This policy reflects our current beta. It will be finalized with legal review before Berth's full public launch.

Privacy Policy

Last updated: 18 August 2026

This Privacy Policy explains how Alexandros Chiotis (operating as an individual — Berth has not yet incorporated a formal business entity) ("we", "us", "Berth") collects, uses, and protects your personal data when you use Berth. We are committed to data minimization: we only collect what the Service actually needs to function.

1. Data We Collect

  • Account data: email address, password (hashed — we never see or store your plain-text password).
  • Onboarding data: your stage, what you're building, and time zone, used solely for matching you into a group.
  • Activity data: the weekly commitments and reports you post, visible to your group members.
  • Technical data: basic usage/error data via our error-monitoring tool (Sentry), used only to fix bugs — not for advertising or profiling.
  • Payment data (future, optional feature): if a paid stake feature launches, payment details are handled entirely by Stripe. Berth never sees or stores your card details.

We do not collect data we don't have a clear, current use for. If a data point isn't tied to a working feature, we don't ask for it.

2. Legal Basis for Processing (GDPR)

  • Performance of a contract — processing your account and onboarding data is necessary to provide the matching and group functionality you signed up for.
  • Legitimate interest — technical/error data, to keep the Service running reliably.
  • Consent — for any optional communications (e.g., product updates) beyond the core weekly reminder emails.

3. How We Use Your Data

  • To match you into a group and run the weekly commitment/report rhythm.
  • To send you Monday/Friday reminder emails (via Resend).
  • To respond to support requests and review reports made through the in-app report button.
  • To maintain and improve the Service (error tracking, security monitoring).

We do not sell your data. We do not use your data for third-party advertising.

4. Who We Share Data With

We use the following processors to operate Berth. Each only receives the data it needs to perform its function:

ProcessorPurposeData Involved
SupabaseDatabase, authentication, hostingAccount data, activity data
VercelApplication hostingTechnical/usage data
ResendSending reminder and account emailsEmail address
SentryError trackingTechnical/error data
UpstashRate limiting / abuse preventionTechnical data (no personal content)
Stripe (future)Payment processing, if the optional stake feature launchesPayment data only

We do not share your data with any other third party except where required by law.

5. Data Retention

  • We retain your account and activity data for as long as your account is active.
  • If you delete your account, we delete your profile, group membership, commitments, and reports within 30 days, except where we are legally required to retain certain records longer.

6. Your Rights (GDPR)

If you are located in the EU/EEA (or another jurisdiction with similar protections), you have the right to:

  • Access — request a copy of the data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your account and data ("right to be forgotten").
  • Data portability — receive your data in a portable format.
  • Object / restrict processing — in certain circumstances.

To exercise any of these rights, contact us at alexchiotis20052@gmail.com. We will respond within the timeframe required by applicable law (typically 30 days under GDPR).

7. International Data Transfers

Our processors (Supabase, Vercel, Resend, Sentry, Upstash, Stripe) may store or process data outside your country, including in the United States. Where this applies, we rely on their respective data protection safeguards (such as Standard Contractual Clauses).

8. Cookies

Berth uses only the minimum cookies required for authentication (session cookies, httpOnly and Secure). We do not use tracking or advertising cookies. If analytics are added later, this section will be updated and users will be notified.

9. Children's Privacy

Berth is not intended for anyone under 18. We do not knowingly collect data from minors.

10. Changes to This Policy

We will notify users of material changes to this Privacy Policy via email or in-app notice before they take effect.

11. Contact

Questions about this Privacy Policy, or to exercise your data rights: alexchiotis20052@gmail.com