Version 2026-10-01. This is a translation for convenience; the Portuguese version prevails.

1. Who we are and how to reach us

Cafeverso is operated by Vitor Loura, under the brand Code Brew (code-brew.io), who is the controller of your personal data under art. 5, VI of Brazilian Law 13.709/2018 (LGPD). Contact for privacy matters: support@code-brew.io. That address is where you exercise the rights described in section 7 and ask anything about this policy.

As a small-scale processing agent (ANPD Resolution 2/2022) we are not required to appoint a formal data protection officer (art. 41), but we publish the contact channel above, which serves the same purpose for you. This policy exists to give you easy, clear access to information about the processing, as art. 9 requires.

Cafeverso is an application for recording coffees, waters, gear, recipes and brew results, and for sharing that material in communities. This policy explains, in plain language, what data the application collects, why it collects it, who it is shared with, and what you can do about it.

2. What data we collect

Account data. Your email address, your name, your country and your time zone. Signing in works through a six-digit code emailed to you; if you choose to set a password, we keep only its hash, never the password in clear text. If you sign in with Google, we receive your Google account identifier, your name and your profile picture.

Optional profile data. Phone number, region and city, a profile photo, the language you prefer for our emails, and the units you prefer for weights and temperatures. None of it is required to use the application: these are fields you fill in if you want to, and can clear whenever you want. Switching the site's language also saves that choice as your email language.

Content you create. Coffees, waters, gear (grinders and brewers), recipes and their versions, brew results, and the communities you own or belong to, including invites you generate or accept.

Technical data. IP address, browser identification and the date and time of requests, recorded automatically in the hosting logs, and the same information when you send us a problem report from inside the application.

Usage data. To know how many people use the application and which pages they visit, we count page views with Vercel Web Analytics. It records the page visited, the referring page, the country, the device and browser type, and a visitor identifier derived (hashed) from your IP address and browser, which changes every day and cannot identify you or follow you across other sites. It writes no cookies and reads no localStorage.

3. Why we use it and on what legal basis

We do not use your data for advertising, we do not profile you, and we make no automated decisions about you.

We keep a record of the processing operations we carry out, as art. 37 requires, and process only the data each of the purposes above needs.

4. Who we share it with

Other users. What you mark as public is visible to anyone who opens the application. What you share into a community is visible to that community's members. Shared recipes can be forked by other users: a fork belongs to whoever forked it and keeps existing even if you delete the original recipe.

Processors (art. 39). We use companies that process data on our behalf and on our instructions: Vercel (hosting, logs and page-view counting), Neon (database), an S3-compatible object store (photos), an SMTP provider (sign-in codes and invitation emails) and Google, only when you choose to sign in with Google.

We do not sell your personal data and do not share it with data brokers.

5. International transfer

The processors listed above host their infrastructure in the United States, so your data is transferred outside Brazil. That transfer relies on art. 33 of the LGPD, through contractual clauses agreed with each processor that guarantee compliance with the principles and rights set out in the law.

6. How long we keep it

We keep your data for as long as your account exists. When you delete your account, we remove your registration, your profile, your content and your community memberships. There is one deliberate exception: recipes other users forked from yours stay with them, because a fork is an independent copy taken at the moment of forking. The processors' server logs expire on each operator's own retention schedule.

7. Your rights

Art. 18 of the LGPD guarantees that you may request, at any time: confirmation that we process your data; access to the data; correction of incomplete, inaccurate or out-of-date data; anonymization, blocking or deletion of data that is unnecessary, excessive or processed unlawfully; portability to another provider; deletion of data processed on the basis of your consent; information about who we share your data with; information about your option not to consent and the consequences of refusing; and withdrawal of consent.

Two of these rights you exercise yourself, immediately, inside your Profile: export of everything we hold about you in a machine-readable format, and deletion of the account. If you own a community that other people belong to, delete it or hand it over first; the application tells you which. Every other request goes by email to support@code-brew.io and is answered within 15 days (art. 19, II). You may also complain to the Brazilian data protection authority (ANPD), under art. 18, § 1.

8. Cookies and local storage

We use strictly necessary cookies only: the session token, which keeps you signed in; the cookie that binds the sign-in code to the browser that requested it; the invite token, which preserves an invitation while you sign in; the terms acceptance cookie, which carries your ticked checkbox through sign-in for up to 30 minutes; and your chosen language. Your theme preference (light or dark) and your view preference (list or grid) live in your browser's localStorage and never reach the server.

We use no analytics and no advertising cookies, and there are no third-party trackers. The page-view counting described in section 2 uses neither cookies nor persistent identifiers. That is why there is no cookie consent banner: there is nothing non-essential for you to accept or refuse. If that changes, the banner appears before any new cookie is written.

9. Security

All traffic runs over TLS. Passwords, where they exist, are stored only as hashes. The sign-in codes sent by email are single-use, expire within a few minutes and are discarded after a small number of wrong attempts. Administrative access to the database is limited to the operator. If a security incident occurs with relevant risk to your rights, we will notify you and the ANPD, as art. 48 requires.

10. Children and teenagers

Cafeverso is intended for people 18 or older. We do not knowingly collect data from children or teenagers (art. 14). If we identify an account belonging to someone under 18, it is removed together with the associated data. If you are a guardian and believe this has happened, write to support@code-brew.io.

11. Changes to this policy

This policy carries a version, printed at the top of this page. Material changes produce a new version and we ask you to accept the new text the next time you open the application. Wording fixes that do not change the meaning do not change the version. Previous versions of this text are available on request via the contact channel: support@code-brew.io.

This English text is provided for convenience. In case of any divergence, the Portuguese version prevails.