Back to overview
Coffee Voyage Icon

Coffee Voyage

Privacy Policy

Last updated: September 5, 2026

01Principle

Coffee Voyage works entirely locally by default: everything you enter is stored in a database on your device, and the app is fully usable without an account and without signing in. In addition, you may voluntarily link a cloud account with Apple or Google. Only then are your cafés, entries and photos also stored on a server and synchronised between your devices. Without that link, your entries never leave the device.

02Controller

The controller within the meaning of the General Data Protection Regulation is Martin Hoffmann, Arndtstr. 49, 04275 Leipzig, Germany, email martin-hoffmann-e-mail@web.de. A data protection officer is not required by law and none has been appointed.

03What the App Stores on Your Device

On your device the app stores what you record: the coffee you drank, the time, your rating, the taste notes you selected, whether the coffee was had at home and, optionally, a note, a price with its currency and a photo. For cafés it stores the name and, optionally, city, country, address and coordinates. As long as you have not linked a cloud account, this data stays solely on the device.

04Cloud Account and Sign-In

Signing in is voluntary and happens via “Sign in with Apple” or “Google Sign-In”. Apple or Google transmits an identity token to our authentication service (Supabase). From that token a pseudonymous account is created, holding a randomly generated user identifier, your email address and, if you release it, your name. With “Sign in with Apple” you may hide your email address; the app works unchanged with the relay address Apple generates. No password is stored, because your identity is verified exclusively by Apple or Google. The legal basis is performance of the usage contract under Art. 6(1)(b) GDPR; signing in itself remains your own voluntary decision.

05Cloud Synchronisation of Your Entries

Once an account is linked, your cafés and coffee entries are additionally stored on our server so that they survive a change of device and are available on several devices. What is transmitted is the same information that is stored locally: drink identifier, time, rating, taste notes, note, price and currency, café name, city, country, address, coordinates and any attached photos. Transmission is encrypted (TLS). On the server, every row is bound to your user identifier by row-level security rules, so only your signed-in device can access it. If you sign out, synchronisation stops; the data on your device remains untouched.

06Friends Feature

In the Friends tab you can add each other using a friend code. When you first sign in, a public profile is created automatically, holding your display name (from your Apple or Google account, or otherwise derived from your email address) and a randomly generated friend code. Whoever enters your code becomes linked to you; from that point on you each see the other's display name and — solely as a list of drinks already tried, without notes, photos, prices or café details — the other's collection. You can end a friendship unilaterally at any time in the Friends tab; it then ends for both sides. If someone opens an invite link carrying your code, our website looks up the associated display name server-side to personalise the invite page (e.g. "Anna is inviting you"); no identifier of the person opening the link is stored in the process.

07Coffee Meetups

With premium you can create a coffee meetup: a label, a location (coordinates), a time window and an optional note. You choose whether the meetup is visible to all your friends or only to individually selected ones. Friends who can see a meetup may accept or decline, optionally with an estimated arrival time; only you, as the host, see that response — the other invited friends do not. Deleting a meetup also removes the associated visibility and response data. Joining, viewing a visible meetup and responding to it are possible without premium; premium is only required to create your own meetups.

08Push Notifications

If you enable notifications for coffee meetups, the app requests your operating system's notification permission and stores a push token issued by Apple or Google, together with your user identifier, on our server. If one of your friends creates a meetup visible to you, this triggers a one-off notification to your device; delivery goes through Expo's push service (expo.dev/privacy) as well as Apple or Google. If you turn notifications off again or delete your account, the stored token is removed.

09Location Information

The app requests location permission only at the moment you explicitly tap “Save current location” while creating a café. The coordinates are stored with that café. To derive the city and country from them, the coordinates are passed to your operating system's geocoding service (Apple or Google). No background location tracking takes place. If a cloud account is linked, the coordinates are synchronised along with the other café details. The app is fully usable without location access; cafés can also be created without coordinates.

10Photos and Camera

When you attach an image to an entry, the app requests access to the camera or the photo library. The selected image is copied into the app's protected storage; the database holds only a reference to it. Beyond the image you pick, the app does not read your photo library. Without a cloud account, nothing is uploaded. With a linked account, your photos are uploaded to a non-public storage area on our server, in a folder tied exclusively to your user identifier and with no public retrieval path. Please note that, depending on the subject, photos may contain further personal data.

11Map Display

The map section loads map material from Apple Maps (iOS) or Google Maps (Android). This transmits technically necessary data such as your IP address and the requested map area to the respective provider. The privacy policies of Apple (apple.com/legal/privacy) and Google (policies.google.com/privacy) apply. Your coffee entries are not transmitted in the process.

12Drink and Recipe Catalogue Sync

On start-up the app fetches the drink and recipe catalogue from our server, so that new coffees and preparation guides can arrive without an app update. This request happens independently of any sign-in and carries no account identifier. As with any server request, technically necessary connection data such as your IP address, the time and the requested resource appear in our processor's logs. These logs are used solely to operate and secure the server, are never combined with your entries and are deleted after a short period. The legal basis is our legitimate interest in a functioning, secure service under Art. 6(1)(f) GDPR. Your own entries are not transmitted during this sync, and the app remains fully usable offline.

13Bean Recommendations and Partner Shops

On the home screen, the recipe screen and the analytics area, the app shows a selection of coffee beans from a public product catalogue that our server sources and regularly updates from participating partner shops (currently roastmarket.de) via the AWIN affiliate network. To compute matching suggestions, the app sends the taste keywords computed on your device (e.g. "chocolatey", "bold") to our server; this request carries no account identifier and is not stored linked to your entries or your user identifier. In the coffee search, the search term you enter is transmitted the same anonymous way. Tapping an offer opens the partner shop's page, via an affiliate link labelled "Ad", in your browser; from that point on, only that shop's and AWIN's (awin.com) own privacy policies apply. The Service Provider may earn a commission on a resulting purchase but does not learn whether or what you bought there, and does not itself log which offers you view or tap.

14Feedback and Drink Requests

If you send feedback in the app or suggest a missing coffee, your message, the type of submission and — for a drink request made from the search — the search term you entered are transmitted to our server. If you are signed in, your user identifier is stored as well so that we can attribute any follow-up; without signing in, the submission carries no identifier. Please do not write anything into the free-text field that you would rather not disclose. The legal basis is our legitimate interest in improving the app under Art. 6(1)(f) GDPR; the submission happens solely on your initiative. Feedback is deleted once it has been reviewed, at the latest after twelve months.

15Purchases and Subscriptions

The app uses RevenueCat to handle its premium features. This involves a pseudonymous, randomly generated user identifier along with purchase status and device information, so that unlocked features can be restored across devices. The purchase itself is processed by the App Store or Google Play; neither the Service Provider nor RevenueCat receives your payment details. Purchase handling is independent of cloud synchronisation: premium works without signing in, and signing in does not unlock premium. Privacy policy: revenuecat.com/privacy.

16Analytics and Tracking

The app itself contains no analytics tools, no advertising tracking, no cookies and no advertising identifier. No profiling and no automated decision-making take place. It is not recorded which parts of the app you use or how long you use them. The one exception is the landing pages of affiliate links to partner shops (see "Bean Recommendations and Partner Shops"): these leave the app, and there the shop and the AWIN affiliate network may use their own cookies or tracking technologies, which the Service Provider has no control over.

17Artificial Intelligence

The app does not use artificial intelligence technologies. The taste profile is a purely descriptive summary of your own entries and is computed entirely on your device. Your entries are never used to train models.

18Processors and Server Location

Account, synchronisation, photo storage, catalogue and feedback all run on Supabase. The project used for Coffee Voyage is hosted in a region within the European Union, so the data is stored in the EU. The platform is provided by Supabase Inc. (USA), with which a data processing agreement including EU standard contractual clauses is in place. Access from the USA is possible only in the context of maintenance and support. Privacy policy: supabase.com/privacy.

19Third-Party Services

The app relies on the following services, each with its own privacy policy: Supabase for account, synchronisation and catalogue (supabase.com/privacy), Apple for “Sign in with Apple”, Apple Maps and purchase handling on iOS (apple.com/legal/privacy), Google for Google Sign-In, Google Maps and Google Play Services on Android (policies.google.com/privacy), RevenueCat for purchases (revenuecat.com/privacy), Expo for push notifications and as the development platform (expo.dev/privacy), and AWIN as the affiliate network for partner-shop offers (awin.com), with roastmarket.de as the only partner shop at present.

20Disclosure of Information

Your coffee entries, notes, photos and café details are not sold, not used for advertising and not passed on to third parties. Data is transmitted only to the processors named above, who act on instructions in order to operate the app, and where the Service Provider is legally obliged to do so, for instance in response to a court or authority order. As an exception, within the voluntary Friends and Meetups feature, your display name, the drinks you've tried (without notes, photos, prices or café details) and any coffee meetups you create are deliberately shared with the users you've added as friends or invited to a meetup — see "Friends Feature" and "Coffee Meetups".

21Data Retention and Deletion

On the device your data stays until you delete individual entries in the app or uninstall it. Uninstalling removes the locally stored entries and photos. If you delete an entry while an account is linked, the deletion is carried over to the server as well. Data held in the cloud remains for as long as your account exists. You can delete your account at any time in the app under “Profile → Delete account”; this irrevocably removes the account together with all associated cafés, entries and photos, your profile (display name and friend code), your friendships, any coffee meetups you created, and your push token from the server. Alternatively an email to martin-hoffmann-e-mail@web.de is enough, in which case deletion follows without undue delay and within 30 days at the latest. As deletion is final, the Service Provider cannot restore the data afterwards.

22Children's Privacy

The app is not directed at anyone under the age of 16. The Service Provider does not knowingly collect data from children and requires neither an account nor a sign-in for the core features. Should the Service Provider learn that an account was created by a child without the consent of a parent or guardian, it will be deleted along with the associated data. A note to the address below is sufficient.

23Security

On the device your entries live in the app's protected storage area, which other applications cannot access under the rules of the operating system. Transmission to the server is always encrypted, the data is encrypted at rest there, and access is restricted to your own account by row-level security. Enabling device encryption and a screen lock is recommended, as the protection of your data depends substantially on the security of your device.

24Your Rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21). Your entries are in any case fully visible, editable and deletable in the app at all times; for access to or portability of the data held in the cloud, an email is enough. For data arising from a purchase or sign-in at Apple, Google or RevenueCat, please contact the respective provider or the Service Provider, who will gladly assist. You also have the right to lodge a complaint with a data protection supervisory authority; the authority responsible for the Service Provider is the Saxon Data Protection Commissioner.

25Changes to This Privacy Policy

This Privacy Policy may be updated from time to time. The Service Provider will notify you of changes by updating this page with the new version and a revised date. You are advised to review this page regularly, as continued use is deemed approval of the changes.

26Contact

If you have any questions regarding privacy while using the app, or wish to exercise one of your rights, please contact the Service Provider by email at martin-hoffmann-e-mail@web.de.