Privacy
Privacy policy
Draft · last updated 26 July 2026
Draft, pending legal review. It describes accurately what the software does, but a Bulgarian lawyer should review it before Bufera is sold.
Who is responsible
Bufera is operated by METEME EOOD (ЕИК 207284523), Sofia 1000, Bulgaria. For questions about this policy or about your data, write to hello@bufera.app.
Two different roles
This distinction decides who you should contact about what.
- For your account — your name, email and sign-in — we are the controller. Contact us directly.
- For the content inside a workspace — the contacts, clients, phone numbers, notes and appointments a customer puts into Bufera — we are only the processor. The business operating that workspace is the controller. If you are one of their contacts and want your details removed, ask them; we act on their instruction.
What we hold
| Data | Why |
|---|---|
| Name, email address, profile picture from Google | To sign you in and show who wrote what |
| Workspace membership and role | To decide what you may see |
| Content you enter: people, phone numbers, addresses, tasks, events, notes, materials, transactions | It is the product; we hold it so you can use it |
| Push subscription for each device where you enable notifications | To deliver notifications; deleting it stops them |
We do not use analytics or tracking cookies, we do not build advertising profiles, and we do not sell data to anyone.
Cookies and what is stored on your device
Bufera uses no cookies. Not on this website, and not in the app. There is no advertising, no profiling, and nothing that follows you to other sites — which is also why you are not being asked to dismiss a consent banner.
Two things are stored, and both are necessary rather than optional:
- Your sign-in session, kept in your browser's local storage while you are signed in to the app, so you are not asked to sign in again on every page. Signing out removes it.
- An offline copy of the app, so it opens quickly and keeps working on a poor connection. Removing Bufera from your home screen removes it.
Neither can be refused without breaking the thing you came for, so neither asks for consent. That is the exception the ePrivacy rules make for strictly necessary storage.
Website statistics
We count visits to this website using Vercel Web Analytics, which is run by the company that already hosts Bufera. It records the page visited, the country it was visited from, the site that linked here, and the kind of device — nothing more.
It does not use cookies and does not store anything on your device. It does not build a profile of you, cannot follow you to other websites, and the data cannot be traced back to an individual. We use it to learn whether anyone is finding Bufera and how, not to learn about you.
Legal basis
Account data and workspace content are processed to perform the contract with the customer (Art. 6(1)(b) GDPR). Where we act as processor, the controller is responsible for having a basis for the contact details they enter.
Who else processes it
These sub-processors are necessary to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU (Frankfurt) |
| Vercel | Hosting, and website visit statistics | EU / global edge |
| Resend | Sending confirmation and password emails | EU (Ireland) |
| Stripe | Subscription payments and invoices | EU (Ireland), with transfers outside the EU under standard contractual clauses |
| Cloudflare R2 | Encrypted backups | EU |
| Sign-in, and notification delivery on Android | Global | |
| Apple | Notification delivery on iPhone | Global |
Card details are entered on Stripe's own pages and never reach Bufera. We are told only that a payment succeeded, and how many seats it covers.
How long we keep it
Content is kept while the workspace exists. Delete something in the app and it is removed from the live database immediately.
Backups are kept for 30 days and then deleted automatically. Deleted data can therefore persist in an encrypted backup for up to 30 days after you remove it — a standard and permitted retention period. Backups are encrypted and stored separately from the live database.
Your rights
Under GDPR you may ask us to:
- give you a copy of the data we hold about you
- correct anything inaccurate
- delete it
- export it in a portable format
- restrict or object to how it is processed
Write to hello@bufera.app. We respond within one month. If you are unhappy with the outcome you may complain to the Bulgarian Commission for Personal Data Protection (КЗЛД).
Security
Every workspace is isolated at the database level, so one customer's data is unreadable to another — enforced by the database itself rather than by application code, and tested automatically on every change. Traffic is encrypted in transit, backups are encrypted at rest, and we hold no passwords: sign-in goes through Google.
Breaches
If a breach is likely to put people at risk we notify the Bulgarian supervisory authority within 72 hours of becoming aware of it, and tell affected people directly where the risk to them is high.
Changes
Material changes will be announced in the app before they take effect. The date at the top of this page shows the current version.