Cuptrace

Privacy Policy

Effective date: 2026-06-07

App: Cuptrace (com.cuptrace)

Data controller: Volodymyr Kubiria, Bonn, Germany

Contact: support@cuptrace.com

Cuptrace is a coffee-evaluation tool built on a non-custodial philosophy: we hold your trust, not your files. This policy is short because we collect little.

What we collect

Email address (optional). Only if you choose to create an account for Organizer, Head Judge, Lab, or Farmer roles. Anonymous Solo mode requires no email. Email is used solely for sign-in and password recovery.

Display name (optional). If you join a multi-user session as a Tester or Judge, the name you type is shown to that session's Organizer and Head Judge so they can tell whose scores are whose. Solo mode never asks for it.

Anonymous user identifier. Firebase generates a random ID (UID) when you first launch the app. It does not identify you personally. It is required for the app to sync your own evaluations across your devices.

Anonymous crash diagnostics. If the app crashes, Firebase Crashlytics records the stack trace and device model. This data contains no personal identifiers. We use it to fix bugs.

Unanswered help questions (product-improvement diagnostics). If you type a question into the in-app help assistant and it cannot find an answer, the question text is uploaded so we can add the missing answer for everyone. This is not behavioral analytics: it fires only on an unanswered help question, never on your normal use of the app. Before upload, email addresses and phone numbers are automatically removed from the text — twice, on your device and again on our server — and the record carries no account identifier: only the scrubbed question, the screen it was asked from, your device language, a timestamp, and the app version. These records are deleted automatically after 90 days.

What we do not collect

What you create inside Cuptrace

Your evaluations, cupping scores, flavor notes, farmer submissions, and Coffee Profile data are your content. We store them solely to render them back to you and sync them across your devices. We do not analyze, profile, mine, sell, or share this content with anyone.

If you join a multi-user cupping session as a Tester or Judge, your evaluations are visible to that session's Organizer and Head Judge. That is the purpose of the session.

If you submit a coffee lot as a Farmer, that submission — the lot details, the farm and producer names, any lab measurements, and the document links you attached — becomes visible to the organization you submitted it to: its Organizer, Head Judge, Lab, and administrators. That is the purpose of the submission. Cupping panelists do not see who you are: samples reach the tasting table under a blind code, carrying only the coffee name and country of origin.

When a lot is exported as a Coffee Passport (PDF certificate), that document carries the farm or producer name and, for each document you attached, a QR code and the link itself — so that a buyer can check provenance from a printed certificate at a trade show or in customs paperwork. Cuptrace never copies the file: the link points to your own storage, and who may open it is decided by the sharing permissions you set there. Anyone holding the PDF can follow those links, so attach only what you are willing to show a buyer.

AI Buyer Notes (optional)

If — and only if — you tap to generate AI Buyer Notes, the cupping data for that one coffee — its flavor descriptors and score, plus the lot metadata you entered (which may include the producer, farm, or business names, but never your own email, name, or account identifier) — is sent to Google's Gemini API to write a short summary back to you. It runs only on your explicit request. We do not send your data to any AI service in the background, and AI never proposes or changes scores. If you never use the feature, no data ever leaves for AI processing.

Where data lives

All data is stored in Firebase (Google LLC) — our primary sub-processor (full list below). Servers are located in Google's global infrastructure. Data transfers from EU to US are governed by Google's Standard Contractual Clauses.

How long we keep it

For as long as your account exists. You can delete your account at any time from Settings → Delete Account. This cascade-deletes all your evaluations, submissions, sessions, and authentication record. Firebase backup retention may keep data for up to 30 days after deletion, after which it is permanently erased.

Your rights

You can access, export, correct, or delete your data at any time from inside the app. For requests we cannot fulfill in-app (rare), email us at the address above. We respond within 30 days.

Children

Cuptrace is intended for users 16 years or older. We do not knowingly collect data from children.

Changes

If we materially change this policy, we will notify you via an in-app prompt before changes take effect.

Sub-processor disclosure

Sub-processor Purpose When Privacy policy
Google Firebase (Authentication, Realtime Database, Firestore, Cloud Functions, Crashlytics) App backend, sync, crash reports, anonymous unanswered-help-question intake Always policies.google.com/privacy
Google Gemini API Generate AI Buyer Notes summary Only when you request it policies.google.com/privacy

Both are Google services. We use no other third-party tools that receive your data. No advertising networks. No analytics SDKs.


This policy reflects Cuptrace's non-custodial architecture: we treat your data the way we treat your files — as something you own, not something we hold. If you have questions, write to us. We answer directly.