Espresso of Interest
HomeHistory
Log
ShelfSettings

Privacy Policy

Last updated: 17 March 2026

1. Who We Are

Espresso of Interest is operated by LogoLess Labs. This policy explains how we collect, use, and protect your personal data in compliance with the Australian Privacy Act 1988, the EU General Data Protection Regulation (GDPR), and the UK GDPR.

2. What We Collect

DataPurposeLegal Basis
Name, email, passwordAccount creation & authenticationContract
Shot logs (dose, yield, time, grind, rating)Core app functionality & AI analysisContract
Bean & equipment selectionsTracking your setup and preferencesContract
Cafe visits (name, location, rating, notes)Logging out-of-home coffee experiencesContract
Tasting notes & flavour tagsFlavour profiling and recommendationsContract
Consent timestampsRecording when you agreed to terms / marketingLegal obligation

We do not collect your location, contacts, browsing history, or any data beyond what you explicitly enter into the app.

3. How We Use Your Data

For your account (Contract basis)

Your individual data powers your personal dashboard — shot history, bean shelf, AI recommendations, cafe visit log. This data is only visible to you when you are logged in.

For aggregated community insights (Legitimate interest)

We combine data from all users into anonymised aggregates that appear on our public content website. For example:

  • Average rating for a bean across all users who logged it
  • Most common drink type for a bean (e.g. "65% flat white")
  • Average extraction parameters (dose, yield, time) for a bean
  • Popular beans at a cafe based on user visit reports
  • Flavour profiles aggregated across multiple users' tasting notes

Privacy safeguards for aggregated data:

  • Aggregates are only published when at least 5 data points exist
  • No individual usernames, shots, or timestamps are ever shown
  • No individual ratings or reviews are published — only averages
  • Data is combined in a way that prevents identification of any individual

For marketing (Consent basis — opt-in only)

If you opt in, we may send you emails about new features, newly added roasters and beans, brewing tips, and early access to beta features. You can withdraw your consent at any time from your account settings or by clicking unsubscribe in any email. We will never sell your email to third parties.

4. AI Processing

When you request a shot analysis, we send your shot parameters (dose, yield, time, grind setting, rating, flavour notes) and the associated bean's recommended recipe to a third-party AI provider (currently via OpenRouter). We do not send your name, email, or any personally identifiable information to AI providers. AI responses are stored in our database for your reference.

5. Data Sharing

We share your data with:

  • AI providers — Shot parameters only (no personal info), for analysis features
  • Our hosting provider (Railway) — Infrastructure only, they process data on our behalf under a data processing agreement
  • The public — Only anonymised aggregates as described in Section 3, never individual data

We do not sell personal data to any third party. We do not share individual user data with roasters, cafes, or any commercial partner.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days. Anonymised aggregate data that has already been computed may persist as it cannot be linked back to you.

7. Your Rights

Under GDPR and the Australian Privacy Act, you have the right to:

  • Access — Request a copy of all data we hold about you
  • Rectification — Correct inaccurate data
  • Erasure — Request deletion of your account and data
  • Portability — Receive your data in a structured, machine-readable format
  • Object — Object to processing based on legitimate interest (aggregation)
  • Withdraw consent — Withdraw marketing consent at any time

To exercise any of these rights, email [email protected]

8. Security

Passwords are hashed with bcrypt (12 rounds). All data is transmitted over HTTPS. Database access is restricted to our application services. We do not store payment information (the Service is currently free).

9. Cookies

We use a single session cookie for authentication. We do not use analytics cookies, tracking cookies, or any third-party advertising cookies.

10. Children

The Service is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes

We may update this policy from time to time. Material changes will be communicated via email or in-app notice. The "Last updated" date at the top indicates the most recent revision.

12. Contact

For privacy questions or data requests: [email protected]

Terms of Service|Create Account