Privacy Policy
Last updated: 5 October 2026
Barberry Garden (barberry.io) is a wine-writing project run by Boris Buliga, registered as a sole proprietor in Ukraine. Most of the site is free to read; it also offers paid memberships and a personal balance. This policy explains what data is collected and how it is used. The short version: we collect little, we don't sell it, and we don't share it with advertisers.
What we collect
Account data
If you create an account, we store your email address and a hashed password. Your account may be linked to a convive profile (public name, avatar) that you provide. This data is stored in our Supabase database and is used solely for authentication and site functionality.
Events and community gatherings
When you sign up for an event or community gathering, we store your registration status (confirmed, waitlisted) and any related event data, such as settlement balances. This information is only visible to you and site administrators.
Payments and balance
If you take a paid membership or top up your balance, the payment is processed by Monobank acquiring. We never see or store your full card number; the processor handles card data on its own secure systems and returns only the result. We keep a record of each transaction (amount, date, the tier or top-up, and its status) tied to your account so your subscription and balance ledger stay accurate.
Cookies and browser storage
We use essential cookies only. If you sign in, Supabase Auth sets session cookies to keep you logged in. These are strictly necessary for authentication and cannot be used to track you across other websites. We do not use any advertising or marketing cookies.
The site also keeps a few things in your browser for your own convenience, such as tasting notes you haven't submitted yet during a live event, or a photo on its way into a form. They stay on your device and aren't used to track you. If you turn off PostHog page analytics (below), that choice is kept there too.
Analytics
When you are signed in, we record how the platform is used: the action (for example, that a draft was published or that you signed up for an event), the kind of page it happened on (a wine page, never which wine), the app you used, and your membership tier. Each event carries a random member id, never your name or email, and never what you write or what is in your cellar. Events go from our servers to PostHog in the EU, are visible only to admins, and PostHog keeps them for a year. You can turn this off at any time in your account settings, under Share usage statistics.
If you are not signed in, we count page views with PostHog in cookieless mode: nothing is stored in your browser, and visits are told apart by a hash of your IP address and browser that changes every day, so the same visitor looks new each day. The IP address itself isn't kept. We record the kind of page, how quickly it loaded and responded, how long you stayed, the site that linked you here, and your browser, system, device type, language and time zone, never the full address, and nothing that identifies you.
We also use Vercel Analytics and Vercel Speed Insights to understand how the site performs. These services collect anonymised, aggregated data (page views, web vitals) without setting cookies or collecting personal information.
Third-party services
- Supabase: database and authentication. Your account data is stored on Supabase infrastructure.
- Vercel: hosting, image storage (Vercel Blob), and the page analytics described above.
- Amazon Web Services: our API server runs on AWS in Stockholm, so requests from the site and apps pass through it. Account emails, such as sign-up confirmations and password resets, are sent with Amazon SES.
- PostHog: usage analytics, as described above. Data is stored in the EU (Frankfurt, Germany). PostHog is a US company and may access it from the US; such transfers are covered by the EU-US Data Privacy Framework and standard contractual clauses.
- Anthropic: if you use the AI tools (identifying or adding a wine from label photos, or reading a receipt), the photos you submit are sent to Anthropic to be read. Anthropic doesn't train its models on them and deletes them within 30 days, unless they are flagged for abuse or the law requires longer. Data is stored in the US and may be processed elsewhere; transfers are covered by standard contractual clauses.
- GitHub: hosts our code, and keeps encrypted backups of our database for seven days.
- Telegram: if you link our Telegram bot, your Telegram user ID is stored for notification delivery. Admins receive notifications via Telegram too, such as a new sign-up (with the member's name, email, and sign-up note) or an error report (with the member's name, the page, and the device).
- Monobank: payment processing (acquiring) for memberships and balance top-ups. Card details are entered on Monobank's own secure systems; we receive only the result of a transaction, never your card number.
Data retention and deletion
Account data is retained for as long as your account exists. If you ask us to delete your account, we remove or anonymise the personal data that identifies you, such as your email, name, avatar, and messenger identifiers, and we delete your usage events from PostHog. Notes, ratings, and catalogue entries you contributed may be kept in anonymised form, detached from your identity, because they are woven into shared event reports and aggregate scores. Encrypted database backups roll over within seven days. To request deletion, contact boris@barberry.io.
Your rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account (see how deletion works above)
- Receive a copy of your data in a portable format
To exercise any of these rights, email boris@barberry.io.
Jurisdiction and terms
Barberry Garden operates under the laws of Ukraine. The terms that govern memberships, the balance, and use of the platform are set out in the public offer.
Changes
This policy may be updated occasionally. Significant changes will be noted on this page with an updated date.
Contact
Questions about this policy? Email boris@barberry.io.