Cupfolio
Cupfolio · privacy

How we handle
your cups.

Last updated · May 8, 2026

Cupfolio is a coffee journal. The whole product is the relationship between you and the cups you remember-so we collect as little as possible, store it in your name, and let you take it with you whenever you want.

This page tells you exactly what we hold, where it lives, and how to leave with it.

1 · What we collect

Data you give us

  • Account. Email address (via Sign in with Google, Sign in with Apple, or magic-link email). Optionally a display name.
  • Equipment. Your grinder and dripper (free text), if you choose to enter them.
  • Coffee data. Beans you log (name, roaster, origin, roast date, weight, price, photo), brews you log (method, grind, water, temperature, time, rating, tasting notes), filter inventory. You decide what to record-none of it is required.
  • Preferences. Brew methods you make, roast preference. Used to surface relevant recipes and nudges.

Data we don’t collect

  • No advertising identifiers.
  • No precise location.
  • No contacts, calendar, or microphone access.
  • No third-party analytics or behaviour tracking.

Permissions we ask for

  • Camera-only when you tap to photograph a bag. Photos are saved to your device.
  • Notifications-only to alert you when a brew is ready or a bag is going stale. We never send marketing pings.

2 · Where your data lives

  • On your device. Cupfolio is local-first. Bags, brews, photos, and notes live in a SQLite database on your phone. You can use the app fully without ever signing in.
  • On Supabase (when signed in). If you sign in, we mirror your data to a private row in our managed Supabase Postgres database, hosted in the EU/US region of your choice. Each row is tied to your user id and protected by row-level security-no other user can read your data.
  • Photos. Bag and beans photos are stored on your device only. We do not upload photos to our servers in v1.

3 · Who we share with

We don’t sell your data. We don’t share it with advertisers. Cupfolio uses three sub-processors strictly to operate the app:

  • Supabase (database, authentication, storage). See their privacy policy.
  • Google (Sign in with Google · OAuth identity only, not analytics). policies.google.com/privacy.
  • Apple (Sign in with Apple, iOS users). Apple may relay a private email address; we never see your real address.

We may add or change sub-processors over time; we’ll update this page when we do.

4 · How long we keep it

For as long as your account exists. When you delete your account, we soft-delete your rows immediately and hard-delete them within 30 days. Local data on your device is wiped when you uninstall the app.

5 · Your rights

  • Export. Settings → Export data writes a portable backup of every bag, brew, and note. It opens in the system share sheet so you can save it anywhere.
  • Edit. Every bag and brew is editable; tap to change, long-press to delete.
  • Delete account. Email hello@cupfolio.appwith the email address you signed up with. We’ll confirm and complete deletion within 30 days.

6 · Children

Cupfolio is not directed at children under 13. We don’t knowingly collect data from children under 13. If you believe a child has signed up, email us and we’ll remove the account.

7 · Security

Data in transit is TLS 1.2+. Data at rest is encrypted at the database level. Authentication uses Supabase’s OAuth/PKCE flow with rotating tokens. We do not store passwords because we don’t use passwords.

8 · Changes to this policy

If we update this policy in a way that affects what we collect or who we share with, we’ll surface the change in-app at next launch and update the “last updated” date above. Material changes get an email to signed-in users.

9 · Get in touch

Privacy questions, account deletion, anything else - hello@cupfolio.app.