Cupping

Legal / Privacy

Privacy, without the fog.

This policy explains what information Cupping processes, why it is needed, who helps us provide the service, and how you can control or delete your data.

Updated September 28, 2026

01

Who is responsible for your data

Cupping is operated by Alejandro Bailo, an individual based in Spain. For privacy questions or requests, email support@coffeecupping.app.

This policy covers the Cupping mobile application, the website at https://www.coffeecupping.app, and support communications.

02

Data we process

Account and profile data

Email address, display name, account identifier, optional profile photo, coffee role, certifications, language preference, and authentication information. If you use Sign in with Apple or Google, those providers send us the identifiers and profile information you authorize them to share. Provider credentials used for revocation are stored server-side and are not exposed through the app.

Cupping and collaboration data

Sessions you create or join, invite and participation records, sample and coffee details, scores, flavor descriptors, defects, custom notes, results, timestamps, and sync status. Participants in the same session can see the information needed for collaboration and shared results according to the session state.

Subscription data

Product identifiers, entitlement status, trial status, purchase and expiry information, and a Cupping account identifier used to keep Pro access in sync. Apple or Google handles payment credentials and billing; Cupping does not receive your full card or bank details.

Device, notification, and local data

Device platform, app language, Expo push token, and notification delivery data when you enable notifications. The app also stores account, session, evaluation, preference, and pending-sync data locally so it can work offline. Session data is persisted on the device so sign-in can be restored between app launches.

Support and website data

If you contact support, we process your email address, message, attachments, and the information needed to resolve the request. Website hosting may generate standard technical logs such as IP address, browser type, requested URL, timestamps, and security events. We do not use advertising trackers. The website does not currently send behavioral analytics to PostHog.

Aggregate service statistics

We calculate weekly statistics from records already needed to provide Cupping: account creation dates, tasting creation and status, participation, and the receipt of completed tastings. This helps us understand whether the service is used and whether people return. Account and tasting identifiers are used inside our database to avoid duplicate counts; they are not included in the aggregate reports sent to PostHog in its European region. These reports do not include coffee details, scores, notes, photographs or label text.

We also use aggregate purchase reports from RevenueCat and acquisition reports from app stores when available. We restrict small groups, keep sources separate, and do not link these reports to individual PostHog profiles. These service statistics do not depend on the optional app analytics setting. You can object to the use of your service records for these statistics by contacting us below, without losing access to Cupping.

Optional app analytics

In app versions offering “Help improve Cupping,” analytics is off by default. If you enable it in Profile, we send selected usage events to PostHog: opening the app or a tasting invitation, joining or creating a tasting, completing evaluations, viewing or closing the Pro screen, confirming Pro access, and opening the result share sheet. Events include timestamps, app version and platform, protocol, participant role, sample count where relevant, and limited outcome categories.

We use coded identifiers derived from your account and tasting, plus random operation identifiers. These are pseudonymous, not fully anonymous, because we can relate the account identifier to your account. We do not send names, email addresses, coffee names, scores, tasting notes, invitation codes, photos, or recordings to PostHog. Session replay, automatic screen recording, advertising identifiers, and IP-based geolocation are disabled.

03

Why we process it

  • Provide the service: create and authenticate accounts, save cupping work, sync devices, run collaborative sessions, restore purchases, and provide support.
  • With your permission: access a selected profile photo and send local or remote notifications after you grant the relevant device permission.
  • Protect and improve Cupping: prevent abuse, diagnose failures, secure accounts, and maintain reliable offline and realtime synchronization.
  • Aggregate service statistics, based on legitimate interest: evaluate service adoption, repeat use and sustainability using limited operational metadata and aggregate commercial reports. We assess this interest against your rights, minimise the data, restrict access, and provide a right to object.
  • Optional analytics, with your consent: understand which features are used and where people encounter difficulties. Refusing or withdrawing consent does not limit Free Cupping or Pro features.
  • Meet legal obligations: comply with valid legal requests, accounting duties, consumer rules, and the requirements of Apple and Google distribution services.

Under European data-protection law, these purposes rely as applicable on performance of our contract with you, your consent, our legitimate interests in operating a secure and reliable service, and compliance with legal obligations.

04

Service providers and recipients

We use providers only where they are needed to operate Cupping:

  • PostHog — aggregate service reports and optional app usage analytics, using its European cloud region. Our analytics does not track you across other companies' apps or websites for advertising.
  • Supabase — authentication, database, storage, realtime synchronization, and server functions.
  • RevenueCat — subscription entitlement management and purchase synchronization.
  • Expo, Apple Push Notification service, and Firebase Cloud Messaging — notification delivery when enabled.
  • Apple and Google — social sign-in, app distribution, purchases, billing, and store-managed subscription records.
  • Vercel — website hosting, delivery, security, and technical logs.
  • Our email provider — delivery and storage of support communications.
We do not sell personal data, run third-party advertising, or share cupping data with data brokers.

We may disclose information when required by law, to protect users or the service, or as part of a future business transfer subject to appropriate notice and safeguards.

05

International data transfers

Some providers operate in or access data from countries outside the European Economic Area. Where required, transfers are covered by an adequacy decision, standard contractual clauses, or another lawful transfer mechanism. Provider privacy notices linked above explain their locations and safeguards in more detail.

06

Retention and deletion

Aggregate reports cover up to 53 weeks and are replaced rather than kept as a separate permanent history. Service reports are recalculated daily; account deletion or an accepted objection removes the relevant service records from subsequent calculations. Changes reach PostHog on its next successful refresh. Purchase and app-store reports are aggregate source reports and cannot be linked back to individual Cupping accounts.

Analytics events already received are kept to understand use of Cupping while your account exists, subject to PostHog's retention limits, unless you request their erasure earlier. We do not export them to a separate archive for longer retention.

Switching off “Help improve Cupping” stops future optional app events and clears pending analytics on that device. It does not erase events already received by PostHog. You can request erasure of those events through the contact below or delete your Cupping account. Account deletion also requests erasure of your PostHog profile and associated events; PostHog processes that erasure asynchronously. We do not reuse the deleted account's analytics identifier for a new account.

Account, profile, and cupping data is generally kept while your account is active so you can access your history and collaborate. Local data remains on your device until it is cleared, the app is removed, or account deletion completes.

When you delete your account, Cupping removes the account and associated profile, avatars, push tokens, provider revocation credentials, RevenueCat customer, hosted sessions and their contents, your participation and evaluations in sessions hosted by others, and the local app store. A non-reversible hash and limited diagnostic state may be retained for at least the 30-day deletion-recovery window and is eligible for later pruning. It does not contain your email or profile.

Support correspondence is kept only as long as reasonably needed to answer the request, maintain security, or establish legal claims. Providers may retain backups, security logs, or transaction records for their own legal and operational retention periods. Apple and Google may retain purchase records independently of Cupping.

07

Your choices and rights

You can:

  • Enable or disable optional analytics in Profile → Help improve Cupping.
  • Object to aggregate analysis of your service records by contacting the address below.
  • Edit your display name, role, certifications, avatar, language, and preferences.
  • Disable notification permission in your device settings.
  • Delete your entire Cupping account from Profile → Danger Zone → Delete account.
  • Request access, correction, deletion, restriction, objection, or portability where the law provides those rights.
  • Withdraw consent without affecting processing that was lawful before withdrawal.

Send requests to support@coffeecupping.app. We may need to verify that the request relates to your account. If you are in the EEA, you may also complain to your local data-protection authority; in Spain, this is the Agencia Española de Protección de Datos.

08

Security

Cupping uses encrypted network connections, authentication controls, database row-level security, protected server credentials, scoped access policies, and device storage appropriate to the data. No online service can guarantee absolute security, so please use a unique password and keep your device and sign-in providers secure.

09

Children

Cupping is a general coffee-evaluation tool and is not designed specifically for children. If local law requires a parent or guardian to authorize a minor's account or purchase, that permission must be obtained before using the relevant feature. Contact us if you believe a child's data was provided without the required authorization.

10

Changes and contact

We may update this policy when Cupping, its providers, or legal requirements change. The updated date will appear at the top, and material changes may also be communicated in the app or by another appropriate channel.

Questions or requests: support@coffeecupping.app