Privacy Policy
Cuptrace is a coffee-evaluation tool built on a non-custodial philosophy: we hold your trust, not your files. This policy is short because we collect little.
What we collect
Email address (optional). Only if you choose to create an account for Organizer, Head Judge, Lab, or Farmer roles. Anonymous Solo mode requires no email. Email is used solely for sign-in and password recovery.
Display name (optional). If you join a multi-user session as a Tester or Judge, the name you type is shown to that session's Organizer and Head Judge so they can tell whose scores are whose. Solo mode never asks for it.
Anonymous user identifier. Firebase generates a random ID (UID) when you first launch the app. It does not identify you personally. It is required for the app to sync your own evaluations across your devices.
Anonymous crash diagnostics. If the app crashes, Firebase Crashlytics records the stack trace and device model. This data contains no personal identifiers. We use it to fix bugs.
Unanswered help questions (product-improvement diagnostics). If you type a question into the in-app help assistant and it cannot find an answer, the question text is uploaded so we can add the missing answer for everyone. This is not behavioral analytics: it fires only on an unanswered help question, never on your normal use of the app. Before upload, email addresses and phone numbers are automatically removed from the text — twice, on your device and again on our server — and the record carries no account identifier: only the scrubbed question, the screen it was asked from, your device language, a timestamp, and the app version. These records are deleted automatically after 90 days. The same question is also sent to Google's Gemini API to try to answer you immediately — see AI features below.
What we do not collect
- We do not collect behavioral analytics. Firebase Analytics is disabled in this app.
- We do not track your location, contacts, advertising ID, or activity in other apps.
- We do not collect or store any files. When you attach a photo or document, you provide a URL that points to your own Google Drive, Dropbox, or iCloud. Cuptrace stores only the URL, never the file.
What you create inside Cuptrace
Your evaluations, cupping scores, flavor notes, farmer submissions, and Coffee Profile data are your content. We store them solely to render them back to you and sync them across your devices. We do not analyze, profile, mine, sell, or share this content with anyone — except what you deliberately publish yourself, which today means one thing only: the optional public coffee profile described below.
If you join a multi-user cupping session as a Tester or Judge, your evaluations are visible to that session's Organizer and Head Judge. That is the purpose of the session.
If you submit a coffee lot as a Farmer, that submission — the lot details, the farm and producer names, any lab measurements, and the document links you attached — becomes visible to the organization you submitted it to: its Organizer, Head Judge, Lab, and administrators. That is the purpose of the submission. Cupping panelists do not see who you are: samples reach the tasting table under a blind code, carrying only the coffee name and country of origin.
When a lot is exported as a Coffee Passport (PDF certificate), that document carries the farm or producer name and, for each document you attached, a QR code and the link itself — so that a buyer can check provenance from a printed certificate at a trade show or in customs paperwork. Cuptrace never copies the file: the link points to your own storage, and who may open it is decided by the sharing permissions you set there. Anyone holding the PDF can follow those links, so attach only what you are willing to show a buyer.
Public coffee profile (optional, off by default)
Once a lot has been certified, the farmer who owns it can switch on Public profile. That creates a web address of the form cuptrace.app/p/… which anyone holding the link can open in a browser — no app, no account. That is the purpose of the feature: a buyer should be able to check a coffee without installing anything.
The page carries only the finished picture of the coffee: its name, country of origin, region, farm name, process, variety, crop year, altitude, the lab measurements, the score and sensory profile, the certifying organisation and date, and the buyer notes. It never carries your email, your name, your account identifier, the event code, or the links to documents you attached.
The switch is off until you turn it on, only that lot's own farmer can turn it on, and turning it off stops the link working immediately. The page asks search engines not to index it (noindex), so it is meant to be reached through the link you hand out, not through a search. If the certification behind the lot is later withdrawn, the page stops serving.
AI features
Cuptrace uses Google's Gemini API in exactly two places. Nothing else in the app sends anything to an AI service.
1. AI Buyer Notes — on your explicit tap. When you tap to generate Buyer Notes for a coffee, the cupping data for that one lot — its flavor descriptors and score, plus the lot metadata you entered (which may include the producer, farm, or business names, but never your own email, name, or account identifier) — is sent to Gemini to write a short summary back to you. It is offered on the farmer's lot view and in the Coffee Profile editor, and it runs only when you ask for it.
2. The in-app help assistant — the question you type. The help assistant first searches a guide built into the app, entirely on your device. If that guide has no answer for you, your question text is sent to Gemini along with the closest guide entries, so it can answer from them. This happens automatically, without a second tap — you asked a question, and we try to answer it rather than leaving you at a dead end. Your question is also passed through the same service for translation, so the search works in your language. Only the question text is sent: no evaluation data, no email, name, or account identifier. You can recognise these answers by the “AI ANSWER · BETA” label.
AI never proposes, estimates, or changes a cupping score. The help assistant is instructed to answer only from the built-in guide and to say so plainly when it cannot. If you use neither feature, nothing of yours reaches an AI service.
Legal basis for processing (GDPR)
- Email & account — performance of a contract (Art. 6(1)(b)): to provide the role-based features you signed up for.
- Anonymous identifier & sync — performance of a contract: to operate the app you are using.
- Crash diagnostics — legitimate interest (Art. 6(1)(f)): to keep the app stable; data contains no personal identifiers.
- Unanswered help questions — legitimate interest (Art. 6(1)(f)): to find and fill gaps in the built-in guide; the record carries no account identifier and is deleted after 90 days.
- Public coffee profile — consent (Art. 6(1)(a)): a certified lot becomes readable by anyone holding its link only after its farmer switches it on, and stops being readable the moment they switch it off.
- AI features — consent (Art. 6(1)(a)): Buyer Notes are processed only when you explicitly tap to generate; a help question is processed because you typed it and asked for an answer. Both are optional features you choose to use.
How we protect your data
- In transit. Everything the app sends — to Firebase and to the Gemini API — travels over HTTPS/TLS. There is no plain-text channel.
- At rest. Your records live in Google Firebase, which encrypts stored data by default on Google's infrastructure.
- Who may read what is enforced on the server, not in the app. Firebase security rules decide, per request, whether an account may read or write a given record. A modified or repackaged copy of the app cannot talk its way past them, because the decision is not made on the device.
- Passwords. Sign-in is handled by Firebase Authentication. We never see, receive, or store your password.
- Files. We store none at all. Attachments are links to your own cloud storage, so who may open the file itself stays governed by the permissions you set there.
- No one else is in the path. Beyond the two Google services named below, there are no advertising networks, no analytics SDKs, and no third-party trackers in this app.
Where data lives
All data we hold is stored in Firebase (Google LLC) — the only place we store your data. The Gemini API listed below processes a request and hands the result back; it is not a place where anything of yours is kept. Servers are located in Google's global infrastructure. Data transfers from EU to US are governed by Google's Standard Contractual Clauses.
Separately, and outside our reach: Android's own backup may copy this app's data into a private folder of your Google Drive (Google caps it at 25 MB per app and does not count it against your storage quota). That copy is yours, not ours — we cannot read it, and you control it in your device's backup settings. We leave this on deliberately, because Solo mode works without an account and therefore has no other copy: switching it off would mean a new phone silently loses your whole cupping history.
How long we keep it
For as long as your account exists. You can delete your account at any time from Settings → Delete Account. This cascade-deletes all your evaluations, submissions, sessions, and authentication record. Firebase backup retention may keep data for up to 30 days after deletion, after which it is permanently erased.
Your rights
You can access, export, correct, or delete your data at any time from inside the app. For requests we cannot fulfill in-app (rare), email us at the address above. We respond within 30 days.
Children
Cuptrace is intended for users 16 years or older. We do not knowingly collect data from children.
Changes
If we materially change this policy, we will notify you via an in-app prompt before changes take effect.
Sub-processor disclosure
| Sub-processor | Purpose | When | Privacy policy |
|---|---|---|---|
| Google Firebase (Authentication, Realtime Database, Firestore, Cloud Functions, Crashlytics) | App backend, sync, crash reports, anonymous unanswered-help-question intake | Always | policies.google.com/privacy |
| Google Gemini API | Generate an AI Buyer Notes summary; answer an in-app help question the built-in guide cannot | When you tap Generate; and when a question you typed into the help assistant has no answer in the built-in guide | policies.google.com/privacy |
Both are Google services. We use no other third-party tools that receive your data. No advertising networks. No analytics SDKs.
Language
This policy is written in English, the authoritative version. Translations into other languages are provided for your convenience; if they conflict, the English version prevails.
This policy reflects Cuptrace's non-custodial architecture: we treat your data the way we treat your files — as something you own, not something we hold. If you have questions, write to us. We answer directly.