BeanboxOne app to brew them allΕΛ

Privacy policy

Last updated 8 October 2026

Beanbox is a small, non-commercial app for keeping a coffee shelf with friends. This page says what it stores, why, where, and who else sees it. In short: only what the app needs, no ads, no analytics, nothing sold.

What Beanbox stores

Your account: email address, and — if you sign in with Google — your name and profile picture. Passwords are handled by our login provider and never seen by the app.

Your profile: handle, display name, language, theme and time zone. Your first handle is made from the part of your email address before the @, plus four random characters, and your first display name is the name your sign-in gives (or, when it gives none, that same part of your email); you can change both any time in Settings, and the handle shows in the invite links you share.

Which parts of a coffee's page you chose to see (Settings → Coffee page), kept with your account so all your devices show the same; only you see this choice.

Visualizer routing rules you choose: tags, notes markers, metadata values or upload formats mapped to your machines. Uncertain imports stay private in a machine-review queue without deducting coffee, until you assign them or identify an existing copy. Rules stay with the connection's machine record; review information stays with the brew until resolved or deleted. Both are included in your data export and removed with your account. Edit revision counters prevent an older form overwriting newer changes. Unsaved editor drafts stay in memory, not in a new browser-storage cache.

Your coffee: beans and bags (grams, roast and freezer dates, notes, your rating of each bag), brews and shots (with a refractometer's TDS reading when you type one), shot curves and machine profiles, ratings and tasting notes, recipes (with each version of their numbers, why it changed, and which recipe and version each brew followed), machines and friends.

The coffees you ask to hear about when they're back (Buy again → “Tell me when it's back”): the coffee's name and roaster, its shop page, what the daily check last found there and when, and when you were told.

If you switch on notifications on a device: that browser's push address (at Google, Apple, Mozilla or Microsoft, depending on the browser), the keys that encrypt the messages, a label such as “Android · Chrome”, and which kinds of notification you want (which bag a new shot went on is on until you switch it off; the weekly digest is off until you switch it on, and if you do, when the last one went, so it comes at most once a week, on Sunday morning on your clock).

Connections you set up: the address of a machine connector (e.g. the Decenza app), your Visualizer.coffee or Fellow login if you connect them, and API keys for your own AI provider. All are encrypted (AES-256-GCM) and only the server can read them. Beanbox API keys are stored only as a hash.

An app you connect with your Beanbox API key can read your Decents' ids and names with read permission and, with brew permission and your confirmation, register a Decent in your Equipment if none exists. This uses the normal machine records, included in your data export and removed with your account; no connection secrets are returned and no physical machine operation is started. Such an app (Decaid's Beanbox plugin, on your Decent's tablet) can also read your bags' details with read permission (the coffee, roast, grams and freezer days; never the price, your rating or your own notes) to keep them on the tablet, and with brew permission note on each bag which Decaid batch it is (its id, kept with the bag), so each shot goes on its bag.

If you link your xBloom account (a beta, open to some accounts): the member id and sign-in token xBloom gives at sign-in, encrypted the same way, the usual grind size you gave, when it was linked and last worked, and what xBloom last refused. Never your xBloom password: it is used once, to sign in.

The machine profiles Beanbox judges for your coffee come from public sources (Decent's apps, Meticulous's own sets, metprofiles.link) and show their author's public name as the source publishes it, with a link to the profile and, from metprofiles.link, its rating, to credit them; an author who'd rather not be named can write to the address below, and their name is taken out.

What it doesn't store

Photos of bags you scan are sent to the AI you chose and are not kept by Beanbox. Only the roaster's product photo address is saved. That photo is shown from where it was found (usually the roaster's website), so your browser loads it from there, as with any picture on a web page; the same goes for photos of gear and machines, and of your friends' bags.

No advertising, no tracking pixels, no analytics.

Who else sees your data

Your name, handle and profile picture are seen by the friends you accept and by people you've sent a friend request to or received one from. You can remove the picture in Settings → Profile, and it isn't taken from your sign-in again. Someone who has your handle or invite link can find you to send a request; nobody can list who uses Beanbox.

Friends you accept see the beans you mark as visible, with your rating and note on each bag, and your recipes, apart from those on a bag you keep private or have archived. A recipe share link can be opened by anyone who has it, and shows your name and, when its bag is one your friends see, the coffee. “New link” on the bag's page makes copies of the old link stop working. Your recipes' versions are yours alone, and a friend who sees your shots sees the recipe a shot followed only when it is one of your recipes they already see.

The friends you've accepted see your shots and brews, unless you switch off “Share my shots with friends” (Settings → Sharing with friends; on by default). They see them in Beanbox and through an AI app they connect to it: the curves and machine profile, the numbers, your rating, taste and notes, and the coffee. Backflush / cleaning runs and brews of bags you keep private or have archived stay hidden, and nobody else sees them, not even someone with a pending friend request. Friends can't change or delete them. Switch it off and they stop seeing them, except in a page their device kept for offline use.

Friends who see your shots can save a shot's settings as their own recipe (“Make it yourself”): its dose, yield, time, temperature and profile, its grind as a note, and your handle and the shot's day as where it came from. It is a copy in their account: it doesn't change your shot or link back to it, and it stays theirs, with your handle in it, if you later stop sharing or delete your account. Your notes, rating and taste aren't copied.

A friend who connects Beanbox to their own AI app (Claude, ChatGPT, Gemini) lets that app read what you share with them, the way they see it in Beanbox: your bags, ratings, recipes and shots, your name and handle.

Your AI, only when you use it. If you connect your own AI key, bag photos and bean details go to that provider (Anthropic, OpenAI, Google, OpenRouter, or your local model) under your account with them. If you connect Beanbox to Claude, ChatGPT, Gemini or GitHub Copilot, that app can read and change your Beanbox data through the tools you approve, and handles it under its own privacy policy. Its access token expires every day and you can disconnect it any time under Settings → Beanbox API keys.

Service providers that run Beanbox: Supabase (database and sign-in, Frankfurt, EU) and Vercel (hosting, functions in Frankfurt, EU). Google provides sign-in if you use it. Supabase and Vercel keep technical logs for a short time (IP address, browser, the pages and addresses requested, and when), to run the service and keep it secure (GDPR Art. 6(1)(f)). Supabase, Vercel and Google are US companies: your data is stored in the EU, and any access from the US is covered by the EU–US Data Privacy Framework or standard contractual clauses. Fellow's cloud, if you connect a Fellow Aiden, and xBloom's servers, if you link an xBloom account, are in the US.

If you connect Visualizer.coffee or a Fellow Aiden, Beanbox's server signs in there with your login to read your brews. When you send a recipe to your Aiden (or automatic recipes you turned on send it), Fellow receives it as a brew profile named after the coffee, with its ratio, temperatures, bloom and pulses; nothing else is uploaded to them. Machines you connect yourself (a Meticulous bridge, Home Assistant) send your shots to Beanbox with a Beanbox key you create and can revoke.

If you link your xBloom account (a beta), Beanbox's server signs in to xBloom (TBDx Inc., servers in the US) once, with the email and password you type, and doesn't keep the password. Then, each time you put a recipe in your xBloom app (or automatic recipes you turned on do), it sends xBloom your member id and the sign-in token with the recipe, named after the bag, with its dose, ratio, grind size and pours; nothing else is uploaded. This uses the xBloom app's own connection, which is unofficial: xBloom's terms don't allow third-party software, and xBloom could suspend the account or block this access.

Roasters you add to the roaster list (name, country, city, website) are visible to everyone on Beanbox; your name is not shown with them.

To find a bean's product page and photo, or list a roaster's coffees, Beanbox's server visits the roaster's website and may search the web by the bean's name. Nothing about you is sent. For a coffee you watch, the server reads that shop's public page once a day in the same way, and sends nothing about you either.

Notifications go through your browser's push service (Google for Chrome and Android, Apple for Safari and iPhone, Mozilla for Firefox, Microsoft for Edge on Windows). Each message is end-to-end encrypted for your device, so the push service carries it without being able to read it. Switching notifications off on a device deletes its push address.

Nobody else. Your data is never sold or shared for marketing.

Cookies

Only what the app needs: your login session; your language, theme and time zone, so pages show in your language and on your clock; and whether you closed the first-steps card. This browser's own storage also keeps two small notes: the dropper you picked in the water builder, and that your time zone was saved.

In any browser you use Beanbox in (installed on a phone or not), the pages you opened last (shelf, brews, bags, equipment) are kept on that device so they open without signal. Signing out or deleting your account removes them and stops that device's notifications.

Keeping and deleting

Your data stays while your account exists. You can delete beans, brews, recipes, machines and API keys yourself at any time. When you delete a shot that came from a machine connection, Beanbox keeps only its id at that service, the machine, time and length, so the next sync doesn't bring it back.

When you connect Claude, ChatGPT, Gemini or GitHub Copilot, Beanbox keeps that connection's tokens: an access key that works for a day and a renewal token that works for 90 days. A daily cleanup deletes them once the connection can no longer be renewed. Used renewal tokens are kept until they expire, to recognise a stolen copy and end the connection.

When you send a recipe to your Meticulous (or automatic recipes you turned on send it), Beanbox keeps the profile it made until your bridge saves it on the machine, and deletes it 30 days later (or after 30 days if no bridge picks it up). The profile goes only to your own bridge and machine.

If you turn on automatic recipes, Beanbox keeps what you turned on, and for 30 days a list of the recipes it made or is making for you: which bag and machine, and whether it reached the machine. The recipes themselves are yours, like any other, and go only to your own machines.

A coffee you watch stays watched until you stop it (the bell on Buy again) or delete your account. Deleting its bag keeps the watch, under “Also watching”.

A profile Beanbox put on your Fellow Aiden stays there, in your Fellow account, until you remove it in the Fellow app: deleting the recipe or your Beanbox account doesn't take it off the brewer.

Unlinking your xBloom account (Equipment → the xBloom → xBloom account) deletes what Beanbox kept of it at once; so does removing the xBloom from Equipment, or deleting your account. The recipes Beanbox put in your xBloom account stay there unless you tick “Also remove Beanbox's recipes from my xBloom” as you unlink, or delete them in the xBloom app.

Settings → Your data: download a copy of everything (a JSON file), or delete your whole account yourself. Deleting removes everything tied to the account at once; backups roll over within 30 days. Backups are encrypted copies of the database (AES-256), and of the photos when the operator backs those up too, kept on the operator's own server and in the operator's Google Drive; Google can't read them. That server may tell Beanbox how each night went (started, done, or which step failed), so the operator hears about a failed backup; nothing from the database goes with it. You can also ask the operator (below).

Your rights

Beanbox uses your data only to run the app you signed up for (GDPR Art. 6(1)(b)); connections and AI are used only when you turn them on. Under the GDPR you can ask to see, correct, export or delete your data, and object to how it's used. You can also complain to your data protection authority (in Greece, the Hellenic DPA, dpa.gr).

Children

Beanbox is not meant for anyone under 16.

Contact

Beanbox is run privately by its owner for friends. Write to: beanbox.privacy@gmail.com