Privacy policy
Last updated 23 September 2026
Who we are
RG-IT B.V. · Vlotstraat 20, 6417 CB Heerlen, the Netherlands · KvK 51460602 · VAT NL850028954B01 · hello@leanbrew.app
We are the controller for your account and billing data and for our logs. For the content of meetings (topics, votes, notes, actions and the names people enter) the customer who hosts the meeting is the controller and we are the processor, under our data processing agreement. If you joined someone else's meeting as a guest, please contact that organisation about the meeting content.
What we process, why, and for how long
| Data | Purpose & legal basis | Kept for |
|---|---|---|
| Name, email, securely hashed password (or your Google identity) | Providing your account — contract | While your account exists, plus 30 days |
| Email verification and password-reset messages | Securing your account — contract | Links expire within 1 hour to 3 days |
| Stripe customer and subscription references, plan status, invoices | Billing — contract and legal obligation | 7 years (Dutch tax law) |
| Technical logs (e.g. IP address, time, request) | Security and keeping the service running — legitimate interest | Up to 30 days |
| Meeting content | Providing the service on the host's instructions | Until the host deletes it or ends their account |
We don't sell data, don't use it for advertising, and don't make automated decisions about you.
Who helps us (sub-processors)
- Google Cloud — hosting (Cloud Run, region europe-west4, the Netherlands)
- MongoDB Atlas — database
- Resend — sending account emails
- Stripe — payments. Stripe also acts as an independent controller for payment processing and fraud prevention; see Stripe's privacy policy.
- Slack — only if a host connects it, and on the host's instruction
Some of these companies have a parent company in the United States. Where data may be transferred outside the EU, this happens under the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
Cookies
We only use cookies that are needed for the app to work, so we don't ask for consent. We don't use analytics, advertising or tracking cookies.
| Name | Purpose | Lifetime |
|---|---|---|
| next-auth.session-token | Keeps you signed in | 30 days |
| next-auth.csrf-token, next-auth.callback-url | Protects sign-in against forged requests | Session |
| lc_guest | Recognises you as the same guest in a meeting | 1 year |
| lc-theme, lc-guest (local storage) | Remembers light/dark mode and your guest name | Until you clear it |
When you pay, Stripe's checkout page may set its own cookies needed for the payment and fraud prevention.
Security
Data is encrypted in transit, passwords are stored as salted hashes, access is limited to what's needed to run the service, and our providers are established cloud companies.
Your rights
You can ask us to access, correct, delete, restrict or export your personal data, or object to how we use it, by emailing hello@leanbrew.app. We respond within one month. You can also file a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Version 2026-09-23.