Koffee

Legal

Privacy Policy

Effective date: June 18, 2026 · Last updated: June 18, 2026

Koffee operates the Koffee mobile app and koffeeapp.xyz. This policy explains what data we collect, why we collect it, and what rights you have over it. If anything is unclear, email us at privacy@koffeeapp.xyz.

1. Data we collect

Account data

When you create an account we collect your email address and the authentication method you chose (email/password, Google, or Apple). If you use Google or Apple Sign-In, those providers share a verified email address with us; we receive no other profile data from them.

App content

As you use the app we store content you create: coffees you save to your collection, tasting scores and notes, brew logs, and any coffee or roaster submissions you contribute.

Approximate location

The map feature requests permission to access your device's approximate location to show nearby roasters. Coordinates are transmitted to Google Places API to find nearby venues. On the web platform they also pass through our Supabase edge function before reaching Google. Location is not stored on our servers and is used only for the map feature.

Usage and diagnostics

We do not run analytics SDKs or advertising trackers. We may receive crash reports and basic diagnostic information from Expo/EAS as part of app delivery. This data does not include personal identifiers.

No payment data

Koffee does not process payments. We collect no financial information.

2. How we use your data

We use your data to provide and operate the Service, personalise your coffee recommendations, sync your data across devices, respond to support requests, and improve the Service using aggregated anonymised patterns. We do not use your data for advertising, profiling for third-party purposes, or automated decision-making.

3. Data sharing and third parties

We do not sell your data. We share data only with the processors needed to operate the Service: Supabase (database and authentication, US), Expo/EAS (app delivery and diagnostics, US), Google Places API (approximate location for the map feature), Google Fonts and Fontshare (font delivery — your IP address is transmitted to load fonts on this website), and Apple and Google (email address on sign-in only). Each processor operates under a Data Processing Agreement. We do not share data with any other parties unless required by law.

4. Data retention and deletion

We retain your account and all associated content for as long as your account is active. If you delete your account we will permanently delete your data within 30 days, except where retention is required by law. To request deletion, email privacy@koffeeapp.xyz with the subject "Delete my account".

5. Your rights

All users

Access a copy of your data, correct inaccuracies, delete your account and data, and withdraw consent where processing is consent-based.

EU/EEA users (GDPR)

Data portability, the right to object to legitimate-interest processing, and the right to lodge a complaint with your national supervisory authority.

California residents (CCPA)

Know what personal information is collected and how it is used, opt out of the sale of personal information (we do not sell data), and non-discrimination for exercising your rights.

To exercise any of these rights, email privacy@koffeeapp.xyz. We will respond within 30 days (GDPR) or 45 days (CCPA).

6. Cookies

The Koffee mobile app does not use cookies. The website at koffeeapp.xyz uses only essential session cookies required for authentication. No advertising or tracking cookies are used.

7. Security

All data in transit is encrypted with TLS 1.2 or higher. Plaintext passwords are never stored — Supabase Auth stores only a salted cryptographic hash. Access to production data is restricted to authorised personnel only, and Supabase Row-Level Security ensures users can only access their own data.

8. International data transfers

Our primary data processor (Supabase) stores data in the United States. If you are located in the EU/EEA, your data is transferred to the US under Standard Contractual Clauses as provided by Supabase's Data Processing Agreement.

9. Children's privacy

Koffee is not directed to children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@koffeeapp.xyz and we will delete it promptly.

10. Changes to this policy

We will post any changes to this page and update the "Last updated" date. For significant changes we will notify users via an in-app notice. Continued use of the Service after an update constitutes acceptance of the revised policy.

11. Geographic access (EU Geo-blocking Regulation)

Koffee complies with Regulation (EU) 2018/302 on unjustified geo-blocking and other forms of discrimination based on customers' nationality, place of residence, or place of establishment within the EU/EEA. We do not block or restrict access to the Service, apply different general conditions of access, or automatically redirect users based on their location within the EU/EEA. All features, content, and pricing conditions are equally available throughout the EU/EEA.

12. Contact

privacy@koffeeapp.xyz — koffeeapp.xyz