This policy explains what information Cupmark collects, why, how it's stored, who it's shared with, and the choices you have. It applies to the Cupmark Android app and this website.
We collect only what's needed to run Cupmark's core features — a learning and brewing app built around your own coffee activity.
| Data | Purpose |
|---|---|
| Account & profile info | Create and secure your account, personalize the app, show your identity to others if you choose to make content public |
| Brewing & sensory data | Power the core features you use the app for — recipes, dial-in suggestions, progress tracking, taste profile |
| Progression data | Calculate XP, rank, achievements, and leaderboard standing accurately and fairly |
| Usage & crash data | Fix bugs, understand which features are actually used, and keep the app reliable |
| Push token | Deliver reminders and updates you've opted into |
| Subscription data | Unlock the features your plan includes and manage your trial/subscription |
Cupmark's backend runs on Supabase, which provides our database, authentication, and file storage on top of managed PostgreSQL infrastructure. Data is encrypted in transit (TLS) between the app and our backend. Access to the database is governed by row-level security policies scoped to your own account — in practice, your brewing data, logs, and private profile fields are readable only by you and by backend functions acting on your behalf, except where you explicitly choose to publish something (for example, a community recipe or a public profile). A public profile exists only after you claim a name in Settings. It is then available at cupmark.app/u/your-name without a sign-in, and it shows derived identity — level, skills, badges, and taste summary — not your email or your raw brew and tasting notes.
We don't sell your data. We share the minimum data necessary with the following service providers, each acting as a processor to help us run the app:
| Provider | What it's used for | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | All account and app data described above |
| Google Play Billing | Subscription purchases, trial management, receipt validation | Purchase/subscription status; Google, not Cupmark, handles your payment details |
| Firebase Cloud Messaging | Delivering push notifications | Device push token, notification content |
| Anthropic (Claude) | Powers the in-app AI Coach and other AI-assisted features | The specific question/context you send to the AI Coach, and relevant brewing context needed to answer it — see below |
| Sentry | Crash and error reporting, when enabled | Technical error details and device/app diagnostic context — not your coffee or account content |
We may also disclose information if required by law, to protect the rights and safety of Cupmark or our users, or in connection with a merger, acquisition, or sale of assets — in which case we'll make reasonable efforts to notify affected users.
Cupmark's AI Coach feature sends the question or context you provide — and relevant brewing context needed to give a useful answer (for example, your current recipe or recent sensory notes) — to Anthropic's Claude models to generate a response. This exchange is used to answer your query and is not used by us to build an advertising profile. See Terms of Service — AI Coach for important limits on what this feature is (and isn't) a substitute for.
Subscriptions are billed and managed entirely through Google Play Billing. Cupmark receives subscription status (active, trial, expired, cancelled) and plan details from Google so we can unlock the right features — we never see or store your card number or other payment instrument details.
You can:
If you're located somewhere with statutory rights beyond these (for example under GDPR or CCPA/CPRA), those rights apply to you in addition to what's described here — contact us and we'll handle the request under the applicable law.
We retain your account data for as long as your account is active. When you delete your account, we delete your personal data and content within the timeframe described on the Account Deletion page, except where we're required to retain limited records (for example, transaction records needed for tax, accounting, or fraud-prevention purposes) — retained data of this kind is minimized and, where practical, anonymized or aggregated so it can no longer identify you.
Cupmark is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at info@cupmark.app and we'll delete it.
We use industry-standard safeguards — encryption in transit, access controls, and row-level database security scoped to each account — to protect your data. No method of transmission or storage is 100% secure, and we can't guarantee absolute security, but we work to keep these protections current.
Our service providers may process and store data in countries other than your own. Where this happens, we rely on our providers' own safeguards (such as standard contractual clauses, where applicable) for cross-border transfers.
We may update this policy as the app evolves. If we make a material change, we'll update the "Last updated" date above and, where appropriate, notify you in the app.
Questions about this policy or your data can be sent to info@cupmark.app.