★ Fine Coffee Appreciation Society ★
Coffee Snobs is an app for finding hidden-gem cafes and rating them. This policy explains exactly what the app collects, what it doesn't, and why. It describes the app as it actually works — not a generic template.
The short version: there is no named account or sign-up, we never ask for your email or password, and we don't track you, advertise to you, or sell anything about you. The app automatically creates an anonymous identity so one person cannot cast unlimited ratings. Most of what you do in the app never leaves your phone at all.
Coffee Snobs ("we", "us") is operated by Latitude 34 Media Group, based in Australia.
Questions, requests, or complaints: privacy@coffeesnobs.cafe
The following is stored in the app's private storage on your device. We cannot see it, and the app's clear-local-data control removes it:
An anonymous user ID and refresh token are stored separately in the iOS Keychain so the app can maintain the same anonymous identity. They are available only while this device is unlocked and are not migrated to another device. Keychain items are managed by iOS and may remain after the app is uninstalled; see section 7 for deleting the associated server-side data.
If you tap the location button and grant permission, the app requests your location from iOS. You control whether iOS gives the app your Precise Location or a reduced-accuracy location in Settings. We request one location fix while you are using the app and never access your location in the background.
The coordinates supplied by iOS are sent over HTTPS to our shared Places service so it can look up cafes near you. The service passes the search location to Google Places (see section 5). Search results are cached against a coordinate rounded to two decimal places — a grid of roughly one kilometre — and are treated as stale after about 12 hours. The cache is not linked to your anonymous user ID.
The app keeps the current device location only in memory for the active app session. It does not write that exact location to app storage or backups, and removes location values saved by older versions. Your exact device fix therefore does not survive an app relaunch. A suburb or city that you type manually is retained so the app can restore that chosen search area.
You can decline the permission, or search by suburb or city name instead — the app works either way.
The first time you open the app, our authentication service automatically
creates an anonymous identity and issues a random user
identifier (for example,
f47ac10b-58cc-4372-a567-0e02b2c3d479). This happens without an
email address, password, name, or sign-up screen. The identifier is not
derived from your phone's hardware or advertising ID and does not tell us
who you are. Short-lived access credentials verify requests; the refresh
token and user ID are held in the iOS Keychain as described above.
We describe it as pseudonymous rather than anonymous, because it is stored alongside your ratings and is consistent over time. That is the correct term under the GDPR, and it is why you can ask us to delete everything filed under it (see section 7).
When you rate a cafe, the app sends a signed anonymous session to our Judge service. The service verifies it and stores: your pseudonymous user ID, which cafe, your score (1–5), and the time. We use the ID to make sure each anonymous identity counts once per cafe, so ratings cannot be stacked to inflate a score. If you re-rate a cafe, your earlier rating is replaced.
Ratings are combined into the public average shown as "Snobs say …". Individual ratings are never displayed to other users.
When you rate a cafe you found through discovery (one not yet in our catalogue), that rating also nominates it. We record the cafe's public details — its name, address, Google Place ID, Google rating and review count when available — plus the optional display name described below. The nomination record is information primarily about the cafe; the signed anonymous session authorises and rate-limits the request.
The app lets you set a display name on your Snob Card. It is optional, it defaults to empty, and it is stored on your device. When you nominate a cafe by rating it from discovery, that name is sent with the cafe's details and stored as the "suggested by" credit, so it is visible to us alongside the nomination.
Please don't put your real name, email address, or anything else identifying in that field unless you're comfortable with it leaving your phone. A nickname is very much in the spirit of the thing.
Like any app that connects to the internet, our hosting provider and the image service automatically receive your IP address and basic connection details as part of delivering the request. We do not use these to build a profile of you.
To be explicit, the app does not collect, and has no ability to collect:
The app contains no advertising, no analytics, and no crash-reporting or tracking SDKs. We do not sell, rent, or trade any data, ever.
Two third parties are necessarily involved in running the app:
Our backend hosting provider supplies the anonymous identity service, hosts our database, and runs our server functions in a data centre in Sydney, Australia. It processes anonymous identifiers, authentication credentials, ratings, nominations, search requests and related connection information on our behalf.
Google Places supplies cafe information — names, addresses, opening hours, and photographs. When our server searches for cafes near you, the location supplied for that search is sent to Google Places. Cafe photographs load in the app directly from Google's servers, which means Google receives your IP address when a photo is displayed. Google's handling of this data is governed by the Google Privacy Policy.
We may also disclose information if required by Australian law.
The anonymous identity, its user ID, ratings and cafe nomination records are kept for as long as the app operates, because they enforce fair voting and form the community scores and rankings that make the app work. The app keeps its refresh token in the device Keychain until it is replaced or removed by iOS. Search results and opening-hours cache entries are treated as stale after about 12 hours; operational records may remain until refreshed or deleted.
The app's exact device-location fix lasts only for the current app session and is not restored after the app relaunches. Infrastructure providers may retain limited request and security logs under their own operational retention practices.
Australian users may complain to the Office of the Australian Information Commissioner if unsatisfied with our response. If you are in the UK or European Economic Area, you also have rights of access, correction, erasure, restriction, and objection under the GDPR; our lawful basis for the limited data we process is our legitimate interest in operating a fair, community-rated cafe guide.
Coffee Snobs is not directed at children and we do not knowingly collect information from anyone under 13. We do not ask for age or direct contact details, so we generally cannot tell a user's age; if you believe a child's data has been submitted, contact us and we will remove it.
All communication between the app and our servers uses encrypted HTTPS connections. Rating and nomination writes require a signed anonymous session and pass through a rate-limited server function; the app cannot write directly to those tables. Database row-level security prevents the app from reading other users' individual ratings, and our internal tables are not reachable from the app. Secret API keys for third-party services are held on our server and are never included in the app.
No system is perfectly secure, but the safest data is the data never collected — which is why we collect so little.
If we change what the app collects, we'll update this policy and the "last updated" date above. Material changes will be highlighted in the app.
“Coffee Snobs judges cafes, not people.”