Privacy Policy

Last updated: TODO: set the real publish date before launch

This draft reflects what Phin actually collects and does with your data today. It has not been reviewed by a lawyer — fill in the bracketed placeholders, confirm the items flagged below with your own diligence, and remove this notice before it goes live.

1. Who is responsible for your data

Phin is currently operated by [Your full legal name / entity once incorporated], based in France, who is the data controller for the personal data described below. Because Phin is used by people in the EU, this policy is written to meet GDPR. If you're located outside the EU, your local privacy law may give you additional or different rights.

No Data Protection Officer has been appointed — for a project this size that's not currently required under GDPR, but revisit this once Phin has scale or processes data at a higher risk level.

2. What we collect

Account data: email address, name, and password (or Google account identifier if you sign in with Google), collected when you create an account.

Waitlist data: just your email address, if you join the waitlist before full launch.

Brewing data you enter: beans (name, roaster, origin, process, roast level, flavor notes), brew logs (method, dose, yield, temperature, time, grind setting, pour stages), tasting ratings and notes (a 5-axis cup profile, overall rating, flavor tags, free-text notes), your gear (grinders, machines, recipes, brew methods), and — if you use bag scanning — photos of coffee bags you upload, which we store.

Usage & device data: collected automatically via analytics (see §4) — pages viewed, general interactions, and standard technical data like browser type and IP address.

3. Why we process it, and on what legal basis

4. Who we share it with

We don't sell your data. We share it with the following service providers, each acting on our instructions to help run Phin:

We don't currently use a separate email-delivery provider for transactional email — once one is added (e.g. for waitlist confirmation emails), this section will be updated to name it.

5. Cookies

Phin currently sets only the essential session cookies needed to keep you signed in (via Supabase authentication). We don't yet have a cookie-consent banner — if or when non-essential cookies (e.g. analytics cookies that aren't strictly necessary) are added, we'll add a consent mechanism before they're set, as GDPR's ePrivacy rules require.

6. How long we keep your data

We keep your account and brewing data for as long as your account is active. If you delete your account, we delete your data as described in §8, except where we're required to keep limited records for legal reasons. Waitlist emails are kept until you ask us to remove them or until you sign up for a full account.

7. Your rights

Under GDPR, you have the right to:

8. Exercising your rights

You can export or permanently delete your account and data at any time from the app's Privacy Center (Profile → Privacy). Export gives you your beans, brews, gear, and recipes; deletion removes that data and your account. For anything the Privacy Center can't do — or to make a formal request — email privacy@phin-app.com.

9. Children

Phin isn't directed at children and requires users to be at least 16. We don't knowingly collect data from anyone under that age.

10. Changes to this policy

We may update this policy as Phin develops. We'll update the "Last updated" date above, and tell you directly about material changes where required by law.

11. Contact

Questions about this policy or your data: privacy@phin-app.com