LEGAL

Privacy policy

Last updated: September 28, 2026

This policy explains what data the Caffculator mobile app and the caffculator.com website ("Caffculator") collect, why and how we use it, and what rights you have. In short: we use your data only to make the app work. We don't sell it, we don't use it for ads, and we don't track you across other apps.

1. Who is responsible

Caffculator is developed and operated by Öncü Hazar Gürgün as an individual developer.
Address: İzmir, Türkiye
Contact: support@caffculator.com

2. What we collect

No sign-up needed. When you first open the app, an anonymous ID is created for you. We don't ask for your name, email or a password. So that you can get back to the same ID after deleting and reinstalling the app, a recovery key is stored on your device (Keychain on iOS, Block Store on Android); our server keeps only a one-way hash of that key.

Profile and plan details (you enter these during onboarding or in settings):

  • your weight, height, birth year (your age is calculated from it) and sex
  • whether you are pregnant or breastfeeding, whether your doctor restricted caffeine, and how sensitive you are to caffeine
  • your goals, roughly how many cups you drink a day, the drinks you have most and your coffee times
  • your sleep quality, bedtime and wake time, sleep threshold, daily limit and water goal preferences
  • your units and theme preference (your language preference stays on your device)
  • the version and date of your health-data consent and, if you withdraw it, the withdrawal date

Pregnancy, breastfeeding, a doctor's restriction and caffeine sensitivity may count as health data. We process them only to calculate your daily caffeine limit, based on the explicit consent you give in the app. You can skip these questions, change them later in settings or withdraw your consent. Users under 18 aren't asked these questions.

Your logs: the coffee, tea and other drinks you add (drink, amount, time, caffeine), water entries, your favorites, the custom drinks you create, the badges you earn and the last day you opened the app.

Notification settings: reminder times and quiet hours. If you allow notifications: your device's push token, device language, time zone, app version and an installation ID.

If you choose to protect your account:

  • Sign in with Apple: the user ID and email Apple shares with us (this may be Apple's private relay address). We don't store the name Apple may share.
  • Sign in with Google: your Google account ID and email address. The name and profile photo address Google sends are kept in the record of our sign-in service (Firebase Authentication); we don't use them.
  • Email sign-in: your email address. To avoid sending the same confirmation email twice, we keep a one-way hash of your address.

Account deletion survey: the optional reason you choose when deleting your account or data (and the short note you write if you choose "Other"). This answer is stored separately from your identity, together with only your platform, app version, how many days you had used the app and whether your account was protected.

Technical data: App Check tokens that confirm requests come from the real app, and IP address, timestamps and error details in server logs. To limit abuse, a one-way hash of your IP address and email address is kept in 1-hour counters.

We don't use any usage-analytics or crash-reporting SDK.

What we don't collect: location, contacts, photos, microphone, advertising identifier (IDFA) or your activity in other apps.

3. How we use it

  • To calculate your personal daily caffeine limit, the caffeine in your body and your water goal
  • To store your logs and show reports, badges and habit summaries
  • To send the reminders you ask for
  • To bring your data back when you reinstall the app or, if you protect your account, on another device
  • To send transactional emails such as sign-in links, account-linked confirmations and account-deletion confirmations
  • To protect the app from abuse and fix errors
  • To answer your support requests

We never use your data for advertising, profiling or sale.

4. Legal basis

  • Providing the app and its features (performance of a contract)
  • Your explicit consent for health data
  • Our legitimate interest in security and error fixing
  • Legal obligations

You can withdraw your consent at any time with Settings › Data & privacy › Withdraw health data consent. Your pregnancy/breastfeeding, doctor-restriction and sensitivity answers are then deleted and your limit follows the general rule. We keep a record of which consent version you gave, when, and when you withdrew it.

5. Where your data is stored and who we share it with

Your data is processed by these infrastructure providers on our behalf:

ProviderPurposeLocation
Google Firebase (Authentication, Cloud Firestore, Cloud Functions, App Check, Hosting)Account, logs, server operations, security, websiteFirestore: Europe (eur3), Functions: Belgium (europe-west1)
ResendSending transactional emailsIreland (eu-west-1)
AppleSign in with AppleApple servers
GoogleSign in with GoogleGoogle servers
Google (Gmail)Support correspondenceGoogle servers

Some providers may technically process data outside the European Union. For users in Türkiye this counts as a transfer abroad under the KVKK. Transfers abroad rely, under Article 9 of the KVKK, on your explicit consent and the appropriate safeguards set out in the law (standard contracts and the providers' security commitments).

We don't share your data with anyone other than these providers, except with authorities when required by law.

6. How long we keep it

  • Your account and logs are kept until you delete them.
  • When you delete your account, your profile, logs, custom drinks, badges, recovery data and email-sending records are permanently deleted from our servers. If an email is linked to your account, we send you a confirmation email as a record of the deletion.
  • Server logs are kept for up to 30 days.
  • Abuse counters are deleted automatically after 1 hour.
  • Deletion survey answers are kept separately from your identity for 24 months, then deleted automatically.
  • If an account you haven't protected (anonymous) isn't opened at all for 24 months, the account and all its data are deleted automatically.
  • We don't keep a separate backup of your data; deleted data can't be restored.

7. Your rights

You have the right to:

  • See your data and get a copy: download all your logs as CSV with Settings › Data & privacy › Export my data.
  • Correct it: edit your profile and logs in the app.
  • Delete it: if you protected your account, use Settings › Account › Delete account; if you use the app anonymously, use Settings › Data & privacy › Delete my account and data. To delete only your logs and keep your account, use Delete all my data. You can also request account deletion at caffculator.com/delete-account.
  • Withdraw your consent (Settings › Data & privacy › Withdraw health data consent), object to processing and ask us to restrict it
  • Any other rights under the KVKK (Article 11) and the GDPR

Send requests to support@caffculator.com. We reply within 30 days. You can also complain to the Turkish Personal Data Protection Authority or, in the EU, to the data protection authority in your country.

8. Security

Data is encrypted in transit (HTTPS/TLS) and stored encrypted on the server. Each user can access only their own data. Server operations accept only requests from the real app, verified with App Check.

9. Children

Caffculator is not intended for anyone under 13. Users under 18 get a lower daily limit and aren't asked about pregnancy, a doctor's restriction or caffeine sensitivity; we don't collect this health data from anyone under 18.

10. Not medical advice

Caffculator provides general estimates. It is not a substitute for medical advice, diagnosis or treatment.

11. Changes

If we update this policy, we change the date on this page. We announce significant changes in the app or by email.

12. Contact

For any questions: support@caffculator.com

← Back to home