🔒 This privacy policy is GDPR & HIPAA compliant and regularly updated to protect your rights
← Back to App
📸
🤖

Privacy Policy

Effective Date: January 15th, 2025
Coffee Insights ("we", "our", or "us") is committed to protecting your privacy and ensuring full compliance with international data protection laws. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our mobile application ("App"), in strict compliance with the General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), and other applicable privacy laws worldwide.
1

Data Controller

The data controller responsible for your personal information is:

Sebastian Cochinescu - Independent App Publisher
Bd. Ion Mihalache 166, Bucharest, Romania
Data Protection Officer:
GDPR Compliance:

We comply with all applicable EU data protection regulations.

2

Data We Collect

Account Information

  • Name and email address from Apple ID or Google Account when using third-party authentication
  • Unique user identifier for account management
  • Authentication tokens (encrypted and securely stored)
  • Account creation and last login timestamps

Photo and Image Data

  • Coffee photos uploaded for AI analysis
  • Image metadata including timestamps, device information, and image properties
  • Processed image data for coffee characteristic analysis (temporarily stored)
  • Historical photo records for user's coffee analysis history

Device and Technical Data

  • Device model, operating system version, and app version
  • IP address (anonymized after 30 days for GDPR compliance)
  • Device language and timezone settings
  • Crash reports and error logs (anonymized)
  • App performance metrics and usage statistics

Location Data (Optional)

  • Approximate location for coffee shop recommendations (only with explicit consent)
  • Location data is never stored permanently and is used only for session-based features

Advertising and Tracking Data

  • Advertising identifiers (IDFA/GAID) only with explicit consent via ATT framework
  • Marketing engagement data (email opens, app store interactions)
  • Attribution data for advertising campaign effectiveness

Health-Related Data (HIPAA Consideration)

Important: While coffee analysis is primarily informational, any dietary or wellness-related insights are treated with strict confidentiality in accordance with HIPAA privacy principles.

4

How We Use Your Data

Core App Functionality

  • AI-powered coffee analysis and quality assessment
  • Photo storage and analysis history management
  • User account creation, authentication, and profile management
  • Personalized coffee insights and recommendations

Service Improvement

  • App performance monitoring and optimization
  • Bug detection, error tracking, and technical support
  • Feature development and user experience enhancement
  • A/B testing for improved functionality

Communication and Marketing

  • Service notifications and important updates
  • Marketing communications (with explicit consent)
  • Customer support and user assistance
  • Promotional campaigns and special offers

Legal and Security

  • Fraud prevention and security monitoring
  • Compliance with legal obligations and regulations
  • Protection of our rights and interests
  • Response to legal requests and court orders
5

Data Sharing

We never sell your personal data. Data sharing is limited to essential service providers and occurs only under strict contractual obligations.

Service Providers (Data Processors)

  • Cloud Infrastructure: Google Cloud Platform, AWS (data hosting and processing)
  • AI Processing: OpenAI Vision Models (coffee analysis - images processed securely and not retained)
  • Analytics: Google Analytics, Firebase Analytics (anonymized usage data only)
  • Authentication: Apple Sign-In, Google OAuth (secure identity verification)
  • Push Notifications: Firebase Cloud Messaging, Apple Push Notification Service

Legal Requirements

  • Law enforcement agencies (when legally required)
  • Regulatory authorities (for compliance purposes)
  • Courts and legal proceedings (under judicial order)
  • Emergency services (to protect health and safety)

Business Transfers

  • In case of merger, acquisition, or sale of assets, users will be notified in advance
  • Data protection standards will be maintained during any business transition

All data sharing arrangements include: Data Processing Agreements (DPAs), strict security requirements, purpose limitation clauses, and regular compliance audits.

6

Data Retention

Account Data

  • Active accounts: Retained while account is active and for 30 days after deletion request
  • Inactive accounts: Automatically deleted after 3 years of inactivity
  • Authentication tokens: Expire automatically after 90 days

Photo and Analysis Data

  • User photos: Retained until manually deleted by user or account closure
  • Coffee analyses: Stored with photos for user history access
  • Temporary AI processing: Images deleted within 24 hours after analysis

Technical and Analytics Data

  • Device logs: Retained for 90 days for debugging purposes
  • Anonymized analytics: Retained for 26 months (Google Analytics default)
  • Crash reports: Retained for 1 year for app stability improvements

Legal and Compliance Data

  • Legal requests: Retained as required by law (typically 5-7 years)
  • Audit logs: Retained for 3 years for security monitoring
  • GDPR requests: Documentation retained for 3 years

Automated Deletion: We use automated systems to ensure data is deleted according to these retention periods. You can request immediate deletion of your data at any time.

7

Your GDPR Rights

Access Rights (Article 15)

  • Request a copy of all personal data we hold about you
  • Receive information about how your data is processed
  • Learn about data sharing and retention periods

Rectification Rights (Article 16)

  • Correct inaccurate or incomplete personal data
  • Update your account information and preferences
  • Modify consent settings and privacy choices

Erasure Rights - "Right to be Forgotten" (Article 17)

  • Request complete deletion of your account and all associated data
  • Remove specific photos or fortune records
  • Withdraw consent and delete related processing activities

Data Portability (Article 20)

  • Export your data in a machine-readable format
  • Transfer your data to another service provider
  • Receive structured data exports within 30 days

Objection Rights (Article 21)

  • Object to processing based on legitimate interests
  • Opt-out of direct marketing and profiling
  • Stop automated decision-making processes

Exercise Your Rights: Submit requests via . We respond within 30 days (extendable to 90 days for complex requests). All requests are free of charge.

8

User Controls and Choices

In-App Controls

  • Photo Management: Delete individual photos or your entire history
  • Account Settings: Update personal information and preferences
  • Privacy Settings: Control data sharing and consent preferences
  • Notification Settings: Manage push notifications and communications

Device-Level Controls

  • Location Services: Disable location access in device settings
  • Camera Permissions: Revoke photo access permissions
  • Tracking Prevention: Use iOS App Tracking Transparency or Android privacy settings
  • Advertising: Reset advertising ID or opt-out of personalized ads

Communication Preferences

  • Unsubscribe from marketing emails via email footer links
  • Disable push notifications in app or device settings
  • Opt-out of promotional communications
  • Control frequency of app notifications
9

Data Security

Technical Safeguards

  • Encryption: AES-256 encryption for data at rest, TLS 1.3 for data in transit
  • Access Controls: Multi-factor authentication and role-based access
  • Network Security: Firewalls, intrusion detection, and VPN access
  • Data Anonymization: Automatic anonymization of analytics data

Organizational Measures

  • Regular security training for all personnel
  • Background checks for employees with data access
  • Incident response procedures and security monitoring
  • Regular security audits and penetration testing

Industry Standards

  • ISO 27001 information security management compliance
  • SOC 2 Type II audited cloud infrastructure
  • GDPR technical and organizational measures (Article 32)
  • Regular third-party security assessments

Security Limitations: While we implement industry-leading security measures, no system is 100% secure. We continuously monitor and improve our security posture.

10

International Data Transfers

Transfer Mechanisms

  • EU Adequacy Decisions: Transfers to countries with adequate protection levels
  • Standard Contractual Clauses: EU-approved data transfer agreements
  • Binding Corporate Rules: For multinational service providers
  • Certification Schemes: Industry-recognized privacy certifications

Data Localization

  • EU user data primarily stored in EU data centers
  • Backup data may be stored in adequacy-approved countries
  • AI processing may occur in secure US facilities under strict contracts
  • Data subject rights remain enforceable regardless of processing location

Safeguards and Guarantees

  • Contractual obligations to maintain EU-level protection
  • Regular compliance audits of international processors
  • Immediate suspension of transfers if protection levels are compromised
  • Notification to users of any significant transfer arrangement changes
11

Children's Privacy

Age Restrictions

  • Minimum Age: 16 years in the EU, 13 years in other jurisdictions
  • Age Verification: Account creation includes age confirmation
  • Parental Consent: Required for users under applicable age limits

Special Protections

  • Enhanced privacy settings for young users
  • Restricted data collection and profiling
  • No behavioral advertising to minors
  • Regular compliance reviews for child safety

Parental Rights

  • Right to access their child's data
  • Right to request deletion of child's account
  • Right to withdraw consent at any time
  • Priority customer support for family-related concerns

Underage Discovery: If we discover a user is under the required age without proper consent, we will immediately delete their account and data.

15

Policy Changes

Notification Process

  • Significant Changes: 30-day advance notice via email and in-app notification
  • Minor Updates: Notification through app updates and website posting
  • Emergency Changes: Immediate notification for security or legal reasons

User Rights During Changes

  • Right to review changes before they take effect
  • Right to withdraw consent if you disagree with changes
  • Right to export your data before policy changes
  • Right to delete your account if changes are unacceptable

Change Documentation

  • Version history maintained for transparency
  • Summary of changes provided with each update
  • Legal basis documented for any new processing activities
  • Regular comprehensive policy reviews every 12 months
16

Contact Information

Data Protection Contacts

Data Protection Officer:

GDPR Compliance:

Security Issues:

General Support:

Supervisory Authority

  • Romania: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
  • Website: www.dataprotection.ro
  • EU Citizens: You may also lodge complaints with your local data protection authority

Response Times: GDPR requests within 30 days | Security issues within 24 hours | General support within 48 hours

12

Cookies & Tracking Technologies

Types of Cookies We Use

Cookie Consent Management

Cookie Control: You can manage cookie preferences in your device settings or through our in-app cookie preferences center.

13

Third-Party Services

Service Provider Details

Data Processing Agreements

14

Data Breach Procedures

Our Commitment

User Rights During a Breach

Security Incident Reporting:
Emergency: