Brewmeo Privacy Policy
Effective Date: 03.09.2026.
1. Introduction
This Privacy Policy explains how Pressensor Kft. ("Pressensor", "we", "our" or "us") collects, uses, stores and protects personal data in connection with the Brewmeo mobile application, web application and related cloud services (collectively, the "Service").
Brewmeo was previously published under the name "Pressensor Coffee Flow". The name change does not affect the identity of the data controller, your account or the way your data is processed.
We are committed to protecting the privacy of our users and to processing personal data in accordance with Regulation (EU) 2016/679 ("GDPR"), Hungarian data protection legislation and other applicable laws.
Please read this Privacy Policy carefully before using the Service.
2. Data Controller
The controller responsible for processing personal data under this Privacy Policy is:
Pressensor Kft.
1022 Budapest, Rókushegyi lépcső 5. 2. em. 5.
Hungary
Email: hello@brewmeo.com
For support-related inquiries you may also contact:
hello@brewmeo.com
3. Core Privacy Principles
Brewmeo has been designed with privacy in mind.
A fundamental feature of the Service is that it may be used entirely without creating a user account.
When the Service is used without registration, brewing profiles, measurements, notes, ratings and settings remain stored locally on the user's own device. Such information is not transmitted to Pressensor and is not stored on Pressensor-operated systems.
As a result, most brewing-related information generated by anonymous users never leaves their device. The only exceptions are the anonymous community statistics event described in Section 11 and the optional usage analytics described in Section 10 (only if you choose to enable it).
Personal data is collected when a user chooses to create an account, interacts with features requiring cloud functionality, or enables the optional usage analytics described in Section 10.
If you create an account, your recorded brews are by default shared publicly in the application's community feed, together with your display name, profile picture and country. You can turn this off at any time — see Section 8.
We do not sell personal data.
We do not use advertising networks.
We do not use behavioural advertising.
We do not use third-party marketing trackers.
We do not create marketing profiles of users.
4. Use of the Service Without an Account
Users may use Brewmeo without registering for an account.
In this mode:
- brewing measurements are stored locally;
- brewing profiles remain on the device;
- synchronization is unavailable;
- cloud backup is unavailable;
- Pressensor does not receive brewing content.
Communication between the mobile device and connected brewing equipment occurs directly through Bluetooth and does not require transmission of brewing data to Pressensor.
Where Bluetooth permissions are requested by the operating system, such permissions are used solely to discover, connect to and communicate with compatible brewing devices.
On Android 11 and older, the operating system requires the location permission in order to scan for nearby Bluetooth devices. Where the application requests this permission, it is used exclusively for Bluetooth device discovery: the application does not determine, store or transmit your location.
Bluetooth and location permissions are not used for advertising, behavioural tracking or location profiling.
5. Information We Collect When You Create an Account
If you choose to create a Brewmeo account, we process certain information necessary to provide account-related functionality.
Depending on how you register, this information may include:
Identity and Account Information
- email address;
- username;
- profile picture (if provided);
- year of birth;
- country of residence;
- unique account identifier;
- account creation date;
- authentication provider information.
Authentication may occur through:
- email-based authentication;
- Sign in with Apple;
- Google Sign-In.
If you use Apple's "Hide My Email" feature, we receive only the anonymised relay email address provided by Apple.
Brewing Content
Where cloud synchronization is enabled, we may process brewing-related content including:
- brewing profiles;
- brewing measurements;
- pressure data;
- scale measurements;
- brewing parameters;
- profile names;
- notes;
- ratings;
- application settings.
This information is processed for storage, synchronization, sharing and backup purposes. Unless you turn community sharing off, brews are also published publicly as described in Section 8; personal notes and ratings are never published.
Purchases
Certain features of the Service can be purchased as in-app purchases through the Apple App Store or Google Play. Payments are processed by Apple or Google under their own terms and privacy policies; Pressensor never receives or stores payment card details.
In connection with such purchases, we may process:
- the identifier of the purchased product;
- purchase and entitlement status;
- transaction or receipt identifiers issued by the store, used to verify the purchase.
Technical Information
When users interact with cloud services, our systems may automatically process technical information such as:
- IP address;
- timestamps;
- device identifiers generated by our systems;
- server logs;
- operating system information;
- application version information.
We use this information solely to operate, maintain and secure the Service.
6. Application Integrity and Abuse Prevention
To protect the Service against fraud, abuse and unauthorised access, Brewmeo may use platform-provided integrity verification technologies.
These include:
- Apple App Attest;
- Google Play Integrity API.
These technologies generate cryptographic verification tokens that help confirm that requests originate from genuine application installations.
These mechanisms are used exclusively for security purposes and are not intended to identify users personally.
Our legal basis for this processing is our legitimate interest in maintaining the security and integrity of the Service under Article 6(1)(f) GDPR.
7. Why We Process Personal Data
We process personal data only where a valid legal basis exists.
Performance of a Contract
We process account information, brewing content and purchase information where necessary to provide:
- account functionality;
- cloud synchronization;
- cloud backup;
- sharing and community functionality;
- purchased features.
Legal basis: Article 6(1)(b) GDPR
Legitimate Interests
We process technical information and security-related information where necessary to:
- protect our infrastructure;
- prevent abuse;
- investigate security incidents;
- maintain service reliability.
Legal basis: Article 6(1)(f) GDPR
Compliance with Legal Obligations
Certain information may be processed where required by accounting, tax, regulatory or legal obligations.
Legal basis: Article 6(1)(c) GDPR
Consent
Where specific optional functionality requires consent — such as the optional usage analytics described in Section 10 — processing is based on the user's consent.
Consent may be withdrawn at any time.
Legal basis: Article 6(1)(a) GDPR
8. Community Sharing
Brewmeo includes a community feature: brews recorded by signed-in users are, by default, published to a public community feed, where they can be viewed by anyone — including people who do not use the application.
Community sharing applies only to signed-in users. If you use the Service without an account, your brews never leave your device (see Section 4).
What Is Public
For each published brew, the following information is publicly visible:
- the brew's name, date and duration;
- brewing measurements and curves (pressure, flow, weight, temperature);
- brewing parameters (for example dose, yield and temperatures);
- equipment details you record (espresso machine, grinder, basket, tamper, beans and roastery information);
- your profile display name (in shortened form), profile picture and country;
- a pseudonymous account identifier that links your published brews together.
The following are never published:
- personal notes;
- taste assessments and ratings;
- your email address and authentication information.
Your Controls
Community sharing can be turned off at any time with the "Share my shots with the community" setting in the application. Turning it off unpublishes all of your brews; the change takes effect within minutes. Deleting a brew likewise removes it from the community feed.
Public Links and Caching
Every published brew has a public web address. Anyone possessing that address may view the brew without authentication, and messaging or social networking services may generate previews when such links are posted.
Public content is served through content delivery networks. After a brew is unpublished or deleted, cached copies may remain accessible for a short period (typically minutes).
Please be aware that while a brew is public, other users may save a copy of it to their own device. Such copies are stored locally on their devices and are not removed when you later unpublish or delete the brew.
Coffee Pulse Posts
Signed-in users may publish short text posts ("Coffee Pulse"). Posting is always an explicit act; posts are reviewed by us before they become visible. A published post is public and shows your profile display name, profile picture and country, like a published brew.
Posting frequency is limited for accounts without an unlimited entitlement. To enforce this, we store the time of your most recent post together with your account.
Signed-in users may like posts. We store which account liked which post — this enforces one like per account and lets us delete your likes together with your account; publicly, only the total number of likes is shown, never who liked.
Coffee Pulse posts and likes are permanently deleted when your account is deleted.
Reports and Moderation
Anyone may report published content (a brew or a Coffee Pulse post) as inappropriate. When a report is submitted, we record the reported content's identifier, its owner's account identifier and a timestamp; we do not record the identity of the reporter. Reports are reviewed manually and retained only as long as needed for moderation.
We may remove content from the community feed, or exclude a user's content from it entirely, where we consider this necessary (for example, following a report).
Users may also hide ("block") another user's content locally on their own device; this preference is stored only on the device and is not transmitted to us.
9. Service Providers and Data Processors
To operate the Service, we rely on trusted third-party service providers.
These providers process personal data on our behalf under contractual safeguards, except where indicated as independent controllers below.
Google Ireland Limited / Google LLC
Services provided:
- Firebase Authentication;
- Firestore;
- Cloud Storage;
- Cloud Functions;
- Hosting;
- Google Analytics for Firebase (GA4) and BigQuery;
- Google Cloud Platform.
Purpose:
- authentication;
- synchronization;
- cloud storage;
- backend operations;
- usage analytics (only if enabled — see Section 10).
Apple Inc.
Where users choose Sign in with Apple, Apple processes authentication information according to its own privacy policies.
Where users make in-app purchases through the App Store, Apple processes the payment as an independent controller according to its own terms and privacy policies.
Google LLC
Where users choose Google Sign-In, Google processes authentication information according to its own privacy policies.
Where users make in-app purchases through Google Play, Google processes the payment as an independent controller according to its own terms and privacy policies.
10. Usage Analytics
To understand how the Service is used and to improve it, we offer optional usage analytics. This is off by default and is collected only if you turn it on.
You are asked once, shortly after you start using the application, whether to enable it, and you can change your choice at any time in the application's settings. Your choice applies whether or not you are signed in.
When enabled, we use Google Analytics for Firebase (Google Analytics 4) to collect usage events, such as:
- which screens and features are opened;
- coarse, non-identifying actions (for example, signing in);
- device model, operating system and application version;
- approximate region (country level), derived from the IP address, which is not stored;
- a pseudonymous application-instance identifier generated by the analytics SDK.
Usage analytics never includes your brewing content — recipes, measurements, pressure curves, notes and ratings are not part of it. It is not linked to your identity or account (no user identifier is set), and it is not used for advertising; advertising and cross-app features of the analytics service are disabled.
The analytics data is processed by Google as our processor and may be exported to Google BigQuery, configured to store the data within the European Union.
Legal basis: consent — Article 6(1)(a) GDPR. Declining, or turning the setting off later, stops further collection.
11. Community Statistics
The application shows aggregate, community-wide brewing activity (for example, how many shots were brewed in the past hour, which countries are most active, and the community's average Brewmeo score).
To feed these statistics, the application sends a single anonymous event when a brew is started. The event contains only:
- a timestamp;
- a country code taken from the device's region settings;
- the device's current Brewmeo score — a number between 0 and 100 that the application computes on the device from your own brewing activity.
The event contains no account, device or user identifier of any kind, and it cannot be linked to you or to your brewing content.
These events are stored solely as aggregates: per-minute activity counters, which are deleted automatically within hours, and daily score totals used for the community average, which are deleted automatically after about 35 days.
Because this data is anonymous, it is not personal data under the GDPR; we describe it here for transparency. The community numbers displayed in the application are presented for engagement and may be smoothed or estimated when actual activity is low.
12. Diagnostic Logs and Feedback
The application keeps a technical log on your device to help diagnose problems. It contains information such as the device model, operating system and application version, timestamps and technical events (for example Bluetooth connections, synchronization steps and errors). If you are signed in, technical messages in the log may include your account identifier.
The log stays on your device. It is sent to us only when you use the "Send feedback" function, which attaches the log to an email that you send from your own mail application. We use logs received this way solely to investigate the issue you report, and we keep them only as long as needed for that purpose. Logs are never combined with the usage analytics described in Section 10.
Legal basis: your request to receive support — Article 6(1)(b) GDPR.
13. International Data Transfers
Our systems are configured to store user data within the European Union whenever possible.
Some service providers may nevertheless process information outside the European Economic Area.
Where international transfers occur, we ensure that appropriate safeguards are implemented, including:
- European Commission adequacy decisions;
- Standard Contractual Clauses;
- other legally recognised transfer mechanisms.
14. Data Retention
Personal data is retained only for as long as necessary.
Account information and synchronized brewing content are retained while the account remains active.
When a user deletes a brewing profile, the brewing content is deleted from active systems.
To ensure reliable synchronization of deletions across multiple devices, a limited technical deletion marker may be retained for up to twelve months.
This deletion marker contains no brewing measurements or brewing content.
Anonymous community statistics are retained as described in Section 11. Diagnostic logs you send us are retained as described in Section 12.
Upon account deletion, account information, synchronized brewing content, the profile picture, Coffee Pulse posts and likes are permanently removed within a reasonable period, subject to legal retention obligations and backup cycles.
15. Security
We implement appropriate technical and organisational measures to protect personal data.
Such measures include:
- encryption of data in transit;
- access controls;
- authentication mechanisms;
- cloud security controls;
- logging and monitoring;
- application integrity verification.
Although we strive to maintain high security standards, no system can be guaranteed to be completely secure.
16. Children
The Service is not directed at children. You must be at least 16 years old — or older, if the age of digital consent in your country is higher — to create an account or to use the community features.
We do not knowingly collect personal data from children below that age. If you believe that a child has provided us with personal data, please contact us at hello@brewmeo.com and we will delete it.
17. Your Rights
Subject to applicable law, users may have the right to:
- obtain access to personal data;
- request correction of inaccurate data;
- request deletion of personal data;
- request restriction of processing;
- object to processing;
- receive data in a portable format;
- withdraw consent where processing is based on consent.
You can delete your account, together with the data described in Section 14, directly in the application (Profile → Account → Delete account). Instructions, including how to request deletion without the application, are available at app.brewmeo.com/delete-account.html.
Other requests may be submitted to:
hello@brewmeo.com
We will respond in accordance with applicable legal requirements.
18. Complaints and Legal Remedies
If you believe your personal data has been processed unlawfully, you have the right to lodge a complaint with a supervisory authority.
In Hungary, the competent authority is:
National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9-11
Hungary
https://www.naih.hu
You also have the right to seek judicial remedies before the competent courts.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical or operational developments.
Material changes will be communicated through the Service or by email where appropriate.
The latest version of this Privacy Policy will always be available through the Service.
20. Contact
Privacy-related questions:
hello@brewmeo.com
General support:
hello@brewmeo.com
Pressensor Kft.
1022 Budapest, Rókushegyi lépcső 5. 2. em. 5.
Hungary