Bufera

Privacy

Privacy policy

Draft · last updated 26 July 2026

Draft, pending legal review. It describes accurately what the software does, but a Bulgarian lawyer should review it before Bufera is sold.

Who is responsible

Bufera is operated by METEME EOOD (ЕИК 207284523), Sofia 1000, Bulgaria. For questions about this policy or about your data, write to hello@bufera.app.

Two different roles

This distinction decides who you should contact about what.

What we hold

DataWhy
Name, email address, profile picture from GoogleTo sign you in and show who wrote what
Workspace membership and roleTo decide what you may see
Content you enter: people, phone numbers, addresses, tasks, events, notes, materials, transactionsIt is the product; we hold it so you can use it
Push subscription for each device where you enable notificationsTo deliver notifications; deleting it stops them

We do not use analytics or tracking cookies, we do not build advertising profiles, and we do not sell data to anyone.

Cookies and what is stored on your device

Bufera uses no cookies. Not on this website, and not in the app. There is no advertising, no profiling, and nothing that follows you to other sites — which is also why you are not being asked to dismiss a consent banner.

Two things are stored, and both are necessary rather than optional:

Neither can be refused without breaking the thing you came for, so neither asks for consent. That is the exception the ePrivacy rules make for strictly necessary storage.

Website statistics

We count visits to this website using Vercel Web Analytics, which is run by the company that already hosts Bufera. It records the page visited, the country it was visited from, the site that linked here, and the kind of device — nothing more.

It does not use cookies and does not store anything on your device. It does not build a profile of you, cannot follow you to other websites, and the data cannot be traced back to an individual. We use it to learn whether anyone is finding Bufera and how, not to learn about you.

Legal basis

Account data and workspace content are processed to perform the contract with the customer (Art. 6(1)(b) GDPR). Where we act as processor, the controller is responsible for having a basis for the contact details they enter.

Who else processes it

These sub-processors are necessary to run the service:

ProviderPurposeLocation
SupabaseDatabase and authenticationEU (Frankfurt)
VercelHosting, and website visit statisticsEU / global edge
ResendSending confirmation and password emailsEU (Ireland)
StripeSubscription payments and invoicesEU (Ireland), with transfers outside the EU under standard contractual clauses
Cloudflare R2Encrypted backupsEU
GoogleSign-in, and notification delivery on AndroidGlobal
AppleNotification delivery on iPhoneGlobal

Card details are entered on Stripe's own pages and never reach Bufera. We are told only that a payment succeeded, and how many seats it covers.

How long we keep it

Content is kept while the workspace exists. Delete something in the app and it is removed from the live database immediately.

Backups are kept for 30 days and then deleted automatically. Deleted data can therefore persist in an encrypted backup for up to 30 days after you remove it — a standard and permitted retention period. Backups are encrypted and stored separately from the live database.

Your rights

Under GDPR you may ask us to:

Write to hello@bufera.app. We respond within one month. If you are unhappy with the outcome you may complain to the Bulgarian Commission for Personal Data Protection (КЗЛД).

Security

Every workspace is isolated at the database level, so one customer's data is unreadable to another — enforced by the database itself rather than by application code, and tested automatically on every change. Traffic is encrypted in transit, backups are encrypted at rest, and we hold no passwords: sign-in goes through Google.

Breaches

If a breach is likely to put people at risk we notify the Bulgarian supervisory authority within 72 hours of becoming aware of it, and tell affected people directly where the risk to them is high.

Changes

Material changes will be announced in the app before they take effect. The date at the top of this page shows the current version.