Skip to content
Coffee Journal

Privacy & GDPR

What Coffee Journal keeps about you, what it never collects, and how to take your data with you or delete it.

Last updated

Summary

We only store what you type in. No analytics, no ads, no tracking, no IP addresses or device details.

  • No analytics, ads or third-party trackers
  • No IP addresses or device details stored
  • Only sign-in cookies, and no tracking cookies
  • Download or delete your data any time

What we store

Only what you give us, so the app can work for you:

Your account

  • Your display name and email address.
  • Your password, stored only as a one-way hash. Nobody can read it back, not even an admin.
  • Your time zone, so times and journal dates match your clock. It's taken from your device when you sign up, and you can change or clear it on the Account page.
  • Your brewing countdown: how many seconds play mode counts down before the first step (3, 5, 10, 15 or 30; 5 until you pick one). You can change it on the Account page.
  • Your role (member or admin), when the account was created and last changed, and, if an admin ever suspends it, the reason they gave and when the suspension ends.
  • If you set up a public profile: your username, the bio you write, whether the profile is public, and the recipe you picked as your favorite.

Your content

  • Your recipes and their version history, and for a copy, which recipe it was copied from.
  • Your recipe lists: each one's name, description, which recipes are in it and in what order, its link's code, and whether anyone with the link can open it.
  • Your bags of beans in My Beans.
  • Your journal entries, and if you share a brew or your whole journal, the code in each share link and when you turned it on.
  • Your gear in My equipment: grinders, brewers, filters, a kettle, a scale and the like, with any notes you add.
  • Any brewers, grinders or roasters you add to the catalog.

Sign-in sessions

A random token, which account it belongs to, and when it was created, last renewed and expires. No IP address or device details.

Passkeys

If you add one: the name you give it, when you added it, and what checking it needs. Nothing about your device. See Passkeys.

Password reset links

Only while one is waiting to be used: its random code, which account it's for, and when it was made and expires. See Forgotten passwords.

What we don't collect

  • No analytics: nothing records which pages you visit or what you click.
  • No advertising, and no third-party trackers, pixels or embeds.
  • No fingerprinting and no location.
  • No IP addresses and no device or browser details, not even the ones a passkey sends along.

Everything the site loads, fonts included, comes from this site itself, so no other company sees your visit. We don't sell your data or share it with anyone, apart from the email service that delivers a password reset email when you ask for one.

Cookies and browser storage

Visitors who aren't signed in get no cookies, apart from a short-lived one for signing in with a passkey. Signing in sets one, only to keep you signed in, and admins get one more for the admin sidebar. Everything else stays in your browser, apart from the list of recently shown recipes that Find recipes sends along.

  • Sign-in cookieCookie

    Keeps you signed in. It holds a random session token and nothing else. It's strictly necessary, which is why there's no consent banner.

  • Passkey checkCookie, for 5 minutes

    Set when you sign in with a passkey or add one, and when the sign-in page opens in a browser that can suggest passkeys. It holds a random code that pairs your passkey's answer with the challenge we sent, and expires after 5 minutes. It's strictly necessary, like the sign-in cookie.

  • Admin sidebarCookie, admins only

    Remembers whether the admin area's sidebar is open or closed.

  • ThemeYour browser only

    Light, dark or system. Kept in this browser and never sent to us.

  • Play-mode soundYour browser only

    Whether the brew-along timer plays sounds. Kept in this browser and never sent to us.

  • Time zone noticeYour browser only

    The time zone you dismissed the “Set your time zone” notice for (your device’s, such as Europe/Berlin), so it stays hidden until that changes. Kept in this browser and never sent to us.

  • Journal viewYour browser only

    Whether My Journal last showed the list, the simple list, the week or the month, so it opens that way next time. Kept in this browser and never sent to us.

  • Recently shown recipesYour browser, sent with Find recipes requests

    Which recipes Find recipes showed in this browser lately (up to 120, as recipe codes), so your next visit starts with ones you haven't just seen. Your browser sends the list each time it loads recipes there; we use it only to put those recipes last and never store it.

  • Find recipes shuffleThis browser tab only

    The shuffle this tab is on, how far down you'd scrolled and the recently shown list it started with, so going Back to Find recipes shows the same recipes in the same place. Cleared when you close the tab. The shuffle's random code is also in the page's address; nothing else is sent to us.

Who can see your data

  • You see everything you've saved.
  • Everyone, signed in or not, can find the recipes you make public in Find recipes, open them and save a copy, with your display name as their author.
  • People you share a recipe link with see that recipe, its shared versions and your display name as its author. Never your bags, your journal, your equipment or your private recipes.
  • People you share a recipe list with see its name and description, your display name, and the recipes in it that they could open anyway. Your private recipes stay with you, even in a shared list. A new list opens to anyone with its link, like a new recipe; pick “Only me” to keep it to yourself. Lists aren't listed anywhere, not even on your profile, and search engines are asked not to list them.
  • Everyone can see your profile page, but only if you make it public. It's off until you do: see Your public profile.
  • People you share a brew or journal link with see that brew, or every brew in your journal. Your journal is private until you turn a link on: see Sharing your journal.
  • Admins see your account and what you share, but never your private content: see What admins see.

Brewers, grinders and roasters you add are only offered to you until an admin checks them. After that, anyone can pick them, without your name.

What admins see

Admins look after the site: they suspend accounts, moderate what people share, and keep the catalog of brewers, grinders and roasters tidy. For that, they see:

  • your display name, and your email address with most of it hidden, such as “d•••••.com”: only its first letter and last four characters show, and none of a short address;
  • when your account was created, your role, and whether it's suspended, why and until when;
  • how many recipes, bags of beans and journal entries you have: the numbers, not what's in them;
  • what you share: your public and link-shared recipes and their shared versions, which they can hide, correct or delete if they break the rules, plus anything you've shared a link to, as anyone with that link would.

They never see your full email address, your passkeys, or anything you keep private: your private recipes, versions of a recipe you haven't shared, your journal, your bags, your equipment, your private recipe lists, or your profile while it isn't public. An admin who already knows your email address can type all of it to find your account, and even then sees it with most of it hidden.

Your public profile

A profile page at /user/your-username is optional and off until you turn it on in your profile settings. It needs a username, which you pick; your display name stays the name on your recipes either way. While it's off, only you can open it (everyone else, admins included, gets “Profile not found”), and your username isn't shown to anyone else.

When it's on, anyone can open it, signed in or not, and sees:

  • your display name, username and bio;
  • numbers from your journal: how many brews (all time and in the last 30 days), your brewing streaks, average days off roast, how much coffee you've used, your busiest day, how many recipes you've brewed, your top brew methods, and the month of your first brew;
  • the public recipes you brew most (yours or other people's), and your favorite: the one you pick, which can be one of your link-shared recipes, or else the public recipe you brew most. A link-shared recipe is only ever shown if you pick it;
  • your public recipes;
  • the brands and models in My equipment (not your notes on them).

It never shows your email, your bags or their notes, or your private recipes, and it shows your journal only if you share it: then it links to your shared journal (see Sharing your journal). While it's on, your name on your recipes and in Find recipes links to it. Search engines are asked not to list it. Turn it off, or change your username, and the old link stops working straight away.

Sharing your journal

Your journal is private. You can share one brew, or your whole journal, with a short link of its own: “Share this brew…” in a brew's menu, and “Share journal” at the top of My journal. Each link is off until you turn it on.

While a link is on, anyone who has it, signed in or not, sees:

  • when you brewed, on their own clock;
  • the recipe as you brewed it: its name, method, brewer, grinder and grind, dose, water and times;
  • the beans: coffee, roaster, origin, process, roast level, roast date and days off roast (never your notes on the bag);
  • your notes and what you want to change next time;
  • your display name, linked to your profile if it's public.

A journal link shows every brew in your journal, newest first, including ones you log later. A recipe is linked only if it's public or one of your own shared recipes. A private recipe, or someone else's link-shared one (its author only gave you the link), is named but not linked.

Shared links aren't listed anywhere, and search engines are asked not to list them. The only place that links one is your public profile, which links your shared journal while both are on. A shared journal never gives out a brew's own link, so turning the journal's link off ends what it showed. Turn a link off and it stops working straight away; turn it on again and you get a new link, so the old one never comes back.

Forgotten passwords

If you forget your password, “Forgot password?” on the sign-in page emails you a link to choose a new one. When you ask:

  • your email address, and the email with its link, go to the email service that delivers this site's emails. Which service that is depends on who runs the site, and it handles the email as it does any other it delivers. Apart from the site's hosting (see Where it's stored), this is the only thing the app ever sends to another service, and only when you ask;
  • we save the link's random code, which account it's for, and when it was made and expires. Nothing else about the request is saved: no IP address and no device details.

The link works once and stops working after 1 hour. Using it signs your account out everywhere, ends any other reset links you asked for, and removes your passkeys, in case someone else added one (you can add yours again once you've signed in). Its code is deleted as soon as it's used, or once it has expired, the next time anyone signs in or asks for a link.

For an address that has no account, nothing is saved or sent. The page says the same thing either way, so nobody can use it to find out whether someone has an account here.

Passkeys

A passkey lets you sign in with your fingerprint, face, screen lock or a security key instead of your password. It's optional: add one, and rename or remove it, on your Account page.

  • The passkey itself (its private key) never leaves your device or password manager. That's also where it keeps your email address, as its account name, so it can show you which account it's for. Whether it syncs to your other devices is up to your device or password manager, not us.
  • We keep the name you give it, when you added it, and what checking it needs: its ID, its public key, and a counter it moves on each time you use it.
  • We don't keep which device, password manager or security key it's on, whether it syncs or is backed up, or how it connects. Your browser sends some of that along; we blank it before anything is saved.
  • Each time you add a passkey or sign in with one, and each time the sign-in page opens in a browser that can suggest passkeys (whether or not you use one), we keep a one-time challenge for 5 minutes at most: a random code and, while you're adding one, which account it's for and its email address. One from the sign-in page names no account. It's deleted as soon as it's used, or once it has expired, the next time anyone signs in. Meanwhile a cookie holds its key (see Cookies and browser storage).

Signing in with a passkey starts a session like any other, with no IP address or device details. Removing a passkey stops it working straight away, but your device or password manager may keep offering it until you delete it there too. Resetting your password removes all of them (see Forgotten passwords).

How long we keep it

Until you delete it, or delete your account. A sign-in session stops working when you sign out, or after about a week without a visit, and expired ones are deleted the next time anyone signs in. A password reset link works for 1 hour at most, and is deleted once it's used or has expired (see Forgotten passwords). A passkey stays until you remove it or reset your password, and a passkey challenge lasts 5 minutes at most (see Passkeys).

When you delete your account, it goes straight away, along with:

  • your password, passkeys, sign-in sessions, any password reset link or passkey challenge still waiting, time zone, brewing countdown and public profile, so your username is free again;
  • your recipes and all their versions, so their share links stop working, and they leave other people's recipe lists;
  • your recipe lists, so their links stop working;
  • your bags, journal entries and equipment, so links to brews or your journal stop working too;
  • brewers, grinders and roasters you added that nobody else uses and an admin hasn't checked yet. Any others stay in the catalog, without your name.

Copies other people made of your recipes are theirs to keep, and if someone logged a brew of a recipe you shared, their private journal keeps the recipe details they brewed, without your name.

Brute-force protection

To stop people guessing passwords, the server counts recent requests to its sign-in service (signing in, signing up, changing a password, asking for or using a password reset link, signing in with or adding a passkey, and the like) from each IP address, and briefly blocks one that sends too many. That count lives only in the server's memory. It's only used for a few seconds (a minute at most), and is cleared the next time anyone uses the sign-in service, or when the server restarts.

Deleting an account is protected too: wrong passwords are counted for that account, in memory, for 15 minutes. So are password reset emails, so nobody can flood your inbox: after 3 in 15 minutes, no more go out until those 15 minutes are up. None of these counts is ever written to the database or to logs.

Your rights under GDPR

We use your data only to run Coffee Journal for you. Under the GDPR you can:

  • See it and take it with you (access and portability): Download my data on the Account page gives you your account details, your sign-in sessions, your passkeys' names and when you added them, and everything you've added, in one JSON file.
  • Correct it (rectification): change your display name, time zone, brewing countdown, public profile and passkeys' names on the Account page, and edit your recipes, recipe lists, bags, journal entries and equipment any time. To change your email, get in touch.
  • Delete it (erasure): Delete my account removes it for good.
  • Object to or restrict how it's used: get in touch.

You can also complain to your local data protection authority.

Where it's stored

In this site's own database. The site runs on a hosting provider's servers, and its database may be run by a separate database provider. They store and process your data on the site owner's behalf (as “processors”, in GDPR's words). For this site, that's Vercel (USA), Neon database (Portland, USA (West) pdx1).

Apart from them, the app doesn't send your data to any other service, except a password reset email when you ask for one (see Forgotten passwords). The hosting provider may keep standard server logs, which usually record when each request came in and from which IP address, outside the app.

Contact

For any question or request about your data, email privacy@myjournal.coffee.