Legal — Privacy Policy
Privacy Policy
Last updated: July 30, 2026
1. Information We Collect
We collect the following information: **Required Information** - Social account information (Google, Apple): name, email address, profile photo - Service usage data: recipe generation history, bean information (including photos), equipment details, brewing feedback (satisfaction and taste ratings such as acidity, sweetness, body, and bitterness), journey (brewing session) records, cafe logs (the cafe visited, visit time, coffee and roaster names, tasting notes, cupping ratings, and photos), equipment addition requests - User request content: general feedback, feature or business proposals, catalog information correction suggestions for equipment or cafes, and self-reported cafe owner or manager status - Device information: browser language setting (locale), device model, OS version - Push notification token: device identifier token (FCM token) for delivering push notifications - Notification preferences: opt-in status per notification type - App analytics: screen views, feature usage frequency - Error information: app crash logs, error stack traces **Optional Information** - Location: coordinates from device GPS or EXIF metadata in a photo you select. We use them for cafe search and matching. Exact EXIF location is used only while processing your request, is not stored, is not permanently stored, and is used during temporary processing. Selected permanent cafe coordinates may be stored as cafe catalog data. A popup cafe location you register is rounded to three decimal places, roughly 100m, before it is stored as shared catalog data. **How We Collect** - Automatically through social login (Google, Apple) - Directly from user input during service use - Automatically during mobile app usage - GPS coordinates when device location permission is granted (with your consent) - EXIF location extracted on device from a photo you select - Cafe search and matching requests are processed by Supabase Edge Functions
2. How We Use Your Information
We use collected information for the following purposes: 1. Account management: identity verification, account administration 2. Service delivery: personalized recipe generation, recipe refinement based on environmental factors such as location and weather, location-based cafe search and matching, brewing record management, bean and recipe card image recognition 3. Service improvement: recipe generation and recommendation quality improvement, usage pattern analysis, service stability improvement through error analysis, review and application of general feedback and catalog information correction suggestions, and equipment catalog expansion 4. Personalized recommendations: taste analysis and bean/equipment recommendations for Plus subscribers 5. Communication: service announcements, welcome emails, direct replies to user requests, push notifications when replies are ready, brewing and feedback reminders, and news
3. Data Retention
1. Personal information is retained for the duration of your service use. 2. Upon account deletion, personal information is promptly destroyed. Permanent cafe information registered by a user is retained in the shared cafe catalog in anonymized form after the link to its creator is severed. A public popup cafe row has no registering account UUID. The service-only account-request-cafe link has expires_at 29 days after creation, and daily cleanup removes expired rows. 3. Where required by applicable law, data may be retained for the legally mandated period.
4. Sharing with Third Parties
We do not share your personal information with third parties without your consent, except: 1. When required by law 2. When you have given prior consent Additionally, when you create and share a share card externally, the information it contains (bean, recipe, satisfaction, statistics, etc.) may be transmitted to external platforms. You control whether and to what extent you share it. When you publish a cafe log, the visit date, coffee name, roaster name, selected tasting notes, and the photos you chose are shown anonymously to other users on that cafe's page. Account information, satisfaction and cupping scores, and personal notes are never published. You choose publication per entry and per photo, and can unpublish at any time. See Section 7-2 of the Terms of Service for details.
5. Service Providers
We use the following service providers to operate the Service: | Provider | Purpose | |----------|----------| | Supabase Inc. | Data storage, authentication, and cafe search and matching request processing through Supabase Edge Functions | | Google LLC | Social login (Google Sign-In), app analytics, crash reporting, push notifications (Firebase Cloud Messaging), image recognition (Gemini Vision API), cafe search and matching through Google Places (for nearby search, coordinates are sent; for text search, search terms are sent), and Android platform reverse geocoding | | NAVER Corporation | Cafe search and matching through NAVER Local; user input or cafe names and addresses are used to construct text queries, and no coordinates are sent | | Apple Inc. | Social login (Sign in with Apple), Apple MapKit place search, and reverse geocoding through device and platform APIs | | PostHog | Product usage analytics | | RevenueCat, Inc. | Subscription billing management | | Open-Meteo | Weather data lookup (based on location coordinates) | | Resend Inc. | Email delivery |
6. Your Rights
You have the right to: 1. Access your personal information 2. Request correction of your information 3. Request deletion of your information (account deletion) 4. Request suspension of data processing You can exercise these rights through the Service settings or by contacting privacy@pourist.app.
7. Data Destruction
1. Personal information is destroyed without delay when the retention period expires or the purpose of processing is achieved. 2. Electronic files are permanently deleted using methods that prevent recovery. Account deletion, through the foreign-key cascade, immediately removes the service-only account-request-cafe link.
8. Security Measures
We implement the following measures to protect your information: 1. Encryption of key data (in transit and at rest) 2. Access control management 3. Security software installation and updates
9. Cookies
The Service may use cookies to improve user experience. You can refuse cookie collection through browser settings, but some features may be limited.
10. Contact
For privacy-related inquiries, please contact: - Email: privacy@pourist.app
11. Changes to This Policy
Changes to this Privacy Policy will be announced within the Service at least 7 days before the effective date.
Effective Date
This Privacy Policy is effective as of July 27, 2026.