Privacy Policy
Last updated: [[EFFECTIVE DATE]]
This Privacy Policy explains how Rascals (“Rascals”, “we”, “us”) collects and uses personal data when you use Stuart, our household- and organisation-management app at stuart.rascals.be (the “Service”).
We are the data controller for the personal data described here. We are based in Belgium and process personal data in line with the EU General Data Protection Regulation (GDPR) and Belgian data-protection law.
Contact: Rascals, Kastanjestraat 21, 8800 Roeselare, Belgium, VAT BE 0792.738.042. Privacy questions: info@rascals.be. No data protection officer is appointed; write to the address above.
1. Who this policy covers
This policy covers people who create a Stuart account and people who are invited into a shared space (an “Entity” — a personal, family, or organisation workspace). If your organisation invited you, that organisation may also have its own privacy terms.
2. What we collect
a. Account data. Your name, email address, and a securely hashed password. If you sign in with Google, we receive your Google account’s name and email.
b. Entity & content data. The information you put into Stuart within an Entity — recipes, inventory items, stock movements, locations, meal plans, suppliers, purchases and uploaded receipts, and similar records. This content is shared with the other members of that Entity according to their role (including a read-only “child” role).
c. Invitations. Email addresses you enter to invite people to an Entity.
d. Billing data. If you subscribe, our payment processor Stripe handles your card details. We do not store full card numbers; we keep a customer/subscription reference, plan, status, and billing history.
e. Integration data (optional, only if you enable it):
- Claude / Anthropic: an API key you provide (stored encrypted). When you use the recipe or receipt importer, the linked web page or receipt image is sent to Anthropic for processing, billed to your own key.
- Google Calendar: if you connect it, we store OAuth tokens (encrypted) and sync meal-plan entries to/from your Google Calendar.
f. Technical data. Standard server logs and cookies needed to run the Service (session, security/CSRF, language preference, “remember me”). See §8.
g. Feedback (test environments only). If a feedback widget is enabled, a submission includes your message, the page URL, your browser’s console log, and an optional screenshot you choose to attach. We do not store the sender’s IP address.
We do not intentionally collect special-category data (health, etc.). Please don’t put such data into free-text fields unless you accept it is processed as ordinary content. [[Revisit this if the roadmap adds health/finance features.]]
3. Why we use it, and our legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Create and run your account and Entities; provide the core features | Performance of a contract (Art. 6(1)(b)) |
| Process subscriptions and payments | Contract; legal obligation (accounting) |
| Send service emails (verification, invitations, billing/price-change notices) | Contract; legitimate interests |
| Optional integrations (Claude, Google Calendar) | Your consent (Art. 6(1)(a)), which you can withdraw |
| Keep the Service secure, prevent abuse, debug | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal/tax obligations | Legal obligation (Art. 6(1)(c)) |
We do not sell your personal data and do not use it for third-party advertising.
4. Who we share it with (sub-processors)
We share personal data only with providers that help us run the Service, under appropriate data-processing agreements:
- DigitalOcean — hosting and database storage (European Union).
- Stripe — payment processing.
- Postmark — sending transactional email.
- Anthropic — only when you use a Claude-powered feature.
- OpenAI — only when you record a spoken note in the feedback widget; the audio is transcribed and not stored.
- Google — only when you connect Google Calendar.
- Bunny Fonts (fonts.bunny.net) — serving web fonts (a GDPR-oriented, no-logging font CDN).
We may also disclose data if required by law, or to protect our rights and users.
5. International transfers
Some providers (e.g. Stripe, Anthropic, Google) may process data outside the EEA (including the United States). Where they do, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses and/or an adequacy decision. [[Confirm each provider’s mechanism.]]
6. How long we keep it
- Account & content: for as long as your account/Entity is active.
- After deletion: removed or anonymised within [[e.g. 30–90 days]], except where we must keep records longer (e.g. invoices for [[7 years]] under Belgian tax law).
- Integration tokens/keys: until you disconnect the integration or delete the Entity.
- Feedback: kept only while the relevant test environment is in use.
7. Your rights
Under the GDPR you can ask us to: access your data; correct it; erase it; restrict or object to processing; receive it in a portable format; and withdraw consent at any time (without affecting prior processing). To exercise these, email info@rascals.be. You also have the right to complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), www.gegevensbeschermingsautoriteit.be.
8. Cookies
We use only cookies needed to operate the Service: a session cookie, a security/CSRF token, your language preference, and an optional “remember me” cookie. We do not use advertising or third-party tracking cookies, so no cookie consent banner is required for these. [[Update if analytics are ever added.]]
9. Security
Passwords are hashed and integration secrets are encrypted at rest. We serve the app over HTTPS and apply a Content-Security-Policy and other safeguards. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a qualifying breach as required by law.
10. Children
Stuart is intended for adults managing a household or organisation. A parent or guardian may give a child read-only access within their family Entity, under their own responsibility. We do not knowingly create accounts for children under [[16]] without parental consent. [[Confirm the age and approach.]]
11. Changes
We may update this policy as the Service evolves. We will post the new version here with a new “Last updated” date and, for material changes, notify you.
12. Contact
Questions or requests: info@rascals.be — Rascals, Kastanjestraat 21, 8800 Roeselare, Belgium.