ShotPulled
Home

Privacy Policy

Last Updated: September 3, 2026

1. Who runs ShotPulled

ShotPulled is operated by Bacosca Iulian PFA (the "Controller"), a sole trader (persoană fizică autorizată) established in Romania (EU):

  • Trade Register no.: F40/4818/2022
  • Sole registration code (CUI): 46937352
  • Registered office: Str. Ion Câmpineanu nr. 24, Sector 1, Municipiul București, Romania
  • Contact: privacy [at] shotpulled [dot] com

The service is hosted on servers located in the European Union (Hetzner Cloud, Germany). This policy describes what data the service handles, why, where it goes, and how you can exercise your rights under the GDPR and equivalent regimes.

2. What data we process

  • Account identity: the sub claim from your identity provider, your verified email, and your display name. Used to identify you across sessions and to keep your data isolated from other accounts.
  • Coffee inventory: bag name, roaster, roast level, roast date, process, origin, notes, sealed/opened state, bag weight, cost. You enter this; it is private to your account.
  • Shot logs: dose, yield, extraction time, sensory tags (bitter / sour / channeling / …), drink intent, optional notes, optional flow/pressure profiles.
  • Equipment: grinder name and setting, machine name and program, optional water recipe.
  • Operational metadata: authentication timestamps, request paths, and HTTP status codes (used for security monitoring and rate limiting). We do not log request bodies or query parameters.

Usage statistics. We measure how the marketing site and the dashboard are used with Plausible Analytics (Plausible Insights OÜ, Estonia, EU-hosted). It uses no cookies, stores no personal data, and does not track you across sites; what we see is page views, referrers, and which buttons and outbound links are clicked, aggregated. The script is served from our own domain, so your browser never contacts Plausible directly — our server forwards the request, including your IP address, which Plausible uses only to generate a daily-rotating hash for counting unique visits and does not store. Nothing we send identifies you: no account id, no email, no user id.

We do not use advertising networks, A/B-testing pixels, session replay, or cross-site tracking, and click and open tracking are switched off. Apart from the analytics described above there are no third-party JavaScript trackers on the marketing or dashboard pages. Fonts are self-hosted on our own server, so no external font service (such as Google Fonts) ever receives your IP address.

3. Lawful basis

Processing is necessary to provide the service you sign up for (GDPR Art. 6(1)(b) — contract). Operational logs used to keep the service secure rely on legitimate interests (Art. 6(1)(f)).

4. Sub-processors

We use the following sub-processors to run the service. Each has its own privacy policy and contractual data-protection terms:

  • Clerk, Inc. (US) — identity provider. Receives your email and authentication events. clerk.com/legal/privacy.
  • Hetzner Online GmbH (DE) — server hosting. Stores your data at rest on the database cluster's disks.
  • Cloudflare, Inc. (US/global) — encrypted off-host backup destination via R2 object storage. Backups are restricted to the operator.
  • Plausible Insights OÜ (EE, EU-hosted) — privacy-friendly usage analytics. Receives page views, referrers and click events, plus your IP address from our server for same-day unique-visit hashing; it is not stored and no cookie is set. plausible.io/privacy.
  • Better Stack (Logtail, US) — operational log aggregation. Receives container-level events (timestamp, log level, message). We avoid placing personal data in log messages; if any is captured incidentally it is retained per Better Stack's default 7-day window.

If you connect ShotPulled to an AI client (Claude Desktop, ChatGPT, etc.) via MCP, every request you make from that client goes through that vendor first. Those interactions are governed by the vendor's privacy policy, not this one.

5. Where your data lives

Your primary database is a replicated cluster on Hetzner machines in Germany (EU): every write is committed to a majority of nodes before it is acknowledged, so no single disk holds the only copy. Encrypted backups replicate off-host to Cloudflare R2. Authentication state and the email tied to your account live inside Clerk (US). Operational logs live in Better Stack (US). Where data leaves the EU to US-based sub-processors, it is protected via the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses (SCCs).

6. Retention

Account data is retained for as long as your account is active. Deleting your account erases its rows from the live database immediately. The off-host backup is a single latest snapshot, overwritten hourly, so a deleted account is out of backups within the hour. One archived snapshot predating our July 2026 database migration is kept as a rollback point, is restricted to the operator, and will be destroyed once that migration is no longer reversible. Operational logs are retained for up to 30 days.

7. Cookies and local storage

Authentication uses Clerk's secure, HTTP-only cookies on the apex domain. No advertising or tracking cookies are set, and our analytics is cookieless — Plausible sets nothing on your device and stores nothing in it. The dashboard stores your theme / font / accent / density preferences in your browser's localStorage; this never leaves your device.

8. Your rights

Under the GDPR you have the right to access, correct, delete, export, restrict, or object to processing of your personal data, and to lodge a complaint with a supervisory authority (such as the National Supervisory Authority for Personal Data Processing — ANSPDCP — in Romania, where the Controller is established). To exercise any of these rights, email privacy [at] shotpulled [dot] com from the address tied to your account.

Deletion is self-service. Use Delete account in Settings, on the web dashboard or in the iOS app. It closes your identity with Clerk and erases every row belonging to the account — beans, shots, recipes, equipment — in one transaction. Nothing is kept for review, and the action cannot be undone. See Retention for how quickly that reaches the backups.

A self-service export is not built yet. Until it is, email the Controller and the export is prepared manually within 30 days, as are any access, correction, restriction or objection requests.

9. Security

Traffic is HTTPS-only (HSTS preload). Authentication is OAuth 2.1 (Clerk) — passwords never reach our server. All cross-tenant access is gated by account isolation in the database. We disclose any confirmed personal-data breach to affected users without undue delay.

10. Children

ShotPulled is not directed at people under 16. We do not knowingly process data of children. If you believe a minor has signed up, contact the Controller and the account will be removed.

11. Changes

We will post material changes to this policy on this page with a new Last Updated date. For substantive changes, signed-in users will be notified by email before the change takes effect.