where applicable)

Where GDPR/UK GDPR applies, our legal bases include:

  • Contract (Art. 6(1)(b)): to provide the Service you requested.
  • Legitimate interests (Art. 6(1)(f)): to secure and improve the Service, prevent abuse, and operate our business.
  • Consent (Art. 6(1)(a)): where required (e.g., certain cookies/marketing).
  • Legal obligation (Art. 6(1)(c)): e.g., tax/accounting compliance.

5) Sharing data (processors and recipients)

We share personal data only as needed to run Tealytics, including with:

  • Vercel — hosting, CDN, and edge functions (US).
  • Convex — database, file storage, and backend functions (US).
  • Brevo (Sendinblue) — transactional email for magic link authentication (EU/France).
  • Google — OAuth 2.0 authentication and the Gemini API for AI features, in particular the teabert AI assistant and label scanning (US). See Section 9.

We may also share data:

  • To comply with law or legal requests.
  • To protect rights, safety, and security (fraud, abuse, incidents).
  • In connection with a merger, acquisition, or asset sale (with appropriate safeguards).

6) International transfers

We may process data in countries outside your country of residence (including the US). Where required by GDPR/UK GDPR, we rely on appropriate safeguards such as:

  • EU Standard Contractual Clauses (SCCs) and/or UK addendum,
  • Adequacy decisions (where applicable),
  • Additional technical/organizational measures as appropriate.

7) Data retention

We keep personal data only as long as necessary:

  • Account data: while your account is active. Deleted immediately upon account deletion (see Section 11).
  • Authentication sessions: expire after 30 days.
  • Magic link tokens: expire after 24 hours and rate-limit logs are purged after 15 minutes.
  • Server access logs: retained per our hosting provider’s standard policy (Vercel).
  • Backups: retained per our database provider’s standard policy (Convex).
  • teabert conversations: automatically deleted 12 months after their last message.
  • AI usage log: internal per-call usage and cost data is deleted after 90 days.

You can delete your account and all data from your account settings at any time (see Section 11).

8) Cookies and tracking

We use only strictly necessary cookies for authentication and security:

  • Session cookies: to keep you signed in (CSRF token, session token).

We do not use marketing or tracking cookies. Because these cookies are strictly necessary to provide the Service you requested, no consent is required (TDDDG § 25 Abs. 2).

8.1 Web analytics (Rybbit)

We use Rybbit, an open-source, privacy-friendly analytics tool that we self-host on our own infrastructure. Your analytics data is never sent to a third-party analytics provider. Rybbit:

  • does not use cookies or any other device storage,
  • does not store your IP address (it is used only transiently to derive coarse data such as country, then discarded),
  • does not track users across websites, and uses no persistent cross-session identifiers,
  • collects only anonymized, aggregated data: page views, referrer URL, browser type, device type, country, anonymized JavaScript error events, and in-app feature usage events (including on authenticated pages once you are signed in).

Because Rybbit stores no information on your device and does not retain personal data, no consent is required under GDPR (Art. 6(1)(f), legitimate interest), TDDDG § 25 Abs. 2, or ePrivacy rules. Use of analytics within the signed-in app is also described in our Terms and Conditions.

9) AI assistant (teabert)

teabert is an optional AI feature for Connoisseur subscribers. When you use teabert, we send your message together with context from your tea data to Google’s Gemini API (Google LLC, US) to generate a reply.

9.1 What we send to Google

  • the text of your chat message,
  • your tea collection (names, types, ratings, stock levels),
  • your teaware (e.g., pots, gaiwan) and its properties,
  • your 25 most recent brewing sessions, including your free-text tasting notes (truncated to 200 characters per session),
  • aggregate statistics about your brewing.

Because your tasting notes are free text, they may contain anything you typed, potentially including names, places, or health-related details, and are sent to Google as described above. If you would rather certain details were not sent, do not enter them in free-text notes, or turn AI features off. Generating a conversation title additionally sends the text of your first message.

9.2 How Google processes the data

We use the paid Gemini API. Under Google’s terms, inputs sent via the paid API are not used to train Google’s models. Processing is governed by Google’s Data Processing Addendum and the EU Standard Contractual Clauses (see Section 6, International transfers).

9.3 Your control

  • You can turn AI features off completely in Settings at any time. When off, nothing is sent to Google.
  • You can delete individual conversations at any time.
  • Deleting your account immediately deletes all teabert conversations.

9.4 Retention

teabert conversations are automatically deleted 12 months after their last message. An internal per-call usage and cost log is kept for 90 days.

9.5 Legal basis

Processing is necessary to provide the paid Connoisseur feature you actively chose to use (Art. 6(1)(b) GDPR).

10) Newsletter and marketing emails

If you opt in, we send you product updates, tips for getting the most out of Tealytics, and a monthly recap of your tea activity by email. You only receive these marketing and lifecycle emails if you have signed up for them.

10.1 Double opt-in sign-up

Signing up for the newsletter uses a double opt-in process: after you sign up, we send a confirmation email with a confirmation link. Your email address is only treated as confirmed once you click that link and confirm your sign-up. Only confirmed addresses receive marketing email.

10.2 Legal basis

The legal basis for sending newsletter and marketing emails is your consent (Art. 6(1)(a) GDPR).

Transactional emails are different: a welcome email when you register, a welcome email when you start a subscription, and a one-time onboarding reminder if you have not yet logged a brewing session, are part of providing the Service you requested. We send these on the basis of Art. 6(1)(b) GDPR (performance of the service you requested), not on the basis of consent.

10.3 Proof of consent

To meet our accountability obligations (Art. 7(1) and Art. 5(2) GDPR), we record the time the opt-in was requested, the version of the consent wording shown to you, and the time and IP address of your confirmation click. We keep this proof for the duration of your subscription plus the statutory limitation period of three years, then delete it.

10.4 Email provider (Brevo)

Our emails are sent through Brevo (Sendinblue GmbH / Brevo). Brevo processes the sending data only on our behalf as a processor under a data processing agreement (Auftragsverarbeitungsvertrag, Art. 28 GDPR).

10.5 Withdrawing consent

You can withdraw your consent at any time with effect for the future, using the unsubscribe link at the bottom of every marketing email or via your email settings. This does not affect the lawfulness of processing carried out before your withdrawal.

11) Your rights

11.1 GDPR/UK GDPR rights (EEA/UK users)

Depending on your situation, you may have rights to:

  • Access your data, correct it, delete it.
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent (where processing is based on consent).
  • Lodge a complaint with a supervisory authority.

11.2 US privacy rights (state laws, where applicable)

Depending on your state, you may have rights to:

  • Access, delete, correct certain personal information.
  • Opt out of certain processing (e.g., targeted advertising) where applicable.
  • Non-discrimination for exercising privacy rights.

How to exercise rights: You can delete your account and all associated data directly from your account settings. You can export your data before deletion. For other requests, email hi@tealytics.app.

12) Children

The Service is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.

13) Security

We use reasonable technical and organizational measures to protect data (access controls, encryption in transit, monitoring). No system is 100% secure, so we cannot guarantee absolute security.

14) Changes

We may update this policy. If changes are material, we will provide notice (email or in-app) and update the effective date.

15) Contact

Privacy questions or requests: hi@tealytics.app
Controller: Philipp Bochmann