Legal
Privacy Policy
Short version. The app keeps your coffee shelf in a database in the EU, on an account that starts out anonymous. If you scan a bag, the photograph leaves your device: it goes to our server and on to Google, which reads the label for you, and the full-size original is saved with the bag if you save it. Usage analytics are off until you switch them on in Profile, and nothing at all is sent before you do. Crash reports are always on. Your coffee data belongs to your account and is not shared with the other Shelf apps, although the login is one account, the subscription is one subscription, and the free AI scan allowance is counted once across that account whichever app used it. The analytics choice is not: this app keeps its own, and section 4 says which apps share theirs. We do not sell any of it. You can export or delete everything from inside the app, without asking us.
What changed in version 2.0, and why. Version 1.0 described an app that had not been released and a launch-notification form on this website. My Coffee Shelf has been on the App Store and Google Play since August 2026 and no such form exists. Version 1.0 also said that analytics start when the app starts, that there is no opt-out switch inside the app, and that they run on our legitimate interests. All three were wrong, and they were wrong in the direction that took something away from you: analytics are off by default, they are switched on only by you in Profile, and they run on your consent. A policy that claims more collection than actually happens, and that understates the rights you have, is as much a fault as one that claims less, so it is being corrected rather than quietly reworded. Version 1.0 also described scan photographs as not retained, named neither RevenueCat nor the mapping providers we use to find cafés, and said nothing about Apple Health or push notifications. Section 22 lists every change.
1. Who we are
My Coffee Shelf is a product of Nisshagen Advisory AB (Org.nr 559526-6742), a company registered in Stockholm, Sweden. We are the data controller for personal data collected through the My Coffee Shelf app on iOS and Android, and through the mycoffeeshelf.com website.
Write to hello@mycoffeeshelf.com with any privacy question, including requests under the GDPR. We have not appointed a data protection officer and are not required to.
This policy covers both the app and the website. Where a section applies to only one of them, it says so.
2. Your account
The app creates an anonymous account the first time you open it. That account holds no email address and no name. It is a random identifier that brings your own shelf back to you the next time you open the app. There is no sign-up wall, and you can use the app indefinitely without ever creating a real account.
An anonymous account is a real record in our database, and everything you enter is stored against it exactly as section 3 describes. Two things follow that are worth stating plainly: an anonymous account can switch usage analytics on, and it is identified to our subscription provider on every launch. Neither of those waits for you to sign up.
If you create a real account so your shelf survives a new phone, we store what you give us for it:
- Email and password: your email address, and a password we never see in readable form. It is hashed by our authentication provider.
- A one-time sign-in link: your email address, so we can send the link to it.
- Sign in with Google: your email address, plus the basic profile Google returns alongside it, which is your name and the web address of your profile picture. Our authentication provider stores that on the account record. We do not read anything else in your Google account.
- Sign in with Apple: the account identifier Apple returns and the email address you choose to share. If you use Apple’s Hide My Email, we only ever see the relay address, never your real one.
Whether your anonymous shelf comes with you depends on the route. Google sign-in tries to promote the same account in place, so your shelf travels. A one-time email link and Sign in with Apple always land on a different account, so the app warns you before it switches and the anonymous shelf stays where it was. Signing out drops you into a fresh anonymous account, and a device that has once held a real account is never quietly anonymised again: it asks you to sign in.
On your device the app stores your sign-in session, your answer to the analytics question, the date you installed it, a flag recording that this device has held a real account, and your unit and language preferences. Signing out clears them, and your analytics answer is written back afterwards so that signing out is not treated as consent.
3. What you record, and who can see it
Everything in the app besides the reference catalogue is content you create, stored against your account:
- Bags: roaster, coffee, origin, process, roast level, bean type, roast date, weight, how much is left, and any notes you write.
- Brews: the drink, the method, dose, yield, grind, time, temperature, cup size, your rating, your tasting note, the estimated caffeine, and which bag, machine and café it came from.
- Equipment: your grinders, brewers and accessories, what you call them, and the maintenance you log against them.
- Cafés: the places you save, your visit count, your notes, and a location if you picked the place from a map result.
- Recipes and shopping list: your own drink recipes, and what you plan to buy.
- Photographs: any picture you attach, covered in full in section 5.
This is private to your account. There is no social feed, no public profile, and no sharing with other people. Database access rules restrict every row to the account that created it.
There is one exception, and it is deliberate. When you add a café by name, the app creates two rows: a private one that holds your visits, your notes and your rating, and a shared catalogue row for the place itself, so that everyone’s visits can aggregate onto one café rather than a hundred spellings of it. The shared row records that you were the one who submitted it. It is visible only to you until we approve it, and after that it is part of the catalogue. The coordinates on a shared row are the venue’s own, never your position.
The same split applies to roasters and coffees you add. The catalogue is shared; your shelf is not.
Deleting your account does not reliably take your name off those rows, and version 2.0 of this policy said it did. It said the shared row stays and your name on it is removed, so nothing points back to you. That is wrong for two of the three kinds and conditional for the third. A café has your identifier cleared, but only on the path where your sign-in record itself is deleted; if the sign-in is kept because another Shelf app still holds your data, your identifier stays on the café. A roaster or a coffee keeps your identifier on both paths, because nothing in the deletion clears those two columns at all. Sections 17 and 22 set this out, and this paragraph exists because section 3 was still carrying the old sentence and contradicting them. Ask us and we will clear all three by hand.
4. What is shared with the other Shelf apps, and what is not
My Coffee Shelf is one of a family of apps that run on one account system. Your coffee data is not shared with any of them. Bags, brews, gear, cafés, recipes and your shopping list live in a part of the database that only this app reads. Nothing you record here appears in My Bar Shelf, My Whiskey Shelf or any other Shelf app.
Five things do reach past this app. They do not all reach the same distance, and version 2.0 of this policy said each of them was “one thing across the whole family”, which was not true of two. Each is now named with the apps it actually touches:
- Your login. One account signs you in to My Coffee Shelf, My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf, My Cigar Shelf and My Supply Shelf.
- Your free AI scan allowance. Five scans in total, not five per app, and the apps sharing those five are My Coffee Shelf, My Whiskey Shelf and My Cigar Shelf, which call the same scan function on our server. Version 2.0 called it one allowance across the whole family. Section 5.
- Your subscription. Held against your account identifier at RevenueCat, so an entitlement bought in one Shelf app can be seen by another asking about the same account. What it unlocks depends on which subscription you bought: a bundle subscription is honoured by the Shelf apps that check for it, a single-app subscription unlocks only the app it was bought for. Version 2.0 said one subscription covers all of them, which is true of the bundle alone. Section 11.
- Deletion. Deleting here checks whether another Shelf app still holds data for you, and keeps the login alive if it does. Section 19.
- Push notification plumbing. The device token and the record of what was sent sit in shared tables, tagged with the app that sent them. Section 12.
Your analytics answer is not one of them, and version 2.0 of this policy said it was. It said “set it here and it is the answer everywhere”. That is wrong, and wrong in the direction that matters: it implied that switching analytics off here switched them off across the family, and it does not.
My Coffee Shelf keeps its own answer, in its own table, in the coffee part of the database. The other Shelf apps keep a single shared answer on your account, and the two never meet. We checked both directions: nothing in this app reads or writes the shared row, and nothing in any other Shelf app reads the coffee one.
So the answer you give here covers My Coffee Shelf and nothing else. My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf and My Cigar Shelf share one answer between the five of them, set in any of those five. My Supply Shelf sends no analytics at all. If you want analytics off everywhere, you have to say so twice: once here, and once in any one of those five. Section 9.
All of that needs a real account. While you are anonymous your identifier is different in every app, so nothing carries across at all: not the subscription, not the scan allowance, not the analytics answer.
5. Photographs, and the scan that reads them
This is the part of the app that sends the most away from your device, so it is set out in full.
The bag scan. When you scan a coffee bag, the app asks for camera or photo library permission, then:
- A copy of the picture is made on your device, resized to 768 pixels on its long edge and re-encoded as a JPEG. This copy exists for the model to read and is not the photograph that gets saved.
- That copy is sent to our own server function, which runs on our database provider’s infrastructure in the EU. Your sign-in token goes with it, so the function knows whose allowance to count.
- Our function forwards the image and a fixed instruction to Google, to the Gemini API, which reads the bag and returns text. Nothing else is sent to Google: not your account identifier, not your email, not your device identifier, and nothing from your shelf.
- The reading comes back and fills in the add form. You review and edit every field.
This happens before anything is saved, and it happens whether or not you go on to add the bag. Backing out of the form does not undo the upload to Google.
The photograph that is kept. A successful scan attaches your original full-resolution capture to the form, not the small copy the model read. If you then save the bag, that original is uploaded to our file storage and kept with it. You can clear the photo in the form before saving if you would rather not keep it.
The same upload happens for any photograph you attach yourself, to a bag, a brew, a piece of equipment or a recipe.
Those files sit in storage that is not access controlled. Each one is at a long web address containing your account identifier and a timestamp, and anyone who has that address can open it without signing in. Listing the folder is blocked, so nobody can browse or enumerate them, and the address is only ever stored in your own record and never published by us. But we are not going to describe the files as private, because they are not.
The free scan allowance. Each successful scan writes one row recording your account identifier, which Shelf app ran the scan, what kind of scan it was and the time. That row exists to count your free allowance, which is five AI scans in total, for the lifetime of the account. It is not a daily or monthly allowance and it does not reset. Version 1.0 of this policy described a per-day cap on this app alone. That is no longer how it works.
Those five are not five per app. The count is kept on your ACCOUNT, in one ledger, and the check that reads it does not filter by app. So an AI scan you ran in any Shelf app comes off the same five. We checked the ledger rather than reasoning about it: it currently holds scans recorded by My Bar Shelf, My Cigar Shelf and My Wine Shelf. Not every Shelf app meters its AI features this way, and each of their policies is the place to read how theirs works. Two earlier versions got this wrong in opposite directions: one said the five were shared across every Shelf app, which was more than we had checked, and the correction named three apps as a closed set, which was less than the ledger actually counts.
If you have a subscription you are not metered at all, but the row is still written. Before running a scan our server asks RevenueCat whether your account holds an active subscription, which sends your account identifier to RevenueCat. Section 11 covers that.
Everything else stays free and uncapped: the shelf, adding a bag by hand, the barcode lookup, the brew log and the catalogue.
What we cannot tell you. We call Google’s general endpoint and have not pinned it to a European region, so you should assume the photograph is processed outside the EU. We do not control what Google does with the image after it has read it, and we are not going to state a retention period we cannot verify. Google’s own terms for that API govern it. If that is not acceptable to you, do not use the scan. Adding a bag by barcode or by hand never sends a photograph anywhere.
The camera and photo library notices inside the app describe attaching a picture to a bag, a brew or a piece of equipment, and are silent about the fact that a scanned bag photograph is also read by a vision model. That is an omission we are correcting. This section describes what the app actually does.
6. Barcode lookups
When you scan a barcode on a bag, the app tries our own catalogue first. If that misses, two external sources are asked:
- Open Food Facts, run by a non-profit in France. This request is made by your phone, so Open Food Facts receives the barcode digits and your device’s IP address. If it returns a product image and you keep it, your device loads that image from their servers too.
- Dabas, a Swedish product data service. This request is made by our server rather than your phone, so Dabas receives the barcode digits and never sees your IP address.
Neither receives your account identifier, your email, a photograph or anything from your shelf.
7. Finding a café near you
The app asks for location in one place: when you are logging a brew away from home and want the café list to show what is actually around you. It is a foreground permission, the app never reads your position in the background, and if you decline the feature simply falls back to typing the name.
When you use it, your device takes a single position fix and sends it to our own server function. That function asks a mapping provider what is nearby:
- Geoapify, when we have a key configured for it, or
- OpenStreetMap through the public Overpass service, when we do not.
Both have handled real requests from this app, because the function falls back silently, so both are named here. What they receive is the coordinate pair and a search radius. Because the call is made by our server and not by your phone, neither provider ever sees your IP address, and neither receives your account identifier.
What happens to the fix afterwards:
- The result is cached against a rounded grid square of roughly one kilometre, with the places found, the provider and the time. That cache row carries no user column and cannot be traced to anyone.
- If you then pick a place, we store the venue’s own coordinates on your private café row, once, so the list can rank by proximity next time. Your position is never written to your account.
- Nothing about the fix goes to our analytics provider.
One correction to the notice the app shows you. The iOS location prompt says your approximate position is “never stored and never linked to your account”. The first half is right: nothing writes your position against you. The second half is more than we can promise, because the call to our own server is authenticated, so at the moment your coordinates arrive our function knows which account sent them. We do not record that pairing, and the cache row has nowhere to put it, but a sentence that says never linked claims something the architecture does not guarantee. The wording is being corrected in the app.
8. Apple Health and caffeine
On iPhone, if you grant it, the app connects to Apple Health for one number: caffeine.
- It reads your dietary caffeine total for the day, from every source Health holds, so the figure the app shows is your real total rather than only what you logged here.
- It writes one caffeine sample per brew you log, with the drink type, the machine, the café and the bean origin attached, so the brew appears in the Health app and counts towards your own totals.
Health data itself stays on your device, inside Apple Health. It is not sent to us and it is not sent to anyone else. What does reach our database is the identifier of the sample we wrote, stored on the brew, so that deleting a brew can also remove the Health entry it created. That is a pointer, not a health measurement, but it is a link between your account and a record in your Health store, so it is named here rather than buried.
Health data is a special category under Article 9 of the GDPR. The processing here rests on your explicit consent, given through Apple’s own Health permission sheet, and you can withdraw it at any time in the Health app or in iOS Settings. Withdrawing it stops the reading and the writing, and leaves what is already in Health under your control there.
9. Usage analytics, which are off until you turn them on
The app can send product analytics to Mixpanel, on its EU service. It does not do so unless you switch it on. This is the section version 1.0 got wrong. That version told you analytics began when the app began, that there was no switch, and that we relied on legitimate interests. None of that is true of the app that shipped.
Before you answer. The setting has three states and starts in the third: yes, no, and not asked. While the answer is anything other than yes, the analytics library is never started. No analytics identifier is generated, no connection to Mixpanel is opened, and nothing is transmitted. It is not a filter applied to data that was gathered anyway.
Between opening the app and reading your stored answer there is a fraction of a second, and events that occur in it are held in memory rather than sent, capped at forty. They are only ever sent if the stored answer turns out to be yes.
Turning it on, and off. Profile, then the analytics switch. It covers My Coffee Shelf and no other app. Your answer is stored in a coffee table that no other Shelf app reads, so turning it off here does not turn it off in My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Beer Shelf or My Cigar Shelf, which share a separate answer of their own. Version 2.0 of this policy called it a single setting covering every Shelf app you use, which was false. Section 4 sets out the real division. Anonymous accounts can use the switch too. You can turn it off again at any time in the same place, and you do not have to give a reason.
If you decline, or turn it off later, anything being held is discarded rather than kept for a later yes, the stored analytics identifier is cleared, and the library is shut down. Turning it back on afterwards starts a fresh identifier, so the new events are not joined to the old profile. Events already delivered stay with Mixpanel. Section 17 says what we do about those.
Your answer is recorded on your device, which is what the app acts on, and mirrored to a row on your account as the record that we asked and what you said. If you reinstall or sign in on a second device, that row supplies the answer you already gave rather than asking again. A newer answer on the device always wins.
What is sent once it is on. Around thirty-five named events, each describing something that happened rather than something you wrote: the app being opened, a bag added or edited or finished, a brew logged or shared, a café or a piece of equipment added, maintenance logged, a shopping item added, a screen opened, a scan hitting the limit, a paywall shown or dismissed, a purchase or restore completing or failing, a notification permission asked and answered, a review prompt, the promotional cards for the other Shelf apps being shown or tapped, and the analytics switch itself being changed.
Attached to every event: whether the account has a subscription, whether it is anonymous, how many days since you installed the app, the platform, and how many bags and pieces of equipment you hold. The Mixpanel library also attaches your operating system, its version, and your device model.
Events are identified by your account identifier, not by your name or your email address. That is pseudonymous rather than anonymous, and this policy is not going to call it anonymous.
Never sent: roaster or coffee names, tasting notes, ratings, café names, equipment names, your shopping list, photographs, your email address, or anything else you typed. Two precise exceptions worth naming: a logged brew carries the database row identifiers of the bag, café, equipment and drink type involved, which are random values that mean nothing outside our database but do let one event be tied to another; and a failed purchase or restore carries the error message the store SDK produced.
Approximate location. We do not suppress the IP address on these events, so Mixpanel resolves it to an approximate city, region and country and stores that against the event and the profile. This is derived from the network address of the request and has nothing to do with the location permission in section 7. If you would rather it did not happen, leave the switch off.
10. Crash and error reports
The app reports crashes and errors to Sentry, on its German service. This is always on and is not covered by the analytics switch, because it is how we find out that the app is broken.
Sending personal data is switched off in our configuration, and we never attach an account to a report, so reports do not carry your email address, a username, your IP address or cookies, and no account is filed against them.
A report contains the error and its message, where in the code it happened, the device model, the operating system and version, the app version, the device locale and timezone, and the state of the app at the time. Screenshots, view hierarchies and session replay are not enabled.
The honest limit. The Sentry library records a breadcrumb trail of network requests, storing the method, the web address and the status of each. Many of our database requests filter on your account identifier, which puts it in the web address, so it can land in a crash report even though we never attach it deliberately. And when a database write fails, the error we attach is the database’s own message, which can quote the value that caused the failure. We are not going to claim that a crash report contains nothing about you.
11. Subscriptions and purchases
Some parts of the app are reserved for subscribers, and the free scan allowance in section 5 is one of the limits a subscription lifts.
We do not take your money and we never see your payment details. Subscriptions are sold and billed by Apple on the App Store or by Google on Google Play. Your card, bank details and billing address are held by them, not by us, and are never sent to us.
We use RevenueCat to know whether a subscription is active. RevenueCat receives your account identifier on every launch, whether or not you have ever bought anything, including while your account is anonymous, because the app has to ask it on each launch what that account is entitled to. It also receives your platform and the IP address of the request, from which it derives an approximate country. If you buy or restore a subscription it additionally receives the purchase and receipt information the store issues, and the country of your store account. Our own server asks RevenueCat about your account again whenever you run a scan, to decide whether to meter it.
RevenueCat processes this in the United States. Section 20 covers that transfer.
What a subscription unlocks depends on which one you bought. RevenueCat holds your entitlements against your account identifier, so an entitlement bought in one Shelf app is visible to another asking about the same account. There are two kinds. A bundle subscription is honoured by the Shelf apps that check for it, so it unlocks more than the app you bought it in. A single-app subscription, which is what most current subscribers hold, unlocks the app it was bought for and is not honoured by the others. Version 2.0 of this policy said one subscription covers every Shelf app on the same account. That is true of the bundle and not of the rest, and it should not have been written as a flat rule.
Either way it needs a real account: while you are anonymous your identifier differs per app, so nothing carries across.
Cancel in your App Store account settings or your Google Play subscriptions. We cannot cancel or refund for you. Deleting your My Coffee Shelf account does not cancel a subscription, so cancel it in the store first or billing continues. The Terms of Service set out the renewal and cancellation terms in full.
12. Notifications
If you allow notifications, the app registers a push token with Expo, the service that builds and delivers our push messages, and stores that token on your account. Our server sends the message text to Expo, which passes it to Apple or Google for delivery to your device.
The messages are not generic. A freshness reminder names your coffee, and a maintenance reminder names your equipment. So your own coffee and equipment names leave our infrastructure through Expo and through Apple or Google in order to reach your lock screen. That is how any push notification with useful text works, and it is stated here because a policy that lists the shelf as private without naming this would be misleading.
We keep a record of which reminder rule fired for you and when, so the same reminder is not sent twice. You can turn notifications off in your device settings at any time, which stops delivery.
13. The permissions the app asks for
- Camera and photo library: photographing or choosing a bag, brew, equipment or recipe picture, and the bag scan. Section 5.
- Location, while using the app: finding cafés near you. Section 7.
- Apple Health, read and write: caffeine only. Section 8.
- Notifications: freshness and maintenance reminders. Section 12.
One correction. The Android build declares a microphone permission that the app does not use. There is no audio code anywhere in it and no microphone permission is declared on iOS at all. It is a leftover in our build configuration, it is being removed, and in the meantime nothing in the app records audio.
14. The website
Reading pages on mycoffeeshelf.com does not require an account, and we do not ask you for anything. There is no launch list and no signup form. Version 1.0 of this policy described one in detail, including a hashed IP address stored against each entry. That form no longer exists on this site, and the section describing it has been removed rather than left standing.
The site uses Vercel Web Analytics for aggregate traffic measurement: page views, referrer, country, device, operating system and browser, with a visitor identifier that is hashed and rotates daily. It is cookieless, it does not follow you across sites, and it does not build a profile of you. There are no advertising pixels and no non-essential cookies, so there is no cookie banner.
The site takes part in the Amazon Associates programme. Some pages link to products on Amazon.se, and every such link is marked Ad. If you buy something through one of them, Amazon pays us a commission. The price you pay does not change. These are ordinary links: nothing on our pages loads from Amazon, this site sets no Amazon cookie, and no Amazon script runs here. The link address carries our Associates tag, which tells Amazon the visit came from this site. Amazon does not tell us who you are. From the moment you follow one of these links, Amazon’s own privacy notice applies.
You can sign in on the website with the same account as the app, using an email address and password, a one-time link, Google or Apple, and you can delete your account there. Signing in stores a session in your browser. That is functional storage, not tracking, and it is cleared when you sign out.
Catalogue pages are assembled on our server, so your browser does not talk to our database in order to read them. Two things do reach our database provider in the EU directly from your browser: the pictures on those pages, which are served from our own storage, and anything you do while signed in on My shelf.
Fonts, on three pages only. The main site self-hosts its typefaces, so no request goes to Google when you browse it. This policy, the terms and the deletion page are older static pages that still load their two typefaces from Google Fonts, which means your browser fetches the font files from Google’s servers and Google receives your IP address as part of that request. No font cookies are set. It is a small thing and it is a request to a third country, so it is named. The app does not load fonts over the network; they ship inside it.
15. Who processes your data
| Who | What they receive | Why | Where |
|---|---|---|---|
| Supabase | Your email address and sign-in, everything on your shelf, your photographs, and the IP address of each request | The database, the sign-in system, file storage and our own server functions | EU, Frankfurt |
| Google, Gemini API | The bag photograph and a fixed instruction. No account identifier, no email, nothing from your shelf | Reading the bag so the form fills itself | Not pinned to a region. Assume outside the EU |
| Mixpanel | Only if you consented: the events in section 9, your account identifier, device and operating system, and an approximate location derived from your IP address | Understanding which parts of the app get used | EU |
| Sentry | Crash and error reports. No account attached, with the limit stated in section 10 | Finding and fixing faults | EU, Germany |
| RevenueCat | Your account identifier on every launch, store purchase and receipt data, store country, platform, request IP address | Knowing whether a subscription is active, across the Shelf apps | United States |
| Expo | Your device push token, and the title and text of each notification, which can include your coffee and equipment names | Delivering freshness and maintenance reminders | United States |
| Apple and Google, as stores | Your payment details, which go to them and not to us. Your sign-in identifier if you use Sign in with Apple or Google. Notification text, for delivery | Selling and billing the subscription, distributing the app, signing you in, delivering notifications | Global, per their own terms |
| Geoapify | A coordinate pair and a search radius. No IP address, no account identifier | Finding cafés near you | EU |
| OpenStreetMap, through Overpass | A coordinate pair and a search radius. No IP address, no account identifier | Finding cafés near you when Geoapify is not configured | EU |
| Open Food Facts | A scanned barcode and your device’s IP address | Looking up a bag we do not hold | France |
| Dabas | A scanned barcode. The request comes from our server, so not your IP address | Looking up a bag we do not hold | Sweden |
| Vercel | Website requests, and the aggregate analytics in section 14 | Hosting this website | United States company |
| Google Fonts | Your IP address when this page, the terms or the deletion page loads its fonts | Serving the typefaces on those three pages | Global |
We do not sell your data, we do not rent it, and we do not share it with data brokers. None of the providers above is an advertising network, and we do not use any of them for advertising. We are describing our own configuration and our contracts with them, not making a promise on their behalf about their other business.
There is no advertising in the app, no advertising identifier, and nothing that Apple defines as tracking, so the app does not show the tracking permission prompt.
16. Lawful basis for each purpose
- Performance of a contract, Article 6(1)(b): creating and holding your account, storing your shelf, brews, gear, cafés, recipes and shopping list, running a scan or a barcode lookup or a nearby search you asked for, sending the reminders you enabled, and managing a subscription you bought. Without this there is no service to provide.
- Consent, Article 6(1)(a): usage analytics, and nothing else under this heading. Off by default, switched on only by you, withdrawable at any time in Profile, and withdrawal does not affect what was processed before. Version 1.0 filed analytics under legitimate interests. That was the wrong basis and it is corrected here.
- Explicit consent, Article 9(2)(a): the caffeine data read from and written to Apple Health, given through Apple’s own permission sheet. Section 8.
- Legitimate interests, Article 6(1)(f): crash and error reporting, so the app keeps working; the scan ledger, so the free allowance can be counted and not circumvented; the shared café, roaster and coffee catalogue, so an entry that works for one person works for the next; and aggregate website analytics.
Giving us this data is not a statutory requirement. It is what the app needs in order to be a shelf: without an account there is nowhere to put a bag.
There is no automated decision-making that produces legal or similarly significant effects, and no profiling. The bag reading is a machine guess that fills a form, and you review and edit every field before anything is saved. The caffeine figure is an estimate for your own interest and is not advice.
17. How long we keep things
- Your account and your shelf: until you delete it. There is no expiry and no automatic clear-out.
- Anonymous accounts: the same, indefinitely. We do not run any job that removes an abandoned anonymous account. If you delete the app without ever signing in, the record stays in our database and there is no way for you or for us to get back to it.
- Scan ledger rows: for the life of the sign-in, because the free allowance is a lifetime one and counting it needs the rows. They are not removed by a coffee deletion; they go when the sign-in record goes.
- Data export files: pressing Export writes a file to private storage and gives you a link that expires after seven days. The link expires; the file does not. Nothing deletes it today, including account deletion. It contains your email address, your account identifier, your sign-in timestamps and every table listed in section 3. If you want an export file removed, write to us and we will remove it.
- Photographs: until you delete the item they belong to, or your account.
- Shared catalogue entries you contributed: kept, because other people’s brews point at them. What happens to the record of who added one differs by kind, and version 2.0 of this policy flattened the three into one sentence. A café has its contributor record cleared, but only when your sign-in record itself is deleted; if the sign-in is kept because another Shelf app holds your data, your identifier stays on the café. A roaster or a coffee keeps your identifier on it either way: nothing in the deletion clears those two, on either path. Ask us and we will clear all three by hand.
- Crash reports: kept by Sentry on the standard retention schedule for our plan and then deleted automatically. Reports are not filed under your account, so there is no reliable way to find yours and delete it on request. If you tell us roughly when a crash happened we will look and remove what we can find.
- Analytics already sent to Mixpanel: deleting your account does not delete them, because we do not run a Mixpanel deletion step today. They are keyed to your account identifier. Ask us and we will delete them by hand.
- Your RevenueCat record: the subscriber record keyed to your account identifier stays with RevenueCat after you delete your account, and it exists even if you never bought anything. Ask us and we will remove it.
- Purchase records held by Apple and Google: kept by them as the sellers, on their own schedules and for their own accounting obligations. We cannot delete those for you.
- Backups: deleted rows can remain in our database provider’s routine backups for a period until those backups age out. We are not going to quote a number for that, because it is our provider’s schedule rather than ours.
18. Your rights under the GDPR
You have the right to access your data, to rectification of anything inaccurate, to erasure, to restriction of processing, to object to processing based on legitimate interests, to portability, and to withdraw consent at any time.
Three of these are buttons rather than emails, and the button is faster than writing to us:
- Access and portability: Profile, then the data export option. It produces a JSON file with your account details, your bags, brews, equipment, maintenance, cafés, shopping list, scan history, your recorded analytics answer and your notification history, and gives you a link to download it. The link is good for seven days.
- Erasure: Profile, then Delete account. Or sign in on this website and delete from your account panel. See section 19.
- Withdrawing consent: Profile, then the analytics switch. For Apple Health, the Health app or iOS Settings.
For anything else, write to hello@mycoffeeshelf.com from the address on the account. We will respond within one month, and it is free of charge. If we cannot identify you from what you send us, we may have to ask for more before we can act. If your account is anonymous we may not be able to identify you at all, which is a consequence of it being anonymous rather than a refusal.
You also have the right to complain to a supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY), imy.se. You can also complain to the authority where you live.
19. Deleting your account
You can do it yourself. In the app: Profile, then Delete account, then confirm twice. On this website: sign in and delete from your account panel. No email and no asking us first. The account deletion page sets out the steps and the full list of what survives.
What is removed: every photograph you uploaded, first; then your brews, your bags, your equipment and its maintenance history, your saved cafés, your own drink recipes, your brew adjustments, your scan history within this app, your recorded analytics answer, and this app’s push token and notification history. Photographs go first on purpose: if that step fails nothing else is deleted and you can try again, rather than being left with files no record points at.
What may stay. Your sign-in record is only deleted if the account holds no data in the other Shelf apps. If you also use My Bar Shelf, My Whiskey Shelf, My Wine Shelf, My Cigar Shelf, My Beer Shelf or My Supply Shelf, the sign-in stays and only the coffee data above is removed, so those apps keep working. The app tells you which case applied. Delete your data there too if you want the sign-in gone, or write to us and we will do it.
Two things the delete does not currently reach, and one is a fault of ours. Your shopping list is not in the list of tables the deletion clears. If your sign-in is removed it goes with it; if your sign-in is kept because another Shelf app holds data, the shopping list stays behind. That is a bug rather than a decision, we are fixing it, and until then you can ask us to remove it. Your scan ledger rows and the record of which reminders fired behave the same way: removed with the sign-in, kept if the sign-in is kept.
Section 17 lists what survives a deletion in every case: export files, analytics already sent, your RevenueCat record, crash reports, and the shared catalogue entries you contributed, which keep your identifier on them in the cases section 17 sets out. Ask and we will remove by hand what the button does not.
One more thing about the analytics answer, because it is easy to read the wrong way. Deleting your account here removes the coffee answer. The five other Shelf apps share a separate answer of their own, and a coffee deletion does not touch it. Section 4 explains the split.
If you have an active subscription, deleting your account does not cancel it. Cancel it in your App Store account settings or your Google Play subscriptions first, or the store will keep billing you.
Deletion is permanent. We cannot restore it afterwards.
20. International transfers
Our database, sign-in, file storage, server functions, crash reporting and analytics are hosted in the European Union: the database and storage in Frankfurt, crash reporting in Germany, analytics on Mixpanel’s EU service. The mapping providers are in the EU, one barcode source is in France and one is in Sweden.
These leave the EEA:
- Google receives bag photographs, at a general endpoint we have not pinned to a European region.
- RevenueCat, in the United States, receives your account identifier and your subscription state.
- Expo, in the United States, receives your push token and the text of each notification.
- Vercel, a United States company, hosts this website.
- Google Fonts receives your IP address on this page, the terms and the deletion page.
- Apple and Google handle distribution, payment, notification delivery and, if you use them, sign-in.
For these we rely on the European Commission’s standard contractual clauses, which form part of the data processing terms these providers publish, together with the safeguards described in those terms.
21. Age
My Coffee Shelf is not directed at children. We do not knowingly collect data from anyone under 16, or under the age of digital consent in your country if that is higher. If you believe a child has given us personal data, write to us and we will delete it.
22. Changes to this policy
If we make material changes we will publish the updated version here and update the version number and effective date at the top of this page. If a change materially affects data we already hold about you, we will tell you before it takes effect.
Version 2.3, 5 September 2026, added one thing: the website now carries Amazon links.
- Added: the Amazon Associates programme. Pages on mycoffeeshelf.com link to products on Amazon.se. Every such link is marked Ad, a purchase through one pays us a commission, and the price you pay does not change. The links are plain links, so section 14’s statement that there are no advertising pixels and no non-essential cookies remains true. Section 14 now says what the link address carries and what Amazon does and does not learn.
Version 2.2, 1 September 2026, corrected four things. Three of them are sentences that described the whole Shelf portfolio as uniform when it is not, and the fourth is a correction version 2.1 made in two sections and missed in a third:
- Section 3 still said your name is removed from a contributed catalogue entry “so nothing points back to you”. Version 2.1 corrected that in sections 17 and 22 and left it standing in section 3, so the same document said two different things. The corrected version is the one in section 3 now: a café has your identifier cleared only when your sign-in record is deleted, and a roaster or a coffee keeps it on both paths because nothing in the deletion clears those two columns. Ask us and we will clear all three by hand.
- “Five things are genuinely shared, and each of them is one thing across the whole family.” Two of the five were not. Section 4 now names the apps each one reaches.
- “Five AI scans in total, shared across every Shelf app you use.” The five are shared between My Coffee Shelf, My Whiskey Shelf and My Cigar Shelf, which call the same scan function on our server. The rest of the Shelf apps meter their AI features on their own terms and this policy does not speak for them. Sections 4 and 5.
- “One subscription covers every Shelf app on the same account.” True of a bundle subscription and not of a single-app one, which unlocks only the app it was bought for and is what most current subscribers hold. Sections 4 and 11.
Version 2.1, 1 September 2026, corrected two things in version 2.0:
- Version 2.0 said your analytics answer was shared across the whole Shelf family. Section 4 said “set it here and it is the answer everywhere” and section 9 called it “a single setting that covers every Shelf app you use with the same account”. Both were false. My Coffee Shelf stores its answer in its own coffee table, which no other Shelf app reads, and the other five apps share a separate answer that this app cannot see. The error mattered in the direction that harms you: it implied that switching analytics off here switched them off everywhere. Sections 4, 9 and 19 now say what actually happens, and that turning analytics off across the family takes two switches rather than one.
- Version 2.0 said your name is removed from any café, roaster or coffee you contributed. That is true of a café, and only when your sign-in record is deleted. A roaster or a coffee keeps your identifier on it on both paths, because nothing in the deletion clears those two. Section 17 now separates the three.
Version 2.0, 31 August 2026, replaced version 1.0 in full. What changed:
- Removed the statement that the app had not yet been released. It has been on the App Store and Google Play since August 2026.
- Removed the entire launch-list apparatus: the signup form, the email, the app identifier, the consent flag and wording, the signup timestamp, the page and referrer, the browser language, the hashed IP address, and the whole of former section 2a explaining how that hash was made. No such form exists on this site and the collection it described does not happen.
- Corrected the lawful basis for analytics from legitimate interests to consent. The app ships an opt-in gate: nothing is sent, and no analytics library is even started, until you say yes. Now section 9.
- Removed the statement that analytics start when the app starts, and the statement that there is no opt-out switch inside the app. There is one, in Profile, and it has shipped since launch. Both statements claimed more collection than actually happens and understated your rights.
- Removed the description of camera images as sent for processing and not retained. Your original full-resolution capture is attached to the bag and, if you save it, uploaded to storage whose files are readable by anyone holding the address. Now section 5.
- Corrected the scan cap. It is not three per day for this app. It is five in total, for the lifetime of the account, with subscribers not metered. Now section 5. The description of those five as shared across every Shelf app was itself wrong and version 2.2 above corrects it.
- Removed the statement that data is permanently deleted within 30 days. The deletion runs in one pass when you confirm it, and section 17 now names what it does not reach.
- Corrected the sharing section. Version 1.0 framed sharing as coffee and bar. The login, the subscription, the scan allowance, the deletion probe and the push plumbing all reach past this app, and coffee content is shared with none of them. Now section 4. Two further corrections have been needed since: version 2.1 removed the analytics answer from that list, because coffee keeps its own, and version 2.2 above replaced “shared across the whole Shelf family” with the apps each item actually reaches.
- Removed the promise that we would update this policy before adding tracking. We shipped a subscription provider, mapping providers, a push provider and a Health integration without saying so here, and repeating the promise would not be worth anything.
- Added: RevenueCat, and that it receives your account identifier on every launch rather than only on purchase. Now section 11.
- Added: Geoapify and OpenStreetMap, what they receive, what they do not, and a correction to the location notice the app shows. Now section 7.
- Added: Apple Health, as special-category data under Article 9, including the sample identifier we store on your brew. Now section 8.
- Added: Expo and push notifications, including that reminder text quotes your own coffee and equipment names. Now section 12.
- Added: Dabas as the second barcode source, and the fact that only the Open Food Facts lookup exposes your IP address.
- Added: the shared café, roaster and coffee catalogue, and what happens to an entry you contributed when you delete your account.
- Added: the limit on what a crash report can contain, the approximate location Mixpanel derives from the request IP, the processor table, the transfers out of the EEA, the Google Fonts request on the three static legal pages, and the Android microphone permission the app declares but does not use.
23. Contact
Questions or concerns about your privacy? Write to hello@mycoffeeshelf.com.
Nisshagen Advisory AB, Stockholm, Sweden.