Privacy Policy

Last updated: April 2026

1. Introduction

Frog Breakfast ("we," "us," or "our") operates the Frog Breakfast web application at frogbreakfast.com. This Privacy Policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have over it.

By using our Service you agree to the practices described in this policy. If you have questions, email us at privacy@frogbreakfast.com.

2. Who Is Responsible for Your Data

Frog Breakfast is the data controller for the personal data you provide through our Service.

Frog Breakfast

General: support@frogbreakfast.com

Privacy inquiries: privacy@frogbreakfast.com

3. What We Collect

Account information

When you sign up we collect your email address and, optionally, a display name. We assign you a unique account ID. These are necessary to provide the service.

Task and productivity data

Everything you create in the app — tasks, categories, tags, notes, time tracking sessions, scheduling decisions, and reflections — is stored in your account and is yours.

Usage analytics

We collect anonymised usage events — things like which features you use, page navigation, and session activity — to understand how the app is used and improve it. These events are stored for 90 days. If you have opted in to analytics cookies, Google Analytics may also receive page view data (see our Cookie Policy).

AI interaction data

When you use AI features (such as voice-to-task), your input is processed by our AI service to generate a response. A log of these interactions is kept for 90 days to enable conversation context within a session. Audio is converted to text in your browser and only the text is sent to our servers — we do not store raw audio.

Technical and device data

Our servers automatically receive standard technical data when you use the Service: your IP address, browser type, device type, and request metadata. This is used for security, diagnostics, and monitoring. Server logs are retained for up to 30 days.

Browser storage

We use your browser's local storage to keep you logged in, remember your preferences (such as theme), and queue actions you take offline so they sync when you reconnect. We do not use traditional tracking cookies for these purposes. See our Cookie Policy for full details.

4. How We Use Your Data

To provide the Service

Storing and syncing your tasks, running the AI features you use, and keeping your account secure.

To improve the Service

Understanding which features are useful, identifying bugs, and training our recommendation models using anonymised, aggregated data.

To communicate with you

Sending product reminders and notifications you have opted into, and responding to support requests. You can unsubscribe from non-essential emails at any time.

To meet legal obligations

Complying with applicable laws and regulations and responding to valid legal requests.

5. Legal Basis for Processing (GDPR)

Where GDPR applies, we rely on the following legal bases:

  • Contract — providing the core task management and productivity features you signed up for.
  • Legitimate interest — security, fraud prevention, service analytics, and improving the product experience.
  • Consent — optional analytics cookies and any processing you specifically opt into (e.g. AI personalisation features). You can withdraw consent at any time.
  • Legal obligation — where we are required to process data by law.

6. Third-Party Services

We use the following third-party services to operate Frog Breakfast. Each is bound by its own privacy policy and, where applicable, a data processing agreement with us.

Amazon Web Services (AWS)

Our primary cloud infrastructure provider. We use AWS for authentication (Cognito), database storage (DynamoDB), AI processing (Bedrock), API hosting, email delivery (SES), and monitoring (CloudWatch). Data is stored in the US East (us-east-1) region. AWS is bound by the AWS Data Processing Addendum.

Stripe

Payment processing for paid plans. Stripe handles all payment card data — we never see or store your card details. See Stripe's Privacy Policy.

Google Analytics

Used to understand how the app is used (page views, feature interactions). Google Analytics only receives data if you opt in to analytics cookies. See Google's Privacy Policy.

Sentry

Error monitoring to help us identify and fix bugs. Sentry may receive technical error data (stack traces, browser info) when an unexpected error occurs. We do not intentionally send personal task content to Sentry. See Sentry's Privacy Policy.

We do not sell your personal data to any third party, and we do not share it with advertisers or data brokers.

7. How Long We Keep Your Data

  • Account and task data — kept until you delete your account.
  • Usage analytics events — deleted automatically after 90 days.
  • AI interaction logs — deleted automatically after 90 days.
  • Scheduling and behavioural event logs — deleted automatically after approximately 12 months.
  • Server logs — retained for up to 30 days, then deleted.
  • Payment records — retained as required by applicable financial regulations.

When you delete your account, your account information and task data are removed from our active systems. Automatic deletion of expiring data (analytics, AI logs) continues on its normal schedule.

8. Your Rights

Depending on where you live, you may have some or all of the following rights regarding your personal data:

Access

Request a copy of the personal data we hold about you.

Correction

Ask us to correct inaccurate data, or update it yourself in the app.

Deletion

Delete your account and associated data at any time via Settings. We will process the deletion promptly.

Portability

Export your task data in JSON format using the export feature in Settings.

Withdraw consent

Change your cookie preferences or opt-out of analytics at any time in Settings → Privacy.

Object or restrict processing

Contact us at privacy@frogbreakfast.com to object to or request restriction of specific processing.

Lodge a complaint

If you are in the EU or UK and believe we have handled your data unlawfully, you have the right to complain to your local data protection authority.

To exercise your rights, contact us at privacy@frogbreakfast.com or use Settings → Privacy & Data. We will respond within 30 days.

9. Security

We take reasonable technical and organisational measures to protect your data. These include encrypted storage and transit (HTTPS/TLS), secure authentication via AWS Cognito, access controls, and ongoing monitoring. No system is perfectly secure, and we cannot guarantee that data is immune to all threats. In the event of a breach that is likely to affect your rights, we will notify you as required by applicable law.

10. International Data Transfers

Our infrastructure is hosted in the United States (AWS us-east-1). If you access the Service from outside the US, your data will be transferred to and processed in the US. AWS participates in the EU-US Data Privacy Framework and provides a Data Processing Addendum that covers cross-border transfer requirements under GDPR.

11. Children

Frog Breakfast is not intended for children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, please contact us at support@frogbreakfast.com and we will delete the account.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will notify you by email or in-app notice. The date at the top of this page shows when the current version was published.

13. Contact Us

Privacy inquiries

privacy@frogbreakfast.com

We aim to respond to all privacy requests within 30 days.