Cupping

Legal / Privacy

Privacy, without the fog.

This policy explains what information Cupping processes, why it is needed, who helps us provide the service, and how you can control or delete your data.

Updated August 15, 2026

01

Who is responsible for your data

Cupping is operated by Alejandro Bailo, an individual based in Spain. For privacy questions or requests, email support@coffeecupping.app.

This policy covers the Cupping mobile application, the website at https://coffeecupping.app, and support communications.

02

Data we process

Account and profile data

Email address, display name, account identifier, optional profile photo, coffee role, certifications, language preference, and authentication information. If you use Sign in with Apple or Google, those providers send us the identifiers and profile information you authorize them to share. Provider credentials used for revocation are stored server-side and are not exposed through the app.

Cupping and collaboration data

Sessions you create or join, invite and participation records, sample and coffee details, scores, flavor descriptors, defects, custom notes, results, timestamps, and sync status. Participants in the same session can see the information needed for collaboration and shared results according to the session state.

Subscription data

Product identifiers, entitlement status, trial status, purchase and expiry information, and a Cupping account identifier used to keep Pro access in sync. Apple or Google handles payment credentials and billing; Cupping does not receive your full card or bank details.

Device, notification, and local data

Device platform, app language, Expo push token, and notification delivery data when you enable notifications. The app also stores account, session, evaluation, preference, and pending-sync data locally so it can work offline. Session data is persisted on the device so sign-in can be restored between app launches.

Support and website data

If you contact support, we process your email address, message, attachments, and the information needed to resolve the request. Website hosting may generate standard technical logs such as IP address, browser type, requested URL, timestamps, and security events. We do not currently use advertising trackers or behavioral analytics on the website or in the app.

03

Why we process it

  • Provide the service: create and authenticate accounts, save cupping work, sync devices, run collaborative sessions, restore purchases, and provide support.
  • With your permission: access a selected profile photo and send local or remote notifications after you grant the relevant device permission.
  • Protect and improve Cupping: prevent abuse, diagnose failures, secure accounts, and maintain reliable offline and realtime synchronization.
  • Meet legal obligations: comply with valid legal requests, accounting duties, consumer rules, and the requirements of Apple and Google distribution services.

Under European data-protection law, these purposes rely as applicable on performance of our contract with you, your consent, our legitimate interests in operating a secure and reliable service, and compliance with legal obligations.

04

Service providers and recipients

We use providers only where they are needed to operate Cupping:

  • Supabase — authentication, database, storage, realtime synchronization, and server functions.
  • RevenueCat — subscription entitlement management and purchase synchronization.
  • Expo, Apple Push Notification service, and Firebase Cloud Messaging — notification delivery when enabled.
  • Apple and Google — social sign-in, app distribution, purchases, billing, and store-managed subscription records.
  • Vercel — website hosting, delivery, security, and technical logs.
  • Our email provider — delivery and storage of support communications.
We do not sell personal data, run third-party advertising, or share cupping data with data brokers.

We may disclose information when required by law, to protect users or the service, or as part of a future business transfer subject to appropriate notice and safeguards.

05

International data transfers

Some providers operate in or access data from countries outside the European Economic Area. Where required, transfers are covered by an adequacy decision, standard contractual clauses, or another lawful transfer mechanism. Provider privacy notices linked above explain their locations and safeguards in more detail.

06

Retention and deletion

Account, profile, and cupping data is generally kept while your account is active so you can access your history and collaborate. Local data remains on your device until it is cleared, the app is removed, or account deletion completes.

When you delete your account, Cupping removes the account and associated profile, avatars, push tokens, provider revocation credentials, RevenueCat customer, hosted sessions and their contents, your participation and evaluations in sessions hosted by others, and the local app store. A non-reversible hash and limited diagnostic state may be retained for at least the 30-day deletion-recovery window and is eligible for later pruning. It does not contain your email or profile.

Support correspondence is kept only as long as reasonably needed to answer the request, maintain security, or establish legal claims. Providers may retain backups, security logs, or transaction records for their own legal and operational retention periods. Apple and Google may retain purchase records independently of Cupping.

07

Your choices and rights

You can:

  • Edit your display name, role, certifications, avatar, language, and preferences.
  • Disable notification permission in your device settings.
  • Delete your entire Cupping account from Profile → Danger Zone → Delete account.
  • Request access, correction, deletion, restriction, objection, or portability where the law provides those rights.
  • Withdraw consent without affecting processing that was lawful before withdrawal.

Send requests to support@coffeecupping.app. We may need to verify that the request relates to your account. If you are in the EEA, you may also complain to your local data-protection authority; in Spain, this is the Agencia Española de Protección de Datos.

08

Security

Cupping uses encrypted network connections, authentication controls, database row-level security, protected server credentials, scoped access policies, and device storage appropriate to the data. No online service can guarantee absolute security, so please use a unique password and keep your device and sign-in providers secure.

09

Children

Cupping is a general coffee-evaluation tool and is not designed specifically for children. If local law requires a parent or guardian to authorize a minor's account or purchase, that permission must be obtained before using the relevant feature. Contact us if you believe a child's data was provided without the required authorization.

10

Changes and contact

We may update this policy when Cupping, its providers, or legal requirements change. The updated date will appear at the top, and material changes may also be communicated in the app or by another appropriate channel.

Questions or requests: support@coffeecupping.app