Privacy
Last updated 22 September 2026. This page is the canonical privacy policy for the Coffee Can Android app. The French version at coffee-can.org/privacy is the one declared in Google Play; this translation is provided for convenience.
Your coffee log stays on your phone. Beans, brews, notes, tasting scores, cafés and photographs live in a database on your device. We have no copy of it and no route to it.
Because of that, there is nothing for us to export or delete on your behalf, and nothing to restore if you lose the phone.
Who we are
Coffee Can is published by the developer reachable at GitHub and hello@coffee-can.org, who is the data controller for the limited processing described below. The app is distributed in France through Google Play.
What stays on your device
Everything you write in the app:
- Beans — name, origin, variety, altitude, roaster, producer, process, roast date and level, and your notes.
- Brews — date, dripper, grinder, grind size, filter, dose, water and its measurements, pour stages, score, extraction, and eleven flavour axes with their tasting notes.
- Cafés — name, city, address, barista, the day you visited, and the cups you drank there.
- Photographs you attach to a bean or a café.
- Your choices about the AI features, and when you made them.
None of this is sent to us. Uninstalling the app deletes it. If your phone backs itself up, that backup may contain it, and that backup is governed by whoever runs it — not by us.
Moving your log to a computer or to another phone is a file you carry yourself. It is not an upload.
Location data in photographs
Photographs often carry the coordinates of where they were taken. When you attach a photo, the app strips that metadata on the phone before the picture is stored or sent anywhere.
Signing in
You do not need an account to log coffee. Signing in with Google is optional and unlocks the AI features and the news feed.
When you sign in, the app receives a Google ID token and sends it to our server. From it, our server keeps:
- your Google account identifier (the
subclaim — a pseudonymous string, not your email address); - usage counters and quota state, so the AI features can be metered;
- rate-limit records;
- ordinary server request logs.
That is the complete list. The app requests no additional Google scopes, so it is never issued an access token to any Google service — it cannot read your mail, your contacts or your files.
On your phone. The app also keeps the display name and profile picture that arrive with the Google token, so the account is recognisable in the app. Both stay on the device — we never receive them, and our server has nowhere to put them. The picture itself is fetched from Google's own image servers when it is shown, so Google sees your device's IP address at that moment. Apart from the roaster photographs described below, it is the only request the app makes to a server that is not ours.
The lawful basis is Article 6(1)(b) — performing the service you asked for — and, for the AI transfers below, Article 6(1)(a), your consent.
The AI features, and what they send
Two features send data off your phone. Each is off until you turn it on, each asks separately, and each explains its own payload immediately before the first time it sends anything.
- Read labels from photos — sends the photograph of the bag you are scanning.
- Suggest brew settings — sends the bean and brew fields you typed. No photograph.
Requests are routed by our server to Anthropic (United States) or Alibaba Cloud's Qwen (China). Which one handles a given request is decided server-side, so both are named here. These transfers leave the European Economic Area.
You can withdraw either consent at any time in the app, under I can → How we use AI. Withdrawal stops future sending immediately. It does not remove what is already in your own log, and it does not reach back into any copy the AI provider may hold.
Roaster photographs and the news feed
Where the app shows a roaster's product photograph, that image is loaded from the roaster's own website at the moment it appears on screen. Their server therefore sees your device's IP address and browser identifiers, as it would if you visited their site. We do not copy those images.
News headlines are fetched through our server. Opening a story hands you to the publisher's own site, which is theirs to serve and governed by their policy.
Your rights
Under the GDPR you may ask for access to, correction of, or erasure of the data we hold, restrict or object to its processing, and withdraw any consent you have given.
- Access. In the app: I can → Privacy → Export my data. It returns the account identifier, usage counters and quota state described above.
- Erasure. In the app: I can → Privacy → Delete account. If you have already uninstalled, use coffee-can.org/delete — it works without reinstalling.
- Withdrawing consent. I can → How we use AI.
Write to hello@coffee-can.org for anything else. You also have the right to complain to the CNIL, the French supervisory authority, at cnil.fr.
How long we keep it
The account record and its counters exist for as long as the account does, and are erased when you delete it. Rate-limit records are short-lived by nature. Server logs are kept for operational and security purposes and rotate.
Children
Coffee Can is not directed at children and we do not knowingly collect anything from them.
Changes
This page always carries the current version and the date it changed. The app links here rather than reproducing the text, so there is one document and no stale copy in a build.
Questions: hello@coffee-can.org · Rights holders and publishers: takedown@coffee-can.org