Privacy Policy
Effective date:
This Privacy Policy explains how Aziz Firat (the “Service Provider,” “we,” “us,” or “our”) handles information when you use the kissaten mobile application and the public pages on kissaten.club (collectively, the “Service”).
The choices available to you
You can use the core Application without creating an account. How information is handled depends on the features you use and the settings you enable:
- Guest use: your coffee bags, recipes, notes, favorites, saved cafés, photos, and preferences stay on your device, except for information sent when you use an online feature as described below.
- Optional iCloud sync: guest data can be synced through your personal iCloud account if you enable that feature.
- Optional kissaten account: signing in with Apple enables a private online backup and sync through our service providers.
- Optional public profile: creating a public profile publishes the profile and selected coffee information described below at a shareable kissaten.club address. You can make the profile private again at any time.
Information we process
Information stored only on your device or in iCloud
When you use the Application as a guest, user-created content is stored locally. If you enable iCloud sync, Apple stores and syncs that content through your personal iCloud account. We do not receive content that remains only on your device or in your personal iCloud, except when an Application feature sends information for online processing as described below.
Account and profile information
If you choose to create a kissaten account, we may process:
- A Sign in with Apple user identifier, your email address or Apple private relay address, and your name if you choose to share it
- Your username, display name, biography, profile emoji, avatar, profile visibility, and account timestamps
- Sync and security information needed to operate, restore, and protect your account
Private subscription and online-feature identity
Online features use a private, randomly generated identifier and a Supabase authentication session, including when you have not created a public profile or signed in with Apple. We use this identity to verify Premium access, protect requests, and recover interrupted work. It does not create a public profile or upload your whole local or iCloud library.
RevenueCat processes this subscription identifier, App Store purchase and transaction information, product and subscription status, and relevant app and device information to validate purchases, restore access, and provide subscription reporting. Our backend stores the mapping needed to provide that access. If you sign in, that mapping can be associated with your kissaten account. We do not send your email address or public profile to RevenueCat for this purpose. Apple handles payment information; we do not receive your complete payment card details.
Private account content
Signed-in users can privately sync content such as preferences, coffee bags and their photos, brewing notes, favorite recipes, saved cafés, and related timestamps. This content is associated with your account and is not made public solely because it is synced.
Public profile content
When you create and keep a public profile, anyone with the address may view it. Depending on the content you have added, the page can include:
- Your username, display name, biography, profile emoji, and avatar
- Current and finished coffee bags and selected details such as the coffee name, roaster, origin, farm, process, variety, roast information, rating, tasting or flavor notes, public note, and bag image or coffee story
- Your selected brewers
Public pages may be shared, indexed, cached, or copied by other people and services. Making your profile private removes public access through Kissaten, but copies outside our control may remain.
AI and import features
When an eligible coffee has enough reviewed information and does not yet have a story, the Application automatically sends a limited coffee profile and selected brewer context through our backend to an AI provider to generate the educational coffee story shown for that bag.
Other AI-assisted features, such as scanning or importing an image or URL and generating a recipe, run only when you choose them. Depending on the feature, inputs can include an image, text recognized from the image, a supplied URL, coffee or brewer details, and relevant recipe or preference context.
AI inputs pass through our backend and Cloudflare AI Gateway to providers such as OpenAI or Google. Cloudflare provides routing, usage monitoring, and cost management. We do not use these inputs for advertising or tracking. A coffee story or other resulting content can become public if it is included in content you choose to publish through a public profile.
Privacy-safe product analytics
The Application sends a small set of feature-completion events so we can understand whether scanning and brewing work reliably. An event can include its event name, the production or test environment, a random app-session identifier, app version and build, and a bounded roast-or-process category when a scan needs more information. Our backend associates events using a one-way hash of the verified anonymous or signed-in account identifier.
These events do not include coffee photos, coffee or recipe details, note text, profile data, names, or email addresses. We use them for product analytics and reliability, not advertising or cross-service tracking.
Support, feedback, and technical information
If you contact us or submit feedback, we process the information you provide and technical details needed to understand the request. Infrastructure providers may also process limited request information such as IP address, timestamps, app or browser version, and security logs when the Application or website communicates with online services.
How we use information
We process information to:
- Provide optional accounts, private backup, and synchronization
- Create and serve public profiles when requested
- Verify purchases, restore Premium access, and report subscription activity
- Recover interrupted requests and prevent duplicate processing
- Generate coffee stories and provide AI-assisted recipe and import features
- Respond to support requests and content reports
- Measure feature completion and improve product reliability
- Protect the Service, prevent abuse, and troubleshoot problems
- Comply with legal obligations and enforce our Terms of Use
Legal bases for processing
Where the General Data Protection Regulation or similar laws apply, our legal bases depend on the feature and can include:
- Performance of a contract: to provide an account, sync, a public page, a subscription, support, and the features you request
- Consent: when you grant device permission or make an optional choice that relies on consent; you can withdraw consent through the relevant settings
- Legitimate interests: to secure and improve the Service, prevent abuse, respond to reports, and understand technical failures, balanced against your rights
- Legal obligation: when processing is required by applicable law
Service providers and disclosures
We use service providers only as needed to operate the Service. These can include:
- Apple for Sign in with Apple, iCloud, and in-app purchases
- Supabase for authentication, database, storage, and backend functions
- RevenueCat for subscription verification, recovery, and reporting
- Cloudflare for AI request routing, usage monitoring, and cost management
- OpenAI and Google for AI processing
- Website hosting and delivery providers
Providers only receive the information needed for their role. We require providers that receive personal information to provide the same or equivalent protection described in this Privacy Policy and required by applicable law. We may also disclose information when required by law, to protect the Service or others, or as part of a business transfer subject to appropriate protections.
Providers may process information outside your country, including in the United States and outside the European Economic Area. When required by law, these transfers are subject to contractual or other legally recognized safeguards.
Retention and deletion
- Local content remains until you delete it or remove the Application.
- Personal iCloud content is controlled through your Apple account and device settings.
- Account content is kept while your account is active or as needed to provide the Service.
- AI inputs are processed to provide the requested feature. Our backend also retains request identifiers, request fingerprints, processing status, usage records, and generated results for supported recovery flows, even before you save a result to your library. These records allow retries to recover completed work. They are retained while needed to provide recovery and secure the Service; a failed or canceled request may have no saved result. Cloudflare and AI providers may also retain request or operational records according to their settings and policies.
- Product analytics, support, security, and technical records are retained only as long as reasonably necessary for the purpose for which they were collected, including measuring release reliability, resolving disputes, and meeting legal obligations.
You can delete your kissaten account inside the Application. The deletion flow removes the online account, private online backup, public profile, and uploaded account media. Your local coffee data remains on your device and can return to personal iCloud sync. The current Application removes previous AI request and recovery records for that account while retaining a separate private subscription identity and the purchase and usage records needed to continue Premium without a public profile. This does not cancel your Apple subscription. You can manage it through Apple subscription settings.
To request deletion of private subscription or online-feature records, including when you have no signed-in account, contact us using the address below. Some purchase, security, or legal records may need to be retained for their stated purpose. We will explain any applicable retention when handling your request.
We retain a hashed account identifier, deletion status, and timestamp as needed to document and secure the deletion process. Where billing records are fully erased, a detached, hashed purchase-period usage record may remain until the relevant allowance or grace-access window ends plus 32 days, to prevent reuse of an already consumed allowance. This record has no name, email, account mapping, or AI content. Residual copies may remain temporarily in infrastructure backups or logs until they are rotated. Public caches and copies controlled by other parties may take longer to disappear.
Your choices and rights
You can:
- Use the core Application without a kissaten account
- Decline or revoke optional device permissions
- Make your profile private or delete your account in the Application
- Manage personal iCloud data through your Apple account
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to receive a portable copy, and to withdraw consent. You may also lodge a complaint with your local data protection authority.
To exercise a privacy right or ask a question, contact hi@azizfirat.com. We may need to verify your request before acting on it.
Security
We use technical and organizational safeguards designed to protect information, including account-based access controls and separate public projections for shared content. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
Children’s privacy
Account and public-profile features are not intended for children under 13. If the law where you live requires parental or guardian consent at a higher age, you may use those features only with that consent. Please contact us if you believe a child has provided personal information without appropriate authorization.
No advertising or cross-service tracking
Kissaten does not sell personal information, show third-party advertising, or track your activity across other companies’ apps and websites for advertising.
Changes to this policy
We may update this Privacy Policy as the Service changes. We will update the effective date and provide additional notice when required by law. Material changes apply prospectively from their stated effective date.
Contact
The controller responsible for the Service is Aziz Firat. For privacy questions or requests, contact hi@azizfirat.com.