Cafie Privacy Policy

Effective date: 25 September 2026 Last updated: 17 September 2026 Applies to: the Cafie mobile application (iOS and Android) and the Cafie website.


1. Who we are

Cafie ("Cafie", "we", "us") is developed and operated by ALBERTO GAUDICOS JR, an individual developer based in Philippines. We are the data controller for the personal information described in this policy.

Contact for all privacy matters, data requests, and support: support@cafie.app

We answer privacy requests within 30 days.

2. The short version

  • Cafie exists to share coffee selfies inside small groups. Photos are the core of the product, and photos of your face are the most sensitive thing we hold. We treat them accordingly.
  • We do not sell your personal information. We do not share it for advertising. There are no advertising SDKs, no trackers, and no analytics profiling in the app.
  • We do not use your photos to train artificial intelligence models, ours or anyone else's.
  • We do not use face recognition and we never create a faceprint or any other biometric identifier from your photos. See Section 5.
  • Your selfie is shown to the other members of the brew circle it joins. On the free plan those members may be people you have never met, matched automatically. Read Section 7 before you submit a photo.

3. Who may use Cafie

Cafie is for people aged 16 or older. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If we learn that we hold information about a user under 16, we delete the account and its content promptly.

Sixteen is the highest age of digital consent set anywhere in the European Economic Area or the United Kingdom, so every Cafie user is old enough to consent to this processing themselves. We therefore do not ask for, or rely on, a parent's consent.

A parent or guardian who believes their child has created an account, or who wants an account removed, should email support@cafie.app and we will remove it.

Please read Section 7 with particular care if you are under 18. On the free plan your photograph is shown to people you have not met, and any of them can save the finished collage and share it outside Cafie.

4. What we collect

We collect only what the app needs to function. Every item below corresponds to something the app actually stores.

4.1 Information you give us

DataWhere it comes fromWhy we hold it
Email addressYou, at sign-upAccount identity, sign-in, password reset, service notices
PasswordYou, at sign-upStored only as a salted hash by our authentication provider. We never see or store your plaintext password.
Display nameYouShown to your friends and to the members of any brew circle you join
Profile photo (avatar)YouShown to your friends and circle members
Coffee selfiesYour device camera, at capture timeThe core feature: validation, your private gallery, and the collage
Friend requests you send and acceptYouBuilding your friends list, which gates who can be invited to a private circle

Cafie is camera-only. There is no gallery or photo-library import, so we never gain access to your existing photo library, and the app does not request photo-library permission.

4.2 Information collected automatically

DataDetailWhy we hold it
Time zoneYour device's IANA time zone name (e.g. Asia/Manila) and UTC offsetCoffee windows open at the same local time-of-day everywhere; this is what makes that possible. Refreshed each time you sign in or your session is restored.
ContinentDerived on our server from the time zone aboveGroups you into the right regional matching pool
Push notification tokenFirebase Cloud Messaging token plus platform (ios / android)Delivering the notifications you enable: a collage is ready, a window is closing
Install identifierA stable per-installation identifier, recorded against the accounts that sign in on itAbuse prevention only: detecting one person running many accounts to game a single brew circle. It is an append-only record, readable only by us.
App version and diagnostic logsStandard server-side request logsDebugging, security, abuse investigation

We do not collect precise or coarse location. No GPS, no IP-based geolocation lookup, no location permission. Time zone is not location: it tells us the hour where you are, not where you are. Continent is derived from that time zone, not from any positioning signal.

4.3 Subscription information

Purchases are processed by Apple (App Store) or Google (Play Store). We never receive or store your card number, billing address, or any payment credential.

We use RevenueCat to reconcile subscription state. RevenueCat is given your Cafie user ID as its customer identifier, and returns your entitlement status. We store only the resulting plan (free or premium) and the number of free uploads you have used.

4.4 Information we do not collect

For the avoidance of doubt, Cafie does not collect contacts, calendar, health data, precise location, browsing history, advertising identifiers (IDFA/AAID), or any data for third-party advertising or cross-app tracking. We do not ask for App Tracking Transparency permission because we do not track you.

5. Face detection, and why it is not biometric identification

This section matters, so it is written plainly.

On your device, before capture. Cafie runs Google ML Kit locally to check that the frame shows exactly one face, is in focus, and is bright enough. This runs entirely on your phone. Nothing from this step (no image, no face geometry, no measurement) is transmitted to us or to anyone else. It exists solely to stop you from uploading an unusable photo.

On our server, after upload. Your uploaded photo is sent to Google's Gemini vision model to answer three questions: is there coffee in the frame, is the subject a real human being, and is this an authentic in-the-moment selfie rather than a screenshot or a photo of a screen. The model returns a pass or fail. It does not identify you.

What we do not do:

  • We do not perform facial recognition or facial matching.
  • We do not generate, store, or derive a faceprint, face template, face embedding, face-geometry scan, or any other unique biometric identifier from your face.
  • We do not attempt to determine your identity, age, gender, race, emotion, or any other characteristic from your face.
  • We do not compare your face against any database, ours or a third party's, and we do not maintain such a database.
  • Your photos are not used to train Google's models or ours. We use Gemini's paid API tier, whose terms bar Google from using submitted content to improve its products. Google may retain a submitted image briefly to check it against its own abuse policies, and deletes it after that window.

We therefore do not collect "biometric identifiers" or "biometric information" as those terms are defined in the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, or comparable laws. Photographs of your face are still personal data (and, in the EU/UK, potentially sensitive data), and we protect them as described throughout this policy.

6. How we use your information, and our legal bases

Where the GDPR or UK GDPR applies, our legal bases are noted in brackets.

  • Creating and maintaining your account, signing you in (performance of a contract)
  • Capturing, validating, storing, and displaying your coffee selfies (performance of a contract; and your explicit consent for the processing of images of you, which you may withdraw at any time by deleting the photo or your account)
  • Screening uploads for coffee, a real person, and authenticity (legitimate interests: keeping the product what it claims to be, and keeping unwanted content out of other people's collages)
  • Forming brew circles, matching free-tier users into groups, and generating collages (performance of a contract)
  • Sending push notifications you have enabled (consent: the OS-level permission is the consent, and revoking it in system settings withdraws it)
  • Managing subscriptions and entitlements (performance of a contract)
  • Detecting and preventing abuse, fraud, multiple-account manipulation, and objectionable content (legitimate interests; legal obligation where applicable)
  • Responding to your support and privacy requests (legal obligation; legitimate interests)
  • Security, debugging, and keeping the service running (legitimate interests)

We do not carry out automated decision-making that produces legal or similarly significant effects. Photo validation is automated, but its only consequence is that a photo is rejected, and you may retake and resubmit, or contact us.

7. Who else can see your photos

Read this before submitting a photo.

  • A submitted selfie is not public and is never posted to an open feed or indexed by search engines.
  • When your photo joins a brew circle, every other member of that circle sees it, both individually and composited into the finished collage.
  • On the Premium plan you choose the members, and only people who are already your accepted friends can be invited.
  • On the Free plan, Cafie matches you automatically with other users you have not met, in groups of up to three, drawn from the pool of people brewing in your region during the same window. You will not know who they are before you submit.
  • Once a collage is generated, any member can save it to their device and share it outside Cafie: to a messaging app, a social network, anywhere. We cannot control, recall, or delete a copy that has left the app. Deleting your account does not retrieve it.

If you are not comfortable with a photograph of your face reaching strangers and potentially being re-shared, do not submit a photo on the free plan.

8. Who we share information with

We share personal information only with the service providers below, only to the extent each needs it to do its job, and under contracts that bar them from using it for their own purposes.

ProviderWhat it handlesData involved
SupabaseAuthentication, database, file storage, serverless functionsEverything in Section 4 (our hosting backbone)
Google (Gemini API)Server-side photo validationThe uploaded image, at validation time
Google (Firebase Cloud Messaging)Push notification deliveryPush token, notification payload
RevenueCatSubscription stateYour Cafie user ID, entitlement status, purchase events
Apple / GooglePayment processing, app distributionPurchase transactions, handled by them and not visible to us
VercelMarketing site hostingWebsite requests only; no app account data

Beyond these, we disclose personal information only:

  • to other users, as described in Section 7;
  • when you ask us to;
  • to comply with a law, subpoena, or valid legal process, or to protect the rights, safety, or property of Cafie, our users, or the public; and
  • to a successor in the event of a merger, acquisition, or sale of assets, in which case we will notify you and this policy will continue to apply until you are told otherwise.

We have never sold personal information and we do not share it for cross-context behavioural advertising.

9. International transfers

Our providers operate servers in the United States and other countries, so your information will be processed outside your country of residence. Where information is transferred out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the providers listed in Section 8.

10. How long we keep things

DataRetention
Photos that fail validationDeleted from storage immediately, along with their database record. Rejected images are removed, not merely flagged.
Uploads that stall mid-validationSwept and deleted automatically by a scheduled cleanup job
Approved photosKept in your private gallery until you delete the photo or your account
CollagesKept while the account exists, so members can revisit them. A collage includes other members' photos, so removing your account removes your image from your own copy but cannot alter copies others have already exported.
Brew circle and membership recordsKept while the account exists
Push tokensUntil the token rotates, you sign out, or you delete your account
Install/account records (anti-abuse)Up to 24 months from last activity
Server and security logsUp to 90 days, except where a longer period is needed for an active investigation
Account records after deletionErased within 30 days, except anything we must retain by law (e.g. tax records of a purchase)

11. Your rights and choices

Inside the app you can, at any time:

  • change your display name and avatar;
  • delete an individual photo;
  • turn notifications off (in Cafie's settings or your device's system settings);
  • manage or cancel your subscription (via your Apple ID or Google Play account); and
  • delete your account permanently, from Account Settings, which erases your profile, your photos, your queue entries, your circle memberships, and your device records.

Depending on where you live, you also have the right to: access a copy of your data; correct inaccurate data; delete data; obtain a portable copy; restrict or object to certain processing; withdraw consent; and lodge a complaint with your data protection authority. In the EU/UK you may complain to your national supervisory authority; in the Philippines, to the National Privacy Commission.

California residents (CCPA/CPRA): you have the rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of, and we do not offer financial incentives for data. We will not discriminate against you for exercising any right.

To exercise any right, email support@cafie.app from the address on your account, or use the in-app controls. We do not charge for this and we will not ask you for more information than we need to verify who you are.

12. How we protect your information

  • All traffic between the app and our servers is encrypted in transit (TLS).
  • Data is encrypted at rest by our hosting provider.
  • Photos live in a private storage bucket: there is no public URL. Access is granted per request and only to the owner and their circle members.
  • Database access is governed by row-level security policies, enforced by the database itself, so one user's rows are not reachable from another user's session.
  • Passwords are salted and hashed by our authentication provider; we never handle plaintext.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulator as required by law.

13. Apple App Store privacy labels

The "App Privacy" section of Cafie's App Store listing reflects this policy. Summarised, Cafie collects data linked to your identity in these categories: Contact Info (email), User Content (photos, display name, avatar), Identifiers (user ID, install identifier), Purchases (subscription status), and Diagnostics. Cafie collects no data used to track you across other companies' apps or websites.

14. Changes to this policy

We will update this page when our practices change, and we will change the "Last updated" date. If a change is material (a new category of data, a new purpose, a new recipient), we will notify you in the app or by email before it takes effect, and where the law requires it, ask for your consent.

15. Contact

ALBERTO GAUDICOS JR Email: support@cafie.app Website: https://cafie.app

If you are in the EEA or UK and cannot resolve a concern with us directly, you may contact your local data protection authority.