Privacy Policy
Privacy Policy
CoffeeCherry operates beanote. This policy explains how we handle your account and coffee-record information, share links you create, required service data, optional model-improvement images, and historical Community data—and the choices you have.
Effective date and last updated: September 29, 2026
1. Operator and Contact Information
CoffeeCherry is the data controller for beanote. You may use the contact information below to request access to, correction of, or deletion of personal information, restriction of processing, withdrawal of consent, or help with any other privacy question.
2. Information We Process and Why
| Category | Information processed | Purpose | Legal basis or choice |
|---|---|---|---|
| Account and authentication | Email address, authenticated user ID, and technical information about login method, login time, and session | Registration, email OTP login, account security, and prevention of misuse | Necessary to create and perform your account agreement; PIPA Art. 15(1)(4), where its conditions are met |
| Consent and policies | Required and optional consent items, policy version, time of consent, refusal or withdrawal, language, platform, and app version; and, where previously collected, a Community Posting Terms acceptance (community-terms-v1) | Recording and enforcing current consent choices, preventing service use before required acceptance, and retaining prior-version policy evidence where needed | |
| Profile and settings | Nickname, profile image, language, theme, coffee equipment, and preference settings | Providing personalized records, recommendations, and screens | |
| Coffee records | Coffee names, roasters, cafés, brewing recipes, optional purchase and roast dates, ratings, notes, and times; and, only after you choose to share, a random share-link ID and the version of the source record | Saving personal records; providing history, comparisons, and recommendations; creating a revocable preview available only through the exact link you choose to share; and, after you accept the current required agreements, validating official roaster or café profile links and an approved logo | |
| Historical Community data and safety records | Where created under earlier versions: public nickname; post and reply text; up to four optional client-resized, EXIF/GPS-free JPEGs per item; image dimensions and storage metadata; post and parent identifiers; timestamps; deletion and moderation status; report reason and reporter; and blocked-user relationship | Responding to access or deletion requests, preserving required reply structure, safety, abuse-prevention, moderation, dispute, and legal evidence, and complying with legal obligations. Version 1.1 does not publish this data in a feed, management screen, or Community permalink preview. | |
| Core photo analysis | A high-quality, EXIF/GPS-free JPEG copy created by the app's on-device canvas with a longest edge of no more than 4096px; raw OCR text and extracted fields; analysis candidates and confidence scores; and user corrections | Recognizing coffee information, conditionally completing missing fields through the paid Gemini service when needed, suggesting analysis results, and creating records | Your existing express consent to core photo analysis and your request to analyze a selected photo |
| Nearby café search | Your optional nearby-search choice: Google Maps search consent on the server and a location choice for the authenticated account on this device; a generic café query on entry or a name you type and, only for a foreground search with OS permission, current latitude/longitude; a separate confirmation event records account ID, time, fixed purpose, provider, and notice version, but not the query or coordinates | Return nearby results through Google Places Text Search and document location use | Separate affirmative nearby-search choice in the initial consent review or Settings, under Location Information Act Arts. 15 and 19 for location use; the Art. 16 confirmation event is kept for six months. Declining stops Google search and location use but does not restrict Lens or core features; no background location use. |
| Images for model improvement (optional) | High-quality, EXIF/GPS-free JPEG copies of photos newly uploaded after optional consent, and records of that consent and its withdrawal | Improving the quality of beanote's recognition model and managing retention and deletion of contributed copies | Separate express consent; optional and OFF by default |
| Usage and diagnostics | Feature-use events, screen and session identifiers, access times, error and server-request logs, and device and browser information | Service operation, incident analysis, security, and aggregated usage statistics | Only as necessary for requested service operation or security, under the applicable PIPA basis; no unrelated advertising profile |
| Customer support | Email address, request details and attachments, and handling history | Reviewing and responding to requests and handling disputes and incidents | Your support request, the service relationship, or a legal obligation, as applicable |
Nearby Café Search
Nearby café search, introduced in native 1.3.6, is location-based. The initial consent review has three required agreements and offers nearby café search and images for AI model improvement as two separate optional choices. Agree all includes both, but neither is needed for Lens or core features. A choice before sign-in is only a draft. After agreement to the required terms, Google Maps search consent is saved on the server while location choice and time are saved for this device's authenticated account. Turning nearby search off stops both Google search and location use; internal suggestions and manual place entry remain available. Settings > Privacy keeps the AI and nearby-search switches visible in the same card. The nearby-search switch can be turned on after a summary of the purpose, the recipient Google LLC, and expandable details, or turned off at any time. No additional search consent popup is shown. You can also contact beanote Support.
In native 1.4.1, entering the foreground Lens café-search step after opting in starts a nearby query and obtains one location fix for that visit if OS permission allows it. The initial query is for cafés; a name you type narrows the distance-ranked results using the same current coordinates through beanote to Google LLC. The app never accesses location in the background. If OS access is denied or the fix times out, it does not request nearby ranking; separately approved typed name-only search and manual entry remain available. beanote does not persist or log raw queries or coordinates. Google results remain transient; if you choose a café, only its place ID and your editable label are saved with the record, not the provider address or other results. A location-bearing request records only account ID, time, fixed purpose, Google LLC, and notice version for six months from that search, including after withdrawal or account deletion. The event contains no query or coordinates and is then deleted.
beanote does not provide personalized third-party advertising or sell personal information. New coffee records, photos, notes, and recipes are not automatically shared with other users. In the signed-in same-coffee comparison, beanote uses only coffee records belonging to the current signed-in account. It may show selected details from those records, such as a rating, date, place, note, or brew information, to help you compare repeat coffee experiences. It does not display record photos, Community averages, or data from other users, and comparison does not make any record public.
When a signed-in user chooses Create share link for one coffee record, beanote creates an unlisted, random https://beanote.me/records/<share-id> address. Anyone with that exact address may view the coffee name, roaster, rating, calendar date, home-or-café context, place, brew method, coffee details, user note, and recipe without signing in. The page excludes the record photo, nickname, profile, account and source-record identifiers, matching data, groups, and all other records. Search engines are instructed not to index the page, and browsers are instructed not to store it. Editing the source record disables the current address so later additions are not silently exposed; sharing again creates a new random address. Stopping sharing, deleting the record, or deleting the account removes beanote access to the address. beanote cannot retrieve a link that someone has already forwarded, a screenshot, a link-preview cache, or another copy made by a recipient. The original coffee record remains private and cannot be read anonymously.
Community is not available in version 1.1. Its Community tab displays only the noticeA better community is on the way.
; it has no public feed, post or reply controls, post-management screen, or Community permalink preview. We do not use version 1.1 to republish Community content created under earlier versions. This notice is a compatibility explanation only and does not reveal prior posts or enable Community functions. Historical Community data may still be processed only for the purposes described in this policy, including retention, deletion, safety, dispute, and legal obligations.
beanote no longer offers general coffee logging on the web or a Community interface. Those routes lead to the installation guide or service home; they do not reopen the web app. This does not itself delete account data, coffee records, or historical Community data. The iOS App Store link is active. The Google Play link is also active now that Android is publicly available. The web host continues to process APIs and app links and to provide the protected admin console, legal and support pages, data-deletion and account-deletion flows, and exact-link coffee-record previews.
Earlier Community versions could process up to four attachments per item. Before a past submission was accepted, the app redrew each selected image, removed EXIF and GPS metadata, limited the longest edge to 1,800px, and targeted each JPEG at 950KB or less; selected originals did not leave the device. The server accepted at most 1MB per image, re-encoded each JPEG without metadata, and sent only that sanitized copy to Google Cloud Vision for SafeSearch and OCR safety screening. Historical approved copies remain private while retained. Version 1.1 does not accept new Community attachments, publish them, or create Community preview URLs.
3. Core Photo Analysis
Before starting the app, you must review and expressly agree to the required Core Photo Analysis notice. Photo upload and analysis begin only after the server confirms that this agreement is active.
- Before upload, the app draws the selected photo onto an on-device canvas and re-encodes it as a high-quality JPEG copy whose longest edge is no more than 4096px.
- Canvas encoding removes device-file metadata such as EXIF, GPS, and the filename. The file selected on your device itself is not uploaded.
- Photo encoding removes EXIF/GPS metadata; photo-analysis inputs do not contain photo-derived location information.
- The metadata-free, high-quality JPEG copy is processed by beanote servers and Google Cloud Vision, and the returned OCR text is analyzed by beanote servers to recognize coffee information.
- Version 1.0.2 and requests without a verified 1.0.3-or-later capability remain Vision-only and never send a photo or OCR text to Gemini.
- For version 1.0.3 or later, only after the current required photo-analysis notice has been expressly accepted and the server-side rollout gate is enabled, the paid Google Gemini service may be used when Vision OCR and beanote analysis cannot identify needed coffee fields sufficiently. When usable OCR evidence exists, only the minimum OCR text needed to fill missing fields is sent; the same sanitized JPEG copy and necessary OCR context are sent only for visual fallback signals such as failed or weak OCR.
- Google LLC processes paid Gemini requests as beanote's processor. Paid-service inputs and outputs are not used to improve Google products. Limited provider security and abuse-monitoring records may be processed under Google's paid-service settings. Equipment, preference profiles, and account identifiers are not included in these requests.
- On version 1.0.4 or later, only after you accept the current Privacy Policy and the server rollout gate is enabled, beanote may send the saved roaster or café name by itself to the paid Gemini service with grounded web search to propose official Instagram, Naver Store, Naver Place, and logo-source candidates. The request excludes your user ID, record ID, photos, notes, recipe, rating, timestamps, and device or GPS location.
- Provider output is never treated as authoritative. beanote separately validates the direct destination, business identity, and availability; search-result or guessed URLs are not stored as verified links. Logo candidates remain private until a human reviewer confirms the exact bytes and content-rights evidence.
- For each sanitized analysis-original JPEG copy and intermediate or derivative JPEG copy retained in private storage for OCR and analysis, deletion begins once 365 days have passed from creation. If you permanently delete your account, deletion of linked analysis copies begins sooner.
- A JPEG copy displayed with a record is retained for as long as that coffee record is maintained. If you delete the record or permanently delete your account, deletion of the linked display copy begins.
4. Optional Consent for Model-Improvement Images
Providing images for model improvement is optional, independent of core photo analysis, and OFF by default. You may use beanote features, including core photo analysis, without consenting.
Once enabled, this preference remains ON until you turn it OFF or permanently delete your account. Each contributed copy is retained for no more than 365 days from creation.
- Only photos you upload after turning this setting ON may be used to improve beanote's recognition model. The same high-quality, EXIF/GPS-free JPEG copy created for core analysis is used for this purpose.
- A copy covered by active optional consent is retained exclusively in dedicated private Google Cloud Storage.
- Deletion of a model-improvement copy in Google Cloud Storage begins 365 days after its creation. If you withdraw optional consent or permanently delete your account sooner, we schedule the copy for deletion before the 365-day period ends.
- While the setting is OFF, no new model-improvement copy is contributed. If you switch from ON to OFF or withdraw consent, we schedule existing contributed copies for deletion and retry failed deletion jobs.
- Even when optional consent is ON, EXIF/GPS and location information are not included in a model-improvement copy or separately transmitted, stored, or used.
Due to the nature of networks and provider operations, deletion may not finish immediately in a single attempt. beanote retries deletion jobs and verifies completion.
5. Retention and Deletion
- Account and profile: until you permanently delete your account
- Coffee records, recipes, ratings, notes, and JPEG copies displayed with records: until you delete the applicable record or permanently delete your account
- Coffee-record share links: until you stop sharing, edit or delete the source record, or permanently delete your account; re-sharing creates a new random address, while copies already made by a recipient cannot be recalled
- Historical Community posts, replies, and optional sanitized JPEG attachments: until the applicable item or account is deleted, subject to a lawful retention requirement. Deletion removes the content and linked attachment from beanote access, while a minimal de-identified structural record may remain only as needed for a deletion request, safety, moderation, abuse prevention, dispute, or legal obligation. Version 1.1 does not provide a Community public permalink preview. beanote cannot recall copies made by third parties before the pause.
- Historical Community safety records: a prior block is deleted when it is undone or either account is deleted; a report submitted by an account is deleted with that reporting account; a report and moderation evidence about an already de-identified item may remain with its structural placeholder only until the related review, safety, dispute, or legal purpose ends or applicable law requires deletion or longer retention
- Scan and usage events: until account deletion or until the applicable service-operation or security purpose ends
- Required and optional consent records: until account deletion or until any retention requirement under applicable law ends
- Nearby-search location-use confirmation events (account ID, time, fixed purpose, provider, and disclosure version; no query or coordinates): six months from each search, including after consent withdrawal or account deletion, then deleted
- Sanitized analysis-original JPEG copies in private storage: up to 365 days from creation
- Intermediate and derivative JPEG copies for OCR and analysis: up to 365 days from creation
- High-quality JPEG copies for model improvement in Google Cloud Storage: up to 365 days from creation; deleted earlier if optional consent is withdrawn or the account is permanently deleted first
- Customer-support records: for as long as needed to resolve the request and respond to disputes
- User ID used for the final account-deletion check: until the final storage check is complete, at least 25 hours after the deletion request
- De-linked asset ID used to prevent reuse in model improvement: for as long as needed to prevent a withdrawn copy from being included in a future dataset
When a retention period ends, we delete the information using methods designed to make recovery impracticable. If the law requires separate retention, only the required information is isolated for the statutory period and then deleted. Provider backups may remain isolated until they expire under each provider's regular overwrite and deletion cycle.
We begin deleting linked storage immediately after account deletion, then conduct a final check after 25 hours, once previously issued upload URLs have expired.
6. Service Providers and International Transfers
The providers below process information only as needed for the disclosed service or feature. Information is transmitted over encrypted networks. You cannot begin using beanote until you accept the required agreements, including the Privacy Policy and core photo-analysis notice. Refusing model-improvement image consent does not affect service use. Photo-derived EXIF/GPS metadata is removed before upload. Nearby-search coordinates are sent in native 1.4.1 only after you enter the foreground Lens café-search step with nearby search enabled for the authenticated account and OS access granted. The initial nearby query and later typed names use one location fix for that visit; the coordinates are not retained by beanote. Google Places processes that request under its applicable terms and privacy policy.
| Processor or recipient | Location and transfer | Information and purpose | Retention |
|---|---|---|---|
| Supabase, Inc. | United States (us-west-1); encrypted transfer when account or storage features are used | Storage and authentication involving account identifiers, email addresses, consent status, profiles, private records, historical Community data and safety evidence where retained, and high-quality EXIF/GPS-free analysis and derivative JPEG copies | Each applicable beanote retention period in Section 5 and the provider's backup-expiration cycle |
| Vercel, Inc. | United States and global infrastructure; encrypted transfer during native API, app-link, and public legal/support requests | Request and device technical information, historical service-request data where retained, and deployment, security, and error logs | Until service processing is complete and for the period needed for operational and security logs |
| Google LLC (Cloud Vision, Cloud Storage, paid Gemini API) | Republic of Korea, United States, and countries where Google infrastructure is located; encrypted transfer during historical Community-image safety processing, core photo analysis, official-profile discovery after you accept the required agreements, or retention of an optionally contributed copy | Where previously submitted, SafeSearch and OCR safety screening of a sanitized, server-re-encoded Community JPEG; Vision analysis of high-quality EXIF/GPS-free JPEG copies; conditional paid-Gemini processing of the minimum OCR text needed to fill missing coffee fields and, only if needed, the same sanitized JPEG copy; on version 1.0.4 or later and after you accept the current required agreements, processing of a saved roastery or café name alone to propose public official-link and logo-source candidates; private retention of high-quality JPEG copies covered by optional model-improvement consent | Historical Community-moderation JPEGs were processed for the pre-publication screening request under Google Cloud service settings. Paid Gemini inputs and outputs are not used to improve Google products and are processed for service delivery and the limited period required by applicable security and abuse-monitoring settings. Analysis and model-improvement copies retained by beanote are each kept for up to 365 days from creation; if optional consent is withdrawn or the account is permanently deleted first, the applicable model-improvement copy is deleted earlier. |
| Google LLC (Google Places Text Search) | Google infrastructure locations; encrypted request only after agreement to the required terms and Google Maps search consent, when you enter the Lens café-search step in the native 1.4.1 app or initiate a search in an earlier supported version | A generic café query on entry or a name you type and, only with device location enabled and OS permission, current latitude/longitude; beanote returns transient results with required Google attribution. Only a place ID and your editable café label are saved if you choose a result; provider address and other results are not saved | Under the Google Maps Platform Places policies, Google Terms of Service, and Google Privacy Policy. beanote does not retain the query or coordinates and keeps only the six-month location-use confirmation event described in Section 5 |
7. Your Rights and Consent Management
You may exercise the following rights through the profile and records screens in the app or through customer support.
- Accessing and correcting your information and deleting individual records
- Requesting access to, correction of, or deletion of historical Community data through customer support or account deletion, subject to applicable retention requirements
- Switching optional model-improvement image consent OFF or withdrawing it
- Changing, withdrawing, or suspending future nearby-search location use anytime with the visible switch in Settings > Privacy or through customer support; required use-confirmation records may remain for their statutory retention period
- Withdrawing a required agreement and requesting termination of service use
- Requesting deletion of your entire account in the app or on the web account deletion page
- Requesting restriction or deletion of personal-information processing and receiving the outcome of your request
Refusing or withdrawing optional model-improvement image consent does not prevent you from continuing to use core photo analysis or other features. After withdrawal, optional processing does not apply to later uploads, and we schedule existing contributed copies for deletion. If you withdraw a required agreement, you must stop using the service, but customer support and the account deletion page remain available.
To protect your account and personal information, we may require identity verification such as an email OTP. After account deletion is complete, you cannot log in and related records cannot be recovered. The minimal nearby-search location-use confirmation event described in Section 5 remains for six months from its search date, including after account deletion, then is deleted.
Version 1.1 has no public Community view, interaction controls, management screen, or Community permalink preview. A historic deletion request removes the applicable content and attachment from beanote access when deletion is required; a minimal de-identified structural record may remain only for the purposes in Section 5. beanote cannot recall copies made outside beanote before the pause. Historical report or moderation matters may be raised with customer support.
8. Security Measures
We apply reasonable technical and administrative safeguards, including canvas re-encoding and metadata removal before upload, encryption in transit, private image storage and short-lived signed URLs, least-privilege access, restricted administrator access, content filtering, protection and deletion of historical Community data and related safety evidence, retry and verification of deletion jobs, and server-only storage of secrets.
9. Users Under 18
beanote is not directed to anyone under 18, and anyone under 18 may not register or use the service. If you learn that information about a user under 18 has been processed, please notify customer support.
10. Changes to This Policy
This revised policy takes effect for beanote 1.3.6 only after you expressly accept it; the prior accepted version remains in effect until then. We will give at least seven days' notice before an ordinary material change and at least 30 days' notice before a material change unfavorable to users, unless a legal requirement, security threat, or other urgent circumstance requires earlier action. A change requiring consent applies to you only after you review it and expressly agree again. Previous versions remain available in the July 17, 2026 Privacy Policy.
Optional Google Maps place search
When this feature is available, you can separately allow Google Maps search to find a café or roastery while logging a coffee. Declining or turning it off does not prevent manual entry, photo analysis, or other coffee-record features.
After you allow search, beanote sends your search text, search language and a temporary search-session token to Google LLC through its server. Selecting a result also sends that place’s Google place ID to request its details. These requests use encrypted connections to Google’s global infrastructure when you search or select a place. Photos, your account email and device GPS location are not included. Avoid entering personal information in the search field.
Google’s place names, addresses and provider attributions are displayed temporarily. Your private log stores the name you entered and, where supported, the selected place ID until that log or account is deleted. beanote does not retain Google’s names or addresses as a place database. Google handles requests under its own privacy policy and applicable retention terms.
You can turn off Google Maps search in Settings → Privacy. This stops future searches; it does not recall requests already processed by Google. Your consent choice, notice version and acceptance or withdrawal evidence are stored with your account under the consent-record retention rules in this policy.
Google Maps search is subject to the Google Maps/Google Earth Additional Terms of Service and Google Privacy Policy. Search results can be incomplete or out of date. Check the address before linking a place, or enter the name manually.