Legal

Privacy Policy

Version 1.0  ·  Effective date: July 2026

We built My Coffee Shelf to be useful, not intrusive. We collect only what we need to run the app and the website, we never sell your data, and you can delete everything at any time.

1. Who We Are

My Coffee Shelf is operated by Nisshagen Advisory AB (Org.nr 559526-6742), a company registered in Stockholm, Sweden. We are the data controller for personal data collected through the My Coffee Shelf mobile app (iOS and Android) and the mycoffeeshelf.com website.

Contact us at hello@mycoffeeshelf.com for any privacy-related questions, including data subject requests under the GDPR.

This policy covers both the app and the website unless a section says otherwise. At the time of writing the app has not yet been released publicly; the website currently collects launch-notification signups only.

2. What Data We Collect

Data Why we collect it Where it’s stored
Email address (app) Account creation and login, if you choose to create an account Supabase (EU)
Sign in with Apple (app) If you sign in with Apple, Apple’s prompt asks you to share your name and email address. We receive and store only the email address contained in the identity token Apple issues. The name is not sent to us and is not stored. If you choose “Hide My Email”, what we store is Apple’s private relay address, not your real one. Supabase (EU)
Google sign-in (app) If you sign in with Google, Google returns the basic profile it holds for you (email address, name and profile picture URL), and that is stored on your account record so we can identify you at login. We do not read anything else from your Google account. Supabase (EU)
Anonymous account identifier (app) The app can be used without signing up. In that case we create an anonymous account so your shelf can be saved and synced. It is not linked to your identity unless you later sign up, in which case the same account is kept. Supabase (EU)
Your coffee shelf Core app functionality: bags, roasters, origins, roast dates, quantities and freshness state Supabase (EU)
Brew logs and gear Core app functionality: the grinders and brewers you own, brew parameters, ratings, notes and the caffeine estimates derived from them Supabase (EU)
Camera images used for scanning Reading a bag’s barcode or label. Sent for processing at the moment of the scan and not retained by us afterwards. Not stored
Scan log (app) A record that a scan happened (your account identifier, the type of scan and the time, with no image kept), so AI scanning can be capped per day and the cost controlled. Deleted with your account. Supabase (EU)
Photos you choose to keep Only if you attach a photo to a bag or a brew yourself Supabase Storage (EU)
Usage events Product analytics to understand how the app is used and improve it. Analytics start when the app starts and there is currently no in-app opt-out. Events record what happened in the app (for example that a brew was logged) together with your account identifier, the same identifier described above, which is a random ID and not your name or email. Mixpanel (EU)
Crash and error reports Diagnosing crashes and bugs. Personally identifying information is disabled by default. Sentry (EU)
Email address (website launch list) Sending you one notification when My Coffee Shelf is released Supabase (EU)
App identifier (website) Which shelf app the signup was for, so the launch email goes to the right list. For this site the value is always coffee_shelf. Supabase (EU)
Consent flag and consent wording (website) Proving the lawful basis for storing your address: whether you ticked the box, and the exact wording you ticked it against Supabase (EU)
Date and time of signup (website) Recording when you signed up and gave consent, so we can show that consent was given and when. Required under GDPR Article 7(1). Supabase (EU)
Page URL and referring page (website) The address of the page you submitted the form from, and the page that sent you there if your browser reported one, so we know which consent text and which channel a signup came from Supabase (EU)
Browser language (website) The language your browser reports, so we can send the launch email in a language you are likely to read Supabase (EU)
Hashed IP address (website) Limiting signups to 5 per hour from the same network so the form cannot be flooded. See section 2a below: your raw IP address is never written to the database. Supabase (EU)

2a. How the Website Handles Your IP Address

When you submit the launch-list form, the server takes the IP address your request arrived from, combines it with a secret salt we hold, hashes it with SHA-256, shortens the result to the first 32 hexadecimal characters, and stores that hash on the signup row. Your raw IP address is never written to the database.

The hash exists for one purpose: counting how many signups have come from the same network in the past hour, so the form can be capped at five per hour and cannot be flooded. It is not used to locate you, to profile you, or for anything else.

A hash cannot be turned back into an IP address: there is no key that reverses it, and without the salt it cannot be recomputed by anyone else. We are still telling you about it plainly because a value derived from your IP address counts as personal data under the GDPR even in hashed form, and it is stored on the row for as long as the row exists rather than discarded after the request. Your rights in section 6 apply to it exactly as they do to your email address: ask us to delete your launch-list entry and the hash goes with it.

The website uses Vercel Web Analytics for aggregate, anonymous traffic measurement (page views, referrers, country-level location). It is cookieless, does not track individuals across sessions or sites, and does not build user profiles. The website sets no advertising cookies and carries no tracking pixels. If we add any, we will update this policy before they take effect.

3. Legal Basis for Processing

We process your personal data under the following legal bases as defined by the GDPR:

4. Third-Party Services

We use a small number of trusted service providers to operate My Coffee Shelf:

We do not sell your data to any third party, and none of our providers use your data for advertising purposes.

5. How Long We Keep Your Data

App data is kept for as long as your account is active. If you delete your account, your personal data (your shelf, brew logs, gear and any photos you saved) is permanently deleted within 30 days. Section 7 explains the one exception, which is the shared sign-in account. Analytics events already sent to Mixpanel are held under your random account identifier and are deleted on request.

Launch-list emails are kept until the launch notification has been sent, or until you ask us to remove your address, whichever comes first. We will not repurpose the list for anything else.

6. Your Rights Under GDPR

As a user in the European Economic Area, you have the right to:

To exercise any of these rights, contact us at hello@mycoffeeshelf.com. We will respond within 30 days.

7. Deleting Your Account

There are two routes to deletion, and both end in the same place:

Deletion removes your shelf, brew logs, gear, scan history and any photos you saved. One thing to be aware of: sign-in accounts are shared across the “my X shelf” apps, so if the same login is also used for My Bar Shelf, the login itself is kept and only your My Coffee Shelf data is erased. Otherwise deleting here would destroy your other app’s account too. The app tells you when this applies, and you can ask us to remove the login as well.

To be removed from the website launch list, email the same address. No account is needed and we will not ask you why.

8. International Transfers

Our database, storage and analytics are hosted in the European Union. Some providers (notably Google Gemini for label scanning, and Apple and Google for app distribution and sign-in) may process data outside the EEA. Where that happens, transfers are covered by the European Commission’s Standard Contractual Clauses or an adequacy decision.

9. Children

My Coffee Shelf is not directed at children. We do not knowingly collect data from anyone under 16, or under the age of digital consent in your country if that is higher. If you believe a child has given us personal data, contact us and we will delete it.

10. Changes to This Policy

If we make material changes to this privacy policy, we will notify you within the app and ask you to review the updated policy before continuing to use My Coffee Shelf. The version number and effective date at the top of this page will be updated accordingly.

11. Contact

Questions or concerns about your privacy? Contact us at hello@mycoffeeshelf.com.

Nisshagen Advisory AB, Stockholm, Sweden.