1. Introduction
Frog Breakfast ("we," "us," or "our") operates the Frog Breakfast web application at frogbreakfast.com. This Privacy Policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have over it.
By using our Service you agree to the practices described in this policy. If you have questions, email us at privacy@frogbreakfast.com.
2. Who Is Responsible for Your Data
Frog Breakfast is the data controller for the personal data you provide through our Service.
3. What We Collect
Account information
When you sign up we collect your email address and, optionally, a display name. We assign you a unique account ID. These are necessary to provide the service.
Task and productivity data
Everything you create in the app — tasks, categories, tags, notes, time tracking sessions, scheduling decisions, and reflections — is stored in your account and is yours.
Usage analytics
We collect anonymised usage events — things like which features you use, page navigation, and session activity — to understand how the app is used and improve it. These events are stored for 90 days. If you have opted in to analytics cookies, Google Analytics may also receive page view data (see our Cookie Policy).
AI interaction data
When you use AI features (such as voice-to-task), your input is processed by our AI service to generate a response. A log of these interactions is kept for 90 days to enable conversation context within a session. Audio is converted to text in your browser and only the text is sent to our servers — we do not store raw audio.
Technical and device data
Our servers automatically receive standard technical data when you use the Service: your IP address, browser type, device type, and request metadata. This is used for security, diagnostics, and monitoring. Server logs are retained for up to 30 days.
Browser storage
We use your browser's local storage to keep you logged in, remember your preferences (such as theme), and queue actions you take offline so they sync when you reconnect. We do not use traditional tracking cookies for these purposes. See our Cookie Policy for full details.
4. How We Use Your Data
To provide the Service
Storing and syncing your tasks, running the AI features you use, and keeping your account secure.
To improve the Service
Understanding which features are useful, identifying bugs, and training our recommendation models using anonymised, aggregated data.
To communicate with you
Sending product reminders and notifications you have opted into, and responding to support requests. You can unsubscribe from non-essential emails at any time.
To meet legal obligations
Complying with applicable laws and regulations and responding to valid legal requests.
5. Legal Basis for Processing (GDPR)
Where GDPR applies, we rely on the following legal bases:
- Contract — providing the core task management and productivity features you signed up for.
- Legitimate interest — security, fraud prevention, service analytics, and improving the product experience.
- Consent — optional analytics cookies and any processing you specifically opt into (e.g. AI personalisation features). You can withdraw consent at any time.
- Legal obligation — where we are required to process data by law.
6. Third-Party Services
We use the following third-party services to operate Frog Breakfast. Each is bound by its own privacy policy and, where applicable, a data processing agreement with us.
Amazon Web Services (AWS)
Our primary cloud infrastructure provider. We use AWS for authentication (Cognito), database storage (DynamoDB), AI processing (Bedrock), API hosting, email delivery (SES), and monitoring (CloudWatch). Data is stored in the US East (us-east-1) region. AWS is bound by the AWS Data Processing Addendum.
Stripe
Payment processing for paid plans. Stripe handles all payment card data — we never see or store your card details. See Stripe's Privacy Policy.
Google Analytics
Used to understand how the app is used (page views, feature interactions). Google Analytics only receives data if you opt in to analytics cookies. See Google's Privacy Policy.
Sentry
Error monitoring to help us identify and fix bugs. Sentry may receive technical error data (stack traces, browser info) when an unexpected error occurs. We do not intentionally send personal task content to Sentry. See Sentry's Privacy Policy.
We do not sell your personal data to any third party, and we do not share it with advertisers or data brokers.
7. How Long We Keep Your Data
- Account and task data — kept until you delete your account.
- Usage analytics events — deleted automatically after 90 days.
- AI interaction logs — deleted automatically after 90 days.
- Scheduling and behavioural event logs — deleted automatically after approximately 12 months.
- Server logs — retained for up to 30 days, then deleted.
- Payment records — retained as required by applicable financial regulations.
When you delete your account, your account information and task data are removed from our active systems. Automatic deletion of expiring data (analytics, AI logs) continues on its normal schedule.
8. Your Rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
Access
Request a copy of the personal data we hold about you.
Correction
Ask us to correct inaccurate data, or update it yourself in the app.
Deletion
Delete your account and associated data at any time via Settings. We will process the deletion promptly.
Portability
Export your task data in JSON format using the export feature in Settings.
Withdraw consent
Change your cookie preferences or opt-out of analytics at any time in Settings → Privacy.
Object or restrict processing
Contact us at privacy@frogbreakfast.com to object to or request restriction of specific processing.
Lodge a complaint
If you are in the EU or UK and believe we have handled your data unlawfully, you have the right to complain to your local data protection authority.
To exercise your rights, contact us at privacy@frogbreakfast.com or use Settings → Privacy & Data. We will respond within 30 days.
9. Security
We take reasonable technical and organisational measures to protect your data. These include encrypted storage and transit (HTTPS/TLS), secure authentication via AWS Cognito, access controls, and ongoing monitoring. No system is perfectly secure, and we cannot guarantee that data is immune to all threats. In the event of a breach that is likely to affect your rights, we will notify you as required by applicable law.
10. International Data Transfers
Our infrastructure is hosted in the United States (AWS us-east-1). If you access the Service from outside the US, your data will be transferred to and processed in the US. AWS participates in the EU-US Data Privacy Framework and provides a Data Processing Addendum that covers cross-border transfer requirements under GDPR.
11. Children
Frog Breakfast is not intended for children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, please contact us at support@frogbreakfast.com and we will delete the account.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will notify you by email or in-app notice. The date at the top of this page shows when the current version was published.
13. Contact Us
General support
support@frogbreakfast.comPrivacy inquiries
privacy@frogbreakfast.comWe aim to respond to all privacy requests within 30 days.